Startup Diligence
Diligence report Infrastructure / DevTools Private / Series D (last disclosed primary round) 2026-07-20

Postman

Category-leading API platform with strong distribution and clear product expansion, but public financial disclosure is still too thin and contradictory for conviction underwriting.

Postman has clear category leadership in API collaboration and workflow context, but public evidence is still too contradictory on revenue and too thin on governance and capital structure to underwrite the company confidently at or near its 2021 peak valuation.

Cover facts

Founded 01
2014 [CO001]
Headquarters 02
San Francisco, California [CO002]
Organizations 04
500 K+ [CO009]
Last disclosed primary valuation 05
5600 USD M [CO011, CO014]
Total raised 06
433 USD M [CO013]
Headcount signal 07
3523 employees [CO019]

Company profile

Postman is a private API platform company founded in 2014 and now headquartered in San Francisco. The company started as a developer tool to simplify API testing and has expanded into a broad lifecycle platform spanning API design, documentation, testing, monitoring, repository management, workflow orchestration, and AI-assisted API work. Public sources show very broad adoption—more than 40 million users and 500,000 organizations—plus meaningful enterprise penetration, but they also show a still-opaque financial and governance profile. Since its 2021 $225 million Series D at a $5.6 billion valuation, Postman has added AI-native product layers and acquired Orbit, liblab, and Fern to broaden community, SDK, and documentation workflows.

Website
www.postman.com
Founded
2014-01-01
Founders
Abhinav Asthana, Ankit Sobti, Abhijit Kane
Founding location
Bangalore, India
Headquarters
San Francisco, California
Product
Postman sells a unified platform for building and using APIs: API design, testing, documentation, mocking, monitoring, repository/discovery, workflow automation through Flows, and newer AI-native features such as Agent Mode and AI Engineer.
Customers
Developers, QA teams, API platform owners, partner and developer-relations teams, and larger enterprises that need shared API workflows, governance, and discoverability.
Business model
Freemium SaaS with seat-based Solo, Team, and Enterprise plans, plus AI credit overages and land-and-expand monetization around collaboration, governance, private API networks, and organization-wide workflow standardization.
Stage
Private / no confirmed primary round since 2021 Series D
Funding status
Last confirmed primary round was a $225 million Series D in August 2021 at a $5.6 billion valuation; public databases place total funding around $433 million, while 2024-2026 secondary pricing indicates a lower current implied mark but no new priced primary event.
[CO001, CO002, CO003, CO004, CO006, CO007, CO011, CO013]

Executive summary

Top strengths

  • Postman appears to have the broadest publicly visible distribution in its category, with 40M+ users and 500K+ organizations.
  • The product has expanded from a request client into a broad API lifecycle platform with repository, workflows, and AI-native tooling.
  • The company still benefits from a strong financing history and recognizable investor base anchored by the 2021 Series D.
  • Customer proof spans major API-centric enterprises and both internal and external developer use cases.
  • Category tailwinds remain favorable as APIs become more revenue-critical and more central to AI-agent workflows.

Top risks

  • Public revenue and ARR estimates conflict materially, leaving current monetization quality unresolved.
  • Governance, cap-table, board, liquidation-preference, and cash-runway disclosures remain too thin for underwriting.
  • Low-end API-client functionality is increasingly commoditized by open-source and local-first alternatives.
  • The company has visible security and trust burdens, including 2024 workspace-exposure criticism and a 2026 Klue-related data incident.
  • Secondary-market discounting suggests the 2021 valuation has already reset downward even without a new primary price.

Open gaps

  • Audited or management-certified revenue, ARR, gross margin, burn, and runway data.
  • Current cap table, investor rights, preference stack, and board composition.
  • Customer retention, expansion, concentration, and contract-duration metrics by segment.
  • Adoption and monetization detail for AI features such as Agent Mode and AI Engineer.
  • Any confirmed 2025-2027 primary financing, tender, IPO, or strategic-exit process.

Contents

Chapter 01

01Company Overview

1.1 Identity, Product, and Scale

Postman remains best understood as a unified API platform rather than a single testing tool. Its official about and product pages describe a platform for building and using APIs across design, testing, distribution, documentation, monitoring, and governance, while the pricing page makes clear that Postman monetizes across free, individual, team, and enterprise tiers. The company says it now serves more than 40 million users and 500,000 organizations, including 98% of the Fortune 500, which frames the platform as a broad systems-of-record layer for API work rather than a point utility. Craft and LinkedIn corroborate the company's private status, San Francisco headquarters, and global footprint, though the most current scale metrics are still predominantly company-provided rather than independently audited. LinkedIn's July 2026 page gives the strongest current headcount signal, at 3,523 employees, which is directionally consistent with Postman's growth-stage office expansion and the 2025 headquarters announcement.[CO001, CO002, CO006, CO007, CO008, CO009]

Snapshot KPI Table
MetricValue / StatusDate / PeriodConfidenceGap / Caveat
Founded2014Founding yearHighNo public legal filing packet reviewed
HeadquartersSan Francisco, CaliforniaCurrentHighBangalore founding history still matters operationally
Users / developers40M+2025-2026MediumCompany-claimed metric, not audited
Organizations500,000+2025-2026HighCorroborated by official and independent profiles
Fortune 500 penetration98%2025-2026MediumCompany-claimed share
Employees3,5232026-07-16MediumLinkedIn self-reported count
Last primary valuation$5.6B2021-08-18HighNo newer priced primary round found
Total raised~$433M2026 database viewMediumRounded from third-party databases
Public ARR estimate$120-150M2024 ET secondary contextLowUnverified external estimate
Public revenue estimate$313.1M2024 GetLatka estimateLowEstimate conflicts with lower ARR reports

Scale and financial rows mix official disclosures with external estimates. Users, organizations, and Fortune 500 share are company-claimed; employee count is from LinkedIn; ARR and revenue estimates are not audited and should be treated cautiously.

[CO001, CO002, CO008, CO009, CO010, CO013]
FO002: Company Snapshot Logic

Founders, capital, product breadth, AI features, and scale metrics reinforce one another in Postman's category position.

[CO003, CO006, CO008, CO011, CO013, CO027]
FO003: Snapshot KPIs

Publicly visible headline metrics show wide adoption but uneven financial disclosure quality.

Users and organizations are company-claimed. Funding is rounded from public databases. Revenue-related disclosure is intentionally summarized as mixed because third-party estimates disagree.

[CO008, CO009, CO011, CO013, CO014, CO018]

1.2 Leadership, Governance, and Dependence

The public record still ties Postman closely to its founding team. The about page says Abhinav Asthana started the project and later recruited Ankit Sobti and Abhijit Kane, and that the three founders still lead the company. Craft adds only a few named executives, including chief revenue officer Zac Auger, but public board composition, preferred-share rights, and succession planning remain opaque. That opacity matters because Postman's current product repositioning toward AI-native workflows and its acquisition integration program appear tightly bound to founder vision. The company has grown large enough that this concentration does not imply fragility in day-to-day execution, yet the absence of disclosed board seats, voting structure, or cap-table mechanics still leaves investors with a meaningful governance diligence hole. In practice, the public view is enough to confirm founder continuity and enterprise go-to-market depth, but not enough to underwrite control rights or transition planning.[CO003, CO004, CO005, CO037, CO040]

Leadership and Founder Table
PersonCurrent public roleEvidenceStrategic relevanceKey-person / diligence note
Abhinav AsthanaCo-founder & CEOPostman about page; Craft profileProduct vision, AI pivot, external face of companyCritical; founder continuity is central to strategy
Ankit SobtiCo-founderPostman about page; Craft profileTechnical and product continuity from earliest daysHigh; exact current operating remit is not fully public
Abhijit KaneCo-founderPostman about page; Craft profileEarly product and developer-experience continuityHigh; current span of control not fully public
Zac AugerChief Revenue OfficerCraft profileSignals scaled enterprise monetization effortMedium; public CRO duties are not deeply documented

Roles beyond CEO and co-founder status are limited in public sources. The main diligence gap is not founder identity but undisclosed board structure and succession planning.

[CO003, CO004, CO005, CO040]

1.3 Funding, Valuation, and Disclosure Quality

Postman's capital history is well established through its own 2021 announcement and TechCrunch coverage. The company raised a $225 million Series D led by Insight Partners at a $5.6 billion valuation, and third-party databases such as GetLatka and Craft converge on roughly $433 million of cumulative capital raised. What is less settled is current monetization. The Economic Times reported that recent secondaries cleared at a 30-40% discount to the 2021 mark and cited people aware of the company's financials who pegged ARR at $120-150 million. GetLatka, by contrast, estimated 2024 revenue at $313.1 million after estimating 2023 revenue at $171.7 million. These are not trivially different numbers: one suggests slower monetization against an outsized last-round mark, while the other suggests far more scale. Without audited revenue, burn, margin, or retention disclosures, the right posture is to treat both as useful but low-confidence signals and to avoid over-fitting either estimate into the core company snapshot.[CO011, CO012, CO013, CO014, CO015, CO016]

Stakeholder or Investor Map
StakeholderPublic roleEvidence of importanceEconomic / control implicationOpen diligence ask
Insight PartnersSeries D leadLed $225M round at $5.6B valuationLikely strongest formal governance influence among named investorsConfirm board seat, super-pro-rata rights, and information rights
Nexus Venture PartnersLegacy investorParticipated in Series D and named in secondary contextLong-tenured investor with continued exposureConfirm current ownership and whether secondary sales changed control
CRVLegacy investorParticipated in Series DEarly-stage sponsorship that may still matter for signalingConfirm continuing stake and governance rights
CoatueGrowth investorJoined Series D; named in official round announcementLarge economic signal but not obviously controllingConfirm whether rights differ from prior investors
Battery VenturesGrowth investorJoined Series D; mentioned in secondary contextAdds late-stage software-market validationConfirm any follow-on or secondary accumulation
BONDGrowth investorJoined Series DGrowth-stage signaling investorConfirm whether BOND retained or sold shares in secondaries

The investor roster is clearer than the cap table. Control rights and current ownership percentages remain private.

[CO011, CO012, CO013, CO015, CO040]

1.4 Strategic Trajectory and Category Positioning

The company's recent strategy is to turn API collaboration into an AI-native systems layer. Postman's 2025 State of the API report argues that API strategy is becoming AI strategy, and the report's own survey data describes APIs as revenue-generating assets that increasingly need collaboration and machine-readable structure. Postman then translated that narrative into product: TechCrunch covered the January 2025 launch of AI Agent Builder, and Postman's own materials introduced Agent Mode and AI Engineer as assistants that can act across collections, specs, environments, and workflow assets. The acquisitions of Orbit, liblab, and Fern fit the same arc. Orbit broadened community and developer-engagement capabilities, liblab added SDK generation, and Fern added documentation plus SDK automation. Together, these moves indicate that Postman is trying to own more of the surface area between API producers, API consumers, and AI agents that will invoke those APIs.[CO022, CO023, CO024, CO025, CO026, CO027]

1.5 Adverse Events and Reliability Signals

The most meaningful recent negative signal is no longer hypothetical. Postman's own trust portal states that a third-party Klue compromise led to exfiltration of customer contact and sales information from Salesforce in June 2026, even though product or core customer data was not accessed from Gong. Separate external reporting from CloudSEK, Cyber Security News, and Treblle also preserved the 2024 public-workspace exposure episode, in which tens of thousands of publicly accessible workspaces surfaced tokens, keys, and other sensitive material. These reports do not mean Postman itself was uniquely insecure; a substantial share of the exposure appears to have come from user behavior and weak secrets hygiene. But they do show that public collaboration carries real governance risk, especially for a platform encouraging broad sharing. Counterbalancing that, Postman's status page showed core services operational at review time and desktop uptime at 100% over the trailing 90-day window. The risk posture is therefore mixed: strong operating continuity, but a growing security-governance burden as the platform scales and becomes more agentic.[CO032, CO033, CO034, CO035, CO036]

Milestone Table
DateEventTypeAmount / statusParticipantsImplication
2014Postman founded as a side project to simplify API testingfoundingAbhinav Asthana; later Ankit Sobti and Abhijit KaneCategory origin story and founder continuity
2021-08Series D announcedfinancing$225M at $5.6B valuationInsight, Coatue, Battery, BOND, CRV, NexusPeak primary mark and capital base
2024-04Orbit acquisition announcedpartnershipAcquisitionPostman + OrbitExpanded developer-community tooling
2024-08Economic Times reports steeply discounted secondary tradesadverse30-40% discount to peakExisting investors and secondary buyersPublic signal that paper valuation compressed
2025-01AI Agent Builder covered by TechCrunchproductLaunchPostmanAPI workflow extended into agent building
2025-07New San Francisco headquarters announcedscaleHQ expansionPostmanPhysical growth signal
2025-10State of the API press release cites 40M users and 500,000 organizationsscaleUser/org milestonePostmanConfirms broad platform adoption
2025-11liblab acquisition announcedproductAcquisitionPostman + liblabAdded SDK generation to lifecycle stack
2026-01Fern acquisition announcedproductAcquisitionPostman + FernAdded docs-as-code and SDK workflow
2026-06Klue-related Salesforce data exfiltration disclosedadverseCustomer contact and sales info affectedPostman + KlueSecurity-governance event requiring trust response

Milestones use public announcement timing, not necessarily deal close timing. The table emphasizes durable narrative inflection points rather than every product release.

[CO001, CO011, CO015, CO021, CO027, CO029]
FO001: Company Milestone Timeline

Public chronology from founding through the 2026 incident disclosure shows both product expansion and increasing governance complexity.

[CO001, CO011, CO015, CO021, CO027, CO029]

1.6 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary and What Postman Actually Sells Into

The easiest analytical mistake with Postman is to define its market too narrowly as API-client software. Postman's product pages put it in a much wider API lifecycle category that includes design, testing, documentation, distribution, monitoring, and governance. The API Repository and Flows pages reinforce that this is not just a single-user request runner: the company is selling shared asset management, discoverability, workflow execution, and cross-team visibility. That broader framing matters because the market is fragmented. Enterprise buyers can source design from Swagger or Stoplight, testing from ReadyAPI, gateways from Kong, and lightweight clients from Insomnia, Bruno, or Hoppscotch. Postman's served market is therefore best described as the collaborative and workflow-centric slice of the broader API management and API development economy. It wins when organizations need common context across teams and machines, not merely a way to fire HTTP requests.[CM001, CM002, CM017, CM018, CM019, CM023]

Market Definition Table
Segment / categoryIncluded spendExcluded spendBuyer / payerWhy it matters to Postman
API collaboration platformShared collections, documentation, mocks, monitoring, repository, workflowsPure gateway infrastructure or bespoke integration servicesEngineering managers, platform teams, API product ownersThis is Postman's core served market
API design / docsOpenAPI design, documentation portals, governance, mock serversGeneral IDE or wiki softwarePlatform architects, developer experience, productMajor adjacent budget line contested by Swagger and Stoplight
API testingFunctional, regression, load-adjacent API validationBroad observability or application QA suitesDevelopers, QA, platform teamsImportant wedge but not the whole market
Gateway / runtime API managementGateways, traffic control, hybrid/serverless runtime connectivityLifecycle collaboration assetsInfrastructure and platform operationsRelevant adjacent market but bought differently
Local / open-source clientsIndividual request execution, collection storage, git-native workflowsEnterprise governance and organization-wide asset managementIndividual developers, small teamsDefines the low-end substitute set

The market table distinguishes collaboration-centered spend from adjacent infrastructure or local-tool spend. Boundaries are approximate because vendors increasingly overlap each other.

[CM001, CM002, CM017, CM023, CM024, CM025]
FM002: Buyer / Segment Map

The category spans low-cost individual tooling and higher-value enterprise governance and workflow control.

[CM020, CM024, CM025, CM033, CM035, CM036]

2.2 Market Size, Growth, and Why Estimates Vary

Public market-size estimates all point the same direction but disagree on magnitude. The Business Research Company, Strategic Market Research, Fortune Business Insights, and Mordor Intelligence all show double-digit or better expansion into the next decade, yet their 2025 market numbers span from roughly $5.24 billion to $8.86 billion. That spread is too large to ignore. It likely reflects different scoping choices around API management software, API gateways, lifecycle tooling, and enterprise services. For diligence purposes, the important conclusion is not the single-number TAM but the consistency of growth direction: each source points to a market still scaling with digital transformation, cloud-native architecture, and AI-driven integration demand. Postman should therefore be treated as operating inside a large and expanding category, but one whose exact edge is blurry enough that precision TAM math would overstate certainty. A range-based view is more honest than a single stacked pyramid with false accuracy.[CM003, CM004, CM005, CM006, CM007]

TAM / sizing lens table
PublisherForecast / base yearGeographyMarket valueGrowth rateMethod caveat
The Business Research Company2025 to 2030Global$5.24B to $20.89B31.8% CAGRLikely centered on API management software with a narrow base year
Strategic Market Research2024 to 2030Global$5.6B to $15.1B18.2% CAGRMethodology summary only; category boundary not deeply disclosed
Fortune Business Insights2025 to 2034Global$6.89B to $37.43B21.7% CAGRBroader long-range forecast with wide horizon
Mordor Intelligence2025 to 2031Global$8.86B to $22.11B16.45% CAGRAppears to include broader enterprise API-management categories

These are market-sizing lenses, not a single precise TAM. The variance is large enough that diligence should use a range rather than a point estimate.

[CM003, CM004, CM005, CM006, CM007]
FM001: Market Estimate Range

Third-party API-management market estimates point to strong growth but a wide spread in base-year scope.

[CM003, CM004, CM005, CM006, CM007]

2.3 Buyers, Users, and Demand Drivers

Postman's own survey data provides the strongest public signal on demand drivers. Testing, development, and documentation consume substantial time for API teams, while 93% of teams say collaboration is still difficult, making coordination a legitimate pain point rather than marketing copy. The same report argues APIs are moving from cost-center plumbing toward revenue assets: 65% of organizations now generate revenue from APIs, and most of those derive a meaningful share of company revenue from them. That shifts the buyer from only frontline developers toward platform leaders, architecture teams, product owners, security, and governance stakeholders who care about discoverability, reuse, and policy control. Postman's Free, Solo, Team, and Enterprise packaging also points to a buyer ladder: individuals can begin cheaply, but the real monetization opportunity is organizational standardization. AI reinforces the case, because when agents call APIs, the value of well-documented, governed, discoverable interfaces rises materially.[CM008, CM009, CM010, CM011, CM013, CM018]

Segment / buyer map
SegmentPrimary userPrimary payerWorkflow needAdoption triggerImplication for Postman
Individual developersApplication or backend developerSelf or managerSend requests, inspect responses, debug APIsFast onboarding and free utilityHigh top-of-funnel reach but low willingness to pay
Team-level API programsDevelopers + tech leadsEngineering managementShared collections, tests, docs, mock environmentsNeed for collaboration and standardizationCore Team-plan monetization zone
Platform / architecture groupsPlatform engineers, architectsVP engineering / platform budgetRepository, governance, discoverability, versioningAPI sprawl and compliance pressureBest fit for enterprise up-sell
Security / governance teamsSecurity engineers, governance leadsSecurity or platform budgetPolicy, secrets handling, agent risk managementAI-agent usage and compliance concernsImportant emerging buyer influence
Developer ecosystem / product teamsDeveloper relations, API product managersProduct or GTMPublic workspaces, onboarding, docs, SDK distributionNeed to grow external API consumptionSupports network effects and ecosystem reach

Buyer and payer roles differ materially by segment. Individual usage is broad, but the highest-value budgets appear when organizations need shared context and governance.

[CM009, CM010, CM018, CM019, CM020, CM036]
FM003: Adoption Funnel or Value-Chain Map

Value compounds as organizations move from single-user experimentation into revenue-linked, governed API programs.

[CM010, CM011, CM012, CM015, CM017, CM018]
FM004: Market Sizing Lens

The market expands from local request tooling into collaboration, governance, and AI-facing workflow infrastructure.

[CM010, CM011, CM012, CM014, CM017, CM018]

2.4 Constraints, Commoditization, and the Investable Slice

The key market constraint is that not every API workflow dollar belongs to Postman. Open-source and local-first tools such as Insomnia, Bruno, and Hoppscotch make it easy for individuals or small teams to avoid SaaS spend altogether, while Stoplight and Swagger keep design budgets contested and Kong keeps infrastructure budgets separated from collaboration spend. Public reviews add a second friction layer: some users view Postman as increasingly enterprise-priced, and others report that large collections or mature workspaces can feel slow or overwhelming. Finally, AI raises governance risk at the same moment it raises market opportunity. Postman's own reports show heightened concern around unauthorized agent access and security teams treating AI-agent readiness as a real operating issue. The investable market, then, is not the whole mass of API-related activity; it is the subset where collaboration, governance, and workflow automation are valuable enough to justify standardization on a paid platform. That higher-value layer is where enterprise budgets, policy needs, and AI workflow complexity finally overwhelm free-tool substitutes in practice today.[CM014, CM015, CM016, CM024, CM025, CM026]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationDiligence ask
APIs as direct revenue driversPositiveCurrentSupports strategic budgets for lifecycle platformsQuantify what share of Postman's customers monetize APIs
AI agents need machine-readable APIsPositiveCurrent to near-termRaises value of governed docs, specs, and workflow automationValidate whether AI upsell expands ARPU or just usage
Collaboration pain across distributed teamsPositiveCurrentSupports repository, workflows, comments, and governance layersMeasure real seat expansion from collaboration features
Open-source / local-first substitutesNegativeCurrentCompresses low-end willingness to paySegment win rates by individual vs enterprise deals
Enterprise pricing friction / performance complaintsNegativeCurrentCan cap expansion if product complexity grows faster than valueReview churn and NRR by plan tier
Security and agent-governance riskMixedCurrent to near-termCan drive governance spend but also slow adoption or raise proof requirementsRequest security roadmap and incident-response learnings

The key constraint is not lack of market activity; it is how much of that activity requires a paid collaboration platform versus a free local client or separate gateway stack.

