Postman MCP Server

Official MCP server for Postman workspaces, collections, OpenAPI specifications, environments, and API testing workflows.

Description

Postman MCP Server is Postman’s official MCP server for API development and API collaboration with AI agents. It connects Claude Code, Cursor, VS Code Copilot, GitHub Copilot CLI, Gemini CLI, Codex, and other MCP-capable tools to Postman workspaces, collections, OpenAPI specifications, and environments. The direct product link points to Postman’s product page at https://www.postman.com/product/mcp-server/, while the repository https://github.com/postmanlabs/postman-mcp-server contains source code, the license, and the concrete README. For Skill Road, this entry matters because API teams often already use Postman as their shared working space, and agents should not infer every API detail from scattered files, comments, or old training data.

Remote, local, and separated by tool scope

Postman documents a remote server at https://mcp.postman.com using OAuth for compatible hosts. It also provides different modes: Minimal for basic Postman operations, Code for generating organized client code from API definitions, Full for a broad set of Postman API tools, and Learn for searching Postman documentation. EU endpoints and local setups use a Postman API key according to the README. Locally, the server starts with npx @postman/postman-mcp-server; flags such as --code or --full expand the tool scope. This separation matters because not every agent should immediately receive more than 100 tools.

API context for coding agents

The strongest use case appears when an agent does not work on API changes in the editor alone. It can understand existing collections, look up specifications, interpret sample requests, account for environments, and prepare client code from an API definition. In teams with shared workspaces, this can reduce context switching: instead of manually reconciling a route in code, an OpenAPI file, and a Postman collection, the agent can access the reviewed API workspace. The server is especially useful for API refactoring, integration work, documentation maintenance, and testing interface behavior.

Authentication, data, and security boundaries

The server can expose Postman workspaces and API information to an MCP client. Which data becomes visible depends on OAuth consent, API key, workspace permissions, and selected mode. Minimal is safer than Full for a first setup. API keys belong in environment variables or secure client inputs, not in prompts, commits, or public configuration. In shared workspaces, teams should decide in advance which collections, environments, secrets, internal APIs, and mock data may be reachable by agents. An agent can make suggestions, but changes to API contracts and production-adjacent environments still require review.

License, GitHub stars, and fit

The repository is Apache-2.0 licensed. The GitHub API reported exactly 311 stars on 2026-09-07; that snapshot is not evidence of quality, security, or enterprise readiness. The server itself is open source, but practical use depends on the Postman workspace, provider plans, API key, OAuth consent, and AI client. This public entry therefore does not state fixed prices. Coding and Automation are the right categories because the server connects development agents to API artifacts and supports repeatable API tasks. A separate API Testing category would only make sense once several qualified API testing and QA entries exist together.

Requirements

MCP client, Postman account or workspace access, and depending on setup OAuth or a Postman API key.

Installation instructions

Connect remote https://mcp.postman.com/minimal with OAuth or run local npx @postman/postman-mcp-server with POSTMAN_API_KEY.

npx @postman/postman-mcp-server

Authentication

OAuth for the standard remote server; API key for EU remote and local server.

Required access permissions

Permissions follow workspace access, API key/OAuth consent, and the selected Minimal, Code, Full, or Learn mode.

Transmitted or stored data

Tool calls access Postman workspaces, collections, specifications, environments, or documentation and return results to the client.

Security risks

Full mode, broad workspace rights, or API keys in unsafe configuration can expose internal APIs and secrets.

License and costs

License
Apache-2.0
Cost
free

The server is Apache-2.0 licensed. Costs depend on the Postman account, workspace, provider plans, and AI client.

Alternatives

Not recorded yet.

At a glance

Provider
Postman
Status
Official server
Deployment
Local and remote
Current version
Not recorded yet.
GitHub stars
317
Last reviewed
07.09.2026

Repository and documentation

Categories

Supported clients