初创公司尽调
尽调报告 Infrastructure / DevTools Private / Series D (last disclosed primary round) 2026-07-20

Postman

Postman 是品类领先的 API 平台,分发能力强、产品扩张路径清晰;但公开财务披露仍太薄且相互矛盾,支撑不了高确信度投资判断。

Postman 在 API 协作和工作流上下文里类别领导力清楚,但公开证据里的收入口径仍互相打架,治理和资本结构披露也太薄,难以在接近 2021 年峰值估值的位置放心承销。

封面要素

成立时间 01
2014 [CO001]
总部 02
San Francisco, California [CO002]
用户 03
40 M+ [CO008]
组织数 04
500 K+ [CO009]
上次披露的新股轮估值 05
5600 USD M [CO011, CO014]
累计融资 06
433 USD M [CO013]
员工数信号 07
3523 employees [CO019]

公司概况

Postman 是一家私有 API 平台公司,2014 年成立,目前总部位于 San Francisco。公司最初是一个简化 API 测试的开发者工具,后来扩展成覆盖 API 设计、文档、测试、监控、存储库管理、工作流编排和 AI 辅助 API 工作的广义生命周期平台。公开来源显示,Postman 被非常广泛采用——超过 40 million 用户和 500,000 个组织——并且有可观的企业渗透;但财务和治理画像仍不透明。自 2021 年以 $5.6 billion 估值完成 $225 million Series D 以来,Postman 增加了 AI 原生产品层,并收购 Orbit、liblab 和 Fern,拓宽社区、SDK 与文档工作流。

官网
www.postman.com
成立时间
2014-01-01
创始人
Abhinav Asthana, Ankit Sobti, Abhijit Kane
创立地点
Bangalore, India
总部
San Francisco, California
产品
Postman 销售一个用于构建和使用 API 的统一平台:API 设计、测试、文档、模拟、监控、存储库 / 发现、通过 Flows 实现的工作流自动化,以及 Agent Mode、AI Engineer 等更新的 AI 原生功能。
客户
开发者、QA 团队、API 平台负责人、合作伙伴与开发者关系团队,以及需要共享 API 工作流、治理和可发现性的大型企业。
商业模式
免费增值 SaaS,包含按席位计费的 Solo、Team 和 Enterprise 计划,另有 AI credit 超额费用;围绕协作、治理、私有 API 网络和组织级工作流标准化做落地扩张式变现。
阶段
Private / no confirmed primary round since 2021 Series D
融资情况
上次确认的新股融资是 2021 年 8 月完成的 $225 million Series D,估值 $5.6 billion;公开数据库把累计融资放在约 $433 million,而 2024-2026 年老股交易定价显示当前隐含估值更低,但没有新的定价新股融资事件。
[CO001, CO002, CO003, CO004, CO006, CO007, CO011, CO013]

执行摘要

主要优势

  • Postman 在同类里拥有最宽的公开可见分发面,用户超过 40M,组织超过 500K。
  • 产品已从请求客户端扩展为覆盖仓库、工作流和 AI 原生工具的 API 生命周期平台。
  • 公司仍受益于强融资历史和可识别投资人基础,2021 年 Series D 是主要锚点。
  • 客户证据覆盖主要 API 中心型企业,以及内部和外部开发者用例。
  • API 对收入越来越关键,也越来越处在 AI 智能体工作流中心,品类顺风仍在。

主要风险

  • 公开 revenue 和 ARR 估计分歧很大,当前商业化质量还没有解开。
  • 治理、股权结构、董事会、清算优先权和现金跑道披露仍太薄,无法承销。
  • 低端 API 客户端功能正被开源和 local-first 替代品快速商品化。
  • 公司有可见的安全和信任负担,包括 2024 年 workspace 暴露批评,以及 2026 年与 Klue 相关的数据事件。
  • 二级市场折价说明,即便没有新的新股定价,2021 年估值也已经向下重置。

未决问题

  • 经审计或管理层认证的收入、ARR、毛利率、烧钱速度和现金跑道数据。
  • 当前股权结构、投资人权利、优先股堆叠和董事会构成。
  • 按细分市场拆分的客户留存、扩张、集中度和合同期限指标。
  • Agent Mode、AI Engineer 等 AI 功能的采用和变现细节。
  • 任何已确认的 2025-2027 新股融资、要约收购、IPO 或战略退出进程。

目录

Chapter 01

01公司概况

1.1 身份、产品与规模

Postman 最适合被理解为统一 API 平台,而不是单一测试工具。官方关于页面和产品页面把它描述成一个用于构建和使用 API 的平台,覆盖设计、测试、分发、文档、监控和治理;定价页也清楚显示,Postman 跨免费、个人、团队和企业层级变现。公司称现在服务超过 40 million 用户和 500,000 个组织,包括 98% 的 Fortune 500,这把平台定位成 API 工作的广义记录系统层,而不是一个点状工具。Craft 和 LinkedIn 佐证了公司的私有状态、San Francisco 总部和全球足迹,不过最新规模指标仍主要来自公司披露,并非独立审计。LinkedIn 2026 年 7 月页面给出了最强的当前员工数信号:3,523 人;这个方向上与 Postman 成长期办公室扩张和 2025 年总部公告一致。[CO001, CO002, CO006, CO007, CO008, CO009]

KPI 快照表
指标数值 / 状态日期 / 期间置信度缺口 / 提醒
成立2014创立年份未查阅公开法律注册文件包
总部San Francisco, California当前Bangalore 创立背景在运营上仍有影响
用户 / 开发者40M+2025-2026公司披露口径,未经审计
组织500,000+2025-2026官方和独立资料相互印证
Fortune 500 渗透率98%2025-2026公司披露比例
员工3,5232026-07-16LinkedIn 自报人数
最近一轮新股估值$5.6B2021-08-18未发现更新的定价新股轮
累计融资~$433M2026 数据库视图来自第三方数据库,已四舍五入
公开 ARR 估计$120-150M2024 ET 老股交易背景未验证的外部估计
公开收入估计$313.1M2024 GetLatka 估计估计与较低 ARR 报道冲突

规模和财务行混合了官方披露与外部估计。用户数、组织数和 Fortune 500 占比来自公司口径;员工数来自 LinkedIn;ARR 和收入估计未经审计,应谨慎处理。

[CO001, CO002, CO008, CO009, CO010, CO013]
FO002: 公司快照逻辑

创始人、资本、产品广度、AI 功能和规模指标相互强化,支撑 Postman 的品类位置。

[CO003, CO006, CO008, CO011, CO013, CO027]
FO003: 快照 KPI

公开可见的头部指标显示采用面很广,但财务披露质量不均。

用户和组织数字来自公司口径。融资金额按公开数据库取整。由于第三方估计不一致,收入披露刻意概括为混合。

[CO008, CO009, CO011, CO013, CO014, CO018]

1.2 领导层、治理与依赖

公开记录仍把 Postman 与创始团队紧紧绑在一起。关于页面称 Abhinav Asthana 启动了该项目,随后招募 Ankit Sobti 和 Abhijit Kane,三位创始人至今仍领导公司。Craft 只补充了少数具名高管,包括首席收入官 Zac Auger;但董事会构成、优先股权利和继任规划仍不透明。这种不透明很重要,因为 Postman 当前转向 AI 原生工作流的产品再定位,以及并购整合计划,看起来都高度依赖创始人愿景。公司规模已经足够大,这种集中并不意味着日常执行脆弱;但董事席位、投票结构或股权结构机制未披露,仍给投资者留下实质性治理尽调缺口。实际来看,公开信息足以确认创始人连续性和企业 GTM 深度,却不足以支撑对控制权或交接规划的判断。[CO003, CO004, CO005, CO037, CO040]

领导层与创始人表
人物当前公开职务证据战略相关性关键人物 / 尽调备注
Abhinav Asthana联合创始人兼 CEOPostman 介绍页;Craft 资料页产品愿景、AI 转向、公司对外门面关键;创始人延续性是战略核心
Ankit Sobti联合创始人Postman 介绍页;Craft 资料页早期技术和产品延续性高;当前具体运营职责未完全公开
Abhijit Kane联合创始人Postman 介绍页;Craft 资料页早期产品和开发者体验延续性高;当前管辖范围未完全公开
Zac Auger首席营收官Craft 资料页体现企业级商业化在扩张中;公开 CRO 职责披露不深

公开来源对 CEO 和联合创始人身份之外的角色披露有限。主要尽调缺口不是创始人身份,而是未披露的董事会结构和继任规划。

[CO003, CO004, CO005, CO040]

1.3 融资、估值与披露质量

Postman 的资本历史已经由其 2021 年公告和 TechCrunch 报道充分确立。公司完成由 Insight Partners 领投的 $225 million Series D,估值 $5.6 billion;GetLatka、Craft 等第三方数据库也都指向约 $433 million 的累计融资。更不确定的是当前变现水平。Economic Times 报道称,近期老股交易相对 2021 年估值以 30-40% 折价成交,并援引了解公司财务的人士,把年经常性收入(ARR)定在 $120-150 million。相比之下,GetLatka 估计 2024 年收入为 $313.1 million,此前估计 2023 年收入为 $171.7 million。这些数字不是小差异:前者暗示,相对于过大的上一轮估值,变现速度偏慢;后者则暗示规模大得多。在没有经审计收入、烧钱速度、利润率或留存披露之前,合理姿态是把两者都当成有用但低置信度的信号,避免把任一估算过度嵌入核心公司快照。[CO011, CO012, CO013, CO014, CO015, CO016]

利益相关方或投资者图谱
利益相关方公开角色重要性证据经济 / 控制含义未决尽调请求
Insight PartnersSeries D 领投方领投估值 $5.6B 的 $225M 轮在已披露投资者中,正式治理影响力可能最强确认董事席位、超比例跟投权和信息权
Nexus Venture Partners老股东参与 Series D,并在老股交易背景中被点名持有时间长且仍有敞口的投资者确认当前持股,以及老股出售是否改变控制权
CRV老股东参与 Series D早期背书仍可能影响市场信号确认是否继续持股及治理权利
Coatue成长期投资者加入 Series D;官方轮次公告中点名经济信号强,但控制力不明显确认权利是否不同于早期投资者
Battery Ventures成长期投资者加入 Series D;在老股交易背景中被提及增加后期软件市场验证确认是否有跟投或二级市场增持
BOND成长期投资者加入 Series D成长期信号型投资者确认 BOND 是否在老股交易中留股或卖股

投资者名单比股权结构表更清楚。控制权利和当前持股比例仍属私有信息。

[CO011, CO012, CO013, CO015, CO040]

1.4 战略轨迹与品类定位

公司近期策略,是把 API 协作升级成 AI 原生系统层。Postman 2025 State of the API 报告提出,API 战略正在变成 AI 战略;报告自己的调查数据也把 API 描述成创收资产,且越来越需要协作和机器可读结构。Postman 随后把这个叙事落进产品:TechCrunch 报道了 2025 年 1 月 AI Agent Builder 的发布,Postman 自己的材料也推出 Agent Mode 和 AI Engineer,把它们定位成能够跨集合、规范、环境和工作流资产行动的助手。Orbit、liblab 和 Fern 的收购也贴合这条弧线。Orbit 拓宽社区和开发者互动能力,liblab 增加 SDK 生成,Fern 增加文档和 SDK 自动化。合在一起,这些动作显示 Postman 想占据 API 生产者、API 消费者和将调用这些 API 的 AI 智能体之间更多表面积。[CO022, CO023, CO024, CO025, CO026, CO027]

1.5 负面事件与可靠性信号

最近最有意义的负面信号已经不再是假设。Postman 自己的信任门户表明,第三方 Klue 遭入侵导致 2026 年 6 月 Salesforce 中的客户联系和销售信息被外泄,尽管 Gong 中的产品或核心客户数据未被访问。CloudSEK、Cyber Security News 和 Treblle 的外部报道也保留了 2024 年公共工作区暴露事件:数以万计的公开可访问工作区浮现出令牌、密钥和其他敏感材料。这些报道并不意味着 Postman 本身独特地不安全;相当一部分暴露看起来来自用户行为和薄弱的密钥卫生。但它们确实说明,公共协作带来真实治理风险,尤其是对一个鼓励广泛共享的平台而言。抵消这一点的是,Postman 状态页在审阅时显示核心服务运行正常,桌面端在过去 90 天窗口中可用时间为 100%。因此风险姿态是混合的:运营连续性强,但平台扩张并变得更智能体化之后,安全治理负担也在上升。[CO032, CO033, CO034, CO035, CO036]

里程碑表
日期事件类型金额 / 状态参与方含义
2014Postman 最初是一个简化 API 测试的副项目创立Abhinav Asthana;后来 Ankit Sobti 和 Abhijit Kane品类起源故事和创始人延续性
2021-08宣布 Series D融资$225M,估值 $5.6BInsight、Coatue、Battery、BOND、CRV 与 Nexus 投资人新股峰值估值和资本基础
2024-04宣布收购 Orbit合作收购Postman 与 Orbit扩展开发者社区工具
2024-08Economic Times 报道大幅折价的老股交易反向较峰值折价 30-40%现有投资者和老股买家账面估值压缩的公开信号
2025-01TechCrunch 报道 AI Agent Builder产品发布PostmanAPI 工作流延伸到智能体构建
2025-07宣布新的 San Francisco 总部规模总部扩张Postman实体扩张信号
2025-10State of the API 新闻稿提到 40M 用户和 500,000 个组织规模用户 / 组织里程碑Postman证实平台采用面很广
2025-11宣布收购 liblab产品收购Postman 与 liblab将 SDK 生成加入生命周期栈
2026-01宣布收购 Fern产品收购Postman 与 Fern加入 docs-as-code 和 SDK 工作流
2026-06披露与 Klue 相关的 Salesforce 数据外泄反向客户联系信息和销售信息受影响Postman 与 Klue需要信任回应的安全治理事件

里程碑采用公开公告时间,不一定等同于交易完成时间。本表强调长期叙事拐点,而不是逐一列出每次产品发布。

[CO001, CO011, CO015, CO021, CO027, CO029]
FO001: 公司里程碑时间线

从创立到 2026 年事故披露的公开时间线显示,公司既在扩大产品,也在面对更复杂的治理问题。

[CO001, CO011, CO015, CO021, CO027, CO029]

1.6 展项

Chapter 02

02市场分析

2.1 市场边界:Postman 实际卖的是什么

分析 Postman 时,最容易犯的错误是把市场过窄地定义为 API 客户端软件。Postman 的产品页面把它放在更宽的 API 生命周期品类里,包括设计、测试、文档、分发、监控和治理。API Repository 与 Flows 页面进一步说明,这不只是一个单用户请求运行器:公司卖的是共享资产管理、可发现性、工作流执行和跨团队可见性。这个更宽的框架很重要,因为市场本身是碎片化的。企业买家可以从 Swagger 或 Stoplight 采购设计能力,从 ReadyAPI 采购测试,从 Kong 采购网关,从 Insomnia、Bruno 或 Hoppscotch 采购轻量客户端。因此,Postman 的服务市场更适合被描述为广义 API 管理和 API 开发经济中的协作与工作流中心切片。它赢在组织需要团队与机器之间的共同上下文,而不只是需要一种发起 HTTP 请求的方式。[CM001, CM002, CM017, CM018, CM019, CM023]

市场定义表
细分市场 / 品类纳入支出排除支出买方 / 付款方对 Postman 的意义
API 协作平台共享集合、文档、Mock、监控、代码库、工作流纯网关基础设施或定制集成服务工程经理、平台团队、API 产品负责人这是 Postman 服务的核心市场
API 设计 / 文档OpenAPI 设计、文档门户、治理、Mock 服务器通用 IDE 或 wiki 软件平台架构师、开发者体验、产品Swagger 和 Stoplight 争夺的重要相邻预算
API 测试功能、回归、近似负载的 API 验证广义可观测性或应用 QA 套件开发者、QA、平台团队重要切入点,但不是完整市场
网关 / 运行时 API 管理网关、流量控制、混合 / 无服务器运行时连接生命周期协作资产基础设施和平台运营相邻市场,但采购方式不同
本地 / 开源客户端单个请求执行、集合存储、Git 原生工作流企业治理和全组织资产管理个人开发者、小团队定义低端替代品集合

市场表把以协作为中心的支出,与相邻基础设施或本地工具支出区分开。边界只是近似值,因为厂商之间的重叠越来越多。

[CM001, CM002, CM017, CM023, CM024, CM025]
FM002: 买方 / 客群地图

该品类横跨低成本个人工具,以及更高价值的企业治理和工作流控制。

[CM020, CM024, CM025, CM033, CM035, CM036]

2.2 市场规模、增长与估算分歧

公开市场规模估算方向一致,但量级不同。The Business Research Company、Strategic Market Research、Fortune Business Insights 和 Mordor Intelligence 都显示未来十年会有双位数或更高增长,但它们给出的 2025 年市场数字从约 $5.24 billion 到 $8.86 billion 不等。这个跨度太大,不能忽略。它很可能反映了各家在 API 管理软件、API 网关、生命周期工具和企业服务上的口径选择不同。尽调中重要的结论不是单点 TAM,而是增长方向的一致性:每个来源都指向一个仍随数字化转型、云原生架构和 AI 驱动集成需求扩大的市场。因此,Postman 应被视为处在一个大型且扩张中的品类里,但这个品类边界足够模糊,精确 TAM 计算会夸大确定性。区间视角比一座带着假精度的单点堆叠金字塔更诚实。[CM003, CM004, CM005, CM006, CM007]

TAM / 规模测算视角表
发布方预测 / 基准年份地域市场规模增长率方法提醒
The Business Research Company2025 to 2030全球$5.24B 至 $20.89B 区间31.8% CAGR可能以 API 管理软件为中心,基准年口径偏窄
Strategic Market Research 市场研究2024 to 2030全球$5.6B 至 $15.1B 区间18.2% CAGR只有方法摘要;品类边界披露不深
Fortune Business Insights2025 to 2034全球$6.89B 至 $37.43B 区间21.7% CAGR时间跨度更长的广义长期预测
Mordor Intelligence2025 to 2031全球$8.86B 至 $22.11B 区间16.45% CAGR似乎纳入更广的企业 API 管理品类

这些是市场规模测算视角,不是一个精确 TAM。差异大到尽调应采用区间,而不是点估计。

[CM003, CM004, CM005, CM006, CM007]
FM001: 市场估计区间

第三方 API 管理市场估计指向强劲增长,但基准年口径分散很大。

[CM003, CM004, CM005, CM006, CM007]

2.3 买家、用户与需求驱动

Postman 自己的调查数据提供了最强的公开需求驱动信号。测试、开发和文档占用 API 团队大量时间,93% 的团队又表示协作仍然困难,这让协调痛点变成真实问题,而不是营销文案。同一份报告认为,API 正在从成本中心管道转向收入资产:65% 的组织现在从 API 创收,其中多数还从 API 获得有意义的公司收入占比。这把买家从一线开发者扩展到平台负责人、架构团队、产品负责人、安全和治理利益方,他们关心可发现性、复用和政策控制。Postman 的 Free、Solo、Team 和 Enterprise 包装也显示出买家阶梯:个人可以低成本开始,但真正的变现机会在组织标准化。AI 进一步强化了这一点,因为当智能体调用 API 时,文档完善、受治理、可发现的接口价值会明显上升。[CM008, CM009, CM010, CM011, CM013, CM018]