[CM010, CM012, CM013, CM014, CM015, CM022]

2.5 Exhibits

Chapter 03

03Competitors

3.1 Competitive Frame: One Platform Versus a Fragmented Stack

Postman is easiest to misread if every rival is forced into a direct apples-to-apples comparison. Some vendors attack only the design slice, some the testing slice, some the runtime gateway layer, and some the free client layer. Postman’s own product pages, however, are clearly trying to collapse these adjacent jobs into a unified lifecycle surface: repository, workflows, documentation, testing, monitoring, and now agentic tooling. That means the company rarely competes only against “another API client.” Instead, it competes against fragmented stacks and against the option to keep different categories separate. The analytical question is not whether any single competitor duplicates every feature. It is whether a buyer can get enough of what they need from point tools, infrastructure platforms, or free substitutes to avoid standardizing on Postman. This matters because a fragmented buying pattern can make Postman look popular at the user layer while still ceding strategic budget to adjacent vendors.[CP001, CP002, CP016, CP025, CP026, CP027]

Competitor Profile Table
CompetitorCategoryBusiness / pricing modelPrimary wedgeLimitation versus Postman
SwaggerHubDesign / docs suiteSubscription softwareSpecification-first design, docs, governanceWeaker as a general workflow and collaboration hub
InsomniaAPI client + collaborationFree/open-source plus paid plansLocal-first and no-login workflow flexibilityLess evidence of broad lifecycle context and enterprise-scale repository depth
StoplightDesign / docs / mockingTeam subscriptionsDesign governance and instant mock serversNarrower workflow than Postman’s full lifecycle pitch
BrunoGit-native API clientFree open sourceVersion-control-native local workflowMinimal enterprise governance or organizational context
ReadyAPIEnterprise API testingCommercial testing suiteMulti-protocol automated testing depthPoint-tool bias versus unified platform story
KongGateway / connectivity platformInfrastructure-style gateway pricingRuntime API connectivity and control planeNot a collaboration-first workspace
GitLabDevSecOps suiteTiered platform subscriptionsBundled engineering platform and AI agentsAPI workflow is adjacent, not core

Rows compare public positioning, not private win rates. The table focuses on how a buyer could avoid adopting Postman end to end.

[CP002, CP003, CP004, CP006, CP007, CP009]
FP001: Competitive Positioning Map

Postman sits high on workflow breadth and enterprise governance relative to point tools, while Kong and GitLab compete from broader platform positions.

[CP003, CP004, CP006, CP007, CP010, CP011]

3.2 Direct and Adjacent Rivals

SwaggerHub and Stoplight are the clearest design-first rivals. Their public positioning emphasizes API design, documentation, governance, and mock-server workflows more than Postman’s broader collaboration context. ReadyAPI is more focused on enterprise testing depth across many protocols. Kong sits further away in runtime API connectivity, but it still competes for strategic API-program budgets because gateway and control-plane decisions often shape how teams evaluate the rest of their tooling. GitLab is a different type of threat again: not an API-only company, but a platform-suite vendor that can bundle AI agents and collaboration into larger DevSecOps contracts. Taken together, these rivals show that Postman’s competition is not a tidy single category. It is a spectrum from design suites through runtime infrastructure and horizontally bundled software platforms. Any serious diligence memo should therefore test whether Postman wins because it is better, or because buyers simply prefer fewer tools.[CP003, CP004, CP006, CP009, CP010, CP011]

Feature / Capability Matrix
Buying criterionPostmanSwaggerHubInsomniaStoplightBrunoReadyAPIKong / GitLab
Shared API repositoryYesPartialLimitedLimitedNoLimitedPartial
Design + documentation workflowYesYesPartialYesLimitedLimitedPartial
Local-first / no-account pathPartialNoYesNoYesNoNo
Enterprise governance / policy surfaceYesYesPartialYesLimitedPartialYes
AI-assisted workflow surfaceYesEmergingLimitedLimitedLimitedLimitedYes
Runtime gateway / platform connectivityLimitedNoNoNoNoNoYes

Capability judgments reflect public product positioning rather than lab-tested parity. “Partial” indicates meaningful but not clearly category-leading coverage.

[CP003, CP004, CP005, CP006, CP007, CP009]
Pricing / Packaging Comparison
PlatformEntry pricing signalEconomic modelIncluded emphasisImplication
PostmanFree; Solo $9; Team $19; Enterprise $49Per user / plan tierBroad lifecycle collaborationAccessible self-serve ladder but enterprise upsell depends on seat expansion
StoplightBasic $44; Startup $113Subscription by team scaleDesign, docs, mock serversDesign-heavy budgets may tolerate premium pricing
InsomniaFree forever local Scratch PadFree/open-source plus paid tiersClient, local, Git, cloud workflowsPressure on low-end willingness to pay
BrunoFree and open sourceNo-account open sourceLocal git-native clientHard to defend pure client pricing against it
KongFree trial then charged per gatewayInfrastructure countGateway runtime and connectivityCompetes for platform budget, not request-client budget
GitLabFree / Premium / Ultimate + AI creditsSuite subscription + usageDevSecOps plus agent platformAPI features can be bundled into larger engineering standardization

Different pricing units matter as much as absolute price. Seat-based collaboration, infrastructure-based gateway billing, and open-source local tooling pull buyers into different evaluation frames.

[CP010, CP011, CP013, CP014, CP015, CP025]
FP002: Feature Breadth / Capability Map

Different rivals cluster around distinct buying centers rather than one perfectly overlapping feature set.

[CP003, CP004, CP006, CP007, CP009, CP010]

3.3 Local-First and Open-Source Substitutes

The most obvious low-end risk comes from tools that deliberately reject the cloud-workspace or enterprise-control model. Insomnia’s free forever local-only Scratch Pad, Bruno’s git-native no-account client, and Hoppscotch’s open-source positioning all give individuals or small teams a credible path away from paying for Postman too early. This does not mean Postman loses the whole competitive race; many of these substitutes are narrow by design. But they matter because they compress willingness to pay for the client layer. Once that layer is commoditized, Postman has to prove that repository visibility, collaboration, governance, and AI context are worth the extra cost and complexity. Review data reinforces this tension: users still like Postman for testing and collaboration, yet some complain about paid-feature drift, debugging friction, or degraded usability at larger scale. In other words, substitutes do not need feature parity to matter; they only need to be good enough for narrower jobs.[CP004, CP005, CP007, CP008, CP020, CP021]

Moat Durability / Competitive Risk Register
Moat claimThreatSeverityWhy it mattersMitigation / diligence ask
40M+ user distributionLow-end tools commoditize request executionHighInstalled base may not monetize if buyers remain on free toolsRequest free-to-paid conversion and expansion data
Unified lifecycle contextBest-of-breed point tools peel away design, testing, or gateway spendHighFragmentation can cap seat consolidationRequest attach-rate by module and bundled deal evidence
AI-native workflow surfaceSuites like GitLab or infrastructure stacks add their own agent layersMediumAI differentiation may compress quicklyTrack adoption and ARPU uplift from AI features
Repository and workflow switching costUser complaints about complexity or performance weaken lock-inMediumMoats fail when users dislike the operational burdenReview churn drivers and large-workspace product telemetry
Enterprise credibilityGitLab and Kong can bundle APIs into broader contractsMediumBundle pressure can change procurement dynamicsRequest large-deal competitive analysis by segment

The risk register focuses on moat durability, not generic company risk. Public sources are suggestive but not sufficient to answer win-rate questions.

[CP021, CP022, CP024, CP028, CP029, CP030]
FP003: Moat / Readiness KPIs

Competitive durability depends on whether Postman monetizes its scale and workflow context faster than rivals monetize their niches.

[CP017, CP018, CP019, CP025, CP027, CP028]

3.4 Moat Durability and Competitive Risk

Postman’s moat is strongest when API work becomes shared, governed, and context-heavy. That is why the repository, flows, Agent Mode, and AI Engineer matter more strategically than the underlying request client. The company’s scale also matters: a platform claiming 40 million users and 500,000 organizations has distribution leverage most niche rivals cannot match publicly. Still, that advantage is not invulnerable. Fragmentation can erode value from below, while bundled platforms can erode it from above. Public sources do not reveal win rates, competitor-specific churn, or retention by segment, so the key unresolved diligence question is whether Postman’s broader platform actually consolidates budgets in practice. If it does, the moat is real. If teams continue buying best-of-breed point tools and free local clients around the edges, the moat may be shallower than the installed base suggests. That is why module attach rates and enterprise standardization behavior matter more than logo counts alone in enterprise procurement cycles worldwide today.[CP013, CP014, CP015, CP017, CP018, CP019]

3.5 Exhibits

Chapter 04

04Financials

4.1 Revenue Model and Pricing Architecture

Postman monetizes as a cloud software platform with a large free top of funnel and progressively higher paid collaboration, governance, and AI tiers. The live pricing page shows a 2026 structure of Free, Solo, Team, and Enterprise plans, with paid upgrades unlocking collaboration, governance controls, larger AI-credit pools, and more operational limits. Product pages for Enterprise, Workspaces, and the API Repository make clear that the monetizable surface is not just sending requests; it is shared asset management, private API discovery, governance, and organization-wide workflow context. That matters because the company's user growth is already enormous. A free plan can still seed adoption, but revenue has to come from converting API work from an individual utility into a system of record for teams and enterprises. External pricing commentary from Apidog and Dev Tools is self-interested and low-confidence, but it is directionally useful because it highlights exactly where Postman is pushing harder on monetization in 2026: collaboration now starts at the Team tier, not the old small-team free motion. The core financial question is therefore not whether Postman has reach; it is whether collaboration, governance, and AI assistance produce enough durable willingness to pay across that reach.[CI001, CI002, CI003, CI004, CI005, CI006]

Revenue Streams Table
Revenue streamMechanismCurrent public value / statusRevenue quality readDiligence ask
Free-to-paid seat conversionSolo or Team upgrades from free usersVery large top of funnel; 40M+ developers and 500k+ organizations in official positioningPotentially strong if collaboration pain converts into paid seats; unproven publiclyRequest free-to-paid conversion, active team workspace count, and seat-expansion cohorts
Team subscriptionsPer-user annual plan for collaborationTeam listed at $19 per user/month billed annuallyGood recurring profile if expansion and retention are healthyProvide average paid seats per account, churn, and discounting by segment
Enterprise subscriptionsPer-user enterprise plan plus governance and org controlsEnterprise listed at $49 per user/month billed annually plus contact-sales motionLikely highest-ACV stream with better retention and governance stickinessBreak out enterprise ARR, contract length, and percentage of seats under annual commitments
AI credit overagesUsage-based consumption above plan allotmentsPricing page lists pay-as-you-go AI overagesAdds incremental monetization but may still be early and volatileShow AI-credit consumption, overage attachment, and margin profile
API program expansionPartner APIs, private networks, monitoring, governance, and repository adoption inside large accountsEnterprise page explicitly ties partner APIs and scale programs to monetization outcomesCould support land-and-expand economics if modules attach after initial adoptionDisclose attach rates for governance, monitoring, and API network features

Rows summarize how Postman converts developer adoption into recurring SaaS revenue. Public sources describe the mechanisms but do not disclose realized mix or net retention by stream.

[CI001, CI004, CI005, CI007, CI008, CI009]
Pricing / Monetization Table
Plan / mechanismList price or statusIncluded monetization leverWhat it signalsSource / caveat
Free$0Solo usage, limited AI credits, top-of-funnel adoptionStill optimized for adoption, but collaboration has been carved outOfficial pricing page is authoritative; external blogs highlight 2026 packaging changes
Solo$9 per user/month annualAdds higher AI-credit pool and individual premium featuresTargets power users before team standardizationPrice is explicit on official page; realized usage is undisclosed
Team$19 per user/month annualCheapest path to multi-user collaboration and shared workspacesThis is the real entry point for paid collaborationMultiple external reviews flag this as the conversion cliff for small teams
Enterprise$49 per user/month annual plus sales-led packagingAdds Private API Network, org controls, governance, and higher pooled AI creditsSupports larger ACVs and stronger switching costsActual enterprise discounting and true average selling price are unknown
AI overages$0.05, $0.04, or $0.035 per credit by tier on the live pageUsage-based upsell on top of seat revenueCan raise ARPU if AI features become habitualPublic sources do not disclose current attach or overage contribution

Pricing is list pricing captured from the live 2026 page and triangulated with external commentary on the March 2026 packaging changes. It does not represent realized net pricing after discounts.

[CI001, CI002, CI003, CI004, CI005]
FI001: Revenue Model Bridge

Shows how Postman converts broad free adoption into higher-value team, enterprise, and usage-based revenue.

This is a monetization logic map, not a quantified revenue bridge.

[CI001, CI004, CI007, CI008, CI011]

4.2 GTM Motion, Conversion Logic, and Efficiency Proxies

Public evidence points to a hybrid sales motion: broad self-serve developer adoption at the top, then team and enterprise expansion where shared workflows matter. Postman says the platform now reaches more than 40 million developers and 500,000 organizations, and the enterprise page still claims 98% of the Fortune 500. Those figures alone do not guarantee revenue quality, but they imply an unusually large pool of already-acquired users that paid conversion can mine without purely greenfield enterprise selling. The 2025 State of the API report strengthens that interpretation by showing both widespread API monetization and persistent collaboration pain, two conditions that support paid team tooling. Review sites reinforce the same pattern at a smaller scale: users repeatedly praise shared collections, environments, and workspaces, while also complaining that pricing has become more aggressive as collaboration and governance features move into higher tiers. That combination suggests healthy product value but also a real ceiling on low-end conversion efficiency if buyers perceive price creep faster than incremental utility. Public CAC, payback, pipeline conversion, and seat expansion metrics remain undisclosed, so the best outside proxy is simply that Postman appears to monetize where organizational coordination becomes expensive enough to justify a platform, not where single developers only need a free request client.[CI006, CI007, CI008, CI009, CI010, CI011]

Unit Economics Table
MetricPublic value / proxyConfidenceWhy it mattersDiligence ask
Top-of-funnel scale40M+ developers, 500k+ organizations, 98% of Fortune 500 in official positioningMediumA huge installed base can lower customer acquisition cost if conversion is efficientProvide active monthly users, active workspaces, and paid-account conversion rates
Collaboration pain proxy93% of teams struggle with API collaboration in the 2025 State of API reportMediumSupports willingness to pay for shared workflows and governanceShow which collaboration features correlate most with paid conversion
API monetization demand proxy65% of organizations generate revenue from APIsMediumSuggests paid API platforms can map to business-critical workflowsDisclose enterprise buyer mix and revenue concentration by use case
Gross margin benchmarkGitLab 2026 companyfacts imply roughly 87% gross margin on $955.2M revenueMediumLate-stage devtools SaaS can be very high margin even while still investing heavilyDisclose Postman gross margin and hosting/support burden by plan
Sales intensity benchmarkGitLab 2026 companyfacts show $434.7M selling and marketing expenseMediumScaled devtools SaaS is often go-to-market intensive even when capex-lightProvide CAC, payback, and S&M as a percentage of revenue
Revenue-per-employee estimateGrowjo estimates $228.8k revenue per employee on $506.1M revenue and 2,212 employeesLowUseful only as a rough external efficiency datapoint because the inputs are disputedReplace with audited headcount and LTM revenue per FTE

Most unit-economics metrics are absent from public disclosures, so this table mixes official demand proxies with public-comp and database proxies. Low-confidence rows should be replaced by management data in diligence.

[CI012, CI013, CI014, CI029, CI037, CI038]
FI002: Unit Economics Bridge

Public proxies suggest that collaboration pain and a massive installed base are the main conversion levers, while list-price friction is the main drag.

The bridge uses public proxies instead of disclosed company unit-economics metrics.

[CI013, CI014, CI018, CI019, CI020]

4.3 Cost Structure, Margin Path, and Capital Adequacy

Postman's delivery model should be structurally capex-light. Nothing in the public product record points to inventory, hardware manufacturing, project finance, or heavy on-premise service delivery. The platform is delivered as software, with value concentrated in cloud collaboration, repository management, monitoring, documentation, governance, and AI-assisted productivity. That does not mean the company is cheap to run. The more relevant public benchmark is a scaled devtools SaaS comp like GitLab, whose 2026 SEC XBRL disclosures show high gross profit but also continued heavy spending on selling, marketing, and R&D. Postman is earlier and private, so its exact ratios could differ materially, yet the likely shape is similar: gross margins should be attractive, while growth investment remains people-intensive rather than asset-intensive. Capital adequacy is much harder to judge. Postman has not publicly disclosed cash, burn, debt, or runway, and recent secondary transactions do not put money into company coffers. The 2021 Series D and the absence of any later primary round imply the current balance sheet has had to carry the company through a long valuation reset cycle. Without management data, investors can only say that the business looks operationally capital-light but disclosure-light on liquidity.[CI021, CI022, CI023, CI024, CI025, CI026]

Capital Adequacy Table
ItemPublic value / statusWhat is knownImplicationDiligence ask
Total funding~$433M to $434MGetLatka, Craft, and Tracxn cluster around this lifetime totalMeaningful historical capitalization, but not a current liquidity answerReconcile total primary capital, secondary volume, and remaining balance-sheet cash
Last primary round$225M Series D at $5.6B in August 2021Official blog and TechCrunch corroborate the eventNo later primary round found, so 2021 cash has had to stretch across the reset cycleRequest current cash balance and board-approved financing plan
Secondary activityDiscounted secondary trades reported in 2024-2026Economic Times and valuation trackers show pricing pressure but no cash to companySecondary liquidity can help employees/investors but does not fund operationsBreak out primary versus secondary liquidity and any tender mechanics
Debt / project financeNo public debt or project-finance obligation foundThe software model does not obviously require asset-backed financingPositive sign for capital intensity, but absence of evidence is not proof of zero debtConfirm whether venture debt, credit lines, or off-balance-sheet commitments exist
Cash / burn / runwayUndisclosedNo public source reviewed disclosed current cash, burn, or runwayThis is the main blocker to underwriting capital adequacy from open sourcesProvide monthly burn, free cash flow, runway, and next-round triggers under base and stress cases

Capital adequacy cannot be closed from public sources. Secondary-market commentary is useful for price discovery but not for liquidity because those trades do not add operating cash.

[CI021, CI022, CI023, CI030, CI031, CI040]
FI003: Financial Estimate Range

Public sources support wide, not narrow, bands for current revenue and implied secondary valuation.

Ranges mix different source methodologies and should be read as public evidence bands rather than audited company guidance.

[CI024, CI029, CI031, CI034]
FI004: Capital Intensity / Cash-Flow Map

Postman looks capex-light, but the missing variables are gross margin, sales efficiency, and remaining cash rather than hardware or inventory needs.

This is a structural cash-flow map derived from public business-model evidence and public-comp benchmarks.

[CI035, CI036, CI037, CI039, CI040]

4.4 Public Traction, Revenue Quality, and Bottom-Line Verdict

The best public growth line available is still the Latka sequence: roughly $52 million in 2021, $102.7 million in 2022, $171.7 million in 2023, and $313.1 million in 2024. If directionally correct, that would make Postman a very large private devtools SaaS company with meaningful scale and still-strong expansion. But the number set is not clean. Growjo publishes a much higher forward revenue estimate and a very different employee count; Economic Times cites people close to the company's financials who estimated only $120-150 million of annualized recurring revenue and explicitly tied the gap to slower-than-expected monetization. Those are not rounding differences. They suggest either different definitions, different periods, or a real mismatch between user adoption and paid revenue conversion. Secondary-market valuation trackers then show wide dispersion in implied marks, which is exactly what one would expect when the business is private, liquid discovery is thin, and official financial reporting is absent. The practical verdict is that Postman probably has attractive gross-margin potential and large enterprise monetization upside, but revenue quality, retention quality, and current cash efficiency remain unresolved until management shares audited or banker-grade operating data.[CI024, CI025, CI026, CI027, CI028, CI029]

Public Financial Gaps Table
Missing metricWhy it mattersCurrent public signalImpact on judgmentExact diligence path
Audited ARR / revenue bridgeNeeded to reconcile conflicting outside estimatesLatka, Growjo, and ET imply very different scale numbersWithout a bridge, current revenue quality stays uncertainObtain management financial pack and banker deck with ARR, revenue, and billing definitions
Gross marginDetermines how much room Postman has to spend on AI, support, and salesNo public company disclosure foundMargin path is inferred rather than measuredRequest gross margin by product, hosting spend, and support/service burden
Net revenue retention / churnThe core test of land-and-expand durabilityNo public NRR, GRR, or cohort disclosures foundSeat growth may look strong while net retention disappointsRequest logo churn, seat churn, NRR, and enterprise cohort expansion
Cash balance and runwayCapital adequacy is unknowable without itNo public cash or burn data reviewedInvestors cannot assess financing urgencyRequest monthly burn, cash, and downside runway assumptions
Discounting and realized ASPsList pricing is not economic truth for late-stage enterprise SaaSOnly list pricing is publicRevenue multiples and conversion efficiency may be overstated if discounts are deepRequest ASP by plan, average discount rate, and channel / direct mix

Every row here is a real underwriting blocker rather than a cosmetic omission. The public record is rich on product and pricing, but thin on realized economics.

