<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — Postman</title>
  <link>https://appsec.fyi/tools.html#postman</link>
  <description>Curated Postman resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/tool/postman.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sun, 06 Sep 2026 16:03:59 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>How Postman Embeds Wiz Risk Data Into Dev Workflows</title>
    <link>https://www.bankinfosecurity.com/how-postman-embeds-wiz-risk-data-into-dev-workflows-a-32484</link>
    <guid isPermaLink="true">https://www.bankinfosecurity.com/how-postman-embeds-wiz-risk-data-into-dev-workflows-a-32484</guid>
    <description>Library integration embeds Wiz risk data into Postman&#x27;s API Catalog, surfacing known exploitable vulnerabilities, secrets, and misconfigurations within developers&#x27; existing workflows. This approach provides one-click remediation commands directly in the interface, improving security KPIs by enabling developers to address risks quickly and efficiently, representing genuine &quot;shift-left&quot; security.</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Wed, 12 Aug 2026 20:46:46 +0000</pubDate>
  </item>
  <item>
    <title>How Postman Embeds Wiz Risk Data Into Dev Workflows</title>
    <link>https://www.govinfosecurity.com/how-postman-embeds-wiz-risk-data-into-dev-workflows-a-32484</link>
    <guid isPermaLink="true">https://www.govinfosecurity.com/how-postman-embeds-wiz-risk-data-into-dev-workflows-a-32484</guid>
    <description>Library for embedding Wiz risk data into developer workflows, specifically Postman&#x27;s API Catalog. This integration surfaces known exploitable vulnerabilities, secrets, and misconfigurations within developer environments, offering one-click remediation commands. The approach enhances security KPIs by allowing developers to quickly address risks directly within their existing tools, representing a genuine shift-left security practice.</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Wed, 12 Aug 2026 20:21:18 +0000</pubDate>
  </item>
  <item>
    <title>Shawkat Emad: 5 SSRFs in Postman. Different services. Different techniques. Different impacts. One of them was marked Informative because the internal team found it just 1 day before mebut I&#x27;ll happily take that as proof I was on the right track. #BugBounty #SSRF #CyberSecurity #HackerOne</title>
    <link>https://x.com/shawkat7h/status/2074488768443134357</link>
    <guid isPermaLink="true">https://x.com/shawkat7h/status/2074488768443134357</guid>
    <description>Shawkat Emad discovered five Server-Side Request Forgery (SSRF) vulnerabilities in Postman, each utilizing different techniques and impacting various services. While one finding was marked &quot;Informative&quot; as the internal team had discovered it a day prior, Emad views this as validation of their investigative approach. The researcher participated in a bug bounty program for this work.</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Sat, 18 Jul 2026 12:48:09 +0000</pubDate>
  </item>
  <item>
    <title>GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing Api&#x27;s (lightweight alternative to postman/insomnia)</title>
    <link>https://github.com/usebruno/bruno</link>
    <guid isPermaLink="true">https://github.com/usebruno/bruno</guid>
    <description>Library for API exploration and testing, Bruno offers a privacy-focused, offline-first alternative to Postman and Insomnia. It stores API collections in local filesystem folders using the Bru markup language, facilitating collaboration via Git or other version control systems. Bruno is available for Mac, Windows, and Linux, with installation options including binary downloads and package managers like Homebrew, Chocolatey, Scoop, Snap, Flatpak, and Apt.</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Mon, 10 Feb 2025 02:27:55 +0000</pubDate>
  </item>
  <item>
    <title>Server SSL certificate verification - HTTPie 3.2.4 (latest) docs</title>
    <link>https://httpie.io/docs/cli/server-ssl-certificate-verification</link>
    <guid isPermaLink="true">https://httpie.io/docs/cli/server-ssl-certificate-verification</guid>
    <description>Library for interacting with HTTP services from the command line, designed for human-friendly testing and debugging. It supports intuitive syntax, formatted output, JSON, forms, uploads, HTTPS, proxies, authentication, custom headers, persistent sessions, downloads, and a plugin system. Installation instructions are provided for various package managers and operating systems, including standalone executables. The documentation details usage for custom methods, headers, JSON data, form submissions, offline requests, authentication, file uploads/downloads, sessions, and URL parameters.</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 13 Dec 2024 03:50:14 +0000</pubDate>
  </item>
  <item>
    <title>Favorite tweet by @fardeenahmed411</title>
    <link>https://twitter.com/fardeenahmed411/status/1534391460262465538</link>
    <guid isPermaLink="true">https://twitter.com/fardeenahmed411/status/1534391460262465538</guid>
    <description>Favorite tweet:

API Bug-Bounty Tools Check list (Part - 1) - Postman (It is like Burpsuite for API) - APISec - AppKnox - Synopsis API Scanner - Data Theorem API Secure #cybersecuritytips #bugbountyti...</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Thu, 09 Jun 2022 00:32:35 +0000</pubDate>
  </item>
  <item>
    <title>API Testing with HTTPie</title>
    <link>https://medium.com/m/global-identity?redirectUrl=https%3A%2F%2Flevelup.gitconnected.com%2Fapi-testing-with-httpie-2d2d0dbe71ab</link>
    <guid isPermaLink="true">https://medium.com/m/global-identity?redirectUrl=https%3A%2F%2Flevelup.gitconnected.com%2Fapi-testing-with-httpie-2d2d0dbe71ab</guid>
    <description>API Testing with HTTPie</description>
    <category domain="tool">Postman</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Wed, 25 Aug 2021 14:25:00 +0000</pubDate>
  </item>
</channel>
</rss>