细分市场 / 买方图谱
细分市场主要用户主要付款方工作流需求采用触发因素对 Postman 的含义
个人开发者应用或后端开发者自己或经理发送请求、检查响应、调试 API快速上手和免费实用性漏斗顶部触达广,但支付意愿低
团队级 API 项目开发者和技术负责人工程管理层共享集合、测试、文档、Mock 环境协作和标准化需求Team 方案核心变现区
平台 / 架构团队平台工程师、架构师工程 VP / 平台预算资料库、治理、可发现性、版本管理API 蔓延和合规压力最适合企业增购
安全 / 治理团队安全工程师、治理负责人安全或平台预算策略、密钥处理、智能体风险管理AI 智能体使用和合规担忧日益重要的买方影响力
开发者生态 / 产品团队开发者关系、API 产品经理产品或 GTM公共工作区、引导上手、文档、SDK 分发扩大外部 API 消费的需求支撑网络效应和生态触达

不同细分市场里,买方和付款方角色差异很大。个人使用面很广,但当组织需要共享上下文和治理时,最高价值预算才会出现。

[CM009, CM010, CM018, CM019, CM020, CM036]
FM003: 采用漏斗或价值链图

组织从单个用户试用走向与收入挂钩、可治理的 API 计划后,价值会持续叠加。

[CM010, CM011, CM012, CM015, CM017, CM018]
FM004: 市场规模测算视角

市场从本地请求工具扩展到协作、治理,以及面向 AI 的工作流基础设施。

[CM010, CM011, CM012, CM014, CM017, CM018]

2.4 约束、商品化与可投资切片

关键市场约束在于,并不是每一美元 API 工作流支出都属于 Postman。Insomnia、Bruno、Hoppscotch 等开源和本地优先工具,让个人或小团队很容易完全绕开 SaaS 支出;Stoplight 和 Swagger 继续争夺设计预算,Kong 则让基础设施预算与协作支出分离。公开评论又增加了第二层摩擦:一些用户认为 Postman 越来越按企业级定价,另一些用户反馈大型集合或成熟工作区会变慢、变压迫。最后,AI 在抬高市场机会的同一时刻也抬高治理风险。Postman 自己的报告显示,团队更担心未经授权的智能体访问,安全团队也把 AI 智能体就绪度当成真实运营议题。因此,可投资市场不是 API 相关活动的整体大盘,而是其中协作、治理和工作流自动化价值足以支撑付费平台标准化的子集。这个更高价值层,正是企业预算、政策需求和 AI 工作流复杂度在今天实际压过免费工具替代品的地方。[CM014, CM015, CM016, CM024, CM025, CM026]

增长驱动因素与约束表
驱动因素 / 约束方向时点含义尽调追问
API 作为直接收入驱动正向当前支撑生命周期平台的战略预算量化 Postman 客户中通过 API 变现的占比
AI 智能体需要机器可读 API正向当前至近期提高受治理的文档、规范和工作流自动化价值验证 AI 增购是在抬高 ARPU,还是只增加用量
分布式团队协作痛点正向当前支撑仓库、工作流、评论和治理层衡量协作功能带来的真实席位扩张
开源 / 本地优先替代品负向当前挤压低端用户付费意愿按个人与企业交易拆分赢率
企业定价摩擦 / 性能投诉负向当前若产品复杂度比价值增长更快,扩张可能受限按套餐层级复盘流失和 NRR
安全与智能体治理风险混合当前至近期既可能拉动治理支出,也可能拖慢采用或抬高证明要求索取安全路线图和事件响应复盘

关键约束不在市场活动不足,而在这些活动有多少必须用付费协作平台承载,而不是免费本地客户端或独立网关栈。

[CM010, CM012, CM013, CM014, CM015, CM022]

2.5 展项

Chapter 03

03竞争格局

3.1 竞争框架:一个平台对抗碎片化技术栈

如果把每个对手都硬塞进直接同口径对比,Postman 最容易被误读。有些供应商只攻击设计切片,有些攻击测试切片,有些攻击运行时网关层,还有些攻击免费客户端层。但 Postman 自己的产品页面显然想把这些相邻工作压缩进一个统一生命周期表面:存储库、工作流、文档、测试、监控,以及现在的智能体工具。因此,公司很少只和“另一个 API 客户端”竞争。它对抗的是碎片化技术栈,以及继续把不同品类分开采购的选项。分析问题不是某一个竞争对手是否复制每项功能,而是买家能否从点工具、基础设施平台或免费替代品里拿到足够需求,从而避免标准化到 Postman。这很重要,因为碎片化购买模式会让 Postman 在用户层看起来很流行,却仍把战略预算让给相邻供应商。[CP001, CP002, CP016, CP025, CP026, CP027]

竞争对手画像表
竞争对手类别商业 / 定价模式主要切入点相比 Postman 的短板
SwaggerHub设计 / 文档套件订阅软件规范优先的设计、文档、治理作为通用工作流和协作中枢较弱
InsomniaAPI 客户端 + 协作免费 / 开源加付费套餐本地优先、无需登录的工作流灵活性广泛生命周期上下文和企业级仓库深度证据较少
Stoplight设计 / 文档 / Mock团队订阅设计治理和即时 Mock 服务器工作流覆盖比 Postman 的完整生命周期叙事更窄
BrunoGit 原生 API 客户端免费开源版本控制原生本地工作流企业治理或组织上下文很少
ReadyAPI企业 API 测试商业测试套件多协议自动化测试深度偏点工具,弱于统一平台叙事
Kong网关 / 连接平台基础设施式网关定价运行时 API 连接和控制平面不是协作优先工作区
GitLabDevSecOps 套件分层平台订阅打包的工程平台和 AI 智能体API 工作流只是相邻能力,不是核心

各行比较的是公开定位,不是内部赢率。表格聚焦买方如何避免端到端采用 Postman。

[CP002, CP003, CP004, CP006, CP007, CP009]
FP001: 竞争定位图

相比单点工具,Postman 在工作流广度和企业治理深度上位置更高;Kong 和 GitLab 则从更宽的平台位置参与竞争。

[CP003, CP004, CP006, CP007, CP010, CP011]

3.2 直接与相邻竞争对手

SwaggerHub 和 Stoplight 是最清晰的设计优先型对手。它们的公开定位更强调 API 设计、文档、治理和模拟服务器工作流,而不是 Postman 更宽的协作上下文。ReadyAPI 更聚焦多协议企业测试深度。Kong 在运行时 API 连接上离得更远,但仍会争夺战略 API 项目预算,因为网关和控制平面决策往往会塑造团队对其余工具的评估方式。GitLab 又是另一类威胁:它不是仅做 API 的公司,而是平台套件供应商,可以把 AI 智能体和协作打包进更大的 DevSecOps 合同。合在一起,这些对手说明 Postman 的竞争并不是一个整齐的单一品类,而是从设计套件到运行时基础设施、再到横向打包软件平台的一条光谱。因此,任何严肃尽调备忘录都应检验:Postman 赢,是因为它更好,还是因为买家只是更偏好更少工具。[CP003, CP004, CP006, CP009, CP010, CP011]

功能 / 能力矩阵
采购标准PostmanSwaggerHubInsomniaStoplightBrunoReadyAPIKong / GitLab
共享 API 仓库部分有限有限有限部分
设计 + 文档工作流部分有限有限部分
本地优先 / 无账号路径部分
企业治理 / 策略覆盖面部分有限部分
AI 辅助工作流覆盖面起步中有限有限有限有限
运行时网关 / 平台连接有限

能力判断基于公开产品定位,而不是实测功能对等性。「部分」表示覆盖有实质内容,但不明显领先同类。

[CP003, CP004, CP005, CP006, CP007, CP009]
定价 / 打包对比
平台入门定价信号经济模型包含重点含义
PostmanFree 免费;Solo $9;Team $19;Enterprise $49按用户 / 套餐层级广泛生命周期协作自助购买门槛低,但企业增购取决于席位扩张
StoplightBasic $44;Startup $113按团队规模订阅设计、文档、Mock 服务器设计预算重的团队可能接受溢价定价
Insomnia永久免费的本地 Scratch Pad免费 / 开源加付费层级客户端、本地、Git、云工作流压低低端付费意愿
Bruno免费且开源无账号开源本地 Git 原生客户端面对它,纯客户端收费很难守住
Kong免费试用后按网关收费基础设施数量网关运行时和连接争夺平台预算,而非请求客户端预算
GitLabFree / Premium / Ultimate + AI 积分套件订阅 + 用量DevSecOps 加智能体平台API 功能可打包进更大的工程标准化采购

定价单位差异不亚于绝对价格。按席位收协作费、按基础设施收网关费、开源本地工具,会把买方拉进不同评估框架。

[CP010, CP011, CP013, CP014, CP015, CP025]
FP002: 功能广度 / 能力图

不同对手围绕不同采购中心聚集,而不是在一套完全重叠的功能上正面撞车。

[CP003, CP004, CP006, CP007, CP009, CP010]

3.3 本地优先与开源替代品

最明显的低端风险来自那些有意拒绝云工作区或企业控制模型的工具。Insomnia 永久免费的仅本地 Scratch Pad、Bruno 的 Git 原生免账号客户端,以及 Hoppscotch 的开源定位,都给个人或小团队提供了可信路径,让他们不用太早为 Postman 付费。这并不意味着 Postman 会输掉整场竞争;这些替代品中很多本来就设计得很窄。但它们重要,因为它们压缩了客户端层的支付意愿。一旦这一层商品化,Postman 就必须证明,存储库可见性、协作、治理和 AI 上下文值得额外成本和复杂度。评论数据也强化了这种张力:用户仍然喜欢 Postman 的测试和协作,但也有人抱怨付费功能漂移、调试摩擦,或大规模使用时可用性下降。换句话说,替代品不需要功能对等也能产生影响;它们只需要在更窄任务上足够好。[CP004, CP005, CP007, CP008, CP020, CP021]

护城河耐久性 / 竞争风险登记
护城河主张威胁严重性为何重要缓释措施 / 尽调追问
40M+ 用户分发低端工具把请求执行商品化如果买方留在免费工具,装机基础可能无法变现索取免费转付费和扩张数据
统一生命周期上下文单点最佳工具切走设计、测试或网关预算工具碎片化可能限制席位整合索取按模块划分的附加率和打包交易证据
AI 原生工作流覆盖面GitLab 这类套件或基础设施栈加入自己的智能体层AI 差异化可能很快被压缩跟踪 AI 功能采用率和 ARPU 提升
仓库和工作流切换成本用户对复杂度或性能的投诉削弱锁定效应用户不喜欢运营负担时,护城河会失效复盘流失驱动因素和大型工作区产品遥测
企业可信度GitLab 和 Kong 可把 API 打包进更广泛的合同打包压力可能改变采购动态按客群索取大单竞争分析

风险登记聚焦护城河耐久性,而非泛泛公司风险。公开来源能提供线索,但不足以回答赢率问题。

[CP021, CP022, CP024, CP028, CP029, CP030]
FP003: 护城河 / 准备度 KPI

竞争耐久度取决于 Postman 能否在对手变现各自细分市场之前,更快把自身规模和工作流上下文变成收入。

[CP017, CP018, CP019, CP025, CP027, CP028]

3.4 护城河耐久性与竞争风险

当 API 工作变得共享、受治理、上下文密集时,Postman 的护城河最强。这也是为什么存储库、Flows、Agent Mode 和 AI Engineer 的战略重要性高于底层请求客户端。公司的规模同样重要:一个声称拥有 40 million 用户和 500,000 个组织的平台,具备大多数细分对手无法公开匹配的分发杠杆。即便如此,这个优势并非坚不可摧。碎片化会从下方侵蚀价值,打包平台会从上方侵蚀价值。公开来源没有披露胜率、按竞争对手划分的流失,或按细分市场划分的留存,所以关键未解尽调问题是:Postman 更宽的平台在实践中是否真的整合了预算。如果答案是是,护城河真实存在;如果团队继续在边缘购买同类最佳点工具和免费本地客户端,护城河可能比装机基础暗示的更浅。因此,在全球企业采购周期里,模块附加率和企业标准化行为比单纯客户 logo 数更重要。[CP013, CP014, CP015, CP017, CP018, CP019]

3.5 展项

Chapter 04

04财务情况

4.1 收入模式与定价架构

Postman 作为云软件平台变现,漏斗顶部有庞大的免费用户,再逐步抬升到付费协作、治理和 AI 层级。实时定价页显示,2026 年结构包括 Free、Solo、Team 和 Enterprise 计划;付费升级解锁协作、治理控制、更大的 AI credit 池和更多运营上限。Enterprise、Workspaces 和 API Repository 产品页面清楚说明,可变现表面不只是发送请求,而是共享资产管理、私有 API 发现、治理和组织级工作流上下文。这一点重要,因为公司的用户增长已经巨大。免费计划仍能播种采用,但收入必须来自把 API 工作从个人工具转化为团队和企业的记录系统。Apidog 和 Dev Tools 的外部定价评论带有自身利益,置信度低,但方向上有用,因为它恰好突出 Postman 在 2026 年更用力推动变现的地方:协作现在从 Team 层开始,而不是过去面向小团队的免费路径。因此,核心财务问题不是 Postman 有没有触达,而是协作、治理和 AI 辅助能否在这种触达上产生足够耐久的支付意愿。[CI001, CI002, CI003, CI004, CI005, CI006]

收入流表
收入流机制当前公开数值 / 状态收入质量判断尽调追问
免费转付费席位转化免费用户升级到 Solo 或 Team漏斗顶部很大;官方定位称有 40M+ 开发者和 500k+ 组织若协作痛点转化为付费席位,潜力较强;公开层面未证明索取免费转付费转化、活跃团队工作区数量和席位扩张队列
Team 订阅面向协作的按用户年度套餐Team 标价为 $19/用户/月,按年计费若扩张和留存健康,经常性收入画像较好提供每账户平均付费席位、流失率和按客群折扣情况
Enterprise 订阅按用户企业套餐,叠加治理和组织控制Enterprise 标价为 $49/用户/月,按年计费,并走联系销售流程可能是 ACV 最高的收入流,留存更好,治理粘性更强拆分企业 ARR、合同期限和年度承诺下席位占比
AI 积分超额费用超出套餐额度后的按用量消费定价页列出按需付费的 AI 超额用量增加增量变现,但可能仍处早期且波动展示 AI 积分消耗、超额附加率和利润率画像
API 项目扩张大客户内部采用合作伙伴 API、私有网络、监控、治理和仓库企业页面明确把合作伙伴 API 和规模化项目与变现结果挂钩如果初始采用后模块能附加,可能支撑先落地后扩张的经济模型披露治理、监控和 API 网络功能的附加率

各行概括 Postman 如何把开发者采用转成经常性 SaaS 收入。公开来源描述了机制,但未披露各收入流的实际组合或净留存。

[CI001, CI004, CI005, CI007, CI008, CI009]
定价 / 变现表
套餐 / 机制标价或状态包含的变现杠杆信号来源 / 注意事项
Free$0单人使用、有限 AI 积分、漏斗顶部采用仍围绕采用率优化,但协作能力已经单独打包官方定价页为准;外部博客强调 2026 年打包变化
Solo$9/用户/月,按年计费增加更高 AI 积分池和个人高级功能团队标准化前先瞄准重度用户官方页面价格明确;实际使用未披露
Team$19/用户/月,按年计费多人协作和共享工作区的最低价路径付费协作真正从 Team 开始多篇外部评论将其标为小团队转化断崖
Enterprise$49/用户/月,按年计费,加销售主导打包增加 Private API Network、组织控制、治理和更高的共享 AI 积分池支撑更大 ACV 和更强切换成本实际企业折扣和真实平均售价未知
AI 超额用量实时页面显示按层级每积分 $0.05、$0.04 或 $0.035席位收入之上的按用量增购若 AI 功能形成习惯,可抬高 ARPU公开来源未披露当前附加率或超额费用贡献

定价为 2026 年实时页面抓取的标价,并与外部关于 2026 年 3 月打包变化的评论交叉验证。不代表折扣后的实际净价。

[CI001, CI002, CI003, CI004, CI005]
FI001: 收入模式桥接图

展示 Postman 如何把广泛免费采用转化为更高价值的团队版、企业版和用量型收入。

这是一张变现逻辑图,不是量化收入桥。

[CI001, CI004, CI007, CI008, CI011]

4.2 GTM 动作、转化逻辑与效率代理

公开证据指向一种混合销售动作:顶部是广泛的自助式开发者采用,随后在共享工作流重要的地方扩张到团队和企业。Postman 称平台现在触达超过 40 million 开发者和 500,000 个组织,企业页面仍声称覆盖 98% 的 Fortune 500。这些数字本身不能保证收入质量,但它们意味着一个异常大的已获客用户池;付费转化可以在其中开采,而不必完全依赖绿地式企业销售。2025 State of the API 报告显示 API 变现广泛存在、协作痛点持续存在,这进一步强化了这一解读;这两个条件都支持付费团队工具。评论网站在更小尺度上强化同一模式:用户反复称赞共享集合、环境和工作区,也抱怨随着协作和治理功能进入更高层级,定价变得更激进。这个组合暗示产品价值健康,但如果买家感知到价格爬升快于增量效用,低端转化效率也会有真实天花板。公开 CAC、回本周期、管线转化和席位扩张指标仍未披露,所以最好的外部代理很简单:Postman 看起来是在组织协调变得足够昂贵、足以支撑一个平台时变现,而不是在单个开发者只需要免费请求客户端时变现。[CI006, CI007, CI008, CI009, CI010, CI011]

单位经济表
指标公开数值 / 代理指标置信度为何重要尽调追问
漏斗顶部规模官方定位称有 40M+ 开发者、500k+ 组织,覆盖 98% 的 Fortune 500若转化效率高,庞大装机基础可降低获客成本提供月活用户、活跃工作区和付费账户转化率
协作痛点代理指标2025 State of API 报告显示,93% 团队遇到 API 协作困难支撑共享工作流和治理的付费意愿展示哪些协作功能与付费转化关系最强
API 变现需求代理指标65% 组织通过 API 创收表明付费 API 平台能切入业务关键工作流披露企业买方组合和按用例划分的收入集中度
毛利率基准据 GitLab 2026 companyfacts 推算,$955.2M 收入下毛利率约 87%成熟期 devtools SaaS 即使仍大举投入,也能有很高毛利率披露 Postman 毛利率和按套餐划分的托管 / 支持负担
销售强度基准GitLab 2026 companyfacts 显示销售和营销费用为 $434.7M规模化 devtools SaaS 即使资本开支轻,也往往销售投入重提供 CAC、回本周期以及 S&M 占收入比例
人均收入估计Growjo 估计,在 $506.1M 收入和 2,212 名员工基础上,每名员工收入为 $228.8k输入数据存在争议,因此只能作为粗略外部效率数据点用经审计员工数和每名 FTE 的 LTM 收入替换