[CI024, CI031, CI032, CI038, CI040]

4.5 Exhibits

Chapter 05

05Product & Technology

5.1 Platform Surface and Customer Workflow

Postman now markets itself as a unified platform across the full API lifecycle rather than as a single API client. The product page bundles design, testing, documentation, monitoring, governance, collaboration, and AI into one surface, while the repository page makes clear that these are not separate bolt-ons sitting on disconnected data. The platform centers on collections, specs, environments, workspaces, and repository state that can be reused across design, testing, publication, and monitoring. For users, that means the product narrative is about reducing tool fragmentation and keeping API work synchronized. For buyers, it means Postman is trying to sell a system of record for API work. This shift matters because it explains why Postman has been able to keep expanding its platform footprint without abandoning its original request-runner wedge. The customer workflow starts with requests and collections, but the monetizable value increasingly sits in shared context, reviewability, and organizational visibility rather than in raw request sending alone.[CE001, CE002, CE003, CE005, CE007, CE008]

Product Module / Asset Matrix
Module / assetPrimary userCurrent status / maturityDifferentiationDiligence gap
API client + collectionsDevelopers and testersCore / matureLarge installed base; reusable collections tied to broader platform assetsNeed active usage split between simple request sending and broader lifecycle use
API Repository + BuilderPlatform engineers and API ownersCore / matureCentral source of truth plus native Git sync across specs, docs, tests, and codeNeed data on adoption of builder workflows versus standalone collection usage
FlowsDevelopers, onboarding, partner teamsScalingTurns workflow docs into executable assets and AI-ready wrappersNeed usage and retention for flows-heavy workspaces
Agent Mode + PostbotDevelopers and QAEarly but rapidly expandingActs on workspace context to generate tests, fix requests, and create docsNeed measured productivity gains and guardrail metrics
AI Engineer + API CatalogPlatform and enterprise engineering leadersBeta / new 2026 surfaceContext graph, review controls, and live API map create a system-of-record moatNeed clarity on rollout status, model providers, and production usage depth

This table maps the major product surfaces visible in 2026 public materials. Maturity labels are analytical judgments based on documentation depth and launch language, not company-announced lifecycle tags.

[CE001, CE003, CE018, CE021, CE022, CE026]
Workflow / Use-Case Table
User jobCurrent workflowPostman solutionMeasurable benefitLimitation
Design and sync an APIWrite a spec, keep docs and tests alignedAPI Builder + Repository + Git syncReduces tool handoffs and keeps artifacts in one graphRequires teams to adopt Postman’s object model
Teach or debug a complex integrationShare docs or scripts that drift from realityFlows + collections + environmentsTurns workflows into executable, inspectable assetsCan feel heavier than a simple README or curl sample
Run regression tests in CIExport scripts manually or rewrite checks elsewhereNewman + Postman API + CLIRuns the same collection logic inside pipelinesSome modern package flows require Postman CLI rather than Newman alone
Prepare APIs for agentsRetrofit docs and examples after launchAgent Mode + Postbot + AI Engineer + API CatalogRaises machine readability and can generate coverage fasterRequires strong permissions and context quality to avoid bad automation
Enforce enterprise controlsManual review of API sprawl and permissionsAudit logs, governance APIs, Secret Scanner, SCIM, Private API NetworkCentralizes policy and operational oversightPublic docs still don’t quantify real-world false-positive rates or control adoption

The use-case table focuses on workflow change rather than on individual feature checkboxes. Benefits are directional and should be tested against live customer usage in diligence.

[CE004, CE014, CE015, CE020, CE021, CE023]
FE001: Product Architecture Map

Shows how Postman layers collections, repository state, workflow tooling, governance, and AI on top of each other.

This is a conceptual layer map synthesized from public product pages and docs.

[CE001, CE003, CE016, CE017, CE021, CE022]
FE002: Customer Workflow / Operating Flow

Illustrates the user path from API design through testing, publication, monitoring, and AI-assisted maintenance.

[CE001, CE003, CE018, CE021, CE026, CE030]

5.2 Architecture, Formats, and Ecosystem Tooling

The clearest architectural pattern in the public record is that Postman has standardized around a reusable asset model. Collections remain the basic unit, variables scope behavior across environments, and the API Repository acts as the central object store around which builder, networks, monitors, and AI features operate. The schema site, Collection SDK, openapi-to-postman converter, Newman CLI, and Postman API all point in the same direction: Postman wants its objects to be programmable and portable enough to plug into broader engineering workflows, but still coherent enough to keep teams inside a common format family. Native Git workflows and the Collection v3 move push further toward code-adjacent development, reducing the criticism that Postman only works well inside a cloud UI. Even so, the design remains opinionated. The richest value depends on assets living in or syncing through the Postman control plane, where governance, cataloging, permissions, comments, and AI can act on them. That is a strength for enterprise standardization and a tradeoff for teams that prefer a thinner local-first toolchain.[CE003, CE004, CE007, CE008, CE009, CE010]

Technology / Operating Architecture Table
Layer / componentRoleKey dependencyStrengthRisk
Collections + schemaPortable asset format for requests and workflowsPostman schema and SDK ecosystemMakes artifacts reusable across UI, CLI, and codeFormat influence can feel like soft lock-in
Repository + workspacesCentral state and permissions layerPostman cloud account and workspace modelSingle source of truth for teamsAdvanced value depends on cloud-managed state
Builder + spec syncDesign and source control bridgeOpenAPI / GraphQL / RAML plus Git integrationKeeps specs, docs, and tests alignedRequires disciplined repo and review practices
Runtime toolingExecute collections locally and in CINode.js, Newman, Postman CLI, Postman APISupports local, automated, and pipeline executionTooling split between Newman and CLI can confuse teams
AI context layerGrounds agents across assets and servicesContext graph, API Catalog, review queues, model infrastructureDifferentiates Postman on system contextPublic disclosure on model-serving internals remains thin

This architecture view reflects what is visible in public product and docs materials. It is a control-plane map, not a full infrastructure diagram.

[CE003, CE007, CE009, CE010, CE012, CE015]
FE003: Critical Dependency Map

Postman’s technical value depends on a few key external and internal nodes: source repos, Node.js tooling, cloud state, and AI control surfaces.

Dependencies are inferred from public docs rather than from an internal architecture review.

[CE004, CE012, CE014, CE016, CE017, CE022]

5.3 AI-Native Direction and 2026 Release Arc

The most important technical story in 2025-2026 is that Postman is redesigning the product around AI-native context. Agent Mode already acts across collections, specs, environments, and history. Postbot handles request troubleshooting, test generation, documentation, and visualization. AI Engineer moves one level up again, using an always-on context graph, sandboxed execution, and review-queue controls to help teams explore systems, run QA, and work on PRs. The March 2026 roadmap and the later “new Postman” launch extend that logic across the full platform: API Catalog becomes the live map, local and CI mock servers bridge dev and test loops, and the unified workbench keeps collections, specs, mocks, flows, and files in one place. The result is a product that is no longer just helping developers make API calls; it is trying to be the context layer through which humans and agents both understand and change API systems. That ambition is differentiating, but it also raises the burden on reliability, permissions, and information architecture.[CE019, CE020, CE021, CE022, CE023, CE024]

Roadmap / Release / Development-Stage Table
Date / stageFeature / milestoneStatusImplicationSource
2025-01AI agent builder launchReleasedConfirmed the platform was moving above single-request workflows into agentic toolingTechCrunch and I Programmer
2026-03 roadmapAPI CatalogAnnounced / rolling outCreates a live operational layer above repos, CI, and runtime dataPostman March 2026 blog
2026-03 roadmapNative Git workflows + local/CI mock serversAnnounced / rolling outBridges the cloud UI with code-adjacent and pipeline workflowsPostman March 2026 blog
2026 platform relaunchUnified workbench + Collection v3ReleasedMakes collections, specs, mocks, and files live together in one workspace modelThe New Postman is Here
2026 platform relaunchMulti-protocol collections and agent-ready APIsReleasedPositions Postman as a broader system-context layer for humans and agentsThe New Postman is Here + AI Engineer page

Roadmap status reflects how the company described each capability at fetch time. Public launch language should be checked against live production access during diligence.

[CE021, CE022, CE026, CE027, CE028, CE029]
FE004: Product Maturity / Capability Map

Highlights which Postman capabilities appear mature versus newly expanding in 2026 public materials.

Maturity judgments are analytical rather than company-assigned lifecycle labels.

[CE003, CE022, CE024, CE026, CE027, CE030]

5.4 Trust, Security, Reliability, and Technical Tradeoffs

Postman publishes more trust and security detail than many private devtools companies, but the picture is still mixed. The security page documents concrete controls such as API key management, audit logs, 2FA, bug bounty coverage, AWS hosting, and data privacy framework certifications. The API docs also show enterprise surfaces for audit logs, Secret Scanner, service accounts, SCIM, and governance APIs, indicating that trust is embedded into the product surface rather than handled only through marketing copy. At the same time, the trust portal shows that third-party integrations can still create exposure, as seen in the Klue-linked incident. Public reviews reinforce a separate operational tradeoff: the same breadth that makes Postman powerful can also make it feel heavy, complex, or too cloud-centric for simpler teams. So the product-tech verdict is favorable on depth and breadth, but diligence should still probe data-boundary design, model-operations controls, and how gracefully the platform performs under very large workspace and collection footprints.[CE017, CE031, CE032, CE033, CE034, CE035]

Trust / Quality / Compliance Table
Control / disclosureStatusScopeWhy it mattersGap
API key management + 2FADocumentedPlatform account securityBaseline identity and token hygiene controls are exposed publiclyNeed finer detail on admin defaults and enforced policies
Audit logs (180 days)DocumentedSecurity access and team management activitiesSupports enterprise oversight and incident reviewNeed retention tiers and export coverage by plan
Bug bounty via HackerOneDocumentedPlatform vulnerability intakeSignals mature external reporting pathNeed detail on response SLAs and payout program scope
Data privacy frameworks + AWS hostingDocumentedPrivacy and infrastructure postureImportant for global enterprise procurementNeed granular data residency and subprocessor flow diagrams
Trust portal incident + subprocessor noticesDocumentedOperational transparency and vendor dependencyShows Postman discloses third-party incidents and vendor changesNeed more technical detail on blast radius containment and detection stack

This table records only trust controls visible in public materials. It is not a substitute for security questionnaires, pen-test results, or architecture review.

[CE017, CE023, CE031, CE032, CE033, CE034]

5.5 Exhibits

Chapter 06

06Customers

6.1 Customer Segmentation and Scale

Postman’s customer base is best understood as a layered ecosystem rather than as a single buyer segment. The company serves individual developers, internal engineering and QA teams, API platform owners, external developer communities, and partner-facing API programs. Official scale claims are large and reasonably consistent across company properties: 40 million developers and 500,000 companies or organizations. Third-party adoption trackers also support a broad footprint, though they lag and sometimes disagree on absolute counts. Landbase shows thousands of verified named companies and a wide sector mix, while Ramp suggests especially high adoption among enterprise organizations inside its DevOps category. The important diligence takeaway is not the exact vanity metric but the pattern: Postman has penetrated a very wide base of API-related users, and the product appears to cross from hobbyist use into serious enterprise standardization when collaboration, partner onboarding, or governance becomes important. That breadth supports a diversified customer funnel even if public contract and spend data remain hidden.[CU001, CU002, CU003, CU004, CU005, CU006]

Customer Segmentation Table
SegmentBuyer / user / payerTypical use caseScale signalGap
Individual developersUser: developer; payer: none or managerSend requests, explore APIs, fork public collections40M+ developer reach claimed by PostmanNo public conversion data from individual to paid team
Internal engineering / QA teamsUser: developers and testers; payer: engineering leadershipShared collections, CI tests, governance, environmentsMedibank and ZEISS show internal standardizationNo public seat counts by team size
API platform / partner teamsUser: partner integration and DevRel teams; payer: platform or productPublic workspaces, partner workspaces, onboarding, documentationPayPal, Autodesk, HubSpot, and Cover Genius are strong examplesPublic sources do not break out revenue by partner-led accounts
Regulated enterprisesUser: engineering plus security and complianceSSO, SCIM, governance, audit, secure sharingZEISS and Medibank highlight compliance featuresNo public win-rate data versus security-conscious competitors
External developer communitiesUser: third-party developers; payer: API publisherFork collections, run examples, reduce TTFCPayPal, Microsoft Graph, Box, Autodesk, and HubSpot all expose official Postman assetsNo public monetization split between external and internal developer programs

Segments are inferred from official scale claims, customer stories, and external customer-domain docs. They describe who uses Postman and why, not the exact commercial packaging by account.

[CU001, CU003, CU005, CU013, CU017, CU020]
Customer Growth / Adoption Trajectory Table
MetricValueDate / periodSourceConfidenceImplicationMissing denominator
Developers40M+2025-2026Postman customer stories / LinkedIn / enterprise pageMediumDeveloper reach is enormous and supports wide funnel breadthUnknown active versus registered split
Organizations / companies500k+2025-2026About page / customer stories / LinkedInMediumBroad organizational footprint reduces single-logo dependenceUnknown paid-account share
Verified named companies3,9062025-08-17LandbaseLow-mediumShows wide named-logo reachMethodology and sampling bias not transparent
Enterprise-category adoption26%2026-07RampLow-mediumSuggests enterprise penetration is meaningfulRamp taxonomy is not a direct market census
HubSpot API calls on Postman+104% in six months2023-11 to 2024-05HubSpot case studyMediumPublic workspace usage can grow quickly when documentation is strongNot equivalent to contract expansion
PayPal public collection forks30,000+2024-2025 story contextPayPal case studyMediumExternal developer engagement appears substantialForks are usage and discovery signals, not revenue

This table mixes official scale claims, company-authored customer stories, and third-party adoption trackers. It shows breadth and growth, not monetized cohort quality.

[CU001, CU002, CU006, CU008, CU015, CU022]
FU001: Customer Journey Map

Illustrates how external and internal users move from discovery to productive collaboration in Postman.

The journey stages are synthesized from customer stories and workspace analytics docs rather than from a single company funnel chart.

[CU009, CU012, CU013, CU023, CU034, CU037]

6.2 Named Customer Proof and Production Usage

The strongest public customer proof comes from organizations whose businesses are already deeply API-centric. PayPal uses Postman to support external and partner developers at global scale and ties the platform directly to lower time to first call, faster testing, and large public-collection fork counts. Autodesk shows how Postman can power partner workspaces and scale partner transactions rather than only internal testing. Medibank demonstrates internal standardization across development and QA with CI/CD and GitHub integration. HubSpot uses a public workspace and workspace analytics to drive and measure developer adoption. ZEISS shows fit in a regulated environment, and Cover Genius shows configuration and partner-integration efficiency gains. These are not all independent sources—most are company-authored case studies—but they are still materially stronger than generic logo walls because they include operational detail, named functions, and concrete outcomes. External customer-domain documentation from Autodesk, Box, and Microsoft further strengthens the picture by showing that major API publishers treat Postman collections and workspaces as real onboarding surfaces for developers.[CU013, CU014, CU015, CU016, CU017, CU018]

Named Customer Proof Table
CustomerSegmentDeployment / use caseProduction vs pilotOutcomeLimitation
PayPalGlobal payments / external developer ecosystemPublic and private API collections, monitoring, mocking, governance, external onboardingProductionTTFC down to 1 minute; 30k+ forks; testing time down to minutesCompany-authored case study
AutodeskPartner integration / industrial softwarePartner Workspaces and public workspace for PWS APIsProductionRequests from 40M per year to 60M per month; 200+ partners onboardedCompany-authored case study
MedibankRegulated healthcare enterpriseInternal development, QA, CI/CD, governance, GitHub integrationProductionTesting cycle -70%; releases accelerated by three weeksCompany-authored case study
HubSpotDeveloper relations / SaaS platformPublic workspace and API Network distributionProductionAPI calls +104% in six months; easier onboarding and feedback loopsCompany-authored case study
ZEISSRegulated manufacturing / e-commerceEnterprise workspaces, SCIM/SSO, mocks, shared testingProductionHundreds of tests in one minute; broader collaborationCompany-authored case study
Cover GeniusPartner-heavy insurtech platformPartner Workspaces, Newman, secure sharing, onboardingProduction50% less config time; doubled efficiency in integrationsCompany-authored case study

Every row represents a publicly attributable production reference with operational detail. Most are company-authored customer stories, so independent corroboration is stronger for rows that also have customer-domain documentation.

[CU013, CU017, CU019, CU020, CU022, CU024]
FU002: Adoption / Deployment Funnel

Maps the public partner funnel from discovery through successful API usage.

[CU009, CU012, CU023, CU034, CU037, CU038]
FU003: Customer Proof Matrix

Compares public customer references by evidence depth, quantified outcomes, and production maturity.

[CU019, CU028, CU029, CU030, CU031, CU035]

6.3 Durability, Satisfaction, and What Public Metrics Can Actually Show

Public durability evidence is decent but indirect. Postman exposes analytics primitives such as active users, active workspaces, API calls, successful users, partner onboarding funnels, and response-code mixes. Customer stories add durable-use proxies such as PayPal’s fork counts, HubSpot’s API-call growth, Medibank’s embedded CI workflows, and ZEISS’s repeated test execution. Reviews across G2, TrustRadius, and Software Advice also show that users keep valuing organization, collaboration, and documentation once they adopt the product. But investors should not confuse these signals with formal retention disclosure. There is still no public NRR, GRR, logo churn, seat expansion, or contract-length dataset that would let an outsider model cohort behavior with precision. The right read is that Postman has strong evidence of repeated operational use and developer habit formation, but weak evidence on monetized durability by segment. That distinction matters because developer love and enterprise spend persistence are related, not identical.[CU009, CU010, CU011, CU012, CU015, CU022]

Retention / Repeat Usage / Satisfaction Table
Metric or proxyValue / statusSegmentConfidenceWhy it mattersDiligence ask
NRR / GRRUndisclosedAll paid segmentsLowTrue commercial durability remains unknownRequest NRR, GRR, and seat-expansion by cohort
PayPal public collection forks30,000+ forksExternal developersMediumShows repeat discovery and reuse around a named enterprise publisherRequest repeat-fork and active-consumption trends over time
HubSpot workspace API calls104% growth in six monthsExternal developersMediumSuggests durable engagement when public workspaces are well-runRequest monthly active developers and successful-call rates
Partner onboarding funnel visibilityDocumented analytics surfacePartner ecosystemsMediumPostman can measure journey steps from workspace visit to successful API responseRequest actual funnel conversion rates across flagship accounts
Review satisfactionGenerally positive, with complaints about heaviness and paid featuresBroad user baseMediumUser love matters, but doesn’t replace contract dataRequest customer satisfaction by segment plus renewal survey results

This table intentionally uses durability proxies because the company does not publicly disclose cohort economics. The main diligence task is to separate product habit from monetized retention.

[CU009, CU012, CU015, CU022, CU031, CU032]
FU004: Retention / Repeat Cohort

Uses public durability proxies as an evidence-strength cohort, not as literal company retention rates.

These percentages are ordinal evidence-strength proxies based on public usage signals such as forks, API-call growth, partner funnels, and repeated workflow embedding. They are not company-wide retention or renewal percentages.

[CU015, CU022, CU031, CU038, CU040]

6.4 Expansion, Concentration, and Procurement Friction

The public record suggests a healthy land-and-expand motion. Customer stories repeatedly point to public workspaces, partner workspaces, GitHub integration, monitoring, governance, identity controls, and analytics as the surfaces that move users from simple request sending into broader organizational deployment. That is encouraging because it implies Postman can deepen revenue inside accounts without needing every user to start on an enterprise plan. Public concentration risk looks low: the visible customer set spans payments, healthcare, SaaS, manufacturing, optics, and insurtech, and there is no sign that one or two logos dominate the story. The main commercial risk is at the low end. Reviews and pricing commentary continue to show that some teams experience the platform as heavy or increasingly paywalled once collaboration becomes mandatory. So the customer chapter ends with a split verdict: Postman has unusually strong public production proof and cross-vertical logo breadth, but still lacks the hard monetized retention disclosures needed to distinguish broad adoption from broad expansion efficiency.[CU012, CU031, CU034, CU035, CU036, CU037]

Expansion and Concentration Risk Table
Expansion driverConcentration or friction riskImpactEvidenceDiligence path
Public workspaces and Run in Postman buttonsLow-end users may consume without payingGreat for acquisition, weaker as a revenue proxyPayPal, HubSpot, Box, Microsoft GraphMap free to paid conversion for publisher-led workspaces
Partner WorkspacesHeavy success if partner programs standardize on PostmanCan deepen strategic embed inside accountsAutodesk, Cover Genius, MedibankMeasure partner workspace expansion ARR and renewal rates
GitHub / CI integrationMakes Postman stickier across engineering workflowsAlso raises implementation complexityMedibank and Newman docsRequest attach rates for Git/CI features by plan
Enterprise governance / identityDrives adoption in regulated enterprisesLonger sales cycles and security reviewsZEISS, Medibank, enterprise pageRequest sales-cycle length and win rates by vertical
Broad logo diversityNo obvious single-customer concentration in public evidencePositive for resilience, but not proof of revenue distributionVisible named logos span multiple verticalsRequest top-10 customer revenue concentration and renewal history

The biggest customer risk is not visible logo concentration but monetization friction as teams move from free or public-workspace use into paid collaboration and governance.

