Passport
ACCESS MANAGEMENTAccess management for humans and agents, controlling who and what can reach your APIs across the stack.
LEARN MORE →From the CEO
Computing is undergoing a dramatic shift. Software is no longer primarily created, consumed, and coordinated by humans. Increasingly, software discovers, orchestrates and interacts with other software, while humans provide direction and judgment. This new type of software artifact is an AI agent.
Agents are proliferating across every organization and they are reshaping how software gets built and used, how industries function, and how work gets measured.
Agents get their abilities through APIs. Agents can gather data, take actions, retain memory, or interact with humans or other machines or agents through APIs. As they get more capable, agents are changing our relationship with computing.
Agents hold enormous power and it’s only going to grow. That power carries risk:
If you do not control your agents, your agents control your company.
Organizations are facing multiple demands at once. They need to determine:
The fundamental question every enterprise is facing is no longer “How do I deploy agents?”. The challenge lies in being truly prepared for this new era and that involves answering:
Who is using these agents? When are agents hallucinating? Who are they aligned with?
If you do not know this, you are not in control of decisions.
Have I made my APIs discoverable and accessible for agents? Have I given them the right access?
If you do not know this, you are not in control of actions.
What happens when something goes wrong? Who holds accountability? Are they working for my organization or on behalf of an outside entity?
If you do not know this, you are not in control of risk.
How much am I spending and am I seeing the outcomes?
If you do not know this, you are not in control of your budget.
How do I scale my agentic enterprise? What will break if and when we start to scale?
If you do not know this, you are not in control of operations.
For more than a decade, Postman has helped more than 500,000 organizations discover, govern, and connect APIs. As agents become the primary consumers of APIs, that same foundation naturally evolves into the control plane for the agent economy.
We believe enterprise computing now requires a new infrastructure layer for the agent economy.
We have been building on several fronts, and together they form Postman’s Agent Stack:
Agents have made API-first a mandate. Earlier this year we rebuilt Postman as an AI-native API platform. We shipped the API Catalog, a system of record for APIs and services, and the AI Engineer, an autonomous engineer that runs on the Context Graph sitting on top of the Catalog.
Postman’s new AI-native platform is the foundational system for these new products. The platform is the supplier of APIs and API context for Fern, Fabric, Passport, and Astro AI.
We built the original Postman for our own needs, and we built the Agent Stack the same way — through our own transformation into an agent-native company. Fabric is where we run our AI workloads. Astro AI is where we run our agents. Passport is how we give agents and humans the right access to our APIs. Fern is how we publish our documentation.
The Agent Stack is how we are accelerating in the age of AI, while staying in control.
We are launching Postman.ai as the central place to communicate our vision and views on AI, our research, and industry benchmarking.
I am excited about the future where humans are the winners in this new era of computing.
Abhinav Asthana
Postman CEO & Co-founder
We are building the infrastructure for agents and APIs. Each product serves a specific layer for our customers to achieve AI sovereignty.
Access management for humans and agents, controlling who and what can reach your APIs across the stack.
LEARN MORE →The AI-native gateway with support for AI, MCP, and APIs, governing policy, identity, and scope at the edge of every enterprise environment.
LEARN MORE →The agent operating system that runs and controls AI agents in production, with runtime, observability, and guardrails at scale.
LEARN MORE →Agent and developer experience covering docs, SDKs, and CLIs, so every API is discoverable, typed, and callable out of the box.
LEARN MORE →The foundation platform every product above is integrated with. Powered by the Context Graph, AI Engineer, and the API Catalog.
LEARN MORE →We publish what we learn building agent infrastructure: benchmarks, evaluations, and field data on how AI agents behave against real APIs.
A vendor-neutral benchmark measuring whether AI agents can reliably execute multi-step API workflows in enterprise contexts, run across 19 models by the Postman AI team.
| Axis | What it tests |
|---|---|
| authentication | refresh / scope a token mid-session |
| discovery | pick the right endpoint among look-alikes |
| schema | repair a body the API rejects |
| multistep | carry state across a chain of calls |
| error_recovery | back off and retry correctly |
| pagination | walk to the last page |
| statefulness | confirm a side-effect actually landed |
Product milestones, partnerships, and research from the teams building the Postman AI stack.
How AI agents evaluate and choose APIs differently than developers, and what it takes to make an API ready for them.
READ →Inside the security measures behind the AI Engineer, including sandboxing and credential isolation.
READ →Fern rebuilt its documentation storage from one monolithic JSON blob into content-addressed pieces, cutting load and publish times on the biggest sites.
READ →Agent performance is not primarily a function of the model. It rests on three coupled systems: data reliability, API consistency, and execution governance.
READ →One install puts your workspaces inside Claude Code: mock servers, spec syncing, test runs, and AI-readiness checks, all in natural language.
READ →Why capable agents need a layered architecture — knowledge, intelligence, and strategic context — rather than a collection of independent agents.
READ →