公开披露中缺少大多数单位经济性指标,因此本表把官方需求代理指标、上市可比公司和数据库代理指标混合使用。 低置信度行应在尽调中用管理层数据替换。

[CI012, CI013, CI014, CI029, CI037, CI038]
FI002: 单位经济模型桥接图

公开代理指标显示,协作痛点和庞大安装基数是主要转化杠杆,标价摩擦则是主要拖累。

该桥使用公开代理指标,而非公司披露的单位经济指标。

[CI013, CI014, CI018, CI019, CI020]

4.3 成本结构、利润率路径与资本充足性

Postman 的交付模式在结构上应当是轻资本开支。公开产品记录中没有任何迹象指向库存、硬件制造、项目融资或重型本地部署服务交付。平台以软件形式交付,价值集中在云协作、存储库管理、监控、文档、治理和 AI 辅助生产力上。这并不意味着公司运营便宜。更相关的公开基准是 GitLab 这样的规模化开发者工具 SaaS 可比公司;其 2026 年 SEC XBRL 披露显示毛利润高,但销售、营销和研发仍持续重投入。Postman 更早期且是私有公司,所以具体比例可能有实质差异;但可能的形态相似:毛利率应有吸引力,而增长投入仍偏人力密集,不是资产密集。资本充足性更难判断。Postman 没有公开披露现金、烧钱速度、债务或现金跑道,近期老股交易也不会把钱放进公司账上。2021 年 Series D 和之后没有新股融资,意味着当前资产负债表必须扛着公司穿过一段漫长估值重置周期。没有管理层数据,投资者只能说,这门生意在运营上看起来轻资本,但在流动性披露上很轻。[CI021, CI022, CI023, CI024, CI025, CI026]

资本充足性表
项目公开数值 / 状态已知信息含义尽调要求
累计融资~$433M 至 $434MGetLatka、Craft 和 Tracxn 的估计集中在这一累计总额附近历史资本化规模可观,但不能回答当前流动性问题对齐累计一级市场融资、二级交易规模和资产负债表剩余现金
最近一轮一级融资2021 年 8 月 $225M Series D 轮,估值 $5.6B官方博客和 TechCrunch 相互印证了这轮融资未发现此后一级融资,因此 2021 年的现金必须撑过估值重置周期要求提供当前现金余额和董事会批准的融资计划
二级交易活动据报道,2024-2026 年有折价二级交易Economic Times 和估值追踪器显示价格承压,但公司没有获得现金二级流动性可帮助员工 / 投资者变现,但不能为运营输血拆分一级融资与二级流动性,并说明任何要约收购机制
债务 / 项目融资未发现公开债务或项目融资义务软件模式并不明显需要资产支持融资对资本强度是正面信号,但缺少证据不等于没有债务确认是否存在风险债、信贷额度或表外承诺
现金 / 烧钱速度 / 现金跑道未披露已审阅公开来源均未披露当前现金、烧钱速度或现金跑道现金数据缺失是仅靠公开来源判断资本充足性的主要卡点提供基准和压力情景下的月度烧钱、自由现金流、现金跑道和下一轮融资触发条件

公开来源无法给出资本充足性的定论。二级市场评论有助于价格发现,但不能说明公司流动性, 因为这些交易不会增加运营现金。

[CI021, CI022, CI023, CI030, CI031, CI040]
FI003: 财务估算区间

公开来源只能支撑较宽而非较窄的当前收入和隐含老股估值区间。

区间混合了不同来源的方法,应理解为公开证据带,而非经审计的公司指引。

[CI024, CI029, CI031, CI034]
FI004: 资本强度 / 现金流图

Postman 看起来资本开支轻,但缺失变量是毛利率、销售效率和剩余现金,而不是硬件或库存需求。

这是一张结构性现金流图,依据公开商业模式证据和可比上市公司基准推导。

[CI035, CI036, CI037, CI039, CI040]

4.4 公开牵引力、收入质量与底线判断

目前最好的公开增长线仍是 Latka 序列:2021 年约 $52 million,2022 年 $102.7 million,2023 年 $171.7 million,2024 年 $313.1 million。如果方向正确,Postman 就是一家非常大型的私有开发者工具 SaaS 公司,规模有意义,扩张仍强。但这组数字并不干净。Growjo 发布了高得多的前瞻收入估算和非常不同的员工数;Economic Times 援引接近公司财务的人士,估计年化经常性收入只有 $120-150 million,并明确把差距归因于低于预期的变现速度。这些不是四舍五入差异。它们暗示口径不同、期间不同,或者用户采用与付费收入转化之间真的不匹配。随后,二级市场估值跟踪器显示隐含标记大幅分散;当公司是私有、流动性发现很薄、官方财务报告缺席时,这正是可以预期的结果。实际判断是,Postman 可能有吸引人的毛利率潜力和大型企业变现上行,但收入质量、留存质量和当前现金效率仍要等管理层分享经审计或投行级运营数据后才能解决。[CI024, CI025, CI026, CI027, CI028, CI029]

公开财务缺口表
缺失指标重要性当前公开信号对判断的影响具体尽调路径
经审计 ARR / 收入桥接用来对齐相互冲突的外部估计Latka、Growjo 和 ET 暗示的规模数字差异很大没有桥接表,当前收入质量仍不确定获取管理层财务包和投行演示材料,明确 ARR、收入和开票定义
毛利率决定 Postman 在 AI、支持和销售上的投入空间未发现公司公开披露利润率路径只能推断,不能直接衡量索取按产品拆分的毛利率、托管支出和支持 / 服务负担
净收入留存 / 流失检验落地后扩张模式韧性的核心指标未发现公开 NRR、GRR 或队列披露席位增长可能看起来强劲,但净留存可能不及预期索取 logo 流失、席位流失、NRR 和企业队列扩张数据
现金余额和现金跑道没有这些数据,资本充足性无法判断已审阅资料中没有公开现金或烧钱数据投资人无法评估融资紧迫性索取月度烧钱、现金和下行情景现金跑道假设
折扣与实际 ASP对后期企业级 SaaS 公司,标价不是真实成交经济性只有标价公开若折扣很深,收入倍数和转化效率可能被高估索取按套餐拆分的 ASP、平均折扣率以及渠道 / 直销组合

本表每一行都是真实的投资判断卡点,不是形式上的遗漏。公开资料在产品和定价上很丰富, 但对实际经济性披露很薄。

[CI024, CI031, CI032, CI038, CI040]

4.5 展项

Chapter 05

05产品与技术

5.1 平台覆盖面与客户工作流

Postman 现在把自己营销成覆盖完整 API 生命周期的统一平台,而不是单一 API 客户端。产品页把设计、测试、文档、监控、治理、协作和 AI 打包到一个表面里;存储库页面也说明,这些不是挂在断裂数据上的独立附加件。平台围绕集合、规范、环境、工作区和存储库状态展开,这些资产可以在设计、测试、发布和监控之间复用。对用户而言,产品叙事是减少工具碎片化,并让 API 工作保持同步。对买家而言,Postman 试图销售的是 API 工作的记录系统。这一转变重要,因为它解释了 Postman 为什么能在不放弃原始请求运行器切入点的情况下,持续扩大平台足迹。客户工作流从请求和集合开始,但可变现价值越来越多地落在共享上下文、可审阅性和组织可见性上,而不只是原始请求发送。[CE001, CE002, CE003, CE005, CE007, CE008]

产品模块 / 资产矩阵
模块 / 资产主要用户当前状态 / 成熟度差异化尽调缺口
API 客户端 + 集合开发者和测试人员核心 / 成熟既有用户基础庞大;可复用集合与更广的平台资产绑定需要拆分简单发送请求与更广生命周期使用的活跃用量
API Repository + Builder平台工程师和 API 负责人核心 / 成熟作为中央事实源,原生 Git 同步贯穿规范、文档、测试和代码需要 Builder 工作流采用率与独立集合使用量的对比数据
Flows开发者、入门引导团队、合作伙伴团队扩展中把工作流文档变成可执行资产和 AI 就绪封装需要 Flows 重度工作区的使用量和留存
Agent Mode + Postbot开发者和 QA早期,但扩张很快基于工作区上下文生成测试、修复请求并创建文档需要已量化生产率提升和护栏指标
AI Engineer + API Catalog平台和企业工程负责人Beta / 2026 年新界面上下文图谱、审查控制和实时 API 地图共同撑起权威记录系统护城河需要明确推出状态、模型供应商和生产使用深度

本表映射 2026 年公开资料可见的主要产品界面。成熟度标签是基于文档深度和发布措辞作出的分析判断, 不是公司宣布的生命周期标签。

[CE001, CE003, CE018, CE021, CE022, CE026]
工作流 / 用例表
用户任务当前工作流Postman 方案可衡量收益限制
设计并同步 API编写规范,并保持文档和测试一致API Builder + Repository + Git 同步减少工具切换,并把资产留在同一张图谱里需要团队采用 Postman 的对象模型
教学或调试复杂集成分享会偏离实际状态的文档或脚本Flows + 集合 + 环境把工作流变成可执行、可检查的资产可能比简单 README 或 curl 示例显得更重
在 CI 中跑回归测试手动导出脚本,或在别处重写检查Newman + Postman API + CLI在流水线中运行同一套集合逻辑部分现代包流程需要 Postman CLI,不能只靠 Newman
让 API 面向智能体就绪上线后再补文档和示例Agent Mode + Postbot + AI Engineer + API Catalog 产品组合提升机器可读性,并能更快生成覆盖需要强权限控制和高质量上下文,避免自动化出错
落实企业控制手工审查 API 蔓延和权限审计日志、治理 API、Secret Scanner、SCIM、Private API Network集中管理策略和运营监督公开文档仍未量化实际误报率或控制采用率

用例表关注工作流变化,而不是单个功能勾选项。收益是方向性的, 应在尽调中用真实客户使用情况验证。

[CE004, CE014, CE015, CE020, CE021, CE023]
FE001: 产品架构图

展示 Postman 如何把集合、仓库状态、工作流工具、治理和 AI 层层叠加。

这是一张概念分层图,综合公开产品页面和文档整理。

[CE001, CE003, CE016, CE017, CE021, CE022]
FE002: 客户工作流 / 运营流程

展示用户从 API 设计出发,经过测试、发布、监控,再到 AI 辅助维护的路径。

[CE001, CE003, CE018, CE021, CE026, CE030]

5.2 架构、格式与生态工具

公开记录中最清晰的架构模式,是 Postman 已经围绕可复用资产模型标准化。集合仍是基本单元,变量跨环境界定行为,API Repository 充当中央对象存储,构建器、网络、监控器和 AI 功能都围着它运行。schema site、Collection SDK、openapi-to-postman converter、Newman CLI 和 Postman API 都指向同一个方向:Postman 希望自己的对象足够可编程、可携带,可以插入更广的工程工作流;同时又足够一致,让团队留在共同格式族里。原生 Git 工作流和 Collection v3 的推进进一步靠近代码相邻开发,降低了“Postman 只在云 UI 里好用”的批评。即便如此,设计仍带有明确取向。最丰富的价值依赖资产住在或同步经过 Postman 控制平面,治理、编目、权限、评论和 AI 才能作用于这些资产。这对企业标准化是优势,对偏好更薄本地优先工具链的团队则是取舍。[CE003, CE004, CE007, CE008, CE009, CE010]

技术 / 运营架构表
层 / 组件作用关键依赖优势风险
集合 + schema请求和工作流的可移植资产格式Postman schema 和 SDK 生态让资产可在 UI、CLI 和代码间复用格式影响力可能形成软锁定感
Repository + 工作区中央状态和权限层Postman 云账户和工作区模型团队的单一事实源高阶价值取决于云端管理状态
Builder + 规范同步设计与源码控制桥梁OpenAPI / GraphQL / RAML 加 Git 集成保持规范、文档和测试一致需要严格的代码仓库和审查实践
运行时工具在本地和 CI 中执行集合Node.js、Newman、Postman CLI 与 Postman API 工具链支持本地、自动化和流水线执行Newman 与 CLI 的工具分裂可能让团队困惑
AI 上下文层为跨资产和服务的智能体提供上下文锚点上下文图谱、API Catalog、审查队列、模型基础设施在系统上下文上拉开 Postman 差异模型服务内部机制的公开披露仍然很薄

本架构视图反映公开产品和文档资料中可见的内容。它是控制平面地图, 不是完整基础设施图。

[CE003, CE007, CE009, CE010, CE012, CE015]
FE003: 关键依赖图

Postman 的技术价值依赖几个关键内外部节点:源代码仓库、Node.js 工具、云端状态和 AI 控制界面。

依赖关系来自公开文档推断,而不是内部架构评审。

[CE004, CE012, CE014, CE016, CE017, CE022]

5.3 AI 原生方向与 2026 发布弧线

2025-2026 年最重要的技术故事,是 Postman 正围绕 AI 原生上下文重做产品。Agent Mode 已经能跨集合、规范、环境和历史行动。Postbot 处理请求排障、测试生成、文档和可视化。AI Engineer 再上一个层级,使用常驻上下文图、沙盒执行和审核队列控制,帮助团队探索系统、运行 QA、处理 PR。2026 年 3 月 roadmap 和之后的“new Postman”发布,把这套逻辑扩展到完整平台:API Catalog 成为实时地图,本地和 CI 模拟服务器连接开发与测试循环,统一工作台把集合、规范、模拟、Flows 和文件放在一处。结果是,产品不再只是帮助开发者发起 API 调用;它试图成为人类和智能体理解并改变 API 系统的上下文层。这个野心有差异化,但也抬高了对可靠性、权限和信息架构的要求。[CE019, CE020, CE021, CE022, CE023, CE024]

路线图 / 发布 / 开发阶段表
日期 / 阶段功能 / 里程碑状态含义来源
2025-01AI 智能体构建器发布已发布证实平台正从单次请求工作流迈向智能体工具TechCrunch 和 I Programmer
2026-03 路线图API Catalog已宣布 / 正在推出在代码仓库、CI 和运行时数据之上创建实时运营层Postman 2026 年 3 月博客
2026-03 路线图原生 Git 工作流 + 本地 / CI mock 服务器已宣布 / 正在推出连接云端 UI 与贴近代码和流水线的工作流Postman 2026 年 3 月博客
2026 平台重塑发布统一工作台 + Collection v3已发布让集合、规范、mock 和文件共存于同一个工作区模型新版 Postman 已到来
2026 平台重塑发布多协议集合和智能体就绪 API已发布将 Postman 定位为面向人类和智能体的更广系统上下文层新版 Postman 已到来 + AI Engineer 页面

路线图状态反映抓取时公司对每项能力的描述方式。尽调期间应将公开发布措辞与实际生产访问权限对照检查。

[CE021, CE022, CE026, CE027, CE028, CE029]
FE004: 产品成熟度 / 能力图

标出 2026 公开材料中哪些 Postman 能力看起来成熟,哪些仍在扩展。

成熟度判断来自分析,不是公司给出的生命周期标签。

[CE003, CE022, CE024, CE026, CE027, CE030]

5.4 信任、安全、可靠性与技术取舍

Postman 发布的信任和安全细节多于许多私有开发者工具公司,但图景仍然混合。安全页面记录了 API key 管理、审计日志、2FA、漏洞赏金覆盖、AWS 托管和数据隐私框架认证等具体控制。API 文档还展示了审计日志、Secret Scanner、服务账号、SCIM 和治理 API 等企业表面,说明信任嵌在产品表面里,而不只是营销文案。同时,信任门户显示第三方集成仍可能制造暴露,Klue 相关事件就是例子。公开评论又强化了另一个运营取舍:让 Postman 强大的同一份广度,也可能让它对更简单团队显得沉重、复杂或过于云中心。因此,产品技术判断在深度和广度上偏正面,但尽调仍应追问数据边界设计、模型运营控制,以及平台在超大工作区和集合规模下表现得多么从容。[CE017, CE031, CE032, CE033, CE034, CE035]

信任 / 质量 / 合规表
控制 / 披露状态范围重要性缺口
API key 管理 + 2FA文档披露平台账户安全基础身份和 token 卫生控制已公开需要更细的管理员默认设置和强制策略细节
审计日志(180 天)文档披露安全访问和团队管理活动支持企业监督和事件复盘需要按套餐拆分的留存层级和导出覆盖范围
通过 HackerOne 发起漏洞赏金文档披露平台漏洞接收显示外部报告路径成熟需要响应 SLA 和奖金计划范围细节
数据隐私框架 + AWS 托管文档披露隐私和基础设施态势对全球企业采购很重要需要细颗粒度的数据驻留和子处理方流程图
信任门户事件 + 子处理方通知文档披露运营透明度和供应商依赖显示 Postman 披露第三方事件和供应商变更需要关于影响半径控制和检测栈的更多技术细节

本表只记录公开资料可见的信任控制。它不能替代安全问卷、渗透测试结果或架构审查。

[CE017, CE023, CE031, CE032, CE033, CE034]

5.5 展项

Chapter 06

06客户情况

6.1 客户分层与规模

Postman 的客户基础最好被理解为分层生态,而不是单一买家细分。公司服务个人开发者、内部工程和 QA 团队、API 平台负责人、外部开发者社区,以及面向合作伙伴的 API 项目。官方规模声明很大,并且在公司资产之间相当一致:40 million 开发者和 500,000 家公司或组织。第三方采用跟踪器也支持其广泛足迹,尽管它们滞后,且有时在绝对数量上不一致。Landbase 显示数千家已验证具名公司和广泛行业组合,Ramp 则暗示在其 DevOps 品类中的企业组织采用尤其高。重要的尽调结论不是精确虚荣指标,而是模式:Postman 已经渗透了非常广泛的 API 相关用户基础;当协作、合作伙伴接入或治理变得重要时,产品似乎会从爱好者使用跨入严肃企业标准化。即使公开合同和支出数据仍被隐藏,这种广度也支持一个多元化客户漏斗。[CU001, CU002, CU003, CU004, CU005, CU006]

客户分群表
分群买方 / 用户 / 付款方典型用例规模信号缺口
个人开发者用户:开发者;付款方:无或经理发送请求、探索 API、fork 公开集合Postman 声称覆盖 40M+ 开发者没有个人转为付费团队的公开转化数据
内部工程 / QA 团队用户:开发者和测试人员;付款方:工程负责人共享集合、CI 测试、治理、环境Medibank 和 ZEISS 显示内部标准化没有按团队规模拆分的公开席位数
API 平台 / 合作伙伴团队用户:合作伙伴集成和 DevRel 团队;付款方:平台或产品公开工作区、合作伙伴工作区、入门引导、文档PayPal、Autodesk、HubSpot 和 Cover Genius 是强案例公开来源未拆分合作伙伴主导账户收入
受监管企业用户:工程,加上安全和合规SSO、SCIM、治理、审计、安全共享ZEISS 和 Medibank 突出合规功能没有相对安全敏感型竞争对手的公开胜率数据
外部开发者社区用户:第三方开发者;付款方:API 发布方fork 集合、运行示例、降低 TTFCPayPal、Microsoft Graph、Box、Autodesk 和 HubSpot 都公开官方 Postman 资产没有外部和内部开发者计划之间变现拆分的公开数据