[CU024, CU025, CU034, CU035, CU036, CU037]

6.5 Exhibits

Chapter 07

07Risks

7.1 Privacy, Legal, and Security Exposure

The central risk theme is that Postman’s growth model and its risk model are partially the same thing. Public workspaces, API discoverability, forks, examples, and shared collections make onboarding fast, but they also create a durable surface for accidental exposure of live tokens and sensitive data. Third-party researchers are unusually aligned here: CloudSEK, Truffle Security, AppSentinels, and follow-on coverage all describe large-scale secret exposure on public Postman assets. Importantly, most of this evidence does not allege that Postman’s core infrastructure was hacked. The more uncomfortable conclusion is that the platform makes it easy for users to create business value quickly, and therefore easy to create business harm quickly when sharing defaults, token handling, or environment semantics are misunderstood. Legal and regulatory risk sits on top of that operational reality. The CCPA, Data Privacy Framework commitments, AI terms, and other evolving contract surfaces mean that any future incident involving regulated personal data or customer credentials could carry enforcement and contractual consequences beyond pure reputation damage.[CR001, CR002, CR003, CR004, CR005, CR006]

Regulatory / Legal Risk Register
Risk / ruleJurisdictionStatusLikelihoodSeverityMitigationResidual exposureDiligence path
Public-workspace exposure involving personal or customer dataU.S. / EU / globalNo known enforcement action reviewed, but repeated public exposure research existsmedium-highhighSecret scanning, private workspaces, vault patterns, audit logshighReview incident history, secret-detection efficacy, and external counsel assessment of privacy exposure
Cross-border data-transfer commitments under DPF and related privacy frameworksEU / U.S. / UK / SwitzerlandPostman says it is certifiedmediummedium-highFramework certification, privacy program, AWS regionsmediumConfirm certifications, transfer impact assessments, and fallback transfer mechanisms
Evolving AI terms and contractual obligationsGlobal / contract-basedLegal hub and archives show active updatesmediummediumPublished AI terms and review controlsmediumReview AI terms diffs, enterprise carve-outs, and indemnity positions
Subprocessor and vendor-incident notification dutiesGlobal / contract-basedTrust portal publishes subprocessor notices and Klue incident updatesmediummedium-highNotification process and transparency portalsmediumRequest full subprocessor inventory, notification SLAs, and vendor-risk playbooks
CCPA / CPRA rights if exposed data is unencrypted and personalCaliforniaLaw is active and well-definedlow-mediumhighReasonable security, vaulting, private workspaces, redactionmediumAssess California user exposure, encryption defaults, and response plans for leaked credentials or PII

Rows are ordered by likely diligence priority rather than by certainty of loss. Regulatory risk is mostly contingent today but could escalate quickly if another high-profile exposure involved regulated data.

[CR004, CR005, CR006, CR007, CR008, CR009]
FR001: Risk heatmap

Residual severity is highest where public sharing, credential handling, and regulatory exposure overlap.

[CR014, CR016, CR022, CR027, CR033, CR034]
FR002: Risk transmission map

Maps how a public-workspace or vendor event flows into customer trust, compliance, revenue, and valuation.

[CR006, CR014, CR015, CR019, CR033, CR035]

7.2 Operational and Reliability Risk

Operationally, Postman is now broader than many users probably realize. The status surface spans login, monitors, mocks, search, docs, API Network, CLI, API Builder, Postbot, and Agent Mode. The captured uptime view is solid, but a wide service surface also means more ways for localized incidents to degrade the user experience. The 2026 Klue incident adds a more subtle point: vendors integrated into surrounding go-to-market or support systems can create risk even when the product core remains secure. Public trust is therefore affected not only by the availability of monitors and collections, but by the handling of the broader ecosystem around customer data, subprocessor changes, and security notifications. Postman does publish a respectable mitigation stack—vault options, 2FA, audit logs, bug bounty, secret scanning APIs, service accounts, SCIM, and status transparency. Yet the residual risk remains elevated because many of the most damaging failure modes still begin with human behavior and permission design rather than with missing checkboxes. Investors should treat operational quality here as a mix of platform resilience and guardrail effectiveness.[CR001, CR002, CR004, CR005, CR006, CR012]

Operational / Quality / Security Risk Register
Failure modeLikelihoodSeverityMitigation maturityResidual exposureUnresolved gap
Public workspace leaks of live credentials or sensitive datahighcriticalmediumhighNeed evidence that default secret-protection and sharing UX now meaningfully reduce leakage rates
Ambiguous token / variable handling leading to unsafe defaultsmedium-highhighmediumhighNeed data on how often initial/current-value or secret-variable mistakes still happen
Third-party SaaS incident touching customer-adjacent systemsmediumhighmediummedium-highNeed clearer blast-radius and dependency mapping for non-core integrations
Outage or degraded performance across broad service surfacemediummedium-highmedium-highmediumNeed component-level SLA and MTTR history beyond the public snapshot
AI-driven automation acting with excessive permissions or poor review boundariesmediumhighearlymedium-highNeed architecture review of model permissions, auditability, and approval gates

The dominant operational concern is still secrets and sharing, not raw uptime. Platform breadth is a secondary amplifier because more services and integrations increase the number of trust-sensitive surfaces.

[CR001, CR004, CR012, CR013, CR014, CR016]

7.3 Dependency, Lock-In, and Competitive Pressure

Postman’s biggest strategic dependencies are not only infrastructure vendors like AWS, but also the product assumptions that made the company large in the first place: a cloud-managed shared workspace model, central object formats, and an increasingly AI-mediated workflow. Those assumptions create frictionless collaboration for many teams, but they also make the platform vulnerable to a wave of local-first challengers. Bruno’s offline-only, Git-native posture is an explicit rebuke to cloud-sync risk and vendor-managed state. Thunder Client makes the same point from inside VS Code, while Insomnia now markets flexible storage modes, identity controls, and MCP support under Kong. GitHub Copilot adds another pressure point by bundling AI assistance into a far larger developer platform. These alternatives do not need full feature parity to matter. They only need to satisfy simpler teams, privacy-sensitive teams, or Git-native teams well enough that Postman becomes a heavier or more expensive option by comparison. That weakens willingness to pay at the low end and can cap expansion if organizations split request running, documentation, and governance across multiple tools instead of standardizing on Postman alone.[CR022, CR023, CR024, CR025, CR026, CR027]

Partner / Dependency Risk Register
DependencyCounterpartyRoleConcentrationFailure scenarioSeverityMitigationResidual exposure
Cloud infrastructureAWSHosts product data and backups, core compute/storage layersHigh structural dependenceRegional disruption, control failure, or cost shock affects availability and data posturehighRedundancy across storage/network/compute and availability zonesmedium
Go-to-market / support vendorsKlue and other subprocessorsHold or touch customer-adjacent data through integrationsMediumVendor compromise creates trust event even if core platform is securehighSubprocessor notices, integration disablement, incident responsemedium-high
Identity and access ecosystemSSO / SCIM / enterprise admin stackEnterprise onboarding and access governanceMediumMisconfiguration or identity failure reduces trust and slows enterprise adoptionmedium-highAudit logs, 2FA, service accounts, SCIM APIsmedium
Public search and API discovery surfacesSearch engines, public workspaces, API NetworkDiscovery and adoption channelsHigh for discoveryPublic indexing exposes assets or leaked credentials at scalehighSecret scanning and private-workspace controlshigh
AI and developer-platform competitionGitHub, Kong/Insomnia, Bruno, VS Code ecosystemAlternative workflow and AI surfacesMedium-highTeams split workflows or move off Postman for local-first or bundled AI pathsmedium-highContinue adding Git-native, local, and AI capabilitiesmedium-high

Not every dependency is a vendor invoice; some are distribution or workflow dependencies whose failure would show up as trust loss or competitive displacement rather than as downtime.

[CR005, CR006, CR012, CR019, CR022, CR024]
People / Execution Risk Register
Role / functionDependency or gapLikelihoodSeverityMitigationDiligence path
Security / product leadershipMust keep growth surfaces safe while still encouraging sharing and public discoverymedium-highhighSecurity controls, vaulting, trust portal transparencyReview roadmap for safer defaults and measurable reduction in public-secret exposure
Platform engineeringMust keep an expanding set of services and AI features coherent and reliablemediummedium-highUnified workbench and productized controlsRequest service-level metrics and release quality data across major surfaces
Enterprise success / supportCustomer training and admin enablement are essential to using workspaces safelymediummediumCustomer success, docs, partner guidanceAssess whether enterprise onboarding meaningfully reduces misconfiguration rates
AI governance / trust teamsNeed to set clear boundaries for what agents can access and changemediumhighReview queues, sandboxing, AI termsRequest internal AI governance policies, approval rates, and incident logs
Executive team / financeMust absorb trust shocks while valuations and monetization remain opaquemediumhighPotential cash cushion, pricing power, existing scaleRequest runway, burn, and contingency planning for trust or churn shocks

Execution risk is elevated because Postman is simultaneously scaling product breadth, AI autonomy, and enterprise governance expectations.

[CR004, CR027, CR028, CR033, CR034, CR036]
FR003: Dependency map

Shows the external nodes whose behavior most affects Postman’s risk posture.

This map emphasizes dependency channels, not a full system architecture.

[CR005, CR006, CR019, CR022, CR024, CR026]

7.4 Financial / Model Risk and Thesis-Break Indicators

The public record still leaves one important risk category unresolved: model resilience under stress. The Economic Times reported a material secondary-market discount and significantly lower ARR than some outside growth trackers suggest, while current burn, runway, and debt remain undisclosed. That matters because trust shocks, pricing backlash, or slower enterprise conversion can all be survived more easily by a company with abundant cash and harder by a company already facing a valuation reset. The practical implication is that investors should not look at Postman’s risks in isolation. Security exposure, customer churn at the low end, or AI competition from larger platforms all matter more if the company lacks financial flexibility. The thesis-break events are therefore concrete: a repeat large-scale credential-exposure cycle, evidence of prolonged customer trust loss, a sharper pricing-driven user outflow, or a financing event that confirms the business is worth materially less than its last primary round without corresponding proof of durable free cash flow.[CR030, CR031, CR032, CR033, CR034, CR038]

Mitigation and Kill Criteria Table
RiskMonitorable triggerThreshold / eventAction implication
Public-secret exposureNew external research or trust noticeEvidence that large-scale public workspace leakage persists or worsens despite mitigationsRe-open investment thesis and demand leakage-rate trend data
Operational trustStatus or trust-portal patternRepeat incident or prolonged multi-surface outage affecting key collaboration or AI servicesDowngrade confidence and test customer references for trust erosion
Competitive pressureCustomer or review signalGrowing movement toward Bruno, Insomnia, Thunder Client, or GitHub-native workflows in target segmentsQuestion low-end expansion and price realization assumptions
Model / financing riskSecondary or financing eventDown-round, tender markdown, or disclosed ARR/burn profile materially below expectationsReset valuation and examine runway contingencies
AI governance riskInternal or external incidentAgent- or AI-driven change creates a security or compliance failure with customer impactTreat as thesis-break unless controls and blast radius are immediately demonstrably contained

These kill criteria are designed for ongoing monitoring after diligence, not just for one-time screening.

[CR016, CR027, CR032, CR033, CR034, CR040]

7.5 Exhibits

Chapter 08

08Valuation

8.1 Investment Thesis and Anti-Thesis

Postman's thesis case starts from the deepest verified financing history among independent API-lifecycle vendors: a confirmed $225 million Series D in August 2021 at a $5.6 billion valuation led by Insight Partners, with total funding tracked at roughly $352-433 million depending on the source. The company has kept moving rather than standing still, announcing AI partnerships with Microsoft and Anthropic and acquiring Fern and liblab within the eight months before this chapter's access date, and a direct API-gateway competitor, Kong, still commands a credible $2 billion private valuation, showing category-level capital access has not collapsed. Applying PitchBook's reported 68.2% average markdown for 2021-vintage unicorns to Postman's peak would imply roughly $1.8 billion, below every 2026 secondary-market estimate reviewed here, so the company appears to be holding up somewhat better than the broad cohort average. The anti-thesis is just as concrete. No primary financing or tender event has been confirmed since 2021; independent secondary-market trackers disagree by more than 2x on current valuation; two credible third-party revenue estimates for the same fiscal year 2024 disagree by more than 2x; the reported secondary discount (30-40%) is two to three times a typical secondary discount; and governance, board composition, and liquidation-preference terms remain undisclosed beyond an ambiguous partial data point. Neither side of this ledger should be read as resolved, and the gap between them is the central fact this chapter tries to make legible rather than paper over.[CV001, CV020, CV024, CV025, CV027, CV039]

Thesis / anti-thesis table
Argument typeArgumentSupporting evidenceWhat would change the view
ThesisPostman has the deepest verified financing history and one of the largest confirmed valuations among independent API-lifecycle vendorsCV001, CV002, CV006A disclosed down-round or a peer surpassing it on a like-for-like basis
ThesisThe company keeps shipping platform-broadening moves (AI partnerships, two 2025-2026 acquisitions) rather than standing stillCV039, CV040Evidence that these moves are not translating into revenue or retention gains
ThesisPostman is holding up better than the average 2021-vintage unicorn markdown, implying relative resilienceCV024, CV025Secondary pricing drifting toward or below the PitchBook 2021-vintage average
ThesisA direct API-gateway competitor (Kong) still commands a credible $2B private valuation, showing category-level capital access has not collapsedCV027Kong or another peer pricing a future round meaningfully below $2B
Anti-thesisNo primary financing or tender event has been confirmed since the 2021 Series D, more than four years before this chapter's access dateCV039, CV041, CV042A confirmed new round, tender, or IPO filing
Anti-thesisIndependent secondary-market trackers disagree by more than 2x on current valuation ($2.2B-$4.8B)CV020Convergence across trackers toward a narrower band
Anti-thesisRevenue estimates disagree by more than 2x for the same fiscal year ($120-150M vs $313.1M for 2024)CV005, CV021, CV044Disclosed audited revenue or a reconciled third-party methodology
Anti-thesisReported secondary discount (30-40%) is roughly 2-3x the typical secondary discount cited for the same marketCV021A narrower observed discount on a fresh secondary print
Anti-thesisGovernance, board composition, and liquidation-preference terms are undisclosed beyond a partial, ambiguous data pointCV012, CV043A disclosed cap table or term summary

Each argument is paired with the evidence that would most directly move it in either direction.

[CV001, CV020, CV021, CV024, CV027, CV039]

8.2 Recommendation, Confidence, Risk Rating, and Valuation Stance

This chapter's evidence supports a research-more / track recommendation for Postman, with medium confidence, a medium-high risk rating, and a fair-to-stretched valuation stance that depends heavily on which revenue estimate an investor believes. That posture is not a hedge for its own sake: it follows directly from stacking strong, well-corroborated financing and scale proof against unresolved revenue, governance, and capital-event gaps that public sources simply do not close. The recommendation logic in this chapter's flow figure traces that exact chain -- financing and comparable-market proof on one side, revenue and governance disclosure gaps on the other, resolving into a price-sensitive rather than admiration-sensitive call. The investment KPI scorecard reflects the same asymmetry: financing history and comparable-market access both score well, secondary-market support sits in the middle (down from peak but ahead of the broad 2021-vintage markdown average), while revenue clarity, governance clarity, and exit-readiness signal all score poorly. No confirmed IPO filing, roadshow, or new financing event exists as of the July 2026 access date, and an EDGAR search under the company name returned no S-1 filing. A target return, hold, or exit stance cannot be responsibly quantified until at least one of the revenue, cap-table, or capital-event gaps closes; until then, the appropriate action is to track the position and revisit this call the moment new disclosure-grade evidence appears.[CV042, CV046, CV047, CV048]

Recommendation summary table
DimensionRatingKey evidence anchorDecision implication
RecommendationResearch-more / trackNo confirmed primary round since 2021; secondary trackers diverge $2.2B-$4.8BDo not initiate a price-committed position until revenue and cap-table gaps close
ConfidenceMediumFinancing history and scale are well corroborated; revenue and preference terms are notTreat this chapter's valuation range as a bracket, not a point estimate
Risk ratingMedium-High30-40% reported secondary discount plus unresolved governance/disclosure gapsSize any exposure to reflect both revenue and structural (preference) risk
Valuation stanceFair-to-stretched (bimodal)Depends on whether $120-150M ARR or $313.1M revenue is closer to realityRequest the underlying revenue definition before committing to either read
Target return / hold / exitHold-and-monitor; no active exit triggerNo confirmed IPO filing or new financing signal as of July 2026Revisit at the next confirmed capital event or disclosure release
Entry discipline checkFails on current public evidencePreference terms, board control, and audited revenue are all undisclosedPrice-sensitive entry should wait for at least one of the three gaps to close

Ratings reflect a synthesis of this chapter's sourced claims; they are analyst judgments, not a company-issued rating.

[CV046, CV047, CV048]
FV001: Recommendation logic

The recommendation moves from strong financing/scale proof through two unresolved evidence gaps to a price-sensitive research-more call.

Node tones reflect qualitative judgment about evidence direction, not a scored model.

[CV001, CV020, CV024, CV025, CV043, CV044]
FV004: Investment KPIs

Postman scores well on financing history and comparable-market access, but poorly on economics clarity and governance disclosure.

Scores are 0-10 analyst judgments synthesizing this chapter's sourced claims, not a company-issued or third-party composite score.

[CV001, CV020, CV027, CV005, CV043, CV042]

8.3 Financing and Valuation Context

Every valuation discussion of Postman has to start from the same anchor: a $225 million Series D closed in August 2021 at a $5.6 billion post-money valuation, led by Insight Partners with Coatue, Battery Ventures, and BOND joining as new investors. Forge Global's own funding table shows a lower primary-only figure ($145 million at $17.54/share, $5.57 billion post-money) and a lower total-funding figure ($352 million versus $433 million from Craft.co, GetLatka, and Inc42), a gap that most likely reflects a primary-versus-total-round distinction rather than a resolved contradiction, but it is not something this chapter can fully reconcile from public evidence. Since that 2021 peak, no new primary round has been confirmed. Instead, five independent secondary-market trackers (Forge, Yahoo Finance, Public.com, Notice.co, Premier Alternatives, and UpMarket) now show 2026 estimates spanning roughly $2.2 billion to $4.8 billion, and the Economic Times separately reported secondary transactions clearing at a 30-40% discount to the 2021 mark -- two to three times a typical secondary discount. Entry-discipline logic therefore has to price in both a wide valuation band and an unresolved, potentially non-participating-or-participating preference stack that no source fully discloses, which is exactly the kind of dilution/preference overhang that should keep any position price-sensitive rather than conviction-sized.[CV001, CV009, CV010, CV011, CV012, CV013]

FV002: Valuation sensitivity

Postman's implied valuation is far more sensitive to which revenue estimate is used than to any single multiple choice.

Revenue x multiple bars are simple bridge outputs for IC discussion, not discounted-cash-flow or company-guided figures; USD billions.

[CV005, CV021, CV013, CV018, CV019, CV032]

8.4 Bull, Base, and Bear Scenarios

The bull case assumes revenue tracks closer to GetLatka's $313.1 million 2024 estimate and that a 2026-2027 primary round or IPO re-rates the company toward UpMarket's own $4.8 billion model estimate or back toward the $5.6 billion 2021 peak; under that path, multiple expansion and revenue growth reinforce each other and the reported secondary discount narrows back toward a typical 10-15%. The base case assumes revenue lands between the two conflicting estimates and secondary pricing simply stays close to where Forge, Yahoo Finance, and Premier Alternatives already show it -- a $2.0-3.3 billion cluster -- with the main risk being that the lack of any confirmed capital event keeps that mark stale and effectively unverifiable indefinitely. The bear case assumes revenue proves closer to the lower $120-150 million ARR estimate implied by Economic Times reporting, and that Postman's valuation drifts toward PitchBook's reported 68.2% average markdown for 2021-vintage unicorns, implying roughly $1.8 billion or below. A governance, security, or customer-concentration shock (several of which already sit in this report's risks chapter as unresolved medium-severity exposures) would accelerate that path. None of the three scenarios can be assigned a precise probability from public evidence alone, but the base case is the one most directly corroborated by multiple independent, currently dated trackers.[CV005, CV019, CV020, CV021, CV024, CV025]

Bull / base / bear scenario table
ScenarioKey assumptionsValuation / return logicKey risksProbability signal
BullRevenue closer to GetLatka's $313.1M 2024 estimate keeps compounding; a 2026-2027 primary round or IPO re-rates the company toward the UpMarket $4.8B model estimate or the $5.6B 2021 peakMultiple expansion plus revenue growth both work in the company's favor; secondary discount narrows back toward typical 10-15%AI-native competitors erode willingness to pay; no capital event materializes to validate the re-rateConsistent with UpMarket's own $4.8B model and the upper end of tracked secondary prints
BaseRevenue sits between the two conflicting estimates; secondary pricing stays roughly where Forge/Yahoo currently show itValuation holds near the $2.2B-$3.3B cluster shown by Forge, Yahoo, and Premier AlternativesContinued lack of a confirmed capital event keeps the mark stale and unverifiableMatches the convergence of Forge, Yahoo Finance, and (on one reading) Premier Alternatives
BearRevenue proves closer to the lower $120-150M ARR estimate; broader SaaS multiple compression continues and Postman tracks the PitchBook 2021-vintage average markdownValuation drifts toward the PitchBook-implied ~$1.8B markdown level or belowA disclosed down-round, customer-concentration shock, or security/governance event (see risks chapter) accelerates the declineAnchored to PitchBook's reported 68.2% average 2021-vintage markdown applied to the $5.6B peak

Scenario valuation logic is a public-evidence bracket for investment-committee discussion, not a discounted-cash-flow output or company guidance.

