4 MIN READ
Picture the API that the engineering lead shipped last quarter. The code is clean, the tests pass, the OpenAPI spec is published, the rate limiter is on, the production credentials are stored in HashiCorp Vault where the security org said they should be. Then the API gets breached, and the postmortem points to a Postman collection the staff engineer exported to a Slack channel six months ago, with the production API key sitting in plain text inside the JSON. The collection got shared, the export got committed, the secret scanner found it too late, and the engineering lead learned the lesson every engineering lead eventually learns: the API was not the weakest link. The way the platform org tested the API was. The pattern has a name now, the Postman problem, named for the API client that became the API team’s favourite way to test production, and the favourite way to leak the production credentials to the outside world.
Lineage worth knowing. The Postman problem repeats across every mid sized engineering org that has shipped an API in the last five years. Postman published a workspace to a public link by accident. An Insomnia export landed in a public GitHub repository because the .gitignore missed the .insomnia folder. A Bruno collection got committed alongside the source code by a contractor who treated the API client like part of the codebase. The leak surface is the workflow itself, not the tool, and the workflow is the thing the AppSec team does not see because the workflow lives on the engineer’s laptop.
How the problem got the name
The shape is consistent across the engineering orgs that have hit it. The API engineer opens Postman, builds a collection for the production endpoint, pastes the API key into the collection header, and saves. The collection syncs to the Postman cloud, the environment file holds the variable, the variable holds the credential, and the credential persists across the engineer’s sessions for as long as the engineer works on the API. The same engineer creates a dev environment and a staging environment, and the production environment gets shared with a colleague over Slack because the colleague is debugging an integration the engineer built last week. The export is the leak. The collection file contains the credential, the environment file contains the credential, and the credential is now wherever the export went, which is everywhere.
What actually leaks
Three credential types, in roughly the order of how much each one hurts when it lands in the wrong hands. The production API key sits as the first, and the production API key is the credential that grants the read access, the write access, the data the production system holds. Stripe, Twilio, SendGrid, the credential works against the live billing or messaging system, and the cost of a leaked Stripe key runs from the moment the key hits the dark web to the moment Stripe rotates the key, with the cost in between being whatever an attacker can charge to the connected card. The OAuth refresh token counts as the second, and the OAuth refresh token is the credential that grants the long lived user scope. A leaked refresh token becomes a year of unauthorised access, and the year of access becomes the breach disclosure the CISO office files in the next quarterly report. The customer scoped credential rounds out the list, and the customer scoped credential amounts to the most damaging variant. The credential impersonates the customer, the credential reads the customer data, the credential writes to the customer account, and the breach lands as a per customer notification rather than a single disclosure.
How to fix it without breaking the workflow
Three moves, and the moves together close the leak without turning the API engineer into a security engineer. Use the secret manager integration. Postman integrates with HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault through a small pre request script, and the integration pulls the credential at request time, evaluates it in the environment variable, and never persists it in the collection. The API engineer keeps the workflow, the AppSec team gets the credential out of the export, and the integration costs a sprint to ship.
Use the ephemeral credential. The platform org issues a credential that lives for 24 hours, scopes to the test environment, and rotates on demand. The credential cannot leak what the credential does not have, because the credential expires before the leak becomes useful, and the platform org that ships the ephemeral credential becomes the org that turns the production system into a system the exported collection cannot touch.
Audit the export. The secret scanner runs on every commit, on every shared Slack channel that holds a JSON file, and on every public Postman workspace URL the AppSec team knows to check. The scanner catches the export the API engineer would have shipped, and the AppSec team that runs the scanner on a daily cadence stands as the team that catches the leak before the leak becomes the breach disclosure.

The bottom line
Secret manager integration, ephemeral credential, export audit. The API engineer who keeps using the collection with the credential in it sits one export away from the breach disclosure, and the AppSec team that ships the three moves runs as the team that closes the leak without breaking the workflow.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