分群基于官方规模声明、客户故事和外部客户文档推断。 它们描述谁使用 Postman 以及为什么使用,而不是账户的具体商业打包方式。

[CU001, CU003, CU005, CU013, CU017, CU020]
客户增长 / 采用轨迹表
指标数值日期 / 期间来源置信度含义缺失分母
开发者40M+2025-2026Postman 客户故事 / LinkedIn / 企业页面开发者覆盖面巨大,支撑宽漏斗活跃与注册用户拆分未知
组织 / 公司500k+2025-2026关于页面 / 客户故事 / LinkedIn广泛组织覆盖降低单一 logo 依赖付费账户占比未知
已验证具名公司3,9062025-08-17Landbase低-中显示具名 logo 覆盖广方法论和抽样偏差不透明
企业类别采用26%2026-07Ramp低-中暗示企业渗透有实质规模Ramp 分类法不是直接市场普查
HubSpot 在 Postman 上的 API 调用六个月内 +104%2023-11 至 2024-05HubSpot 案例研究文档扎实时,公开工作区使用量可以快速增长不等同于合同扩张
PayPal 公开集合 fork 数30,000+2024-2025 故事语境PayPal 案例研究外部开发者参与度看起来相当高fork 是使用和发现信号,不等于收入

本表混合了官方规模说法、公司撰写的客户案例和第三方采用度追踪;展示的是广度和增长, 不是已货币化的队列质量。

[CU001, CU002, CU006, CU008, CU015, CU022]
FU001: 客户旅程图

展示外部和内部用户如何在 Postman 中从发现走向有效协作。

旅程阶段综合客户案例和工作区分析文档整理,而不是来自单一公司漏斗图。

[CU009, CU012, CU013, CU023, CU034, CU037]

6.2 具名客户证明与生产使用

最强的公开客户证明来自那些业务已经高度围绕 API 展开的组织。PayPal 使用 Postman 在全球规模支持外部和合作伙伴开发者,并把平台直接连接到更短的首次调用时间、更快测试和大型公共集合 fork 数。Autodesk 展示 Postman 如何驱动合作伙伴工作区,并扩大合作伙伴交易,而不只是内部测试。Medibank 展示了通过 CI/CD 和 GitHub 集成在开发与 QA 间的内部标准化。HubSpot 用公共工作区和工作区分析推动并衡量开发者采用。ZEISS 展示了在受监管环境中的适配,Cover Genius 展示了配置和合作伙伴集成效率提升。这些并非全是独立来源——多数是公司撰写的案例研究——但它们仍明显强于泛泛的 logo 墙,因为它们包含运营细节、具名职能和具体结果。来自 Autodesk、Box 和 Microsoft 的外部客户域文档进一步增强了这一图景,因为它们显示大型 API 发布方把 Postman 集合和工作区当成真实的开发者接入表面。[CU013, CU014, CU015, CU016, CU017, CU018]

具名客户证据表
客户细分群体部署 / 用例生产环境 / 试点结果局限
PayPal全球支付 / 外部开发者生态公开和私有 API 集合、监控、mock、治理、外部接入生产环境TTFC 降至 1 分钟;30k+ 个 fork;测试时间降至数分钟公司撰写的案例研究
Autodesk合作伙伴集成 / 工业软件Partner Workspaces 和面向 PWS APIs 的公共工作区生产环境请求量从每年 40M 增至每月 60M;接入 200+ 个合作伙伴公司撰写的案例研究
Medibank受监管医疗健康企业内部开发、QA、CI/CD、治理、GitHub 集成生产环境测试周期 -70%;发布提前三周公司撰写的案例研究
HubSpot开发者关系 / SaaS 平台公共工作区和 API Network 分发生产环境API 调用六个月增长 104%;入门和反馈闭环更顺畅公司撰写的案例研究
ZEISS受监管制造 / 电商企业工作区、SCIM/SSO、mock、共享测试生产环境一分钟完成数百次测试;协作范围扩大公司撰写的案例研究
Cover Genius合作伙伴密集型保险科技平台Partner Workspaces、Newman、安全共享、入门生产环境配置时间减少 50%;集成效率翻倍公司撰写的案例研究

每一行都是可公开归属、带运营细节的生产环境案例。多数来自公司撰写的客户故事; 若同时有客户域名下的文档,独立佐证更强。

[CU013, CU017, CU019, CU020, CU022, CU024]
FU002: 采用 / 部署漏斗

描绘公开合作伙伴漏斗,从发现一直到成功使用 API。

[CU009, CU012, CU023, CU034, CU037, CU038]
FU003: 客户验证矩阵

按证据深度、量化结果和生产成熟度对公开客户案例进行对比。

[CU019, CU028, CU029, CU030, CU031, CU035]

6.3 耐久性、满意度与公开指标真正能说明什么

公开耐久性证据不错,但比较间接。Postman 暴露了活跃用户、活跃工作区、API 调用、成功用户、合作伙伴接入漏斗和响应码组合等分析原语。客户故事又增加了耐久使用代理,如 PayPal 的 fork 数、HubSpot 的 API 调用增长、Medibank 嵌入式 CI 工作流,以及 ZEISS 的重复测试执行。G2、TrustRadius 和 Software Advice 上的评论也显示,用户采用产品后会持续重视组织、协作和文档。但投资者不应把这些信号误当成正式留存披露。公开市场仍没有 NRR、GRR、logo 流失、席位扩张或合同期限数据集,能让外部人精准建模队列行为。正确解读是:Postman 有强证据证明重复运营使用和开发者习惯形成,但按细分市场划分的变现耐久性证据弱。这个区别重要,因为开发者喜爱和企业支出持续性有关联,却并不相同。[CU009, CU010, CU011, CU012, CU015, CU022]

留存 / 重复使用 / 满意度表
指标或代理指标数值 / 状态细分群体置信度重要性尽调请求
NRR / GRR未披露所有付费细分真实商业韧性仍未知请求按队列提供 NRR、GRR 和席位扩张数据
PayPal 公共集合 fork30,000+ 个 fork外部开发者说明具名企业发布方能带来持续发现和复用请求随时间变化的重复 fork 和活跃使用趋势
HubSpot 工作区 API 调用六个月增长 104%外部开发者公共工作区运营得好时,参与度可能更持久请求月活开发者和成功调用率
合作伙伴接入漏斗可见性有文档记录的分析界面合作伙伴生态Postman 能衡量从访问工作区到成功收到 API 响应的路径步骤请求旗舰账户的实际漏斗转化率
评价满意度整体正面,但有对笨重体验和付费功能的抱怨广泛用户群用户喜爱很重要,但不能替代合同数据请求按细分提供客户满意度及续约调研结果

本表有意使用耐久性代理指标,因为公司没有公开披露队列经济性。核心尽调任务是拆开产品使用习惯和货币化留存。

[CU009, CU012, CU015, CU022, CU031, CU032]
FU004: 留存 / 重复队列

把公开持续性代理指标作为证据强度队列使用,并非公司实际留存率。

这些百分比是基于 fork 次数、API 调用增长、合作伙伴漏斗和重复嵌入工作流等公开使用信号形成的有序证据强度代理,并非公司整体留存率或续约率。

[CU015, CU022, CU031, CU038, CU040]

6.4 扩张、集中度与采购摩擦

公开记录暗示健康的落地扩张动作。客户故事反复指向公共工作区、合作伙伴工作区、GitHub 集成、监控、治理、身份控制和分析;这些表面把用户从简单请求发送推进到更宽的组织部署。这是鼓舞人的,因为它意味着 Postman 能在账户内加深收入,而不需要每个用户一开始就购买 Enterprise 计划。公开集中度风险看起来低:可见客户集横跨支付、医疗、SaaS、制造、光学和保险科技,没有迹象显示一两个客户 logo 主导故事。主要商业风险在低端。评论和定价评论继续显示,一旦协作变成必需,一些团队会觉得平台沉重或越来越多功能被付费墙锁住。因此,客户章节以一个分裂判断收尾:Postman 拥有异常强的公开生产证明和跨垂直 logo 广度,但仍缺少区分广泛采用与广泛扩张效率所需的硬性变现留存披露。[CU012, CU031, CU034, CU035, CU036, CU037]

扩张与集中度风险表
扩张驱动集中或摩擦风险影响证据尽调路径
公共工作区和 Run in Postman 按钮低端用户可能只使用不付费利于获客,但作为收入代理指标较弱PayPal、HubSpot、Box 与 Microsoft Graph 集成梳理发布方主导工作区从免费到付费的转化
Partner Workspaces合作伙伴项目若以 Postman 为标准,需要重度客户成功支持可加深账户内战略嵌入Autodesk、Cover Genius、Medibank衡量 Partner Workspaces 扩张 ARR 和续约率
GitHub / CI 集成让 Postman 更深地嵌入工程工作流也抬高实施复杂度Medibank 和 Newman 文档请求按套餐提供 Git/CI 功能附加率
企业治理 / 身份推动受监管企业采用销售周期和安全审查更长ZEISS、Medibank、企业页请求按垂直行业提供销售周期长度和胜率
客户标识多样性广公开证据中看不到明显单一客户集中利于韧性,但不能证明收入分布可见具名客户标识横跨多个垂直行业请求前 10 大客户收入集中度和续约历史

最大客户风险不是可见客户标识集中,而是团队从免费或公共工作区用法转向付费协作和治理时的货币化摩擦。

[CU024, CU025, CU034, CU035, CU036, CU037]

6.5 展项

Chapter 07

07风险

7.1 隐私、法律与安全暴露

核心风险主题是,Postman 的增长模型和风险模型部分是同一件事。公共工作区、API 可发现性、fork、示例和共享集合让接入变快,但也为有效令牌和敏感数据的意外暴露制造了耐久表面。第三方研究者在这里罕见地一致:CloudSEK、Truffle Security、AppSentinels 和后续报道都描述了公开 Postman 资产上大规模密钥暴露。重要的是,大多数证据并没有指控 Postman 核心基础设施被黑。更不舒服的结论是,平台让用户很容易快速创造业务价值,因此当共享默认设置、令牌处理或环境语义被误解时,也很容易快速制造业务伤害。法律和监管风险叠加在这个运营现实之上。CCPA、Data Privacy Framework 承诺、AI 条款和其他演进中的合同表面意味着,未来任何涉及受监管个人数据或客户凭据的事件,都可能带来超出纯声誉损伤的执法和合同后果。[CR001, CR002, CR003, CR004, CR005, CR006]

监管 / 法律风险登记表
风险 / 规则司法辖区状态可能性严重程度缓释措施剩余敞口尽调路径
涉及个人或客户数据的公共工作区暴露美国 / 欧盟 / 全球未看到已知执法行动,但已有多次公共暴露研究中高secret 扫描、私有工作区、vault 模式、审计日志审查事故历史、secret 检测效能,以及外部律师对隐私暴露的评估
DPF 及相关隐私框架下的跨境数据传输承诺欧盟 / 美国 / 英国 / 瑞士Postman 称已获得认证中高框架认证、隐私计划、AWS 区域确认证书、传输影响评估和备选传输机制
演变中的 AI 条款和合同义务全球 / 基于合同法律中心和归档显示条款在持续更新已发布 AI 条款和审核控制审查 AI 条款差异、企业客户例外条款和赔偿立场
子处理方和供应商事故通知义务全球 / 基于合同信任门户发布子处理方通知和 Klue 事故更新中高通知流程和透明度门户请求完整子处理方清单、通知 SLA 和供应商风险预案
若暴露数据未加密且属于个人信息,触发 CCPA / CPRA 权利加利福尼亚法律已生效且界定清晰中低合理安全措施、vault、私有工作区、脱敏评估加州用户暴露、加密默认设置,以及泄露凭据或 PII 的响应计划

各行按可能的尽调优先级排序,而非按损失确定性排序。当前监管风险大多取决于条件, 但如果下一次高曝光事件涉及受监管数据,风险会迅速升级。

[CR004, CR005, CR006, CR007, CR008, CR009]
FR001: 风险热力图

公开共享、凭证处理和监管暴露叠加之处,剩余严重性最高。

[CR014, CR016, CR022, CR027, CR033, CR034]
FR002: 风险传导图

呈现公共工作区或供应商事件如何流向客户信任、合规、收入和估值。

[CR006, CR014, CR015, CR019, CR033, CR035]

7.2 运营与可靠性风险

从运营上看,Postman 现在的广度可能超过许多用户意识到的范围。状态表面横跨登录、监控器、模拟服务、搜索、文档、API Network、CLI、API Builder、Postbot 和 Agent Mode。截取到的可用时间视图扎实,但宽服务表面也意味着本地化事件有更多方式削弱用户体验。2026 年 Klue 事件又增加了一个更微妙的点:接入周边 GTM 或支持系统的供应商,即便产品核心仍安全,也能制造风险。因此,公共信任不仅受监控器和集合可用性影响,也受客户数据周边生态、分包处理方变更和安全通知处理方式影响。Postman 确实发布了一套体面的缓释栈——保管库选项、2FA、审计日志、漏洞赏金、密钥扫描 API、服务账号、SCIM 和状态透明度。但剩余风险仍然偏高,因为许多破坏力最大的失败模式,仍始于人为行为和权限设计,而不是缺少复选框。投资者应把这里的运营质量视为平台韧性与护栏有效性的组合。[CR001, CR002, CR004, CR005, CR006, CR012]

运营 / 质量 / 安全风险登记表
失效模式可能性严重程度缓释成熟度剩余敞口未解决缺口
公共工作区泄露有效凭据或敏感数据极高需要证据证明默认 secret 保护和分享 UX 现在能明显降低泄露率
token / 变量处理模糊,导致不安全默认值中高需要数据说明 initial/current-value 或 secret-variable 错误仍发生多频繁
波及客户相邻系统的第三方 SaaS 事故中高需要更清晰的影响半径和非核心集成依赖图
广泛服务面停机或性能退化中高中高需要超过公开快照的组件级 SLA 和 MTTR 历史
AI 驱动自动化以过高权限运行,或审核边界不足早期中高需要审查模型权限、可审计性和审批门架构

主要运营担忧仍是 secrets 和分享,而不是单纯服务可用性。平台宽度是第二层放大器, 因为更多服务和集成会增加对信任敏感的触点数量。

[CR001, CR004, CR012, CR013, CR014, CR016]

7.3 依赖、锁定效应与竞争压力

Postman 最大的战略依赖不只是 AWS 这类基础设施厂商,还包括把公司做大的那些产品假设:云端托管的共享工作区模型、中心化对象格式,以及越来越由 AI 介入的工作流。这些假设让很多团队协作起来几乎没有摩擦,也让平台暴露在本地优先挑战者的冲击下。Bruno 坚持只离线、Git 原生,明确反驳云同步风险和厂商托管状态。Thunder Client 从 VS Code 内部提出同样主张;Insomnia 在 Kong 旗下开始主打灵活存储模式、身份控制和 MCP 支持。GitHub Copilot 又叠加一层压力:它把 AI 辅助打包进一个大得多的开发者平台。这些替代方案不需要做到完整功能对等才会产生影响。它们只要足够满足更简单的团队、隐私敏感团队或 Git 原生团队,Postman 相比之下就会显得更重或更贵。低端支付意愿会被削弱;如果组织把请求运行、文档和治理拆到多种工具里,而不是只标准化到 Postman,扩张上限也会被压住。[CR022, CR023, CR024, CR025, CR026, CR027]

合作伙伴 / 依赖风险登记表
依赖对手方角色集中度失败情景严重程度缓释措施剩余敞口
云基础设施AWS托管产品数据和备份,承载核心计算 / 存储层结构性依赖高区域性中断、控制失效或成本冲击会影响可用性和数据态势跨存储 / 网络 / 计算和可用区冗余
销售与支持供应商Klue 和其他子处理方通过集成持有或触达客户相邻数据即使核心平台安全,供应商被攻破也会引发信任事件子处理方通知、禁用集成、事件响应中高
身份与访问生态SSO / SCIM / 企业管理栈企业接入和访问治理配置错误或身份故障会削弱信任并拖慢企业采用中高审计日志、2FA、服务账户、SCIM APIs
公共搜索和 API 发现界面搜索引擎、公共工作区、API Network发现与采用渠道发现渠道集中度高公开索引会把资产或泄露凭据大规模暴露secret 扫描和私有工作区控制
AI 与开发者平台竞争GitHub、Kong/Insomnia、Bruno、VS Code 生态替代工作流和 AI 界面中高团队分流工作流,或因本地优先 / 捆绑 AI 路径离开 Postman中高继续加入 Git 原生、本地和 AI 能力中高

并非每个依赖都是供应商账单;有些是分发或工作流依赖,失效时体现为信任流失或竞争替代, 而不是停机。

[CR005, CR006, CR012, CR019, CR022, CR024]
人员 / 执行风险登记表
角色 / 职能依赖或缺口可能性严重程度缓释措施尽调路径
安全 / 产品领导层既要保护增长触点安全,又要继续鼓励分享和公开发现中高安全控制、vault、信任门户透明度审查更安全默认设置的路线图,以及公共 secret 暴露率能否可量化下降
平台工程必须让不断扩展的服务和 AI 功能保持一致、可靠中高统一工作台和产品化控制请求主要界面的服务级指标和发布质量数据
企业客户成功 / 支持客户培训和管理员赋能,对安全使用工作区至关重要客户成功、文档、合作伙伴指南评估企业接入是否明显降低配置错误率
AI 治理 / 信任团队需要为智能体能访问和修改什么设定清晰边界审核队列、沙箱、AI 条款请求内部 AI 治理政策、审批率和事故日志
管理团队 / 财务在估值和货币化仍不透明时,必须吸收信任冲击潜在现金缓冲、定价权、现有规模请求现金跑道、烧钱速度,以及信任或流失冲击下的应急计划

执行风险偏高,因为 Postman 同时在扩大产品宽度、AI 自主性和企业治理预期。

[CR004, CR027, CR028, CR033, CR034, CR036]
FR003: 依赖关系图

显示哪些外部节点的行为最影响 Postman 的风险姿态。

本图强调依赖通道,而非完整系统架构。

[CR005, CR006, CR019, CR022, CR024, CR026]

7.4 财务 / 模型风险与投资逻辑破裂指标

公开记录仍留下一个重要风险未解:经营模型在压力下的韧性。Economic Times 报道了实质性的老股市场折价,ARR 也显著低于部分外部增长追踪方给出的水平;当前烧钱速度、现金跑道和债务仍未披露。这一点重要,因为信任冲击、定价反弹或企业转化放缓,公司现金充裕时更容易扛过去;如果公司已经面对估值重置,难度会高得多。实际含义是,投资者不应孤立看 Postman 的风险。公司若缺少财务弹性,安全暴露、低端客户流失,或来自大型平台的 AI 竞争都会被放大。因此,投资逻辑破裂事件很具体:再次出现大规模凭证暴露循环;有证据显示客户信任长期受损;定价驱动的用户流出更急;或一次融资事件确认公司价值已明显低于上一轮新股估值,同时又没有耐久自由现金流的相应证明。[CR030, CR031, CR032, CR033, CR034, CR038]