[CV005, CV021, CV024, CV025, CV020, CV019]
FV003: Valuation / return range

Public evidence supports a wide bear-to-bull valuation band because both the revenue base and the applicable multiple are contested.

Ranges are scenario-based bridges built from this chapter's sourced claims, designed for investment-committee discussion rather than management guidance or a DCF output.

[CV050, CV051, CV024, CV025, CV020]

8.5 Comparable Valuation Lenses

No single public or private peer matches Postman's exact product mix and disclosure profile, so this chapter blends several lenses. On direct private financing, Kong Inc. -- a named competitor in Postman's own competitive set -- closed a $175 million Series E in November 2024 at a $2 billion valuation led by Tiger Global and co-led by Balderton, a useful signal that category-level private capital access has not disappeared. SmartBear, an adjacent API-lifecycle and quality-tooling vendor, remains privately owned in equal parts by Francisco Partners and Vista Equity Partners with no disclosed valuation at all, illustrating how little some PE-held peers reveal publicly. On public comparables, GitLab trades at roughly 5.8x its $955.2 million fiscal 2026 revenue (market cap $5.52 billion), Atlassian trades at a directly reported 3.82x price-to-sales on $6.19 billion trailing revenue (market cap $23.67 billion, down 52.65% year over year), and Datadog trades at roughly 25x its $3.67 billion trailing revenue (market cap $92.08 billion) -- a more than 6x spread that shows how much growth quality and category positioning matter versus a flat sector multiple. IBM's roughly $11 billion acquisition of Confluent, at about 11x its reported revenue run rate, adds a strategic-buyer M&A anchor for data/API infrastructure assets. Together these lenses bound plausible multiples without resolving which one Postman itself should trade at.[CV027, CV028, CV029, CV031, CV032, CV033]

Comparable valuation table
ComparableMetricMultiple / valuation / statusRelevanceLimitation
Postman (2026 secondary cluster)Forge/Yahoo Forge Price-derived valuation~$2.22B (Jul 2026), down 24-33% across trailing windowsThe most current, if imperfect, market-clearing signal for the company itselfDerived from thin private-market data, not an audited transaction
Postman (2021 peak, for contrast)Confirmed primary Series D valuation$5.6B (Aug 2021)The reference point every discount/markdown figure in this chapter is measured againstMore than four years stale; no confirmed capital event since
Kong Inc.Private Series E valuation$2.0B (Nov 2024)Closest direct API-management/gateway competitor with a recent, disclosed primary roundDifferent product mix (runtime gateway vs. collaboration platform) limits like-for-like comparison
SmartBearPE sponsor-owned; no disclosed valuationUndisclosed (Francisco Partners / Vista Equity, equal owners)Adjacent API-lifecycle and quality-tooling vendor at PE-hold scaleNo public valuation or revenue figure exists to benchmark against
GitLab Inc. (public)Market cap / FY26 revenue$5.52B / $955.2M revenue -> ~5.8xPublic DevSecOps platform comp with disclosed, audited financialsBroader DevSecOps scope than pure API tooling; not a like-for-like product match
Atlassian (public)Market cap / TTM revenue$23.67B / $6.19B revenue -> 3.82x (P/S)Larger public collaboration-software comp showing where a mature, diversified peer tradesFar larger scale and diversified product suite versus Postman's single-category focus
Datadog (public)Market cap / TTM revenue$92.08B / $3.67B revenue -> ~25xShows the top end of achievable public multiples for high-growth infrastructure softwareObservability, not API tooling; multiple reflects a very different growth/margin profile
IBM / Confluent (M&A)Acquisition price / revenue run rate$11B / >$1B run rate -> ~11xRecent large data-infrastructure M&A comp showing strategic-buyer appetite for platform assetsConfluent is a data-streaming platform, not an API-lifecycle tool; deal terms are strategic, not pure financial

No single public or private peer matches Postman's product mix and disclosure profile; the table blends direct pricing, a competitor financing, a PE-owned adjacent vendor, three public comps, and one M&A anchor to bound the discussion.

[CV013, CV020, CV027, CV029, CV030, CV031]

8.6 Exit Readiness and Final Diligence Asks

Postman shows no public exit-readiness signal as of the July 2026 access date. Its own press-media page lists product and partnership announcements through April 2026 with no IPO reference, a dedicated third-party IPO tracker returned a bot-blocked response rather than usable data, and an SEC EDGAR company-name search restricted to Form S-1 returned no matching filer or filing. That absence of evidence is itself evidence worth recording, not a basis for assuming an IPO is either imminent or ruled out. The kill-trigger table in this chapter lays out six concrete, monitorable thresholds -- a below-$2.0 billion primary print, disclosed revenue below the bear-case floor, two more years with no capital event, a materially wider secondary discount, a compounding governance or security event, or a confirmed IPO filing -- any of which should move the recommendation in a specific direction rather than triggering a vague reassessment. The final diligence asks table converts the chapter's open questions into concrete requests: audited or management-reviewed revenue reconciling the two conflicting 2024 estimates, a current cap table and preference-stack summary, confirmation of any 2025-2027 primary financing or tender, retention and concentration metrics, AI-feature monetization proof, and any signal of IPO or strategic-exit intent. Closing even two or three of these would materially sharpen this chapter's confidence level on the next refresh.[CV039, CV041, CV042, CV043, CV044, CV052]

Thesis-break and kill triggers table
TriggerThresholdTransmission to thesisAction implication
New primary round or tender priced below current secondary clusterBelow ~$2.0B post-moneyConfirms the market, not just secondary trackers, has repriced the company downwardReassess valuation stance toward 'expensive' and revisit position sizing
Disclosed revenue materially below the low estimateBelow ~$120M ARR for FY2025/2026Undercuts even the bear-case revenue assumption used in this chapter's sensitivity rangeMove recommendation toward avoid pending a fuller revenue reconciliation
No capital event or audited disclosure through 202724+ further months with zero new financing/disclosure signalExtends the disclosure gap that already prevents a price-committed callMaintain track/research-more; do not upgrade recommendation on time alone
Secondary discount widens materially beyond current rangeDiscount exceeds ~50% to the 2021 mark on a fresh printWould put Postman closer to or beyond the PitchBook 2021-vintage average markdownTreat as confirmation of the bear scenario and reweight probability accordingly
Governance or security event compounds beyond current risk recordA new material breach, litigation loss, or leadership departureWould add to the risks chapter's existing cluster of medium-severity exposures and could impair enterprise trustEscalate risk rating to high/critical and pause any new commitment
Confirmed IPO filing or roadshow announcementAn S-1 filing or public roadshow disclosureWould replace this chapter's disclosure gaps with audited, regulator-reviewed dataRe-run this valuation chapter's analysis entirely once filing-grade data exists

Triggers are framed as public-evidence thresholds an investor could monitor; none has occurred as of the July 2026 access date.

[CV042, CV044, CV021, CV024]
Final diligence asks table
TopicMissing evidenceWhy it mattersDiligence path / owner
Audited or management-reviewed revenueGAAP revenue, ARR by segment, and a reconciliation of the $120-150M vs. $313.1M 2024 estimatesDetermines which end of the valuation-sensitivity range is realisticRequest via management data room or a signed NDA-covered financial package
Cap table and liquidation preferenceCurrent board composition, preference stack, dividend and participation termsChanges realized common-equity payout in any downside or acquisition scenarioRequest cap-table summary from company counsel or via a secondary-market intermediary with data access
Confirmed 2025-2027 primary financing or tenderAny priced round, structured financing, or company-run tender since the 2021 Series DWould replace stale 2021 pricing and thin secondary-tracker estimates with a market-clearing signalMonitor SEC EDGAR, press releases, and secondary-market platforms; ask company IR directly
Retention and expansion metricsNet revenue retention, logo retention, and customer concentration by segmentValidates whether the higher GetLatka revenue trajectory is durable or front-loaded by one-time expansionRequest cohort-level retention data or a customer-reference call program
AI-feature monetization proofAdoption, ARPU uplift, or attach-rate data for Agent Mode / AI EngineerTests whether recent AI investment is defending or expanding the moat versus commoditizing pricingRequest product-usage telemetry or a management Q&A focused specifically on AI-feature monetization
IPO or strategic-exit intentAny internal timeline, banker engagement, or roadshow planning signalDetermines whether a near-term liquidity event is realistic for return-modeling purposesAsk management or board-adjacent sources directly; monitor EDGAR S-1 filings each quarter

Asks are ordered by how directly they would move the valuation range in this chapter, not by ease of collection.

[CV043, CV044, CV039, CV042]

8.7 Exhibits

Disclaimer

This report relies only on public sources reviewed through 2026-07-20 and is not a substitute for management diligence, customer calls, legal review, or access to private financial materials.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Postman was founded in 2014. High SO001, SO010
CO002 Postman was founded in Bangalore and is now headquartered in San Francisco. High SO001, SO002
CO003 Abhinav Asthana founded Postman and remains its CEO. High SO001, SO010
CO004 Ankit Sobti and Abhijit Kane were recruited by Asthana early and still lead the company as co-founders. Medium SO001, SO010
CO005 Craft lists Zac Auger as Postman's chief revenue officer. Medium SO010
CO006 Postman describes itself as an API platform for building and using APIs. High SO001, SO003
CO007 The current platform spans API design, testing, distribution, documentation, monitoring, and governance. Medium SO003
CO008 Postman says more than 40 million users or developers use the platform. High SO012, SO020
CO009 Postman says 500,000 organizations use the platform. High SO001, SO020
CO010 Postman says 98% of the Fortune 500 are customers. High SO001, SO020
CO011 Postman closed a $225 million Series D round in August 2021 at a $5.6 billion valuation. High SO007, SO008
CO012 Insight Partners led the 2021 Series D round, with Coatue, Battery Ventures, and BOND joining alongside CRV and Nexus Venture Partners. High SO007, SO008
CO013 Public databases put Postman's total funding at roughly $433 million. Medium SO009, SO010
CO014 Postman's last publicly disclosed primary valuation is still the 2021 $5.6 billion Series D mark. Medium SO007, SO009
CO015 Economic Times reported in 2024 that recent Postman secondary transactions cleared at a 30-40% discount to the 2021 peak valuation. Medium SO014
CO016 Economic Times reported that people aware of Postman's financials estimated ARR at $120-150 million in 2024. Medium SO014
CO017 GetLatka estimated Postman's 2024 revenue at $313.1 million after estimating 2023 revenue at $171.7 million. Medium SO009
CO018 The Economic Times ARR estimate and GetLatka revenue estimate describe materially different monetization levels and cannot be reconciled from public disclosures alone. Medium SO009, SO014
CO019 LinkedIn showed 3,523 employees on Postman's company page on July 16, 2026. Medium SO012
CO020 Postman publicly lists offices in San Francisco, Bangalore, and Tokyo and says distributed team members span multiple continents. High SO001, SO002
CO021 Business Wire reported in July 2025 that Postman opened a new San Francisco headquarters to accelerate growth and innovation. Medium SO019
CO022 Postman's 2025 State of the API report surveyed more than 5,700 developers, architects, and executives. High SO005, SO006
CO023 The 2025 State of the API report found that APIs are increasingly treated as the foundation for AI-agent adoption. Medium SO005, SO006
CO024 The 2025 State of the API report says 65% of organizations generate revenue from their API programs. Medium SO005, SO006
CO025 The 2025 State of the API report says 74% of API-revenue-generating organizations derive at least 10% of total company revenue from APIs. Medium SO005, SO006
CO026 The 2025 State of the API report says 70% of developers are aware of MCP but only 10% use it regularly. Medium SO005, SO006
CO027 TechCrunch reported that Postman launched AI Agent Builder in January 2025 on top of its API platform. Medium SO013
CO028 Postman announced Agent Mode in June 2025 as an AI-native assistant that can build, test, and debug APIs in natural language. Medium SO015, SO004
CO029 Postman acquired Orbit in April 2024 to strengthen developer-community engagement around APIs. Medium SO016
CO030 Postman acquired liblab in November 2025 to expand from API collaboration into SDK generation across the API lifecycle. Medium SO017
CO031 Postman acquired Fern in January 2026 to add docs-as-code and production-ready SDK generation for developer experience. Medium SO018
CO032 Postman's trust portal says a compromised Klue integration led to exfiltration of customer contact data and sales information from Salesforce on June 11-12, 2026. Medium SO021
CO033 CloudSEK reported that more than 30,000 publicly accessible Postman workspaces exposed tokens, keys, or other sensitive data in late 2024. Medium SO023, SO025
CO034 Treblle summarized the same workspace exposure episode as a signal that public-collaboration defaults can create secrets-management risk. Medium SO022
CO035 CloudSEK wrote that Postman later added secret-protection alerts and guidance for moving exposed assets to private or team workspaces. Medium SO023
CO036 Postman's status page showed core browser, login, monitor, mock, API, and documentation services operational at the time of review, with desktop reporting 100.0% uptime over the last 90 days. Medium SO024
CO037 Craft describes Postman as a private, active company. Medium SO010
CO038 Postman's pricing page lists Free, Solo, Team, and Enterprise plans, showing monetization beyond a pure free developer tool. Medium SO004
CO039 In its 2021 Series D announcement, Postman said the platform had 17 million developers and more than 60 million app downloads at that time. Medium SO007
CO040 Public evidence does not disclose Postman's board composition, preferred-share terms, or full cap table. Low
CM001 Postman competes in a broad API lifecycle platform market rather than only the narrow API-client segment. Medium SM004, SM006, SM007
CM002 The practical market boundary around Postman includes design, testing, documentation, collaboration, distribution, monitoring, and governance. Medium SM004, SM006
CM003 The Business Research Company sized the global API management market at $5.24 billion in 2025 and projected $20.89 billion by 2030 at a 31.8% CAGR. Medium SM010
CM004 Strategic Market Research sized the API management market at $5.6 billion in 2024 and $15.1 billion by 2030 at an 18.2% CAGR. Medium SM011
CM005 Fortune Business Insights sized the market at $6.89 billion in 2025 and projected $37.43 billion by 2034. Medium SM012
CM006 Mordor Intelligence sized the market at $8.86 billion in 2025 and projected $22.11 billion by 2031. Medium SM013
CM007 The spread across third-party market-size estimates indicates that API management and API lifecycle boundaries remain definition-sensitive rather than precise. Medium SM010, SM011, SM012, SM013
CM008 Postman's 2025 State of the API survey covered more than 5,700 developers, architects, and executives. High SM001, SM002
CM009 The same survey says testing is the most common API activity at 81%, followed by development at 73% and documentation at 58%. High SM001, SM002
CM010 Postman says 65% of organizations generate revenue from APIs. High SM001, SM002
CM011 Among organizations that generate API revenue, Postman says 74% derive at least 10% of total company revenue from APIs. High SM001, SM002
CM012 Postman says 70% of developers are aware of MCP but only 10% use it regularly. High SM001, SM002
CM013 Postman says 93% of teams struggle with API collaboration, creating duplicated work, delays, and degraded quality. High SM001, SM002
CM014 Postman says 51% of developers cite unauthorized agent access as a top security risk in the AI era. High SM001, SM002
CM015 Postman's security report says it surveyed 246 security professionals about API risk and AI readiness. Medium SM003
CM016 The security report frames AI-agent readiness, API revenue impact, and governance at scale as the top themes for security leaders. Medium SM003
CM017 Postman's product page frames the category as a unified platform for designing, testing, distributing, documenting, and monitoring APIs. Medium SM004
CM018 The API Repository page positions discoverability, versioning, and a private API network as buying criteria for larger organizations. Medium SM006
CM019 The Flows page positions visual workflow execution and fast onboarding as value for cross-functional teams, not just backend developers. Medium SM007
CM020 Postman's packaging from Free to Solo, Team, and Enterprise implies a market spanning individual developers through enterprise platform buyers. Medium SM005
CM021 TechCrunch described Postman's AI Agent Builder as combining large language models, APIs, and flows to let users build functional agents. Medium SM009
CM022 Postman's own 2025 product repositioning argues that humans and agents will work together across the software development lifecycle. Medium SM008
CM023 Swagger markets an integrated solution for AI-ready API design, testing, and documentation, showing that API design remains a major adjacent spend pool. Medium SM014, SM015
CM024 Insomnia markets open-source and free-tier workflows, unlimited collection running, and a local-only scratch pad with no login required. Medium SM016, SM017
CM025 Bruno positions itself as a free, open-source, git-native API client that requires no account. Medium SM020, SM021
CM026 Stoplight packages visual design, interactive docs, and instant mock servers for individuals at $44 per month and small teams at $113 per month. Medium SM018, SM019
CM027 Kong's pricing page shows that gateway-oriented API programs are often bought on infrastructure-style metrics such as gateway count rather than per-seat collaboration. Medium SM024
CM028 ReadyAPI positions low-code automated testing across REST, SOAP, Kafka, JDBC, and JMS, underscoring that API testing alone is its own adjacent budget line. Medium SM023
CM029 Hoppscotch positions itself as an open-source API development ecosystem, reinforcing low-end tool abundance in the category. Low SM022
CM030 Public reviews show some users believe features that used to be free are increasingly pushed into paid plans. Medium SM025
CM031 Public reviews also flag that Postman can feel slow or overwhelming with large collections or on weaker machines. Medium SM025
CM032 Software Advice reviews describe Postman as strong for API functional testing but still sometimes difficult to debug. Medium SM026
CM033 The combination of Insomnia, Bruno, Hoppscotch, and similar tools means the low end of the API-client market is under real commoditization pressure. Medium SM016, SM020, SM022
CM034 The combination of Swagger, Stoplight, Kong, and ReadyAPI shows that enterprise buyers do not purchase a single API market category; they assemble capabilities across design, governance, gateway, and testing. Medium SM014, SM019, SM023, SM024
CM035 Postman's differentiated market claim is strongest when API collaboration and shared lifecycle context matter more than local request execution alone. Medium SM004, SM006, SM007, SM016, SM020
CM036 The API market tailwind depends heavily on enterprises treating APIs as durable products with governance, reuse, and monetization goals rather than one-off technical artifacts. Medium SM001, SM002, SM004
CM037 Open public evidence does not cleanly separate SMB versus enterprise contribution inside Postman's paying base. Low
CP001 Postman competes across a wider API lifecycle surface than a simple request client. Medium SP001, SP003, SP004
CP002 TechCrunch identified Stoplight and Kong as named competitors to Postman as early as the 2021 Series D coverage. Medium SP007
CP003 Swagger positions SwaggerHub as an integrated solution for API design, testing, and documentation. Medium SP009, SP010
CP004 Insomnia markets itself as an open-source platform with local, Git, or cloud workflows. Medium SP011, SP012
CP005 Insomnia’s free forever local-only Scratch Pad and no-login workflow target buyers who want to avoid SaaS lock-in. Medium SP011, SP012
CP006 Stoplight sells API design workflows with interactive docs and instant mock servers. Medium SP013
CP007 Bruno markets a git-native API client that is free, open source, and requires no account. Medium SP014, SP015
CP008 Hoppscotch markets itself as an open-source API development ecosystem. Low SP016
CP009 ReadyAPI positions itself as a low-code automated testing platform spanning REST, SOAP, Kafka, JDBC, and JMS. Medium SP017
CP010 Kong’s pricing model is infrastructure-oriented, with a free trial followed by gateway-based charging rather than seat-based collaboration pricing. Medium SP019
CP011 GitLab positions itself as an intelligent orchestration platform for DevSecOps with a Duo Agent Platform layered into pricing tiers. Medium SP020
CP012 GitLab’s FY2026 Q4 release said the company crossed $1 billion in ARR, showing the scale of adjacent platform-suite competition. Medium SP026
CP013 Postman’s own packaging remains relatively accessible at Free, $9 Solo, $19 Team, and $49 Enterprise list pricing. Medium SP002
CP014 Stoplight’s pricing starts at $44 per month for an individual Basic plan and $113 per month for Startup teams, indicating a design-first premium. Medium SP013
CP015 Kong’s pricing shows API runtime programs can be bought on infrastructure count rather than per-user collaboration. Medium SP019
CP016 Postman’s strongest differentiator is a combination of shared collections, repository visibility, documentation, testing, and workflow execution in one surface. Medium SP001, SP003, SP004
CP017 Agent Mode extends Postman’s competition from human API workflows into AI-assisted execution and debugging. Medium SP005
CP018 AI Engineer positions Postman to compete on agentic engineering context, not just API request tooling. Medium SP006
CP019 TechCrunch and I Programmer both framed AI Agent Builder as a material Postman expansion into agent building on top of APIs. High SP008, SP025
CP020 TrustRadius describes Postman as free for small teams and independent developers while reserving higher tiers for broader API management and collaboration. Medium SP021
CP021 G2 reviews say features that used to be free increasingly require paid plans. Medium SP023
CP022 G2 reviews also say the app can feel slow or overwhelming when collections become large. Medium SP023
CP023 Software Advice reviews still describe Postman as strong for functional API testing, but sometimes difficult to debug. Medium SP024
CP024 Trustpilot includes severe negative user anecdotes, including claims of scrambled cloud-synced collection content and deleted environments. Low SP022
CP025 Bruno and Insomnia make clear that low-end request execution is already commoditized by free or open-source alternatives. Medium SP011, SP014, SP015
CP026 Stoplight and SwaggerHub show that design and documentation can be bought from focused specialists without adopting Postman end to end. Medium SP009, SP013
CP027 Kong and GitLab show that upper-end competition can come from broader platforms that bundle API-adjacent needs into infrastructure or DevSecOps contracts. Medium SP019, SP020, SP026
CP028 Postman’s scale claims of 40M+ users and 500,000 organizations give it a distribution advantage that most niche API tools cannot match publicly. Medium SP001, SP007
CP029 TechCrunch’s 2025 AI-builder coverage suggests Postman is using its installed base to move faster into AI-centric API workflows than point-tool rivals. Medium SP008
CP030 Postman’s repository and workflow layers matter because they create switching cost above the request-client level. Medium SP003, SP004, SP005
CP031 SwaggerHub is likely the strongest design-first rival for teams that care more about specification governance and developer portals than execution context. Medium SP009, SP010
CP032 Insomnia, Bruno, and Hoppscotch are the clearest local-first or open-source substitutes for cost-sensitive teams. Medium SP011, SP014, SP016
CP033 Kong is the clearest infrastructure-centric adjacent rival because its pricing and positioning revolve around gateways and connectivity rather than collaboration seats. Medium SP019
CP034 GitLab is the clearest suite-bundling rival because its platform can absorb API workflows into a larger DevSecOps standardization motion. Medium SP020, SP026
CP035 Public sources do not reveal objective head-to-head win rates, net retention by competitor, or segment-level churn against any rival. Low
CP036 The most credible moat risk is not one knockout rival but fragmentation: point tools can peel off design, testing, gateway, or local-client budgets independently. Medium SP009, SP011, SP017, SP019
CP037 The most credible moat strength is that Postman unifies context across human users and emerging agent workflows in one platform. Medium SP001, SP005, SP006, SP008
CI001 Postman publicly monetizes through Free, Solo, Team, and Enterprise plans plus AI-related overages. Medium SI001
CI002 The 2026 Free plan is positioned for solo usage rather than multi-user collaboration. High SI001, SI026, SI027
CI003 The Solo plan is listed at $9 per user per month when billed annually. High SI001, SI026
CI004 The Team plan is listed at $19 per user per month when billed annually. High SI001, SI026, SI027
CI005 The Enterprise plan is listed at $49 per user per month when billed annually and includes higher pooled AI credits plus organization controls. High SI001, SI002, SI026
CI006 Postman Enterprise positions the platform as trusted by over 40 million developers and 98% of the Fortune 500. Medium SI002
CI007 Postman's enterprise messaging explicitly frames partner APIs as a revenue-scaling surface for customers. Medium SI002
CI008 Workspaces are presented as the collaborative layer where teams build, test, and distribute APIs together. Medium SI015
CI009 The API Repository is described as a cloud-based, version-controlled centralized store for API artifacts. Medium SI016
CI010 Flows is positioned as executable workflow documentation that teams can inspect, run, debug, and clone. Medium SI017
CI011 Agent Mode is positioned as a team productivity and test-generation aid for building AI-ready APIs. Medium SI018
CI012 Postman's 2025 State of the API report says 65% of organizations generate revenue from their API programs. Medium SI005
CI013 Postman's 2025 State of the API report says 93% of teams struggle with API collaboration. Medium SI005
CI014 Postman says it serves more than 500,000 organizations. High SI003, SI022
CI015 LinkedIn currently exposes a 3,523-employee view on the Postman company page while also showing a company-size band of 501-1,000 employees, indicating that public headcount signals are noisy. Medium SI022
CI016 TrustRadius reviews highlight collaboration, shared workspaces, and test automation as valued parts of the product. Medium SI024, SI028
CI017 G2 reviews repeatedly praise collections, environments, and team collaboration as reasons users keep Postman in daily workflows. Medium SI025
CI018 G2 reviews also complain about pricing creep, heavier performance, and the migration of collaboration features into paid tiers. Medium SI025
CI019 Competitor commentary from Apidog and Dev Tools describes the 2026 packaging change as pushing any real multi-user collaboration into paid plans. Low SI026, SI027
CI020 The public conversion story is therefore strongest where shared workflow pain becomes expensive enough to justify a team platform, not where single developers only need a free client. Medium SI001, SI005, SI015, SI024, SI025
CI021 Postman closed a $225 million Series D at a $5.6 billion valuation in August 2021. High SI004, SI021
CI022 GetLatka, Craft, and Tracxn cluster Postman's lifetime funding around roughly $433 million to $434 million. Medium SI006, SI008, SI011
CI023 Tracxn says Postman has raised about $434 million over six rounds, with the latest round being Series D in August 2021. Medium SI011
CI024 GetLatka estimates Postman generated $313.1 million of revenue in 2024. Medium SI006
CI025 GetLatka estimates Postman generated $171.7 million of revenue in 2023. Medium SI006
CI026 GetLatka estimates Postman generated $102.7 million of revenue in 2022. Medium SI006
CI027 GetLatka also lists Postman at roughly $52 million of revenue in 2021. Medium SI006
CI028 Those Latka estimates imply very fast scaling from 2022 through 2024 even if absolute precision is uncertain. Medium SI006
CI029 Growjo publishes a much higher forward estimate of roughly $506.1 million annual revenue and about 2,212 employees. Low SI009
CI030 The Economic Times reported that recent secondary deals cleared at a 30-40% discount to Postman’s 2021 valuation. Medium SI010
CI031 The Economic Times also cited people aware of Postman’s financials who estimated annualized recurring revenue at only $120-150 million. Medium SI010
CI032 Public revenue and ARR estimates for Postman are inconsistent enough that outside investors cannot reconcile the company’s current monetization scale from open sources alone. Medium SI006, SI009, SI010, SI012, SI013
CI033 Craft still shows an older $2 billion market valuation snapshot alongside $433 million of total funding, underscoring how stale private-company databases can be on valuation marks. Low SI008
CI034 Premier Alternatives shows a current valuation field around $3.3 billion while PM Insights and other trackers frame the current mark very differently, reinforcing illiquid price discovery. Low SI012, SI013
CI035 The live product record shows no evidence of inventory, manufacturing, project finance, or other hardware-style capital demands. Medium SI002, SI015, SI016, SI017
CI036 Postman therefore appears structurally capex-light relative to software businesses that require physical fulfillment or financing assets. Medium SI002, SI015, SI016, SI017
CI037 GitLab's 2026 SEC companyfacts show roughly $955.2 million of revenue and $834.5 million of gross profit for the year ended January 31, 2026. Medium SI020
CI038 Those GitLab facts imply gross margin of roughly 87% for a scaled public devtools SaaS benchmark. Medium SI020
CI039 GitLab's 2026 SEC companyfacts also show about $434.7 million of selling and marketing expense and $274.6 million of R&D expense, illustrating that scaled devtools SaaS can remain people-intensive even when gross margins are high. Medium SI020
CI040 No public source reviewed disclosed Postman’s current cash balance, burn, debt, net revenue retention, or runway. Medium SI003, SI004, SI008, SI011
CE001 Postman currently defines itself as a unified platform for designing, testing, distributing, documenting, and monitoring APIs. High SE001, SE015
CE002 The marketed product surface includes API client, design, documentation, collaboration, distribution, testing, monitoring, security, governance, and AI. Medium SE001
CE003 The API Repository is positioned as a cloud-based, version-controlled central source of truth for API artifacts. High SE002, SE026
CE004 The API Builder supports design workflows across OpenAPI, GraphQL, and RAML and can keep assets aligned with source code through native Git support. High SE002, SE014
CE005 The Private API Network is positioned as an internal catalog with versioning and visibility controls for team or organizational APIs. High SE002, SE028
CE006 The Public API Network is positioned as a large public API discovery hub built on public workspaces. Medium SE002
CE007 Collections remain the fundamental container object in Postman for grouping requests, responses, and workflow assets. High SE006, SE011
CE008 Variables and environments are a first-class mechanism for scoping the same workflow across local, test, and production contexts. High SE007, SE020
CE009 Postman publicly publishes the Collection schema, and v2.1.0 is listed as a stable schema version. High SE008, SE011
CE010 The Postman Collection SDK is a Node.js module for creating, manipulating, and exporting collections outside the main UI. Medium SE011
CE011 The openapi-to-postmanv2 package exists as a published conversion layer from OpenAPI into Postman collections. High SE012, SE026
CE012 Newman is the command-line collection runner for Postman and is designed for CI and automation use cases. High SE009, SE010, SE024, SE025
CE013 Newman is built on Node.js and can run collections from exported JSON files or collection URLs. Medium SE025
CE014 Newman can fetch and run a collection through the Postman API inside a CI environment. High SE024, SE026, SE027
CE015 Newman cannot execute package-library scripts from the command line, which leaves some modern workflow execution to the Postman CLI. Medium SE025
CE016 The Postman API exposes programmatic management for collections, environments, monitors, specs, workspaces, pull requests, roles, and other core assets. Medium SE026
CE017 The Postman API also exposes higher-end surfaces including API Catalog, API Governance, Audit Logs, Private API Network, SCIM, SDKs, Secret Scanner, and Service Accounts. High SE026, SE028
CE018 Flows turns workflow documentation into an executable artifact that teams can inspect, run, debug, and clone. Medium SE003
CE019 Flows can generate an initial workflow from a prompt and is explicitly framed as a way to make APIs easier for AI agents to consume. Medium SE003, SE022
CE020 Agent Mode uses collections, specs, environments, and history as grounded context for natural-language API work. Medium SE004
CE021 Agent Mode can fix broken requests, write tests, generate docs, organize collections, and otherwise act directly on Postman assets. High SE004, SE015
CE022 AI Engineer is positioned as a higher-level agentic teammate with an always-on context graph across APIs and services. High SE005, SE015
CE023 AI Engineer is designed to run in a secure sandbox and route output through human approval and existing review queues. Medium SE005
CE024 Postbot is Postman’s AI assistant for troubleshooting requests, writing tests and documentation, visualizing data, and helping users navigate docs. Medium SE023
CE025 Postbot documentation says Enterprise teams get dedicated infrastructure and that Postbot inputs and outputs are not used to train Postman’s AI models. Medium SE023
CE026 Postman’s March 2026 roadmap introduced an API Catalog, native Git workflows, local and CI mock servers, multi-protocol support, and a unified workbench. High SE014, SE015
CE027 The new Postman platform says Collections, specs, environments, mocks, flows, and files can now live together in a unified workbench. Medium SE015
CE028 Postman says it now supports HTTP, GraphQL, gRPC, MCP, MQTT, WebSockets, and AI requests in the same collection. Medium SE015
CE029 The platform now uses a new Collection v3 format to make local, code-adjacent workflows more practical. Medium SE015
CE030 The API Catalog is described as a live operational layer tied to where APIs are built, tested, and observed rather than a static registry. High SE014, SE015, SE028
CE031 Postman security disclosures include API key management, 180-day audit logs, and 2FA. Medium SE016
CE032 Postman says it complies with the EU-U.S., UK, and Swiss data privacy frameworks and hosts customer data and backups on AWS in the EU and U.S. Medium SE016
CE033 The shared responsibility model means Postman provides platform controls while expecting customers to safeguard their own data and credentials in use. Medium SE016
CE034 The trust portal shows that Postman publicly documents subprocessor changes and the 2026 Klue-related incident affecting Salesforce-connected sales data. Medium SE017
CE035 Reviews on G2, TrustRadius, and Software Advice consistently praise request organization, automation, and documentation workflows. Medium SE018, SE019, SE020
CE036 The same review sources also surface platform heaviness, complexity growth, and paid-feature creep as meaningful product tradeoffs. Medium SE018, SE020
CE037 TechCrunch and I Programmer both framed the 2025 AI agent builder launch as a major expansion of Postman beyond a request client. High SE013, SE021
CE038 Developer-signal artifacts such as the Newman repo, npm packages, published schemas, and GitHub Actions tutorials show that Postman has built an ecosystem around its collection format rather than a closed GUI-only tool. Medium SE008, SE009, SE010, SE011, SE012, SE027
CE039 Much of Postman’s advanced value still depends on cloud-managed state, central catalogs, and workspace permissions even as Git-native workflows expand. Medium SE002, SE014, SE015, SE026