缓释与否决标准表
风险可监控触发信号阈值 / 事件行动含义
公共 secret 暴露新的外部研究或信任公告有证据显示,尽管已有缓解措施,大规模公开工作区泄露仍在持续或恶化重审投资逻辑,并要求提供泄露率趋势数据
运营信任状态页或信任门户模式重复事故,或影响关键协作 / AI 服务的长时间多面故障下调置信度,并通过客户访谈检验信任是否受损
竞争压力客户或评测信号目标客群更多转向 Bruno、Insomnia、Thunder Client 或 GitHub 原生工作流重新质疑低端扩张与价格兑现假设
估值模型 / 融资风险老股交易或融资事件降价轮、要约折价,或披露的 ARR / 烧钱画像显著差于预期重置估值,并检查现金跑道应急预案
AI 治理风险内部或外部事故智能体或 AI 驱动的变更引发安全 / 合规失败,并影响客户除非能立刻证明控制措施和影响范围已被压住,否则按投资逻辑破裂处理

这些终止标准用于尽调后的持续监控,而不只是一次性筛选。

[CR016, CR027, CR032, CR033, CR034, CR040]

7.5 证据要点

Chapter 08

08估值

8.1 投资逻辑与反向逻辑

Postman 的正向投资逻辑先落在独立 API 生命周期厂商中最深、且已验证的融资历史上:2021 年 8 月完成 $225 million Series D,估值 $5.6 billion,由 Insight Partners 领投;不同来源统计的累计融资约为 $352-433 million。公司没有停在原地:在本章访问日期前八个月内,它宣布与 Microsoft、Anthropic 的 AI 合作,并收购 Fern 和 liblab;直接 API 网关竞争对手 Kong 仍有可信的 $2 billion 私有估值,说明品类层面的资本通道并未坍塌。若把 PitchBook 报告的 2021 年独角兽平均 68.2% 减记套到 Postman 峰值估值上,对应约 $1.8 billion,低于本文查看的每一个 2026 年老股市场估计,因此公司看起来比同代广义队列平均表现略好。 反向逻辑同样具体。2021 年后,没有新股融资或要约流动性事件得到确认;独立老股市场追踪方对当前估值的分歧超过 2x;针对同一个 2024 财年,两个可信第三方收入估计相差超过 2x;报道中的老股折价(30-40%)是典型老股折价的两到三倍;除一个含糊的局部数据点外,治理、董事会构成和清算优先权条款仍未披露。这本账的任何一边都不能视为已经定论;两边之间的缺口,正是本章要讲清楚、而不是掩盖的核心事实。[CV001, CV020, CV024, CV025, CV027, CV039]

投资逻辑 / 反向逻辑表
论点类型论点支持证据改变判断的因素
投资逻辑在独立 API 生命周期厂商里,Postman 的融资历史经核验最深,已确认估值也处在最高梯队之一CV001, CV002, CV006披露的降价轮,或可比口径下有同业超过它
投资逻辑公司没有停在原地,仍在推出拓宽平台的动作(AI 合作、2025-2026 年两笔收购)CV039, CV040有证据显示,这些动作没有转化为收入或留存提升
投资逻辑Postman 比 2021 年同批独角兽的平均估值下调更扛跌,说明韧性相对更强CV024, CV025老股交易价格滑向或跌破 PitchBook 统计的 2021 年同批平均水平
投资逻辑直接 API 网关竞争对手 Kong 仍拿到可信的 $2B 私募估值,说明品类层面的融资通道尚未坍塌CV027Kong 或其他同业未来轮次定价明显低于 $2B
反向逻辑自 2021 年 Series D 以来,公司没有确认任何新股融资或要约事件,距本章访问日期已超过四年CV039, CV041, CV042确认的新轮融资、要约或 IPO 申报
反向逻辑独立老股市场跟踪器对当前估值的判断相差超过 2 倍($2.2B-$4.8B)CV020各跟踪器收敛到更窄区间
反向逻辑同一财年收入估计相差超过 2 倍(2024 年 $120-150M vs $313.1M)CV005, CV021, CV044披露经审计收入,或第三方方法论完成口径调和
反向逻辑据报道的老股折价(30-40%)大约是同一市场典型老股折价的 2-3 倍CV021新的老股成交价显示折价收窄
反向逻辑除一个局部且含混的数据点外,治理、董事会构成和清算优先权条款均未披露CV012, CV043披露股权结构表或条款摘要

每个论点都配有最能直接推动判断上行或下行的证据。

[CV001, CV020, CV021, CV024, CV027, CV039]

8.2 建议、置信度、风险评级与估值立场

本章证据支持对 Postman 采取“继续研究 / 观察”的建议,置信度中等,风险评级中高,估值立场介于合理和偏高之间,且高度取决于投资者相信哪一个收入估计。这种姿态不是为对冲而对冲:它直接来自把强且相互印证充分的融资与规模证据,和公开来源无法填补的收入、治理、资本事件缺口放在一起比较。本章流程图的建议逻辑追踪的正是这条链:一边是融资和可比市场证据,另一边是收入与治理披露缺口,最后得出的是对价格敏感、而非对公司好感敏感的判断。 投资 KPI 记分卡反映同样的不对称:融资历史和可比市场准入得分都高;老股市场支撑处在中位(低于峰值,但高于 2021 年独角兽整体减记均值);收入清晰度、治理清晰度和退出准备信号得分都低。截至 2026 年 7 月访问日期,没有已确认的 IPO 申报、路演或新融资事件;以公司名检索 EDGAR,也未返回 S-1 申报。在收入、股权结构表或资本事件三个缺口至少填补一个之前,目标回报、持有或退出立场都无法负责任地量化;在此之前,合适动作是跟踪仓位,并在出现可披露级新证据时立即重审结论。[CV042, CV046, CV047, CV048]

建议摘要表
维度评级关键证据锚点决策含义
建议继续研究 / 观察2021 年以来未确认新股轮;老股交易跟踪口径在 $2.2B-$4.8B 分化收入和股权结构表缺口补齐前,不要启动锁价持仓
置信度融资历史和规模有充分交叉印证;收入和优先权条款没有将本章估值区间视为边界,而不是点估值
风险评级中高据报道老股折价 30-40%,且治理 / 披露缺口仍未解决头寸规模要同时反映收入风险和结构性(优先权)风险
估值立场合理到偏高(双峰)取决于 $120-150M ARR 与 $313.1M 收入哪一个更接近现实在采信任一口径前,先要求提供底层收入定义
目标回报 / 持有 / 退出持有并监控;暂无主动退出触发器截至 2026 年 7 月,未见已确认 IPO 申报或新融资信号下一次确认资本事件或披露发布时重审
入场纪律检查按当前公开证据不通过优先权条款、董事会控制和审计收入均未披露对价格敏感的入场至少应等到三项缺口之一补齐

评级综合了本章有来源支持的主张;它们是分析师判断,不是公司发布的评级。

[CV046, CV047, CV048]
FV001: 建议逻辑

建议从融资与规模的强证据出发,经过两个未解决证据缺口,落到价格敏感的「继续研究」判断。

节点语气反映对证据方向的定性判断,不是打分模型。

[CV001, CV020, CV024, CV025, CV043, CV044]
FV004: 投资 KPI

Postman 在融资历史和可比市场可及性上得分较好,但经济性清晰度和治理披露偏弱。

分数是 0-10 分的分析师判断,综合了本章有来源支撑的主张,不是公司发布或第三方综合评分。

[CV001, CV020, CV027, CV005, CV043, CV042]

8.3 融资与估值背景

Postman 的每一次估值讨论都必须从同一个锚点开始:2021 年 8 月完成的 $225 million Series D,投后估值 $5.6 billion,由 Insight Partners 领投,Coatue、Battery Ventures 和 BOND 作为新投资者加入。Forge Global 自己的融资表给出较低的仅新股部分数字($145 million,$17.54/share,投后 $5.57 billion)和较低的累计融资数($352 million,而 Craft.co、GetLatka 和 Inc42 为 $433 million)。这个缺口最可能反映新股部分与整轮总额的口径差异,而不是已经解决的矛盾;但仅凭公开证据,本章无法完全对齐。 自 2021 年峰值后,没有新的新股轮得到确认。相反,五个独立老股市场追踪方(Forge、Yahoo Finance、Public.com、Notice.co、Premier Alternatives 和 UpMarket)现在给出的 2026 年估计大约落在 $2.2 billion 到 $4.8 billion 之间;Economic Times 另行报道,老股交易以较 2021 年标记 30-40% 的折价成交——这是典型老股折价的两到三倍。因此,入场纪律必须同时计入很宽的估值区间,以及一个未解决、可能为不参与或参与型的优先股堆叠,且没有任何来源完整披露。这正是稀释 / 优先权悬而未决的类型,任何仓位都应保持价格敏感,而不是按高确信度做大。[CV001, CV009, CV010, CV011, CV012, CV013]

FV002: 估值敏感性

采用哪组收入估计,比选择哪个单一倍数更能左右 Postman 的隐含估值。

收入 x 倍数柱只是供投资委员会讨论的简单桥接输出,不是折现现金流或公司指引数字;单位为十亿美元。

[CV005, CV021, CV013, CV018, CV019, CV032]

8.4 乐观、基准与悲观情景

乐观情景假设收入更接近 GetLatka 的 $313.1 million 2024 年估计,并且 2026-2027 年的新股轮或 IPO 把公司重新定价到 UpMarket 自己 $4.8 billion 的模型估计,或回到 2021 年 $5.6 billion 峰值附近;在这条路径下,倍数扩张和收入增长彼此强化,报道中的老股折价也收窄回典型的 10-15%。基准情景假设收入落在两个冲突估计之间,老股价格只是维持在 Forge、Yahoo Finance 和 Premier Alternatives 已经显示的位置附近——$2.0-3.3 billion 区间——主要风险在于,没有任何已确认资本事件会让这个标记长期陈旧、实际上无法验证。 悲观情景假设收入更接近 Economic Times 报道暗示的较低 $120-150 million ARR 估计,并且 Postman 估值向 PitchBook 报告的 2021 年独角兽平均 68.2% 减记靠拢,对应约 $1.8 billion 或更低。治理、安全或客户集中度冲击(其中几项已在本报告风险章节中作为未解决的中等严重暴露出现)会加速这条路径。仅凭公开证据,三个情景都无法分配精确概率;但基准情景是多个独立且日期仍新的追踪方最直接印证的情景。[CV005, CV019, CV020, CV021, CV024, CV025]

乐观 / 基准 / 悲观情景表
情景核心假设估值 / 回报逻辑主要风险概率信号
乐观收入更接近 GetLatka 对 2024 年 $313.1M 的估计并持续复合增长;2026-2027 年新股轮或 IPO 将公司重新定价到 UpMarket $4.8B 模型估值或 2021 年 $5.6B 峰值附近倍数扩张和收入增长同时利好公司;老股折价收窄回典型 10-15% 区间AI 原生竞争者削弱付费意愿;没有资本事件落地来验证重新定价与 UpMarket 自身 $4.8B 模型及跟踪老股成交价上沿一致
基准收入落在两个冲突估计之间;老股价格大致维持在 Forge / Yahoo 当前显示水平估值维持在 Forge、Yahoo 和 Premier Alternatives 显示的 $2.2B-$3.3B 集群附近确认资本事件持续缺位,估值仍陈旧且无法验证符合 Forge、Yahoo Finance 以及(一种解读下)Premier Alternatives 的收敛区间
悲观收入最终更接近较低的 $120-150M ARR 估计;SaaS 整体倍数压缩延续, Postman 跟随 PitchBook 统计的 2021 年同批平均下调幅度估值滑向 PitchBook 推导的约 $1.8B 下调水平或更低披露降价轮、客户集中度冲击,或安全 / 治理事件(见风险章节)会加速下行以 PitchBook 报告的 2021 年同批平均估值下调 68.2% 为锚,并套用至 $5.6B 峰值

情景估值逻辑只是供投资委员会讨论的公开证据区间,不是 DCF 输出,也不是公司指引。

[CV005, CV021, CV024, CV025, CV020, CV019]
FV003: 估值 / 回报区间

公开证据支持从悲观到乐观的宽估值带,因为收入基数和适用倍数都存在争议。

区间基于本章有来源支撑的主张搭出情景桥接,用于投资委员会讨论,不是管理层指引或 DCF 输出。

[CV050, CV051, CV024, CV025, CV020]

8.5 可比估值视角

没有一个公开或私有同行能完全匹配 Postman 的产品组合和披露画像,因此本章混合使用几个视角。直接私有融资方面,Postman 自己竞争集合中点名的 Kong Inc. 于 2024 年 11 月完成 $175 million Series E,估值 $2 billion,由 Tiger Global 领投、Balderton 联合领投;这说明品类层面的私人资本通道并未消失。相邻的 API 生命周期与质量工具厂商 SmartBear 仍由 Francisco Partners 和 Vista Equity Partners 各半持有,完全没有披露估值,显示部分 PE 持股同行对外披露得多么有限。 公开可比公司方面,GitLab 的市值约为其 $955.2 million 2026 财年收入的 5.8x(市值 $5.52 billion);Atlassian 对 $6.19 billion 过去十二个月收入的直接披露市销率为 3.82x(市值 $23.67 billion,同比下跌 52.65%);Datadog 的市值约为其 $3.67 billion 过去十二个月收入的 25x(市值 $92.08 billion)。超过 6x 的跨度说明,相比平面的行业倍数,增长质量和品类位置更重要。IBM 以约 $11 billion 收购 Confluent,约为其披露收入运行率的 11x,也为数据 / API 基础设施资产提供了战略买方 M&A 锚点。合起来,这些视角给出可行倍数边界,但无法解决 Postman 自身应该按哪一个倍数交易。[CV027, CV028, CV029, CV031, CV032, CV033]

可比估值表
可比对象指标倍数 / 估值 / 状态参考意义局限
Postman(2026 年老股集群)Forge / Yahoo Forge Price 推导估值约 $2.22B(2026 年 7 月),按滚动窗口计下跌 24-33%就公司自身看,这是最新的市场出清信号,虽不完美来自稀薄的私募市场数据,不是经审计交易
Postman(2021 年峰值,用于对照)已确认新股 Series D 估值$5.6B (Aug 2021)本章所有折价 / 估值下调数字都以它为参照点已滞后超过四年;此后没有确认资本事件
Kong Inc.私募 Series E 估值$2.0B (Nov 2024)最接近的直接 API 管理 / 网关竞争对手,且最近披露过新股轮产品组合不同(运行时网关 vs. 协作平台),限制可比口径比较
SmartBearPE 机构持有;未披露估值未披露(Francisco Partners / Vista Equity,各持一半)PE 持有规模的相邻 API 生命周期和质量工具厂商没有公开估值或收入数字可作基准
GitLab Inc.(上市)市值 / FY26 收入$5.52B / $955.2M 收入 -> ~5.8x公开 DevSecOps 平台可比公司,披露经审计财务范围比纯 API 工具更宽,是 DevSecOps 平台;产品并非完全可比
Atlassian(上市)市值 / TTM 收入$23.67B / $6.19B 收入 -> 3.82x (P/S)更大的上市协作软件可比公司,显示成熟、多元化同业的交易位置规模远大于 Postman,产品组合也更分散;Postman 仍聚焦单一品类
Datadog(上市)市值 / TTM 收入$92.08B / $3.67B 收入 -> ~25x展示高增长基础设施软件在公开市场可拿到的倍数上沿可观测性公司,不是 API 工具;倍数反映的增长 / 利润率画像差异很大
IBM / Confluent(并购)收购价 / 收入运行率$11B / >$1B 运行率 -> ~11x近期大型数据基础设施并购可比案例,显示战略买家仍愿意买平台资产Confluent 是数据流平台,不是 API 生命周期工具;交易条款带战略属性,不是纯财务交易

没有哪一家公开或私营同业能完全匹配 Postman 的产品组合和披露画像;本表混合了直接定价、竞争对手融资、PE 持有的相邻厂商、三家上市可比公司和一个并购锚点,用来框定讨论范围。

[CV013, CV020, CV027, CV029, CV030, CV031]

8.6 退出准备度与最终尽调请求

截至 2026 年 7 月访问日期,Postman 没有公开退出准备信号。公司自己的媒体新闻页列出截至 2026 年 4 月的产品和合作公告,没有提到 IPO;一个专门的第三方 IPO 追踪器返回的是机器人拦截响应,而不是可用数据;将 SEC EDGAR 公司名检索限制在 Form S-1 后,也没有找到匹配的申报人或文件。缺少证据本身值得记录,但不能据此假设 IPO 即将发生或已经被排除。 本章的否决触发表列出六个具体、可监控阈值:低于 $2.0 billion 的新股定价、披露收入低于悲观情景下限、再过两年仍无资本事件、老股折价显著扩大、治理或安全事件叠加,或确认 IPO 申报。任何一个出现,都应把建议推向明确方向,而不是触发含糊重估。最终尽调请求表把本章开放问题转成具体要求:经审计或管理层复核、能对齐两个冲突 2024 年估计的收入;当前股权结构表和优先股堆叠摘要;确认 2025-2027 年是否有任何新股融资或要约流动性交易;留存和集中度指标;AI 功能变现证明;以及 IPO 或战略退出意图的任何信号。即便只解决其中两三个,下一次刷新时本章置信度也会明显更清晰。[CV039, CV041, CV042, CV043, CV044, CV052]

投资逻辑破裂与终止触发器表
触发器阈值对投资逻辑的传导行动含义
新股轮或要约定价低于当前老股集群投后低于 ~$2.0B确认下调重定价的不只是老股跟踪器,而是整个市场将估值立场重估为“昂贵”,并重审头寸规模
披露收入显著低于低位估计FY2025/2026 ARR 低于 ~$120M连本章敏感性区间中的悲观收入假设也被打穿在完成更完整的收入调和前,将建议调向回避
到 2027 年仍无资本事件或经审计披露再过 24+ 个月仍没有任何新融资 / 披露信号披露缺口继续拉长,已经无法给出锁价判断维持观察 / 继续研究;不要仅因时间推移就上调建议
老股折价明显扩大,超出当前区间新成交价较 2021 年标记折价超过 ~50%会让 Postman 接近甚至超过 PitchBook 统计的 2021 年同批平均下调幅度按悲观情景得到验证处理,并相应重配概率
治理或安全事件在当前风险记录上继续叠加新的重大泄露、诉讼败诉或领导层离职会叠加到风险章节已有的中等严重度风险集群,并可能损害企业信任将风险评级上调至高 / 危急,并暂停任何新承诺
确认 IPO 申报或路演公告S-1 申报或公开路演披露经审计且监管审核过的数据会替代本章披露缺口一旦有申报级数据,完整重跑本估值章节分析