CE040 Public product materials still leave technical diligence gaps around model-serving architecture, detailed data residency boundaries, and internal reliability SLOs. Medium SE005, SE016, SE017
CU001 Postman’s customer stories directory says 40 million developers and 500,000 companies rely on the platform. High SU002, SU010
CU002 Postman’s about page says more than 500,000 organizations use Postman. High SU001, SU010
CU003 The enterprise page says Postman is trusted by over 40 million developers and 98% of the Fortune 500. High SU011, SU010
CU004 Postman’s 2021 Series D announcement said the platform had 17 million developers and customers such as Salesforce, Stripe, Kroger, Cisco, and PayPal. Medium SU012
CU005 Public sources imply Postman serves multiple customer constituencies at once: internal developers, QA and platform teams, partner engineers, and external public API consumers. Medium SU002, SU005, SU024, SU025, SU026, SU028
CU006 Landbase says 3,906 verified companies use Postman and that usage is broad across industries and geographies. Medium SU008
CU007 Landbase still describes Postman as used by 25 million developers, which lags the company’s more recent 40 million figure and shows that third-party customer databases can be stale. Medium SU008, SU002, SU010
CU008 Ramp says Postman ranks #2 in its DevOps category and is used by 13% of organizations in that category, with 26% adoption among enterprise companies. Medium SU009
CU009 Workspace reports and analytics documentation show that Postman tracks active users, active workspaces, API requests, response codes, partner funnels, and AI usage over time. High SU005, SU006
CU010 Public workspace metrics are available to all plans, while broader reports sit behind enterprise plans. High SU004, SU005
CU011 The analytics API includes customer-relevant metrics for partner engagement funnels, success rates, API distribution, and API testing runs. Medium SU006
CU012 The workspace reports documentation explicitly defines a partner onboarding funnel from total partners to successful API responses. Medium SU005
CU013 PayPal says Postman reduced time to first call from hours to one minute. Medium SU003
CU014 PayPal says testing time fell to minutes from hours and that enterprise users save roughly one hour of developer time per week. Medium SU003
CU015 PayPal says its public Postman collection has more than 30,000 forks and ranks number seven among the top ten collections on the Postman Public API Network. Medium SU003
CU016 PayPal also says thousands of its developers use Postman daily and that workspaces and collections have become everyday vocabulary inside the company. Medium SU003
CU017 Autodesk says partner API requests rose from 40 million per year to 60 million per month after its Postman-centered workflow scaled. Medium SU024
CU018 Autodesk says time to first call fell to three minutes and that it onboarded over 200 global partners to PWS APIs using workspaces. Medium SU024
CU019 Autodesk’s external APS documentation shows that its OpenAPI specs can be imported directly into Postman to generate usable collections. Medium SU014
CU020 Medibank says Postman reduced testing cycle times by 70% and accelerated feature releases by three weeks. Medium SU025
CU021 Medibank says it standardized Postman across development and QA, embedded tests into CI/CD, and connected collections to GitHub for branched reviews. Medium SU025
CU022 HubSpot says total API calls on Postman increased by 104% in six months while it used a public workspace as a central source of truth for developers. Medium SU026
CU023 HubSpot says workspace reports are used to collect API adoption metrics and that Run in Postman buttons are attached to organized collections. Medium SU026
CU024 ZEISS says hundreds of test cases can now be run in one minute and that shared workspaces and mock servers accelerated development. Medium SU027
CU025 ZEISS also says it uses SSO, SCIM, domain capture, and enterprise governance because it operates in a highly regulated environment. Medium SU027
CU026 Cover Genius says Postman cut API configuration time by 50% and doubled efficiency in partner integrations. Medium SU028
CU027 Cover Genius says Partner Workspaces, Newman, and audit trails improved partner onboarding, testing, and security. Medium SU028
CU028 Box developer docs maintain an official Postman collection with more than 170 API endpoints organized by resource type. Medium SU015
CU029 Microsoft Graph docs tell users to fork the official collection into a private workspace and explicitly warn against using a public workspace for sensitive credentials. Medium SU016
CU030 The broadest public customer proof is strongest for API-centric and partner-heavy organizations such as PayPal, Autodesk, HubSpot, ZEISS, Medibank, and Cover Genius. Medium SU003, SU024, SU025, SU026, SU027, SU028
CU031 Public evidence for durability is indirect: forks, API-call growth, partner onboarding funnels, and shared-workspace reuse are visible, but NRR, GRR, and contract length are not. Medium SU003, SU005, SU006, SU026
CU032 Reviews across G2, TrustRadius, and Software Advice are broadly positive on organization, collaboration, and documentation. Medium SU017, SU018, SU019
CU033 The same review sources surface heaviness, complexity, and paid-feature creep as real friction points for teams. Medium SU017, SU019
CU034 Expansion appears to follow a land-and-expand pattern through public workspaces, partner workspaces, GitHub or CI integration, monitoring, and enterprise governance. Medium SU003, SU024, SU025, SU026, SU027, SU028
CU035 No public source reviewed indicates material single-customer concentration; the visible logo set spans payments, healthcare, manufacturing, optics, SaaS, and insurtech. Medium SU003, SU024, SU025, SU026, SU027, SU028
CU036 Procurement friction likely exists for smaller teams because collaboration increasingly sits behind paid tiers and because the platform can feel heavy for basic needs. Medium SU017, SU019, SU023
CU037 The API Network and Integrations directory make discoverability itself part of Postman’s customer acquisition surface for API publishers and consumers. High SU021, SU022
CU038 The 2026 platform relaunch consolidated internal, partner, and public workspace analytics, reinforcing that multi-sided customer behavior is central to the product. High SU020, SU023
CU039 The State of the API report’s finding that 65% of organizations generate revenue from API programs helps explain why customer stories focus on onboarding, governance, and partner distribution rather than only on request sending. Medium SU013
CU040 Public evidence is still insufficient to estimate logo churn, NRR, GRR, or typical contract duration by segment. Medium SU005, SU006, SU017
CR001 Postman publicly discloses Local Vault, Vault Integrations, API key management, audit logs, and 2FA as security controls. Medium SR001
CR002 Postman says audit logs retain key security-access and team-management activity for 180 days. Medium SR001
CR003 Postman says it runs a private bug bounty program with HackerOne. Medium SR001
CR004 Postman explicitly frames security as a shared-responsibility model in which customers must safeguard their own data and credentials in use. Medium SR001
CR005 Postman says it complies with the EU-U.S., UK, and Swiss Data Privacy Frameworks, uses AWS-hosted infrastructure in the EU and U.S., and offers a 99.9% enterprise SLA. Medium SR001, SR020
CR006 The trust portal says a third-party provider, Klue, triggered a 2026 incident affecting Salesforce-connected sales data rather than core platform services. Medium SR002
CR007 The trust portal also publishes subprocessor notices and gives customers a short objection window on data-protection grounds. Medium SR002
CR008 Postman’s legal hub includes AI Terms, Professional Services Terms, Website Terms of Use, workshop terms, and archived contract versions. Medium SR003
CR009 The legal archives page shows repeated updates to Terms of Service, Product Terms, and AI Terms across 2025. Medium SR005
CR010 California’s CCPA creates rights and breach-related legal consequences when nonencrypted personal data is exposed because a business failed to maintain reasonable security. Medium SR019
CR011 The official Data Privacy Framework site confirms the regulatory framework Postman cites, which means any future adequacy or certification drift would directly affect its public compliance claims. Medium SR020, SR001
CR012 The status page shows a wide operational footprint that includes login, monitors, mocks, API Network, search, docs, integrations, Postbot, CLI, API Builder, and Agent Mode. Medium SR006
CR013 The status page also shows 100% desktop-platform uptime over the trailing 90-day window captured during this review. Medium SR006
CR014 CloudSEK says its year-long investigation found more than 30,000 publicly accessible Postman workspaces exposing sensitive information such as access tokens, refresh tokens, API keys, and test data. Medium SR007, SR008
CR015 CloudSEK describes practical impacts ranging from PII leaks and admin credential exposure to payment-key abuse and refresh-token hijacking. Medium SR007
CR016 Truffle Security says at least 4,000 live secrets are currently leaking on Postman and that its sample found 1,689 live unique credentials across about 40,000 workspaces. Medium SR009
CR017 Truffle also says 16% of public OpenAI forks and 20% of Pynt forks contained live credentials. Medium SR009
CR018 Truffle attributes the exposure problem to public forks, confusing Initial vs Current value semantics, misleading “secret” variable labels, and insufficient default secret-scanning enforcement. Medium SR009
CR019 AppSentinels argues that public Postman workspaces can be indexed like normal webpages, turning a collaboration feature into an attack-discovery surface even without any platform breach. Medium SR010
CR020 InfoSec Write-ups presents a practical secret-scanning workflow for exposed Postman APIs, reinforcing that the issue is operationally exploitable rather than merely theoretical. Medium SR011
CR021 UpGuard and Panorays both maintain ongoing vendor-risk surfaces for Postman, indicating that third-party monitoring of its security posture is persistent. Medium SR012, SR013
CR022 Bruno positions itself as open-source, Git-native, offline-only, and explicitly anti-cloud-sync. High SR014, SR015
CR023 Bruno stores collections as plain text on the filesystem and supports Git-based collaboration and CLI execution, directly challenging Postman’s workspace-centric model. High SR014, SR015
CR024 Insomnia now markets local, Git, or cloud storage options, no-login scratch pad, SCIM/SAML/OIDC identity controls, MCP support, and an AI-native workflow. Medium SR016
CR025 Thunder Client markets itself as a lightweight local-storage VS Code extension with Git sync and CLI support. Medium SR017
CR026 GitHub Copilot extends AI automation pressure from a much broader developer platform than Postman’s single-product surface. Medium SR018
CR027 Postman’s 2026 product launches made AI, native Git workflows, API Catalog, and a unified workbench central to the platform. High SR026, SR027
CR028 Agent Mode can act across collections, specs, environments, and history, which raises the importance of permission boundaries and review controls. Medium SR029
CR029 The Postman API now exposes Secret Scanner, Audit Logs, SCIM, Private API Network, and Service Accounts endpoints, showing that many mitigations are productized rather than purely procedural. Medium SR028
CR030 The API Network and its learning-center docs make public APIs and workspaces intentionally discoverable, so growth surface and attack surface overlap. High SR021, SR022
CR031 G2, TrustRadius, and Software Advice all show that users value collaboration and test automation, but also complain about paid-feature drift, complexity, and slowness at larger scale. Medium SR023, SR024, SR025
CR032 Apidog and Dev Tools argue that the 2026 packaging changes push multi-user teams toward paid tiers and may increase churn among budget-sensitive teams. Low SR031, SR032
CR033 The Economic Times reported secondary transactions at a 30-40% discount to the 2021 valuation and cited ARR estimates of only $120-150 million, highlighting model-risk and financing sensitivity. Medium SR030
CR034 No public source reviewed discloses current burn, runway, or debt, so capital-pressure risk cannot be resolved from open sources. Medium SR001, SR002, SR030
CR035 The highest-severity operational risk is not a platform intrusion but the repeatable public leakage of valid credentials through workspaces and forks. Medium SR007, SR009, SR010
CR036 Residual exposure stays high because many mitigations still depend on users correctly choosing private workspaces, proper variable fields, short-lived tokens, and narrow permissions. Medium SR001, SR009, SR010
CR037 Postman’s dependence on AWS, third-party SaaS vendors like Klue, identity providers, and public indexing surfaces means important parts of its trust posture remain outside direct product code. Medium SR001, SR002, SR006, SR021
CR038 Local-first alternatives reduce both cloud exposure and switching friction, weakening Postman’s ability to rely on collaboration lock-in as the only moat. Medium SR014, SR015, SR016, SR017
CR039 If a future public-workspace leak involved regulated personal data at scale, Postman could face privacy-enforcement exposure on top of reputational damage. Medium SR019, SR007, SR010
CR040 A thesis-break event would be a repeat high-profile credential-exposure episode, a prolonged trust-damaging outage, or evidence that AI- and local-first competitors are displacing Postman in teams that need collaboration. Medium SR006, SR014, SR016, SR018, SR023, SR030
CV001 Postman closed a $225 million Series D round in August 2021 at a $5.6 billion post-money valuation led by Insight Partners, with new investors Coatue, Battery Ventures, and BOND alongside existing investors CRV and Nexus Venture Partners. High SV002, SV003
CV002 TechCrunch reported that Postman's 2021 Series D brought the company's total funding across all rounds to more than $430 million. Medium SV003
CV003 Craft.co lists Postman's total funding at $433 million and separately shows a 'Market Valuation' field of $2 billion dated 2020-06-11, which predates and understates the confirmed $5.6 billion 2021 Series D mark. Medium SV006
CV004 GetLatka states in prose that Postman 'reached a $3.6 billion valuation in 2021' during its Series D, while its own funding table on the same page lists that identical round at a $5.6 billion valuation, an internal inconsistency on GetLatka's page. Medium SV005
CV005 GetLatka estimates Postman's revenue grew from about $8.4 million in 2018 to $313.1 million in 2024, including $171.7 million in 2023 and $102.7 million in 2022. Medium SV005
CV006 GetLatka and Craft.co both independently show Postman's total funding at $433 million across five rounds (Seed $1M 2015, Series A $7M 2016, Series B $50M 2019, Series C $150M 2020, Series D $225M 2021). Medium SV005, SV006
CV007 Inc42's funding tracker shows Postman's total funding at $433 million and its Series D at $225 million, consistent with Postman's own announcement, but shows Postman's Indian entity Postdot Technologies Private Limited reporting revenue of roughly Rs185.7 crore for FY2024 -- a figure that reflects only the Indian legal entity, not global consolidated revenue. Medium SV013
CV008 Inc42 lists Postman's employee count at approximately 3,490 as of its most recent update. Low SV013
CV009 Forge Global's funding table shows Postman's Series D primary raise as $145 million at a $17.54 per-share price and $5.57 billion post-money valuation, a lower primary-only figure than the $225 million widely reported for the full round. Medium SV007
CV010 Forge Global shows Postman's cumulative funding across four priced rounds (Series A through D) at $352 million, roughly $80 million below the $433 million total shown by Craft.co, GetLatka, and Inc42. Medium SV007
CV011 Forge Global's data shows Postman's Series C priced at a $2.06 billion post-money valuation on 2020-06-11, which is consistent with TechCrunch's contemporaneous reporting that the 2021 Series D valued Postman 'up from $2 billion a year ago.' High SV007, SV003
CV012 Forge Global's disclosed Series D terms show a 1.0x liquidation preference multiplier and preference order of 1, but the page displays both 'cumulative/non-cumulative' and 'participating/non-participating' as unresolved toggle-style fields rather than a single confirmed value, leaving the actual preference stack terms ambiguous from public evidence. Low SV007
CV013 As of July 17-20, 2026, Forge Global's derived 'Forge Price' for Postman was $7.00 per share, implying an estimated valuation of approximately $2.22 billion, and Yahoo Finance's private-market listing for the same ticker (POSM.PVT) independently shows the identical $2.22 billion estimate. High SV007, SV011
CV014 Forge Global shows its Postman price down between roughly 9.8% and 32.7% across trailing 7-day, 1-month, 3-month, 6-month, 1-year, and all-time windows as of July 2026. Medium SV007
CV015 Yahoo Finance describes Forge Price as a derived data point calculated from a proprietary model incorporating publicly available primary funding round information, secondary market transactions, and indications of interest on Forge and other private-market trading platforms. Medium SV011
CV016 Public.com's model, sourced to Nasdaq Private Markets, estimated Postman's secondary share price at $7.64 as of June 2026, down $2.37 (23.68%) over the trailing six months, and separately lists Postman's founding year as 2015 rather than the 2014 founding year shown by Forge Global, Craft.co, and Postman's own materials. Low SV009
CV017 Notice.co's page title metadata listed a Postman secondary share price estimate of $8.07 as of July 18, 2026, but the underlying page body did not render for independent verification because the content is JavaScript-only. Low SV012
CV018 Premier Alternatives displays conflicting valuation figures for Postman on the same page: the page's <title> metadata states 'Postman Valuation: $2.2B (2026)' while the visible body text states a 'Current Valuation' of $3.3 billion and a 9.46x capital-efficiency ratio against $352.0 million raised. Medium SV010
CV019 UpMarket's own valuation model estimates Postman at $4.8 billion, distinct from the $5.6 billion 'Latest Price' it displays, which is simply the stale 2021 Series D mark rather than a current estimate; UpMarket also mislabels that Series D reference as occurring in 'Series C Apr 2019' terminology on its previous-price field, another internal labeling inconsistency. Medium SV014
CV020 Across the analyst-market-data trackers reviewed in this chapter (Forge/Yahoo Finance, Public.com, Notice.co, Premier Alternatives, and UpMarket), 2026 estimates of Postman's implied valuation span roughly $2.2 billion to $4.8 billion, and every one of them sits below the confirmed $5.6 billion 2021 Series D peak. Medium SV007, SV009, SV010, SV011, SV014
CV021 The Economic Times reported that Postman's secondary-market share transactions cleared at a 30-40% discount to the company's 2021 primary valuation, versus a typical 10-15% discount for secondary transactions generally, calling it a steep decline in value for SaaS firms on revenue multiples. Medium SV004
CV022 A person described by the Economic Times as aware of Postman's financials said that, based on revenue projections, the company's valuation is being readjusted downward from its 2021 peak-cycle level, and that further batches of secondaries at a similar discount range may follow. Medium SV004
CV023 The Economic Times reported that Postman did not respond to its request for comment on the reported secondary-market discount, and that existing investors including Nexus Venture Partners, BOND Capital, and Battery Ventures purchased some of the shares being sold by earlier angel and early investors. Medium SV004
CV024 PitchBook reported in February 2026 that US startups whose last priced round was in 2021 traded at an average valuation markdown near 68.2% relative to that round, while 2022-vintage startups averaged a 52.1% markdown. Medium SV030
CV025 Applying PitchBook's reported 68.2% average markdown for 2021-vintage startups to Postman's $5.6 billion Series D mark would imply a valuation near $1.8 billion, which is below every analyst-market-data estimate for Postman reviewed in this chapter (roughly $2.2 billion to $4.8 billion), suggesting Postman's current secondary pricing is holding up somewhat better than the broad 2021-vintage cohort average. Medium SV030, SV007
CV026 PitchBook reported that the top 10 US startups by valuation represented a record 51.8% of total US unicorn value, up from 18.5% in 2022, indicating that late-stage private capital is concentrating in a small number of mega-valued companies rather than spreading evenly across the unicorn population. Medium SV030
CV027 Kong Inc., a direct API-management/gateway competitor named in Postman's own competitive set, closed a $175 million Series E financing in November 2024 (a mix of primary and secondary transactions) at a $2 billion valuation, led by Tiger Global and co-led by new investor Balderton, bringing Kong's total capital raised to $345 million. High SV016, SV017
CV028 Kong's Series E round added new investors Teachers' Venture Growth (Ontario Teachers' Pension Plan's late-stage arm) and 137 Ventures, alongside continued participation from Andreessen Horowitz, Index Ventures, CRV, Sapphire Ventures, and Notable Capital, and Balderton partner Rana Yared joined Kong's board. Medium SV016, SV017
CV029 SmartBear, an adjacent API-lifecycle and software-quality tooling vendor, has been jointly and equally owned by Francisco Partners (since its 2017 acquisition) and Vista Equity Partners (since a subsequent investment) with no disclosed current valuation, and reports serving more than 15 million developers, testers, and operations engineers across more than 24,000 organizations. Medium SV023
CV030 GitLab Inc. is a NASDAQ-listed public company (ticker GTLB, CIK 1653482) headquartered at 268 Bush Street, San Francisco, that files periodic reports with the SEC, including an annual report (10-K) for its fiscal year 2026 filed on 2026-03-17. High SV018, SV019
CV031 GitLab reported fiscal year 2026 total revenue of $955.2 million, up 26% year over year, with fourth-quarter revenue of $260.4 million (+23% YoY), and stated that fiscal year 2026 saw the company cross $1 billion in annualized recurring revenue. Medium SV020
CV032 GitLab's market capitalization was approximately $5.52 billion as of July 19, 2026 (down 13.27% year over year), implying a revenue multiple near 5.8x on its $955.2 million fiscal 2026 revenue. Medium SV021, SV020
CV033 Atlassian's market capitalization was approximately $23.67 billion as of July 17, 2026, down 52.65% over the prior year, against $6.19 billion in trailing-twelve-month revenue (up 24.74% YoY), for a price-to-sales ratio of 3.82x as directly reported by Stock Analysis. Medium SV022, SV032
CV034 Datadog's market capitalization was approximately $92.08 billion as of July 2026 (up 89.85% year over year) against roughly $3.67 billion in trailing-twelve-month revenue, implying a revenue multiple near 25x -- illustrating that public devtools/observability multiples can vary by more than 6x depending on growth quality and category positioning. Medium SV028, SV029
CV035 IBM agreed to acquire data-streaming company Confluent for approximately $11 billion, a deal that gives IBM a platform with an annual revenue run rate topping $1 billion, implying roughly an 11x revenue-run-rate multiple as a data-infrastructure M&A comparable; IBM's prior large software acquisition was the $6.5 billion purchase of HashiCorp. Medium SV024
CV036 Multiples.vc's July 2026 public software comparables show wide EV/revenue dispersion by category, noting that design and engineering software such as Autodesk and Adobe commands premium multiples by successfully integrating AI features, while other horizontal SaaS segments trade at steep discounts amid AI-disruption ('creative destruction') concerns. Medium SV025
CV037 Capstone Partners' 2026 M&A outlook describes a gradual, private-equity-led reopening of middle-market dealmaking after a multi-year downcycle, citing five consecutive quarters of platform-acquisition growth and expectations that interest-rate cuts and improving CEO confidence will be key catalysts through 2026. Medium SV026
CV038 EY's mid-2026 M&A activity report found that US technology deal value roughly doubled year over year with deal volume up 29% in the April-June quarter, driven by buyer appetite for AI model development, coding/automation capabilities, and connectivity/compute-enabling platforms. Medium SV027
CV039 Postman's own press-media page lists product and partnership announcements through April 2026 -- including a Microsoft AI model-choice collaboration (2026-04-16) and an Anthropic Claude-on-Amazon-Bedrock integration (2026-03-31) -- but no announcement referencing an IPO filing, roadshow, or public-listing timeline as of the July 2026 access date. Medium SV001
CV040 Postman's press-media page shows the company made two acquisitions within the prior eight months of the access date: Fern (announced 2026-01-08) and liblab (announced 2025-11-14), both framed as accelerating a unified API-lifecycle and developer-experience platform strategy. Medium SV001
CV041 A dedicated third-party IPO-tracking page for Postman (ipos.fyi) returned an HTTP 429 rate-limited/bot-checkpoint response when checked in July 2026, so no independent IPO-readiness signal could be corroborated from that source. Low SV015
CV042 A search of the SEC EDGAR company database restricted to the company name 'postman' and Form S-1 returned no matching filer or filing rows as of the July 2026 access date, consistent with no public evidence of a Postman S-1 registration statement having been filed. Medium SV031
CV043 No source reviewed in this chapter discloses Postman's board composition, a current capitalization table, or resolved liquidation-preference/dividend terms beyond the named Series D investor list and an ambiguous 1.0x preference multiplier shown on one secondary-market tracker. Low
CV044 No public source reviewed discloses Postman's GAAP revenue, gross margin, cash balance, or burn rate, so the Economic Times' implied 2024 ARR range and GetLatka's $313.1 million 2024 revenue estimate should both be treated as third-party proxies rather than audited figures when used in any revenue-multiple valuation math. Low
CV045 Because Postman's own disclosed revenue is unavailable, a defensible sensitivity framework must bracket the entry price using the two conflicting third-party revenue estimates (roughly $120-150 million ARR per Economic Times-sourced commentary and $313.1 million revenue per GetLatka) alongside the $2.2 billion-$5.6 billion valuation band already observed across trackers, rather than assuming either revenue figure is authoritative. Medium SV004, SV005, SV007
CV046 The combination of unresolved governance/cap-table opacity, no audited financials, and no confirmed 2026 primary financing round means that even a favorable reading of Postman's demand-side evidence cannot currently support a price-insensitive buy call; a research-more/track posture is the evidence-consistent recommendation. Medium SV004, SV007, SV030
CV047 This chapter's evidence supports a 'research-more' recommendation for Postman, medium confidence, medium-high risk rating, and a 'fair-to-stretched' valuation stance depending on which revenue estimate is assumed, rather than a buy or avoid call. Medium SV004, SV005, SV007, SV030
CV048 The recommendation logic chain runs from (a) verified scale and financing history, through (b) two mutually exclusive revenue estimates and a multi-tracker secondary-valuation discount cluster, to (c) unresolved governance and cash-flow disclosure gaps, concluding in (d) a price-sensitive research-more call rather than an admiration-based buy call. Medium SV003, SV005, SV007, SV004