这些触发器按投资人可监控的公开证据阈值设定;截至 2026 年 7 月访问日期均未发生。

[CV042, CV044, CV021, CV024]
最终尽调问题表
主题缺失证据为什么重要尽调路径 / 负责人
经审计或管理层审阅的收入GAAP 收入、按分部划分的 ARR,以及对 2024 年 $120-150M vs. $313.1M 两组估计的调和决定估值敏感性区间哪一端更现实通过管理层数据室或签署 NDA 覆盖的财务包索取
股权结构表和清算优先权当前董事会构成、优先股堆叠、股息和参与分配条款会改变下行情景或收购情景下普通股实际回款向公司律师索取股权结构摘要,或通过有数据访问权的老股市场中介获取
已确认 2025-2027 年新股融资或要约2021 年 Series D 之后任何定价轮、结构化融资或公司发起的要约会用市场出清信号替代陈旧的 2021 年定价和稀薄的老股跟踪估计监控 SEC EDGAR、新闻稿和老股市场平台;直接询问公司 IR
留存和扩张指标净收入留存、客户 logo 留存,以及按分部划分的客户集中度验证较高的 GetLatka 收入轨迹是否可持续,还是由一次性扩张前置拉动索取队列级留存数据,或开展客户访谈计划
AI 功能变现证明Agent Mode / AI Engineer 的采用率、ARPU 提升或附加销售率数据检验近期 AI 投资是在守住或扩大护城河,还是在面对商品化定价压力索取产品使用遥测,或围绕 AI 功能变现开展管理层问答
IPO 或战略退出意图任何内部时间表、投行接触或路演规划信号决定短期流动性事件是否足够现实,可纳入回报模型直接询问管理层或接近董事会的消息源;每季度监控 EDGAR S-1 申报

这些问题按它们对本章估值区间的直接影响排序,而不是按获取难度排序。

[CV043, CV044, CV039, CV042]

8.7 证据要点

免责声明

本报告仅依赖截至 2026-07-20 审阅的公开来源,不能替代管理层尽调、客户访谈、法律审查或访问私人财务材料。

证据索引

结论
编号陈述可信度来源
CO001 Postman was founded in 2014. SO001, SO010
CO002 Postman was founded in Bangalore and is now headquartered in San Francisco. SO001, SO002
CO003 Abhinav Asthana founded Postman and remains its CEO. SO001, SO010
CO004 Ankit Sobti and Abhijit Kane were recruited by Asthana early and still lead the company as co-founders. SO001, SO010
CO005 Craft lists Zac Auger as Postman's chief revenue officer. SO010
CO006 Postman describes itself as an API platform for building and using APIs. SO001, SO003
CO007 The current platform spans API design, testing, distribution, documentation, monitoring, and governance. SO003
CO008 Postman says more than 40 million users or developers use the platform. SO012, SO020
CO009 Postman says 500,000 organizations use the platform. SO001, SO020
CO010 Postman says 98% of the Fortune 500 are customers. SO001, SO020
CO011 Postman closed a $225 million Series D round in August 2021 at a $5.6 billion valuation. SO007, SO008
CO012 Insight Partners led the 2021 Series D round, with Coatue, Battery Ventures, and BOND joining alongside CRV and Nexus Venture Partners. SO007, SO008
CO013 Public databases put Postman's total funding at roughly $433 million. SO009, SO010
CO014 Postman's last publicly disclosed primary valuation is still the 2021 $5.6 billion Series D mark. SO007, SO009
CO015 Economic Times reported in 2024 that recent Postman secondary transactions cleared at a 30-40% discount to the 2021 peak valuation. SO014
CO016 Economic Times reported that people aware of Postman's financials estimated ARR at $120-150 million in 2024. SO014
CO017 GetLatka estimated Postman's 2024 revenue at $313.1 million after estimating 2023 revenue at $171.7 million. SO009
CO018 The Economic Times ARR estimate and GetLatka revenue estimate describe materially different monetization levels and cannot be reconciled from public disclosures alone. SO009, SO014
CO019 LinkedIn showed 3,523 employees on Postman's company page on July 16, 2026. SO012
CO020 Postman publicly lists offices in San Francisco, Bangalore, and Tokyo and says distributed team members span multiple continents. SO001, SO002
CO021 Business Wire reported in July 2025 that Postman opened a new San Francisco headquarters to accelerate growth and innovation. SO019
CO022 Postman's 2025 State of the API report surveyed more than 5,700 developers, architects, and executives. SO005, SO006
CO023 The 2025 State of the API report found that APIs are increasingly treated as the foundation for AI-agent adoption. SO005, SO006
CO024 The 2025 State of the API report says 65% of organizations generate revenue from their API programs. SO005, SO006
CO025 The 2025 State of the API report says 74% of API-revenue-generating organizations derive at least 10% of total company revenue from APIs. SO005, SO006
CO026 The 2025 State of the API report says 70% of developers are aware of MCP but only 10% use it regularly. SO005, SO006
CO027 TechCrunch reported that Postman launched AI Agent Builder in January 2025 on top of its API platform. SO013
CO028 Postman announced Agent Mode in June 2025 as an AI-native assistant that can build, test, and debug APIs in natural language. SO015, SO004
CO029 Postman acquired Orbit in April 2024 to strengthen developer-community engagement around APIs. SO016
CO030 Postman acquired liblab in November 2025 to expand from API collaboration into SDK generation across the API lifecycle. SO017
CO031 Postman acquired Fern in January 2026 to add docs-as-code and production-ready SDK generation for developer experience. SO018
CO032 Postman's trust portal says a compromised Klue integration led to exfiltration of customer contact data and sales information from Salesforce on June 11-12, 2026. SO021
CO033 CloudSEK reported that more than 30,000 publicly accessible Postman workspaces exposed tokens, keys, or other sensitive data in late 2024. SO023, SO025
CO034 Treblle summarized the same workspace exposure episode as a signal that public-collaboration defaults can create secrets-management risk. SO022
CO035 CloudSEK wrote that Postman later added secret-protection alerts and guidance for moving exposed assets to private or team workspaces. SO023
CO036 Postman's status page showed core browser, login, monitor, mock, API, and documentation services operational at the time of review, with desktop reporting 100.0% uptime over the last 90 days. SO024
CO037 Craft describes Postman as a private, active company. SO010
CO038 Postman's pricing page lists Free, Solo, Team, and Enterprise plans, showing monetization beyond a pure free developer tool. SO004
CO039 In its 2021 Series D announcement, Postman said the platform had 17 million developers and more than 60 million app downloads at that time. SO007
CO040 Public evidence does not disclose Postman's board composition, preferred-share terms, or full cap table.
CM001 Postman competes in a broad API lifecycle platform market rather than only the narrow API-client segment. SM004, SM006, SM007
CM002 The practical market boundary around Postman includes design, testing, documentation, collaboration, distribution, monitoring, and governance. SM004, SM006
CM003 The Business Research Company sized the global API management market at $5.24 billion in 2025 and projected $20.89 billion by 2030 at a 31.8% CAGR. SM010
CM004 Strategic Market Research sized the API management market at $5.6 billion in 2024 and $15.1 billion by 2030 at an 18.2% CAGR. SM011
CM005 Fortune Business Insights sized the market at $6.89 billion in 2025 and projected $37.43 billion by 2034. SM012
CM006 Mordor Intelligence sized the market at $8.86 billion in 2025 and projected $22.11 billion by 2031. SM013
CM007 The spread across third-party market-size estimates indicates that API management and API lifecycle boundaries remain definition-sensitive rather than precise. SM010, SM011, SM012, SM013
CM008 Postman's 2025 State of the API survey covered more than 5,700 developers, architects, and executives. SM001, SM002
CM009 The same survey says testing is the most common API activity at 81%, followed by development at 73% and documentation at 58%. SM001, SM002
CM010 Postman says 65% of organizations generate revenue from APIs. SM001, SM002
CM011 Among organizations that generate API revenue, Postman says 74% derive at least 10% of total company revenue from APIs. SM001, SM002
CM012 Postman says 70% of developers are aware of MCP but only 10% use it regularly. SM001, SM002
CM013 Postman says 93% of teams struggle with API collaboration, creating duplicated work, delays, and degraded quality. SM001, SM002
CM014 Postman says 51% of developers cite unauthorized agent access as a top security risk in the AI era. SM001, SM002
CM015 Postman's security report says it surveyed 246 security professionals about API risk and AI readiness. SM003
CM016 The security report frames AI-agent readiness, API revenue impact, and governance at scale as the top themes for security leaders. SM003
CM017 Postman's product page frames the category as a unified platform for designing, testing, distributing, documenting, and monitoring APIs. SM004
CM018 The API Repository page positions discoverability, versioning, and a private API network as buying criteria for larger organizations. SM006
CM019 The Flows page positions visual workflow execution and fast onboarding as value for cross-functional teams, not just backend developers. SM007
CM020 Postman's packaging from Free to Solo, Team, and Enterprise implies a market spanning individual developers through enterprise platform buyers. SM005
CM021 TechCrunch described Postman's AI Agent Builder as combining large language models, APIs, and flows to let users build functional agents. SM009
CM022 Postman's own 2025 product repositioning argues that humans and agents will work together across the software development lifecycle. SM008
CM023 Swagger markets an integrated solution for AI-ready API design, testing, and documentation, showing that API design remains a major adjacent spend pool. SM014, SM015
CM024 Insomnia markets open-source and free-tier workflows, unlimited collection running, and a local-only scratch pad with no login required. SM016, SM017
CM025 Bruno positions itself as a free, open-source, git-native API client that requires no account. SM020, SM021
CM026 Stoplight packages visual design, interactive docs, and instant mock servers for individuals at $44 per month and small teams at $113 per month. SM018, SM019
CM027 Kong's pricing page shows that gateway-oriented API programs are often bought on infrastructure-style metrics such as gateway count rather than per-seat collaboration. SM024
CM028 ReadyAPI positions low-code automated testing across REST, SOAP, Kafka, JDBC, and JMS, underscoring that API testing alone is its own adjacent budget line. SM023
CM029 Hoppscotch positions itself as an open-source API development ecosystem, reinforcing low-end tool abundance in the category. SM022
CM030 Public reviews show some users believe features that used to be free are increasingly pushed into paid plans. SM025
CM031 Public reviews also flag that Postman can feel slow or overwhelming with large collections or on weaker machines. SM025
CM032 Software Advice reviews describe Postman as strong for API functional testing but still sometimes difficult to debug. SM026
CM033 The combination of Insomnia, Bruno, Hoppscotch, and similar tools means the low end of the API-client market is under real commoditization pressure. SM016, SM020, SM022
CM034 The combination of Swagger, Stoplight, Kong, and ReadyAPI shows that enterprise buyers do not purchase a single API market category; they assemble capabilities across design, governance, gateway, and testing. SM014, SM019, SM023, SM024
CM035 Postman's differentiated market claim is strongest when API collaboration and shared lifecycle context matter more than local request execution alone. SM004, SM006, SM007, SM016, SM020
CM036 The API market tailwind depends heavily on enterprises treating APIs as durable products with governance, reuse, and monetization goals rather than one-off technical artifacts. SM001, SM002, SM004
CM037 Open public evidence does not cleanly separate SMB versus enterprise contribution inside Postman's paying base.
CP001 Postman competes across a wider API lifecycle surface than a simple request client. SP001, SP003, SP004
CP002 TechCrunch identified Stoplight and Kong as named competitors to Postman as early as the 2021 Series D coverage. SP007
CP003 Swagger positions SwaggerHub as an integrated solution for API design, testing, and documentation. SP009, SP010
CP004 Insomnia markets itself as an open-source platform with local, Git, or cloud workflows. SP011, SP012
CP005 Insomnia’s free forever local-only Scratch Pad and no-login workflow target buyers who want to avoid SaaS lock-in. SP011, SP012
CP006 Stoplight sells API design workflows with interactive docs and instant mock servers. SP013
CP007 Bruno markets a git-native API client that is free, open source, and requires no account. SP014, SP015
CP008 Hoppscotch markets itself as an open-source API development ecosystem. SP016
CP009 ReadyAPI positions itself as a low-code automated testing platform spanning REST, SOAP, Kafka, JDBC, and JMS. SP017
CP010 Kong’s pricing model is infrastructure-oriented, with a free trial followed by gateway-based charging rather than seat-based collaboration pricing. SP019
CP011 GitLab positions itself as an intelligent orchestration platform for DevSecOps with a Duo Agent Platform layered into pricing tiers. SP020
CP012 GitLab’s FY2026 Q4 release said the company crossed $1 billion in ARR, showing the scale of adjacent platform-suite competition. SP026
CP013 Postman’s own packaging remains relatively accessible at Free, $9 Solo, $19 Team, and $49 Enterprise list pricing. SP002
CP014 Stoplight’s pricing starts at $44 per month for an individual Basic plan and $113 per month for Startup teams, indicating a design-first premium. SP013
CP015 Kong’s pricing shows API runtime programs can be bought on infrastructure count rather than per-user collaboration. SP019
CP016 Postman’s strongest differentiator is a combination of shared collections, repository visibility, documentation, testing, and workflow execution in one surface. SP001, SP003, SP004
CP017 Agent Mode extends Postman’s competition from human API workflows into AI-assisted execution and debugging. SP005
CP018 AI Engineer positions Postman to compete on agentic engineering context, not just API request tooling. SP006
CP019 TechCrunch and I Programmer both framed AI Agent Builder as a material Postman expansion into agent building on top of APIs. SP008, SP025
CP020 TrustRadius describes Postman as free for small teams and independent developers while reserving higher tiers for broader API management and collaboration. SP021
CP021 G2 reviews say features that used to be free increasingly require paid plans. SP023
CP022 G2 reviews also say the app can feel slow or overwhelming when collections become large. SP023
CP023 Software Advice reviews still describe Postman as strong for functional API testing, but sometimes difficult to debug. SP024
CP024 Trustpilot includes severe negative user anecdotes, including claims of scrambled cloud-synced collection content and deleted environments. SP022
CP025 Bruno and Insomnia make clear that low-end request execution is already commoditized by free or open-source alternatives. SP011, SP014, SP015
CP026 Stoplight and SwaggerHub show that design and documentation can be bought from focused specialists without adopting Postman end to end. SP009, SP013
CP027 Kong and GitLab show that upper-end competition can come from broader platforms that bundle API-adjacent needs into infrastructure or DevSecOps contracts. SP019, SP020, SP026
CP028 Postman’s scale claims of 40M+ users and 500,000 organizations give it a distribution advantage that most niche API tools cannot match publicly. SP001, SP007
CP029 TechCrunch’s 2025 AI-builder coverage suggests Postman is using its installed base to move faster into AI-centric API workflows than point-tool rivals. SP008
CP030 Postman’s repository and workflow layers matter because they create switching cost above the request-client level. SP003, SP004, SP005
CP031 SwaggerHub is likely the strongest design-first rival for teams that care more about specification governance and developer portals than execution context. SP009, SP010
CP032 Insomnia, Bruno, and Hoppscotch are the clearest local-first or open-source substitutes for cost-sensitive teams. SP011, SP014, SP016
CP033 Kong is the clearest infrastructure-centric adjacent rival because its pricing and positioning revolve around gateways and connectivity rather than collaboration seats. SP019
CP034 GitLab is the clearest suite-bundling rival because its platform can absorb API workflows into a larger DevSecOps standardization motion. SP020, SP026
CP035 Public sources do not reveal objective head-to-head win rates, net retention by competitor, or segment-level churn against any rival.
CP036 The most credible moat risk is not one knockout rival but fragmentation: point tools can peel off design, testing, gateway, or local-client budgets independently. SP009, SP011, SP017, SP019
CP037 The most credible moat strength is that Postman unifies context across human users and emerging agent workflows in one platform. SP001, SP005, SP006, SP008
CI001 Postman publicly monetizes through Free, Solo, Team, and Enterprise plans plus AI-related overages. SI001
CI002 The 2026 Free plan is positioned for solo usage rather than multi-user collaboration. SI001, SI026, SI027
CI003 The Solo plan is listed at $9 per user per month when billed annually. SI001, SI026
CI004 The Team plan is listed at $19 per user per month when billed annually. SI001, SI026, SI027
CI005 The Enterprise plan is listed at $49 per user per month when billed annually and includes higher pooled AI credits plus organization controls. SI001, SI002, SI026
CI006 Postman Enterprise positions the platform as trusted by over 40 million developers and 98% of the Fortune 500. SI002
CI007 Postman's enterprise messaging explicitly frames partner APIs as a revenue-scaling surface for customers. SI002
CI008 Workspaces are presented as the collaborative layer where teams build, test, and distribute APIs together. SI015
CI009 The API Repository is described as a cloud-based, version-controlled centralized store for API artifacts. SI016
CI010 Flows is positioned as executable workflow documentation that teams can inspect, run, debug, and clone. SI017
CI011 Agent Mode is positioned as a team productivity and test-generation aid for building AI-ready APIs. SI018
CI012 Postman's 2025 State of the API report says 65% of organizations generate revenue from their API programs. SI005
CI013 Postman's 2025 State of the API report says 93% of teams struggle with API collaboration. SI005
CI014 Postman says it serves more than 500,000 organizations. SI003, SI022
CI015 LinkedIn currently exposes a 3,523-employee view on the Postman company page while also showing a company-size band of 501-1,000 employees, indicating that public headcount signals are noisy. SI022
CI016 TrustRadius reviews highlight collaboration, shared workspaces, and test automation as valued parts of the product. SI024, SI028
CI017 G2 reviews repeatedly praise collections, environments, and team collaboration as reasons users keep Postman in daily workflows. SI025
CI018 G2 reviews also complain about pricing creep, heavier performance, and the migration of collaboration features into paid tiers. SI025
CI019 Competitor commentary from Apidog and Dev Tools describes the 2026 packaging change as pushing any real multi-user collaboration into paid plans. SI026, SI027
CI020 The public conversion story is therefore strongest where shared workflow pain becomes expensive enough to justify a team platform, not where single developers only need a free client. SI001, SI005, SI015, SI024, SI025
CI021 Postman closed a $225 million Series D at a $5.6 billion valuation in August 2021. SI004, SI021
CI022 GetLatka, Craft, and Tracxn cluster Postman's lifetime funding around roughly $433 million to $434 million. SI006, SI008, SI011
CI023 Tracxn says Postman has raised about $434 million over six rounds, with the latest round being Series D in August 2021. SI011
CI024 GetLatka estimates Postman generated $313.1 million of revenue in 2024. SI006
CI025 GetLatka estimates Postman generated $171.7 million of revenue in 2023. SI006
CI026 GetLatka estimates Postman generated $102.7 million of revenue in 2022. SI006
CI027 GetLatka also lists Postman at roughly $52 million of revenue in 2021. SI006
CI028 Those Latka estimates imply very fast scaling from 2022 through 2024 even if absolute precision is uncertain. SI006
CI029 Growjo publishes a much higher forward estimate of roughly $506.1 million annual revenue and about 2,212 employees. SI009
CI030 The Economic Times reported that recent secondary deals cleared at a 30-40% discount to Postman’s 2021 valuation. SI010
CI031 The Economic Times also cited people aware of Postman’s financials who estimated annualized recurring revenue at only $120-150 million. SI010
CI032 Public revenue and ARR estimates for Postman are inconsistent enough that outside investors cannot reconcile the company’s current monetization scale from open sources alone. SI006, SI009, SI010, SI012, SI013
CI033 Craft still shows an older $2 billion market valuation snapshot alongside $433 million of total funding, underscoring how stale private-company databases can be on valuation marks. SI008
CI034 Premier Alternatives shows a current valuation field around $3.3 billion while PM Insights and other trackers frame the current mark very differently, reinforcing illiquid price discovery. SI012, SI013
CI035 The live product record shows no evidence of inventory, manufacturing, project finance, or other hardware-style capital demands. SI002, SI015, SI016, SI017
CI036 Postman therefore appears structurally capex-light relative to software businesses that require physical fulfillment or financing assets. SI002, SI015, SI016, SI017
CI037 GitLab's 2026 SEC companyfacts show roughly $955.2 million of revenue and $834.5 million of gross profit for the year ended January 31, 2026. SI020
CI038 Those GitLab facts imply gross margin of roughly 87% for a scaled public devtools SaaS benchmark. SI020
CI039 GitLab's 2026 SEC companyfacts also show about $434.7 million of selling and marketing expense and $274.6 million of R&D expense, illustrating that scaled devtools SaaS can remain people-intensive even when gross margins are high. SI020
CI040 No public source reviewed disclosed Postman’s current cash balance, burn, debt, net revenue retention, or runway. SI003, SI004, SI008, SI011
CE001 Postman currently defines itself as a unified platform for designing, testing, distributing, documenting, and monitoring APIs. SE001, SE015
CE002 The marketed product surface includes API client, design, documentation, collaboration, distribution, testing, monitoring, security, governance, and AI. SE001
CE003 The API Repository is positioned as a cloud-based, version-controlled central source of truth for API artifacts. SE002, SE026
CE004 The API Builder supports design workflows across OpenAPI, GraphQL, and RAML and can keep assets aligned with source code through native Git support. SE002, SE014
CE005 The Private API Network is positioned as an internal catalog with versioning and visibility controls for team or organizational APIs. SE002, SE028
CE006 The Public API Network is positioned as a large public API discovery hub built on public workspaces. SE002
CE007 Collections remain the fundamental container object in Postman for grouping requests, responses, and workflow assets. SE006, SE011
CE008 Variables and environments are a first-class mechanism for scoping the same workflow across local, test, and production contexts. SE007, SE020
CE009 Postman publicly publishes the Collection schema, and v2.1.0 is listed as a stable schema version. SE008, SE011
CE010 The Postman Collection SDK is a Node.js module for creating, manipulating, and exporting collections outside the main UI. SE011
CE011 The openapi-to-postmanv2 package exists as a published conversion layer from OpenAPI into Postman collections. SE012, SE026
CE012 Newman is the command-line collection runner for Postman and is designed for CI and automation use cases. SE009, SE010, SE024, SE025
CE013 Newman is built on Node.js and can run collections from exported JSON files or collection URLs. SE025
CE014 Newman can fetch and run a collection through the Postman API inside a CI environment. SE024, SE026, SE027
CE015 Newman cannot execute package-library scripts from the command line, which leaves some modern workflow execution to the Postman CLI. SE025
CE016 The Postman API exposes programmatic management for collections, environments, monitors, specs, workspaces, pull requests, roles, and other core assets. SE026
CE017 The Postman API also exposes higher-end surfaces including API Catalog, API Governance, Audit Logs, Private API Network, SCIM, SDKs, Secret Scanner, and Service Accounts. SE026, SE028
CE018 Flows turns workflow documentation into an executable artifact that teams can inspect, run, debug, and clone. SE003
CE019 Flows can generate an initial workflow from a prompt and is explicitly framed as a way to make APIs easier for AI agents to consume. SE003, SE022
CE020 Agent Mode uses collections, specs, environments, and history as grounded context for natural-language API work. SE004
CE021 Agent Mode can fix broken requests, write tests, generate docs, organize collections, and otherwise act directly on Postman assets. SE004, SE015
CE022 AI Engineer is positioned as a higher-level agentic teammate with an always-on context graph across APIs and services. SE005, SE015
CE023 AI Engineer is designed to run in a secure sandbox and route output through human approval and existing review queues. SE005
CE024 Postbot is Postman’s AI assistant for troubleshooting requests, writing tests and documentation, visualizing data, and helping users navigate docs. SE023
CE025 Postbot documentation says Enterprise teams get dedicated infrastructure and that Postbot inputs and outputs are not used to train Postman’s AI models. SE023
CE026 Postman’s March 2026 roadmap introduced an API Catalog, native Git workflows, local and CI mock servers, multi-protocol support, and a unified workbench. SE014, SE015
CE027 The new Postman platform says Collections, specs, environments, mocks, flows, and files can now live together in a unified workbench. SE015
CE028 Postman says it now supports HTTP, GraphQL, gRPC, MCP, MQTT, WebSockets, and AI requests in the same collection. SE015
CE029 The platform now uses a new Collection v3 format to make local, code-adjacent workflows more practical. SE015
CE030 The API Catalog is described as a live operational layer tied to where APIs are built, tested, and observed rather than a static registry. SE014, SE015, SE028
CE031 Postman security disclosures include API key management, 180-day audit logs, and 2FA. SE016
CE032 Postman says it complies with the EU-U.S., UK, and Swiss data privacy frameworks and hosts customer data and backups on AWS in the EU and U.S. SE016
CE033 The shared responsibility model means Postman provides platform controls while expecting customers to safeguard their own data and credentials in use. SE016
CE034 The trust portal shows that Postman publicly documents subprocessor changes and the 2026 Klue-related incident affecting Salesforce-connected sales data. SE017
CE035 Reviews on G2, TrustRadius, and Software Advice consistently praise request organization, automation, and documentation workflows. SE018, SE019, SE020
CE036 The same review sources also surface platform heaviness, complexity growth, and paid-feature creep as meaningful product tradeoffs. SE018, SE020
CE037 TechCrunch and I Programmer both framed the 2025 AI agent builder launch as a major expansion of Postman beyond a request client. SE013, SE021
CE038 Developer-signal artifacts such as the Newman repo, npm packages, published schemas, and GitHub Actions tutorials show that Postman has built an ecosystem around its collection format rather than a closed GUI-only tool. SE008, SE009, SE010, SE011, SE012, SE027
CE039 Much of Postman’s advanced value still depends on cloud-managed state, central catalogs, and workspace permissions even as Git-native workflows expand. SE002, SE014, SE015, SE026
CE040 Public product materials still leave technical diligence gaps around model-serving architecture, detailed data residency boundaries, and internal reliability SLOs. SE005, SE016, SE017
CU001 Postman’s customer stories directory says 40 million developers and 500,000 companies rely on the platform. SU002, SU010
CU002 Postman’s about page says more than 500,000 organizations use Postman. SU001, SU010
CU003 The enterprise page says Postman is trusted by over 40 million developers and 98% of the Fortune 500. SU011, SU010
CU004 Postman’s 2021 Series D announcement said the platform had 17 million developers and customers such as Salesforce, Stripe, Kroger, Cisco, and PayPal. SU012
CU005 Public sources imply Postman serves multiple customer constituencies at once: internal developers, QA and platform teams, partner engineers, and external public API consumers. SU002, SU005, SU024, SU025, SU026, SU028
CU006 Landbase says 3,906 verified companies use Postman and that usage is broad across industries and geographies. SU008
CU007 Landbase still describes Postman as used by 25 million developers, which lags the company’s more recent 40 million figure and shows that third-party customer databases can be stale. SU008, SU002, SU010
CU008 Ramp says Postman ranks #2 in its DevOps category and is used by 13% of organizations in that category, with 26% adoption among enterprise companies. SU009
CU009 Workspace reports and analytics documentation show that Postman tracks active users, active workspaces, API requests, response codes, partner funnels, and AI usage over time. SU005, SU006
CU010 Public workspace metrics are available to all plans, while broader reports sit behind enterprise plans. SU004, SU005
CU011 The analytics API includes customer-relevant metrics for partner engagement funnels, success rates, API distribution, and API testing runs. SU006
CU012 The workspace reports documentation explicitly defines a partner onboarding funnel from total partners to successful API responses. SU005
CU013 PayPal says Postman reduced time to first call from hours to one minute. SU003
CU014 PayPal says testing time fell to minutes from hours and that enterprise users save roughly one hour of developer time per week. SU003
CU015 PayPal says its public Postman collection has more than 30,000 forks and ranks number seven among the top ten collections on the Postman Public API Network. SU003
CU016 PayPal also says thousands of its developers use Postman daily and that workspaces and collections have become everyday vocabulary inside the company. SU003
CU017 Autodesk says partner API requests rose from 40 million per year to 60 million per month after its Postman-centered workflow scaled. SU024
CU018 Autodesk says time to first call fell to three minutes and that it onboarded over 200 global partners to PWS APIs using workspaces. SU024
CU019 Autodesk’s external APS documentation shows that its OpenAPI specs can be imported directly into Postman to generate usable collections. SU014
CU020 Medibank says Postman reduced testing cycle times by 70% and accelerated feature releases by three weeks. SU025
CU021 Medibank says it standardized Postman across development and QA, embedded tests into CI/CD, and connected collections to GitHub for branched reviews. SU025
CU022 HubSpot says total API calls on Postman increased by 104% in six months while it used a public workspace as a central source of truth for developers. SU026
CU023 HubSpot says workspace reports are used to collect API adoption metrics and that Run in Postman buttons are attached to organized collections. SU026
CU024 ZEISS says hundreds of test cases can now be run in one minute and that shared workspaces and mock servers accelerated development. SU027
CU025 ZEISS also says it uses SSO, SCIM, domain capture, and enterprise governance because it operates in a highly regulated environment. SU027
CU026 Cover Genius says Postman cut API configuration time by 50% and doubled efficiency in partner integrations. SU028
CU027 Cover Genius says Partner Workspaces, Newman, and audit trails improved partner onboarding, testing, and security. SU028
CU028 Box developer docs maintain an official Postman collection with more than 170 API endpoints organized by resource type. SU015
CU029 Microsoft Graph docs tell users to fork the official collection into a private workspace and explicitly warn against using a public workspace for sensitive credentials. SU016