CV049 The core investment thesis for Postman rests on durable API-tooling distribution (verified $5.6 billion peak financing, 17 million-plus developers at the 2021 raise, named enterprise logos) while the core anti-thesis rests on unresolved monetization proof, a 30-40% reported secondary discount, and no confirmed capital event since 2021. Medium SV002, SV004, SV007
CV050 Bull, base, and bear valuation scenarios for Postman diverge primarily on which revenue estimate proves closer to reality and whether secondary-market pricing recovers toward the UpMarket/Forge upper band or drifts toward the PitchBook-implied 2021-vintage average markdown. Medium SV005, SV007, SV014, SV030
CV051 A revenue-multiple sensitivity framework built on the conflicting $120-150 million and $313.1 million revenue estimates, combined with the 3.8x-25x range observed across Atlassian, GitLab, and Datadog, brackets plausible valuation outcomes for Postman between roughly $0.5 billion and $8 billion before qualitative adjustment for growth quality and disclosure risk. Medium SV005, SV004, SV022, SV021, SV028
CV052 The most decision-relevant final diligence asks for Postman are: audited or management-reviewed revenue/ARR by segment, a current cap table with liquidation-preference and dividend terms, evidence of any 2025-2026 primary financing or tender event, and disclosed retention/expansion metrics to validate which revenue estimate is closer to reality. Medium SV004, SV005, SV007
CV053 Thesis-break triggers for Postman include: a confirmed primary round or tender priced meaningfully below the $2.2 billion Forge/Yahoo cluster, disclosed revenue materially below the $120-150 million low estimate, a governance or security event that impairs enterprise trust beyond what is already reflected in the company's public risk record, or continued absence of any capital event through 2027 alongside further secondary-discount widening. Medium SV004, SV007
Sources
IDPublisherTitleQuote
SO001 Postman About Postman Postman is an API platform for building and using APIs.
SO002 Postman Contact Us | Postman
SO003 Postman Postman API Platform - Build, Test & Manage
SO004 Postman Plans & Pricing | Postman API Platform
SO005 Postman 2025 State of the API Report | Postman
SO006 Postman 2025 State of the API Report
SO007 Postman Postman’s Series D Funding and the API-First World
SO008 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise | TechCrunch
SO009 GetLatka Postman Revenue, Valuation & Funding History (2024)
SO010 Craft.co Postman Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co
SO011 Craft.co Postman Corporate Headquarters, Office Locations and Addresses | Craft.co
SO012 LinkedIn Postman | LinkedIn
SO013 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SO014 The Economic Times Postman: SaaS star Postman sees 30-40% cut in valuation in secondary deal - The Economic Times
SO015 Postman The New Postman is Here: AI-Native and Built for the Agentic Era
SO016 Postman Announcing Postman has acquired Orbit
SO017 Postman Postman acquires liblab to build the unified API lifecycle platform
SO018 Postman Postman acquires Fern
SO019 Business Wire Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation
SO020 Business Wire One in Four Developers Now Design APIs for AI Agents, According to Postman’s 2025 State of the API Report
SO021 Postman Postman Customer Trust Portal
SO022 Treblle 30,000 APIs Exposed: Lessons from the Postman Data Breach
SO023 CloudSEK Postman Data Leaks: The Hidden Risks Lurking in Your Workspaces | CloudSEK
SO024 Postman Postman Status
SO025 Cyber Security News Postman Data Leak - 30,000 Publicly Accessible Workspaces Could Lead Massive Hack
SM001 Postman 2025 State of the API Report | Postman
SM002 Postman 2025 State of the API Report
SM003 Postman 2025 State of the API for Security | Postman Report
SM004 Postman Postman API Platform - Build, Test & Manage
SM005 Postman Plans & Pricing | Postman API Platform
SM006 Postman API Repository | Postman API Platform
SM007 Postman Flows | Visual Workflow Documentation | Postman API Platform
SM008 Postman The New Postman is Here: AI-Native and Built for the Agentic Era
SM009 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SM010 The Business Research Company API Management Market Share, Size, Trends, Report 2026
SM011 Strategic Market Research Api Management Market 2026: Expert-Crafted Insights You Can Trust
SM012 Fortune Business Insights API Management Market Size, Trends | Global Report [2034]
SM013 Mordor Intelligence API Management Market Size, Share & Trends Report 2026-2031
SM014 Swagger Build AI-Ready APIs | Design, Test & Scale APIs Faster with Swagger
SM015 Swagger Swagger Pricing | Flexible Plans for Every Team
SM016 Insomnia The Collaborative API Development Platform
SM017 Insomnia Pricing
SM018 Stoplight OpenAPI Design & Documentation Management Tool | Stoplight
SM019 Stoplight API Design Plans and Pricing | Stoplight
SM020 Bruno Bruno - The Git-Native API Client
SM021 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia)
SM022 Hoppscotch Hoppscotch • Open source API development ecosystem
SM023 SmartBear Automated API Testing Platform | API Testing Tools | ReadyAPI
SM024 Kong Kong Pricing for API and AI Connectivity Platform | Konnect
SM025 G2 The G2 on Postman
SM026 Software Advice Postman Software Reviews, Demo & Pricing
SP001 Postman Postman API Platform - Build, Test & Manage
SP002 Postman Plans & Pricing | Postman API Platform
SP003 Postman API Repository | Postman API Platform
SP004 Postman Flows | Visual Workflow Documentation | Postman API Platform
SP005 Postman Agent Mode | Postman API Platform
SP006 Postman Meet the AI Engineer | Postman
SP007 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise | TechCrunch
SP008 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SP009 Swagger Build AI-Ready APIs | Design, Test & Scale APIs Faster with Swagger
SP010 Swagger Swagger Pricing | Flexible Plans for Every Team
SP011 Insomnia The Collaborative API Development Platform
SP012 Insomnia Pricing
SP013 Stoplight API Design Plans and Pricing | Stoplight
SP014 Bruno Bruno - The Git-Native API Client
SP015 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia)
SP016 Hoppscotch Hoppscotch • Open source API development ecosystem
SP017 SmartBear Automated API Testing Platform | API Testing Tools | ReadyAPI
SP018 SmartBear ReadyAPI Pricing | API Testing for Teams & Enterprises | ReadyAPI
SP019 Kong Kong Pricing for API and AI Connectivity Platform | Konnect
SP020 GitLab Pricing
SP021 TrustRadius Postman Reviews & Ratings 2026 | TrustRadius
SP022 Trustpilot Postman is rated "Average" with 3 / 5 on Trustpilot
SP023 G2 The G2 on Postman
SP024 Software Advice Postman Software Reviews, Demo & Pricing
SP025 I Programmer Postman Launches AI Agent Builder
SP026 GitLab GitLab Reports Fourth Quarter and Full Year Fiscal Year 2026 Financial Results; Board of Directors Authorizes $400 million for Share Repurchase Program
SI001 Postman Plans & Pricing | Postman API Platform Free, Solo, Team, and Enterprise tiers are live on the 2026 pricing page.
SI002 Postman Postman Enterprise | AI-native API Platform Trusted by over 40M developers and 98% of the Fortune 500.
SI003 Postman About Postman Postman is an API platform for building and using APIs.
SI004 Postman Postman’s Series D Funding and the API-First World We’ve closed a Series D investment round of $225 million that values the company at $5.6 billion.
SI005 Postman 2025 State of the API Report | Postman APIs have become profit drivers, with 65% of organizations generating revenue from their API programs.
SI006 Latka Postman Revenue, Valuation & Funding History (2024) In 2024, Postman's revenue reached $313.1M. The company previously reported $171.7M in 2023.
SI007 Sacra Postman funding, news & analysis
SI008 Craft Postman Financials | Craft.co Total Funding $433 M.
SI009 Growjo Postman: Revenue, Competitors, Alternatives Postman's estimated annual revenue is currently $506.1M per year.
SI010 The Economic Times Postman sees 30-40% cut in valuation in secondary deal People aware of Postman’s financials said it is estimated to be clocking annualised recurring revenue (ARR) of $120-150 million.
SI011 Tracxn Postman Postman has raised a total funding of $434M over 6 rounds.
SI012 PM Insights Postman Valuation | PM Insights Postman Valuation and Overview.
SI013 Premier Alternatives Postman Valuation: $2.2B (2026) Current Valuation $3.3B.
SI014 CompWorth Postman – Financial Footprint & Growth Factors – 2026
SI015 Postman Postman Workspaces | API Collaboration | Postman API Platform One place where teams collaborate to build, test, and distribute APIs.
SI016 Postman API Repository | Postman API Platform Postman provides a cloud-based, version-controlled, centralized repository for all API artifacts.
SI017 Postman Flows | Visual Workflow Documentation | Postman API Platform Flows gives your team something they can inspect, execute, debug, and clone, not just read.
SI018 Postman Agent Mode | Postman API Platform Agent Mode can help your team debug faster, generate test coverage, and build quality, AI-ready APIs.
SI019 U.S. Securities and Exchange Commission GitLab submissions JSON Gitlab Inc. is a Nasdaq-listed operating company and large accelerated filer.
SI020 U.S. Securities and Exchange Commission GitLab companyfacts JSON GitLab's SEC companyfacts include revenue, gross profit, R&D, and selling-and-marketing facts through the 2026 filing set.
SI021 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise TechCrunch reported Postman was valued at $5.6 billion in a $225 million fundraise.
SI022 LinkedIn Postman | LinkedIn Discover all 3,523 employees.
SI023 Business Wire Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation.
SI024 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, as well as collaboration and test automation.
SI025 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SI026 Apidog Postman Pricing 2026: What They Changed & Why You Should Switch The Team plan at $19 per user monthly is the cheapest option for collaboration.
SI027 Dev Tools Postman's 2026 Pricing Changes: What They Mean for Your API Testing Workflow Postman Free is now limited to 1 user.
SI028 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts and collaboration tools.
SE001 Postman Postman API Platform - Build, Test & Manage Postman is a unified platform for designing, testing, distributing, documenting, and monitoring APIs.
SE002 Postman API Repository | Postman API Platform Postman provides a cloud-based, version-controlled, centralized repository for all API artifacts.
SE003 Postman Flows | Visual Workflow Documentation | Postman API Platform Flows gives your team something they can inspect, execute, debug, and clone, not just read.
SE004 Postman Agent Mode | Postman API Platform Agent Mode understands your collections, specs, environments, and history so every response is grounded in your actual APIs.
SE005 Postman Meet the AI Engineer | Postman Powered by an always-on, continuously updated context graph of your APIs and services across your organization.
SE006 Postman Docs Create and manage request collections in Postman | Postman Docs A collection is one of the fundamental elements in Postman.
SE007 Postman Docs Store and reuse values using variables | Postman Docs Variables enable you to store and reuse values in Postman.
SE008 Postman Postman Schemas Collections v2.1.0 is listed as stable on the schema site.
SE009 GitHub GitHub - postmanlabs/newman: Newman is a command-line collection runner for Postman Newman is a command-line collection runner for Postman.
SE010 npm newman Newman is a command-line collection runner for Postman.
SE011 npm postman-collection Postman Collection SDK is a NodeJS module that allows a developer to work with Postman Collections.
SE012 npm openapi-to-postmanv2 openapi-to-postmanv2 is a published package for converting OpenAPI definitions to Postman collections.
SE013 TechCrunch Postman launches an AI agent builder on top of its API platform TechCrunch reported Postman launched an AI agent builder on top of its API platform.
SE014 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing These features make AI and native Git workflows core parts of the Postman platform.
SE015 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Postman now lets teams organize HTTP, GraphQL, gRPC, MCP, MQTT, WebSockets, and AI requests in the same collection.
SE016 Postman Postman Security - Compliance, Privacy, & Reliability Audit logs track key activities related to security access and team management for the past 180 days.
SE017 Postman Postman Customer Trust Portal On June 13, Postman became aware of a potential data security incident after a third-party provider, Klue, notified us that it had been compromised.
SE018 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SE019 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, as well as collaboration and test automation.
SE020 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts, detailed request and response analysis, and easy organization of collections.
SE021 I Programmer Postman Launches AI Agent Builder Postman has launched an AI agent builder on top of its API platform.
SE022 QATechTools Postman AI Features: Real API Testing Scenario Scenario-based walkthrough of Agent Mode, Postbot, and Flows.
SE023 Postman Docs About Postbot | Postman Docs Your inputs and outputs will not be used for training Postman or Postman’s artificial intelligence models.
SE024 Postman Docs Run Postman Collections in your CI environment using Newman | Postman Docs You can use Newman and the Postman API to run Postman Collections in your continuous integration (CI) environment.
SE025 Postman Docs Install and run Newman | Postman Docs Newman is built on Node.js.
SE026 Postman Docs Integrate Postman into your development toolchain | Postman Docs Use the Postman API to programmatically manage your Postman assets and integrate Postman into your development toolchain.
SE027 Tayyab Akmal Postman Newman GitHub Actions: API Test CI/CD Setup (2026) Newman integrates seamlessly into GitHub Actions to execute your entire API test suite on every push, pull request, and deployment.
SE028 Postman Integrate Postman into your development toolchain | Postman Docs The API Catalog API enables you to programmatically manage your API Catalog.
SU001 Postman About Postman More than 500,000 organizations use Postman.
SU002 Postman API Customer Stories | Postman API Platform Learn why 40 million developers and 500,000 companies rely on Postman.
SU003 Postman PayPal API Case Study | Postman API Platform Time to first call reduced from hours to 1 minute.
SU004 Postman Announcing public workspace metrics Public workspace metrics help API publishers see engagement and quality signals.
SU005 Postman Docs View reports about workspaces | Postman Docs Workspace reports give insights into active users, active workspaces, API requests, and usage trends over time.
SU006 Postman Docs Get analytics data | Postman Docs Gets analytics data based on the specified resource, metrics, and given filters.
SU007 Postman Postman Insights | API Observability | Postman API Platform Postman Insights provides API observability and production visibility.
SU008 Landbase Postman As of 2026, 3,906 verified companies use Postman.
SU009 Ramp Postman Ramp Rate: A Data-Backed Look As of July 2026, 13% of organizations in the DevOps category use Postman.
SU010 LinkedIn Postman | LinkedIn More than 40 million developers and 500,000 organizations use Postman.
SU011 Postman Postman Enterprise | AI-native API Platform Trusted by over 40M developers and 98% of the Fortune 500.
SU012 Postman Postman’s Series D Funding and the API-First World There are now 17 million developers on the Postman API Platform.
SU013 Postman 2025 State of the API Report | Postman 65% of organizations generate revenue from their API programs.
SU014 Autodesk Platform Services Using APS OpenAPI Specs with Postman You can import Autodesk OpenAPI specs directly into Postman and instantly generate a collection.
SU015 Box Postman Collection - Box Dev Docs The Box Postman Collection includes over 170 API endpoints organized by resource type.
SU016 Microsoft Use Postman with the Microsoft Graph API - Microsoft Graph To use the Postman collection, fork it to your own Postman workspace.
SU017 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SU018 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, collaboration, and test automation.
SU019 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts and collaboration tools.
SU020 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Reporting has been consolidated so internal, partner, and public workspace analytics live in a single destination.
SU021 Postman Postman Integrations | Postman API Platform Postman integrates with the tools teams already use every day.
SU022 Postman Postman | Postman API Network Explore official API references and public workspaces on the Postman API Network.
SU023 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing The new Team plan will support collaborative API development, testing, and distribution across shared workflows.
SU024 Postman Autodesk Case Study | Postman API Platform Partner API requests jumped from 40 million per year to 60 million per month.
SU025 Postman Medibank Case Study | Postman API Platform Testing cycle times have been reduced by 70% which has sped up feature releases by three weeks.
SU026 Postman HubSpot Case Study | Postman API Platform The total number of API calls on Postman increased by 104% in the six months from November 2023 to May 2024.
SU027 Postman The ZEISS Case Study | Postman API Platform Hundreds of test cases can now be run in one minute.
SU028 Postman Cover Genius Case Study | Postman API Platform Using Postman has doubled our efficiency in delivering key integration requirements to partners.
SU029 TheirStack Companies that use Postman (67,301) TheirStack lists more than 67,000 companies associated with Postman usage signals.
SU030 Postman Public Workspace Metrics report
SR001 Postman Postman Security - Compliance, Privacy, & Reliability Audit logs track key activities related to security access and team management for the past 180 days.
SR002 Postman Postman Customer Trust Portal On June 13, Postman became aware of a potential data security incident after a third-party provider, Klue, notified us that it had been compromised.
SR003 Postman Postman Legal Browse Postman’s legal documents, privacy policies, terms of service, and other legal resources.
SR004 Postman Postman Terms of Service
SR005 Postman Legal Archives | Postman Terms of Service and Product Terms were updated multiple times in 2025.
SR006 Postman Postman Status 100.0% uptime over the last 90 days is shown for the desktop platform view.
SR007 CloudSEK Postman Data Leaks: The Hidden Risks Lurking in Your Workspaces More than 30,000 publicly accessible Postman workspaces were disclosing sensitive information.
SR008 Cyber Security News Postman Data Leak - 30,000 Publicly Accessible Workspaces Could Lead Massive Hack Cyber Security News summarized the 30,000-workspace exposure problem.
SR009 Truffle Security (The) Postman Carries Lots of Secrets At least 4,000 live secrets are currently leaking on Postman.
SR010 AppSentinels Postman Workspace Exposure: 30k+ Public Workspaces Exposed Public Postman workspaces can be indexed like any other webpage.
SR011 InfoSec Write-ups Postman Secret Scanning: A Practical Guide to Finding Exposed APIs Practical guide to finding exposed APIs and secrets.
SR012 UpGuard Postman Security Rating, Vendor Risk Report, and Data Breaches Vendor risk tracking page for Postman.
SR013 Panorays Postman
SR014 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) Bruno stores your collections directly in a folder on your filesystem.
SR015 Bruno Bruno - The Git-Native API Client No cloud sync. No account. No login.
SR016 Insomnia The Collaborative API Development Platform Store data locally, via Git, or in the cloud.
SR017 Visual Studio Marketplace Thunder Client - Visual Studio Marketplace Thunder Client is a lightweight REST API client extension with local storage and Git sync.
SR018 GitHub GitHub Copilot · Your AI pair programmer GitHub Copilot is an AI pair programmer integrated into the GitHub platform.
SR019 California Office of the Attorney General California Consumer Privacy Act (CCPA) The CCPA gives consumers more control over the personal information that businesses collect about them.
SR020 Data Privacy Framework Data Privacy Framework Official Data Privacy Framework site.
SR021 Postman Docs Explore public APIs on the Postman API Network | Postman Docs Explore public APIs on the Postman API Network.
SR022 Postman Postman | Postman API Network Postman operates a public API network / reference library.
SR023 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SR024 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, collaboration, and test automation.
SR025 Software Advice Postman Software Reviews, Demo & Pricing Some users report that the platform can become slow with large requests and team workspaces.
SR026 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing AI and native Git workflows are becoming core parts of the platform.
SR027 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Internal, partner, and public workspace analytics now live in a single destination.
SR028 Postman Docs Integrate Postman into your development toolchain | Postman Docs The Postman API exposes Audit Logs, Secret Scanner, SCIM, and Private API Network endpoints.
SR029 Postman Agent Mode | Postman API Platform Agent Mode understands your collections, specs, environments, and history so every response is grounded in your actual APIs.
SR030 The Economic Times Postman sees 30-40% cut in valuation in secondary deal People aware of Postman’s financials said it is estimated to be clocking annualised recurring revenue (ARR) of $120-150 million.
SR031 Apidog Postman Pricing 2026: What They Changed & Why You Should Switch The Team plan at $19 per user monthly is now the cheapest option for collaboration.
SR032 Dev Tools Postman's 2026 Pricing Changes: What They Mean for Your API Testing Workflow Postman Free is now limited to 1 user.
SR033 Postman Privacy Center
SV001 Postman Press and Media | Postman Postman Announces Collaboration with Microsoft to Expand AI Model Choice, Accelerate Developer Workflows, and Unify API Governance (2026-04-16).
SV002 Postman Postman's Series D Funding and the API-First World We've closed a Series D investment round of $225 million that values the company at $5.6 billion.
SV003 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise Postman said on Wednesday it has raised $225 million in a new financing round that values it at $5.6 billion, up from $2 billion a year ago.
SV004 The Economic Times Postman sees secondaries at steep discount Postman ... has struck secondary deals at a 30-40% discount recently ... secondary transactions are typically finalised at 10-15% discount to the last primary valuation.
SV005 Latka (GetLatka) Postman Revenue, Valuation & Funding History In 2024, Postman's revenue reached $313.1M... Postman reached a $3.6B valuation in 2021, set during its $225M Series D.
SV006 Craft.co Postman Company Profile Market Valuation $2B (2020-06-11); Total Funding $433M.
SV007 Forge Global Invest and Sell Postman Stock - Forge Forge Price $7.00 (7/20/2026); Forge Price valuation $2.22B; total funding $352M across 4 priced rounds.
SV008 Tracxn Postman Company Profile
SV009 Public.com Postman (PSTM) Private Company Stock Postman's estimated secondary market share price is $7.64 as of June 2026.
SV010 Premier Alternatives Postman Valuation Page title states 'Postman Valuation: $2.2B (2026)' while body text states 'Current Valuation $3.3B' and a 9.46x capital-efficiency ratio against $352.0M raised.
SV011 Yahoo Finance Postman (POSM.PVT) Private Company Quote Estimated Valuation $2.22B; Total Amount Raised $352M; Latest Amount Raised $145M; Total Funding Rounds 4.
SV012 Notice.co Postman Stock $8.07 | How to Buy, Valuation, Stock Price, IPO Page title metadata shows a $8.07 valuation figure; body content did not render (JavaScript-only page).
SV013 Inc42 Postman - Total Funding, Funding Over Time, Funding By Rounds and More Total funding: $433.00 Mn+; Revenue: Rs185.7 Cr+ (FY24) [Postdot Technologies Private Limited]; Employee count: 3,490.
SV014 UpMarket Postman Stock | Pre-IPO Private Markets Latest Price $5.6B (Series D, Aug 2021); UpMarket Estimate $4.8B, based on UpMarket valuation model.
SV015 ipos.fyi Postman IPO Tracker Fetch returned HTTP 429 (Vercel security checkpoint); no page content could be retrieved.
SV016 Kong Inc. Kong Secures $175 Million in New Financing Kong Inc. ... today announced it has closed a $175 million in up-round Series E financing ... at a $2 billion valuation ... This brings Kong's total capital raised to $345 million.
SV017 Balderton Capital Kong Secures $175M New Financing at $2Bn Valuation to Power the API World The round was co-led by Tiger Global and Balderton ... Balderton Partner Rana Yared joins the Kong board.
SV018 U.S. Securities and Exchange Commission EDGAR filer browse - CIK 1653482 (GitLab Inc.)
SV019 U.S. Securities and Exchange Commission EDGAR 10-K filings list - CIK 0001653482 (GitLab Inc.) Annual report [Section 13 and 15(d)] filed 2026-03-17, Acc-no 0001628280-26-018731.
SV020 GitLab Inc. GitLab Reports Fourth Quarter and Full Year Fiscal Year 2026 Financial Results Fiscal Year 2026 ... Total revenue of $955.2 million, up 26% year-over-year ... Fiscal year 2026 saw GitLab cross $1 billion in ARR.
SV021 CompaniesMarketCap.com GitLab Market Cap On Jul 19th, 2026 the market cap of GitLab was reported to be $5.52 Billion USD (-13.27% YoY).
SV022 Stock Analysis Atlassian (TEAM) Market Cap & Net Worth Atlassian has a market cap of $23.67 billion as of July 17, 2026 ... decreased by -52.65% in one year.
SV023 Francisco Partners SmartBear Announces Investment From Vista Equity Partners Francisco Partners ... will continue as an investor with Vista and Francisco Partners as equal owners of the company ... more than 15 million developers, testers and operations engineers at over 24,000 organizations.
SV024 Constellation Research IBM buys Confluent for $11 billion IBM said it will acquire data streaming company Confluent in a deal valued at $11 billion ... an annual revenue run rate topping $1 billion ... Big Blue's latest large deal being the $6.5 billion purchase of HashiCorp.
SV025 Multiples.vc Public software valuations in July 2026 Horizontal SaaS public comps in July 2026 show wide valuation dispersion ... Design and engineering software commands premium multiples, as companies like Autodesk and Adobe successfully integrate AI features.
SV026 Capstone Partners Middle Market M&A Poised to See Steady, Gradual Reopening in 2026 Private equity reemerged as a dominant force, ending a three-year lull with five consecutive quarters of platform acquisition growth.
SV027 EY M&A activity report Technology: M&A momentum remained strong, with deal value doubling YoY and volume rising 29%, reflecting sustained appetite for AI, software and digital infrastructure assets.
SV028 CompaniesMarketCap.com Datadog Revenue Revenue in 2026 (TTM): $3.67 Billion USD.
SV029 CompaniesMarketCap.com Datadog Market Cap On Jul 19th, 2026 the market cap of Datadog was reported to be $92.08 Billion USD (89.85% YoY).
SV030 PitchBook Top 10 startups now control record 51.8% of total unicorn value 2021-vintage unicorns trade at an average markdown near 68.2% to their last round, while 2022-vintage unicorns average a 52.1% markdown.
SV031 U.S. Securities and Exchange Commission EDGAR company search: 'postman' + Form S-1 EDGAR company-name search for 'postman' restricted to Form S-1 returned no matching filer/filing rows as of the access date.
SV032 Stock Analysis Atlassian (TEAM) Revenue Revenue (ttm) $6.19B, up 24.74% year-over-year; P/S Ratio 3.82.