CU030 The broadest public customer proof is strongest for API-centric and partner-heavy organizations such as PayPal, Autodesk, HubSpot, ZEISS, Medibank, and Cover Genius. SU003, SU024, SU025, SU026, SU027, SU028
CU031 Public evidence for durability is indirect: forks, API-call growth, partner onboarding funnels, and shared-workspace reuse are visible, but NRR, GRR, and contract length are not. SU003, SU005, SU006, SU026
CU032 Reviews across G2, TrustRadius, and Software Advice are broadly positive on organization, collaboration, and documentation. SU017, SU018, SU019
CU033 The same review sources surface heaviness, complexity, and paid-feature creep as real friction points for teams. SU017, SU019
CU034 Expansion appears to follow a land-and-expand pattern through public workspaces, partner workspaces, GitHub or CI integration, monitoring, and enterprise governance. SU003, SU024, SU025, SU026, SU027, SU028
CU035 No public source reviewed indicates material single-customer concentration; the visible logo set spans payments, healthcare, manufacturing, optics, SaaS, and insurtech. SU003, SU024, SU025, SU026, SU027, SU028
CU036 Procurement friction likely exists for smaller teams because collaboration increasingly sits behind paid tiers and because the platform can feel heavy for basic needs. SU017, SU019, SU023
CU037 The API Network and Integrations directory make discoverability itself part of Postman’s customer acquisition surface for API publishers and consumers. SU021, SU022
CU038 The 2026 platform relaunch consolidated internal, partner, and public workspace analytics, reinforcing that multi-sided customer behavior is central to the product. SU020, SU023
CU039 The State of the API report’s finding that 65% of organizations generate revenue from API programs helps explain why customer stories focus on onboarding, governance, and partner distribution rather than only on request sending. SU013
CU040 Public evidence is still insufficient to estimate logo churn, NRR, GRR, or typical contract duration by segment. SU005, SU006, SU017
CR001 Postman publicly discloses Local Vault, Vault Integrations, API key management, audit logs, and 2FA as security controls. SR001
CR002 Postman says audit logs retain key security-access and team-management activity for 180 days. SR001
CR003 Postman says it runs a private bug bounty program with HackerOne. SR001
CR004 Postman explicitly frames security as a shared-responsibility model in which customers must safeguard their own data and credentials in use. SR001
CR005 Postman says it complies with the EU-U.S., UK, and Swiss Data Privacy Frameworks, uses AWS-hosted infrastructure in the EU and U.S., and offers a 99.9% enterprise SLA. SR001, SR020
CR006 The trust portal says a third-party provider, Klue, triggered a 2026 incident affecting Salesforce-connected sales data rather than core platform services. SR002
CR007 The trust portal also publishes subprocessor notices and gives customers a short objection window on data-protection grounds. SR002
CR008 Postman’s legal hub includes AI Terms, Professional Services Terms, Website Terms of Use, workshop terms, and archived contract versions. SR003
CR009 The legal archives page shows repeated updates to Terms of Service, Product Terms, and AI Terms across 2025. SR005
CR010 California’s CCPA creates rights and breach-related legal consequences when nonencrypted personal data is exposed because a business failed to maintain reasonable security. SR019
CR011 The official Data Privacy Framework site confirms the regulatory framework Postman cites, which means any future adequacy or certification drift would directly affect its public compliance claims. SR020, SR001
CR012 The status page shows a wide operational footprint that includes login, monitors, mocks, API Network, search, docs, integrations, Postbot, CLI, API Builder, and Agent Mode. SR006
CR013 The status page also shows 100% desktop-platform uptime over the trailing 90-day window captured during this review. SR006
CR014 CloudSEK says its year-long investigation found more than 30,000 publicly accessible Postman workspaces exposing sensitive information such as access tokens, refresh tokens, API keys, and test data. SR007, SR008
CR015 CloudSEK describes practical impacts ranging from PII leaks and admin credential exposure to payment-key abuse and refresh-token hijacking. SR007
CR016 Truffle Security says at least 4,000 live secrets are currently leaking on Postman and that its sample found 1,689 live unique credentials across about 40,000 workspaces. SR009
CR017 Truffle also says 16% of public OpenAI forks and 20% of Pynt forks contained live credentials. SR009
CR018 Truffle attributes the exposure problem to public forks, confusing Initial vs Current value semantics, misleading “secret” variable labels, and insufficient default secret-scanning enforcement. SR009
CR019 AppSentinels argues that public Postman workspaces can be indexed like normal webpages, turning a collaboration feature into an attack-discovery surface even without any platform breach. SR010
CR020 InfoSec Write-ups presents a practical secret-scanning workflow for exposed Postman APIs, reinforcing that the issue is operationally exploitable rather than merely theoretical. SR011
CR021 UpGuard and Panorays both maintain ongoing vendor-risk surfaces for Postman, indicating that third-party monitoring of its security posture is persistent. SR012, SR013
CR022 Bruno positions itself as open-source, Git-native, offline-only, and explicitly anti-cloud-sync. SR014, SR015
CR023 Bruno stores collections as plain text on the filesystem and supports Git-based collaboration and CLI execution, directly challenging Postman’s workspace-centric model. SR014, SR015
CR024 Insomnia now markets local, Git, or cloud storage options, no-login scratch pad, SCIM/SAML/OIDC identity controls, MCP support, and an AI-native workflow. SR016
CR025 Thunder Client markets itself as a lightweight local-storage VS Code extension with Git sync and CLI support. SR017
CR026 GitHub Copilot extends AI automation pressure from a much broader developer platform than Postman’s single-product surface. SR018
CR027 Postman’s 2026 product launches made AI, native Git workflows, API Catalog, and a unified workbench central to the platform. SR026, SR027
CR028 Agent Mode can act across collections, specs, environments, and history, which raises the importance of permission boundaries and review controls. SR029
CR029 The Postman API now exposes Secret Scanner, Audit Logs, SCIM, Private API Network, and Service Accounts endpoints, showing that many mitigations are productized rather than purely procedural. SR028
CR030 The API Network and its learning-center docs make public APIs and workspaces intentionally discoverable, so growth surface and attack surface overlap. SR021, SR022
CR031 G2, TrustRadius, and Software Advice all show that users value collaboration and test automation, but also complain about paid-feature drift, complexity, and slowness at larger scale. SR023, SR024, SR025
CR032 Apidog and Dev Tools argue that the 2026 packaging changes push multi-user teams toward paid tiers and may increase churn among budget-sensitive teams. SR031, SR032
CR033 The Economic Times reported secondary transactions at a 30-40% discount to the 2021 valuation and cited ARR estimates of only $120-150 million, highlighting model-risk and financing sensitivity. SR030
CR034 No public source reviewed discloses current burn, runway, or debt, so capital-pressure risk cannot be resolved from open sources. SR001, SR002, SR030
CR035 The highest-severity operational risk is not a platform intrusion but the repeatable public leakage of valid credentials through workspaces and forks. SR007, SR009, SR010
CR036 Residual exposure stays high because many mitigations still depend on users correctly choosing private workspaces, proper variable fields, short-lived tokens, and narrow permissions. SR001, SR009, SR010
CR037 Postman’s dependence on AWS, third-party SaaS vendors like Klue, identity providers, and public indexing surfaces means important parts of its trust posture remain outside direct product code. SR001, SR002, SR006, SR021
CR038 Local-first alternatives reduce both cloud exposure and switching friction, weakening Postman’s ability to rely on collaboration lock-in as the only moat. SR014, SR015, SR016, SR017
CR039 If a future public-workspace leak involved regulated personal data at scale, Postman could face privacy-enforcement exposure on top of reputational damage. SR019, SR007, SR010
CR040 A thesis-break event would be a repeat high-profile credential-exposure episode, a prolonged trust-damaging outage, or evidence that AI- and local-first competitors are displacing Postman in teams that need collaboration. SR006, SR014, SR016, SR018, SR023, SR030
CV001 Postman closed a $225 million Series D round in August 2021 at a $5.6 billion post-money valuation led by Insight Partners, with new investors Coatue, Battery Ventures, and BOND alongside existing investors CRV and Nexus Venture Partners. SV002, SV003
CV002 TechCrunch reported that Postman's 2021 Series D brought the company's total funding across all rounds to more than $430 million. SV003
CV003 Craft.co lists Postman's total funding at $433 million and separately shows a 'Market Valuation' field of $2 billion dated 2020-06-11, which predates and understates the confirmed $5.6 billion 2021 Series D mark. SV006
CV004 GetLatka states in prose that Postman 'reached a $3.6 billion valuation in 2021' during its Series D, while its own funding table on the same page lists that identical round at a $5.6 billion valuation, an internal inconsistency on GetLatka's page. SV005
CV005 GetLatka estimates Postman's revenue grew from about $8.4 million in 2018 to $313.1 million in 2024, including $171.7 million in 2023 and $102.7 million in 2022. SV005
CV006 GetLatka and Craft.co both independently show Postman's total funding at $433 million across five rounds (Seed $1M 2015, Series A $7M 2016, Series B $50M 2019, Series C $150M 2020, Series D $225M 2021). SV005, SV006
CV007 Inc42's funding tracker shows Postman's total funding at $433 million and its Series D at $225 million, consistent with Postman's own announcement, but shows Postman's Indian entity Postdot Technologies Private Limited reporting revenue of roughly Rs185.7 crore for FY2024 -- a figure that reflects only the Indian legal entity, not global consolidated revenue. SV013
CV008 Inc42 lists Postman's employee count at approximately 3,490 as of its most recent update. SV013
CV009 Forge Global's funding table shows Postman's Series D primary raise as $145 million at a $17.54 per-share price and $5.57 billion post-money valuation, a lower primary-only figure than the $225 million widely reported for the full round. SV007
CV010 Forge Global shows Postman's cumulative funding across four priced rounds (Series A through D) at $352 million, roughly $80 million below the $433 million total shown by Craft.co, GetLatka, and Inc42. SV007
CV011 Forge Global's data shows Postman's Series C priced at a $2.06 billion post-money valuation on 2020-06-11, which is consistent with TechCrunch's contemporaneous reporting that the 2021 Series D valued Postman 'up from $2 billion a year ago.' SV007, SV003
CV012 Forge Global's disclosed Series D terms show a 1.0x liquidation preference multiplier and preference order of 1, but the page displays both 'cumulative/non-cumulative' and 'participating/non-participating' as unresolved toggle-style fields rather than a single confirmed value, leaving the actual preference stack terms ambiguous from public evidence. SV007
CV013 As of July 17-20, 2026, Forge Global's derived 'Forge Price' for Postman was $7.00 per share, implying an estimated valuation of approximately $2.22 billion, and Yahoo Finance's private-market listing for the same ticker (POSM.PVT) independently shows the identical $2.22 billion estimate. SV007, SV011
CV014 Forge Global shows its Postman price down between roughly 9.8% and 32.7% across trailing 7-day, 1-month, 3-month, 6-month, 1-year, and all-time windows as of July 2026. SV007
CV015 Yahoo Finance describes Forge Price as a derived data point calculated from a proprietary model incorporating publicly available primary funding round information, secondary market transactions, and indications of interest on Forge and other private-market trading platforms. SV011
CV016 Public.com's model, sourced to Nasdaq Private Markets, estimated Postman's secondary share price at $7.64 as of June 2026, down $2.37 (23.68%) over the trailing six months, and separately lists Postman's founding year as 2015 rather than the 2014 founding year shown by Forge Global, Craft.co, and Postman's own materials. SV009
CV017 Notice.co's page title metadata listed a Postman secondary share price estimate of $8.07 as of July 18, 2026, but the underlying page body did not render for independent verification because the content is JavaScript-only. SV012
CV018 Premier Alternatives displays conflicting valuation figures for Postman on the same page: the page's <title> metadata states 'Postman Valuation: $2.2B (2026)' while the visible body text states a 'Current Valuation' of $3.3 billion and a 9.46x capital-efficiency ratio against $352.0 million raised. SV010
CV019 UpMarket's own valuation model estimates Postman at $4.8 billion, distinct from the $5.6 billion 'Latest Price' it displays, which is simply the stale 2021 Series D mark rather than a current estimate; UpMarket also mislabels that Series D reference as occurring in 'Series C Apr 2019' terminology on its previous-price field, another internal labeling inconsistency. SV014
CV020 Across the analyst-market-data trackers reviewed in this chapter (Forge/Yahoo Finance, Public.com, Notice.co, Premier Alternatives, and UpMarket), 2026 estimates of Postman's implied valuation span roughly $2.2 billion to $4.8 billion, and every one of them sits below the confirmed $5.6 billion 2021 Series D peak. SV007, SV009, SV010, SV011, SV014
CV021 The Economic Times reported that Postman's secondary-market share transactions cleared at a 30-40% discount to the company's 2021 primary valuation, versus a typical 10-15% discount for secondary transactions generally, calling it a steep decline in value for SaaS firms on revenue multiples. SV004
CV022 A person described by the Economic Times as aware of Postman's financials said that, based on revenue projections, the company's valuation is being readjusted downward from its 2021 peak-cycle level, and that further batches of secondaries at a similar discount range may follow. SV004
CV023 The Economic Times reported that Postman did not respond to its request for comment on the reported secondary-market discount, and that existing investors including Nexus Venture Partners, BOND Capital, and Battery Ventures purchased some of the shares being sold by earlier angel and early investors. SV004
CV024 PitchBook reported in February 2026 that US startups whose last priced round was in 2021 traded at an average valuation markdown near 68.2% relative to that round, while 2022-vintage startups averaged a 52.1% markdown. SV030
CV025 Applying PitchBook's reported 68.2% average markdown for 2021-vintage startups to Postman's $5.6 billion Series D mark would imply a valuation near $1.8 billion, which is below every analyst-market-data estimate for Postman reviewed in this chapter (roughly $2.2 billion to $4.8 billion), suggesting Postman's current secondary pricing is holding up somewhat better than the broad 2021-vintage cohort average. SV030, SV007
CV026 PitchBook reported that the top 10 US startups by valuation represented a record 51.8% of total US unicorn value, up from 18.5% in 2022, indicating that late-stage private capital is concentrating in a small number of mega-valued companies rather than spreading evenly across the unicorn population. SV030
CV027 Kong Inc., a direct API-management/gateway competitor named in Postman's own competitive set, closed a $175 million Series E financing in November 2024 (a mix of primary and secondary transactions) at a $2 billion valuation, led by Tiger Global and co-led by new investor Balderton, bringing Kong's total capital raised to $345 million. SV016, SV017
CV028 Kong's Series E round added new investors Teachers' Venture Growth (Ontario Teachers' Pension Plan's late-stage arm) and 137 Ventures, alongside continued participation from Andreessen Horowitz, Index Ventures, CRV, Sapphire Ventures, and Notable Capital, and Balderton partner Rana Yared joined Kong's board. SV016, SV017
CV029 SmartBear, an adjacent API-lifecycle and software-quality tooling vendor, has been jointly and equally owned by Francisco Partners (since its 2017 acquisition) and Vista Equity Partners (since a subsequent investment) with no disclosed current valuation, and reports serving more than 15 million developers, testers, and operations engineers across more than 24,000 organizations. SV023
CV030 GitLab Inc. is a NASDAQ-listed public company (ticker GTLB, CIK 1653482) headquartered at 268 Bush Street, San Francisco, that files periodic reports with the SEC, including an annual report (10-K) for its fiscal year 2026 filed on 2026-03-17. SV018, SV019
CV031 GitLab reported fiscal year 2026 total revenue of $955.2 million, up 26% year over year, with fourth-quarter revenue of $260.4 million (+23% YoY), and stated that fiscal year 2026 saw the company cross $1 billion in annualized recurring revenue. SV020
CV032 GitLab's market capitalization was approximately $5.52 billion as of July 19, 2026 (down 13.27% year over year), implying a revenue multiple near 5.8x on its $955.2 million fiscal 2026 revenue. SV021, SV020
CV033 Atlassian's market capitalization was approximately $23.67 billion as of July 17, 2026, down 52.65% over the prior year, against $6.19 billion in trailing-twelve-month revenue (up 24.74% YoY), for a price-to-sales ratio of 3.82x as directly reported by Stock Analysis. SV022, SV032
CV034 Datadog's market capitalization was approximately $92.08 billion as of July 2026 (up 89.85% year over year) against roughly $3.67 billion in trailing-twelve-month revenue, implying a revenue multiple near 25x -- illustrating that public devtools/observability multiples can vary by more than 6x depending on growth quality and category positioning. SV028, SV029
CV035 IBM agreed to acquire data-streaming company Confluent for approximately $11 billion, a deal that gives IBM a platform with an annual revenue run rate topping $1 billion, implying roughly an 11x revenue-run-rate multiple as a data-infrastructure M&A comparable; IBM's prior large software acquisition was the $6.5 billion purchase of HashiCorp. SV024
CV036 Multiples.vc's July 2026 public software comparables show wide EV/revenue dispersion by category, noting that design and engineering software such as Autodesk and Adobe commands premium multiples by successfully integrating AI features, while other horizontal SaaS segments trade at steep discounts amid AI-disruption ('creative destruction') concerns. SV025
CV037 Capstone Partners' 2026 M&A outlook describes a gradual, private-equity-led reopening of middle-market dealmaking after a multi-year downcycle, citing five consecutive quarters of platform-acquisition growth and expectations that interest-rate cuts and improving CEO confidence will be key catalysts through 2026. SV026
CV038 EY's mid-2026 M&A activity report found that US technology deal value roughly doubled year over year with deal volume up 29% in the April-June quarter, driven by buyer appetite for AI model development, coding/automation capabilities, and connectivity/compute-enabling platforms. SV027
CV039 Postman's own press-media page lists product and partnership announcements through April 2026 -- including a Microsoft AI model-choice collaboration (2026-04-16) and an Anthropic Claude-on-Amazon-Bedrock integration (2026-03-31) -- but no announcement referencing an IPO filing, roadshow, or public-listing timeline as of the July 2026 access date. SV001
CV040 Postman's press-media page shows the company made two acquisitions within the prior eight months of the access date: Fern (announced 2026-01-08) and liblab (announced 2025-11-14), both framed as accelerating a unified API-lifecycle and developer-experience platform strategy. SV001
CV041 A dedicated third-party IPO-tracking page for Postman (ipos.fyi) returned an HTTP 429 rate-limited/bot-checkpoint response when checked in July 2026, so no independent IPO-readiness signal could be corroborated from that source. SV015
CV042 A search of the SEC EDGAR company database restricted to the company name 'postman' and Form S-1 returned no matching filer or filing rows as of the July 2026 access date, consistent with no public evidence of a Postman S-1 registration statement having been filed. SV031
CV043 No source reviewed in this chapter discloses Postman's board composition, a current capitalization table, or resolved liquidation-preference/dividend terms beyond the named Series D investor list and an ambiguous 1.0x preference multiplier shown on one secondary-market tracker.
CV044 No public source reviewed discloses Postman's GAAP revenue, gross margin, cash balance, or burn rate, so the Economic Times' implied 2024 ARR range and GetLatka's $313.1 million 2024 revenue estimate should both be treated as third-party proxies rather than audited figures when used in any revenue-multiple valuation math.
CV045 Because Postman's own disclosed revenue is unavailable, a defensible sensitivity framework must bracket the entry price using the two conflicting third-party revenue estimates (roughly $120-150 million ARR per Economic Times-sourced commentary and $313.1 million revenue per GetLatka) alongside the $2.2 billion-$5.6 billion valuation band already observed across trackers, rather than assuming either revenue figure is authoritative. SV004, SV005, SV007
CV046 The combination of unresolved governance/cap-table opacity, no audited financials, and no confirmed 2026 primary financing round means that even a favorable reading of Postman's demand-side evidence cannot currently support a price-insensitive buy call; a research-more/track posture is the evidence-consistent recommendation. SV004, SV007, SV030
CV047 This chapter's evidence supports a 'research-more' recommendation for Postman, medium confidence, medium-high risk rating, and a 'fair-to-stretched' valuation stance depending on which revenue estimate is assumed, rather than a buy or avoid call. SV004, SV005, SV007, SV030
CV048 The recommendation logic chain runs from (a) verified scale and financing history, through (b) two mutually exclusive revenue estimates and a multi-tracker secondary-valuation discount cluster, to (c) unresolved governance and cash-flow disclosure gaps, concluding in (d) a price-sensitive research-more call rather than an admiration-based buy call. SV003, SV005, SV007, SV004
CV049 The core investment thesis for Postman rests on durable API-tooling distribution (verified $5.6 billion peak financing, 17 million-plus developers at the 2021 raise, named enterprise logos) while the core anti-thesis rests on unresolved monetization proof, a 30-40% reported secondary discount, and no confirmed capital event since 2021. SV002, SV004, SV007
CV050 Bull, base, and bear valuation scenarios for Postman diverge primarily on which revenue estimate proves closer to reality and whether secondary-market pricing recovers toward the UpMarket/Forge upper band or drifts toward the PitchBook-implied 2021-vintage average markdown. SV005, SV007, SV014, SV030
CV051 A revenue-multiple sensitivity framework built on the conflicting $120-150 million and $313.1 million revenue estimates, combined with the 3.8x-25x range observed across Atlassian, GitLab, and Datadog, brackets plausible valuation outcomes for Postman between roughly $0.5 billion and $8 billion before qualitative adjustment for growth quality and disclosure risk. SV005, SV004, SV022, SV021, SV028
CV052 The most decision-relevant final diligence asks for Postman are: audited or management-reviewed revenue/ARR by segment, a current cap table with liquidation-preference and dividend terms, evidence of any 2025-2026 primary financing or tender event, and disclosed retention/expansion metrics to validate which revenue estimate is closer to reality. SV004, SV005, SV007
CV053 Thesis-break triggers for Postman include: a confirmed primary round or tender priced meaningfully below the $2.2 billion Forge/Yahoo cluster, disclosed revenue materially below the $120-150 million low estimate, a governance or security event that impairs enterprise trust beyond what is already reflected in the company's public risk record, or continued absence of any capital event through 2027 alongside further secondary-discount widening. SV004, SV007
来源
编号出版方标题引文
SO001 Postman About Postman Postman is an API platform for building and using APIs.
SO002 Postman Contact Us | Postman
SO003 Postman Postman API Platform - Build, Test & Manage
SO004 Postman Plans & Pricing | Postman API Platform
SO005 Postman 2025 State of the API Report | Postman
SO006 Postman 2025 State of the API Report
SO007 Postman Postman’s Series D Funding and the API-First World
SO008 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise | TechCrunch
SO009 GetLatka Postman Revenue, Valuation & Funding History (2024)
SO010 Craft.co Postman Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co
SO011 Craft.co Postman Corporate Headquarters, Office Locations and Addresses | Craft.co
SO012 LinkedIn Postman | LinkedIn
SO013 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SO014 The Economic Times Postman: SaaS star Postman sees 30-40% cut in valuation in secondary deal - The Economic Times
SO015 Postman The New Postman is Here: AI-Native and Built for the Agentic Era
SO016 Postman Announcing Postman has acquired Orbit
SO017 Postman Postman acquires liblab to build the unified API lifecycle platform
SO018 Postman Postman acquires Fern
SO019 Business Wire Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation
SO020 Business Wire One in Four Developers Now Design APIs for AI Agents, According to Postman’s 2025 State of the API Report
SO021 Postman Postman Customer Trust Portal
SO022 Treblle 30,000 APIs Exposed: Lessons from the Postman Data Breach
SO023 CloudSEK Postman Data Leaks: The Hidden Risks Lurking in Your Workspaces | CloudSEK
SO024 Postman Postman Status
SO025 Cyber Security News Postman Data Leak - 30,000 Publicly Accessible Workspaces Could Lead Massive Hack
SM001 Postman 2025 State of the API Report | Postman
SM002 Postman 2025 State of the API Report
SM003 Postman 2025 State of the API for Security | Postman Report
SM004 Postman Postman API Platform - Build, Test & Manage
SM005 Postman Plans & Pricing | Postman API Platform
SM006 Postman API Repository | Postman API Platform
SM007 Postman Flows | Visual Workflow Documentation | Postman API Platform
SM008 Postman The New Postman is Here: AI-Native and Built for the Agentic Era
SM009 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SM010 The Business Research Company API Management Market Share, Size, Trends, Report 2026
SM011 Strategic Market Research Api Management Market 2026: Expert-Crafted Insights You Can Trust
SM012 Fortune Business Insights API Management Market Size, Trends | Global Report [2034]
SM013 Mordor Intelligence API Management Market Size, Share & Trends Report 2026-2031
SM014 Swagger Build AI-Ready APIs | Design, Test & Scale APIs Faster with Swagger
SM015 Swagger Swagger Pricing | Flexible Plans for Every Team
SM016 Insomnia The Collaborative API Development Platform
SM017 Insomnia Pricing
SM018 Stoplight OpenAPI Design & Documentation Management Tool | Stoplight
SM019 Stoplight API Design Plans and Pricing | Stoplight
SM020 Bruno Bruno - The Git-Native API Client
SM021 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia)
SM022 Hoppscotch Hoppscotch • Open source API development ecosystem
SM023 SmartBear Automated API Testing Platform | API Testing Tools | ReadyAPI
SM024 Kong Kong Pricing for API and AI Connectivity Platform | Konnect
SM025 G2 The G2 on Postman
SM026 Software Advice Postman Software Reviews, Demo & Pricing
SP001 Postman Postman API Platform - Build, Test & Manage
SP002 Postman Plans & Pricing | Postman API Platform
SP003 Postman API Repository | Postman API Platform
SP004 Postman Flows | Visual Workflow Documentation | Postman API Platform
SP005 Postman Agent Mode | Postman API Platform
SP006 Postman Meet the AI Engineer | Postman
SP007 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise | TechCrunch
SP008 TechCrunch Postman launches an AI agent builder on top of its API platform | TechCrunch
SP009 Swagger Build AI-Ready APIs | Design, Test & Scale APIs Faster with Swagger
SP010 Swagger Swagger Pricing | Flexible Plans for Every Team
SP011 Insomnia The Collaborative API Development Platform
SP012 Insomnia Pricing
SP013 Stoplight API Design Plans and Pricing | Stoplight
SP014 Bruno Bruno - The Git-Native API Client
SP015 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia)
SP016 Hoppscotch Hoppscotch • Open source API development ecosystem
SP017 SmartBear Automated API Testing Platform | API Testing Tools | ReadyAPI
SP018 SmartBear ReadyAPI Pricing | API Testing for Teams & Enterprises | ReadyAPI
SP019 Kong Kong Pricing for API and AI Connectivity Platform | Konnect
SP020 GitLab Pricing
SP021 TrustRadius Postman Reviews & Ratings 2026 | TrustRadius
SP022 Trustpilot Postman is rated "Average" with 3 / 5 on Trustpilot
SP023 G2 The G2 on Postman
SP024 Software Advice Postman Software Reviews, Demo & Pricing
SP025 I Programmer Postman Launches AI Agent Builder
SP026 GitLab GitLab Reports Fourth Quarter and Full Year Fiscal Year 2026 Financial Results; Board of Directors Authorizes $400 million for Share Repurchase Program
SI001 Postman Plans & Pricing | Postman API Platform Free, Solo, Team, and Enterprise tiers are live on the 2026 pricing page.
SI002 Postman Postman Enterprise | AI-native API Platform Trusted by over 40M developers and 98% of the Fortune 500.
SI003 Postman About Postman Postman is an API platform for building and using APIs.
SI004 Postman Postman’s Series D Funding and the API-First World We’ve closed a Series D investment round of $225 million that values the company at $5.6 billion.
SI005 Postman 2025 State of the API Report | Postman APIs have become profit drivers, with 65% of organizations generating revenue from their API programs.
SI006 Latka Postman Revenue, Valuation & Funding History (2024) In 2024, Postman's revenue reached $313.1M. The company previously reported $171.7M in 2023.
SI007 Sacra Postman funding, news & analysis
SI008 Craft Postman Financials | Craft.co Total Funding $433 M.
SI009 Growjo Postman: Revenue, Competitors, Alternatives Postman's estimated annual revenue is currently $506.1M per year.
SI010 The Economic Times Postman sees 30-40% cut in valuation in secondary deal People aware of Postman’s financials said it is estimated to be clocking annualised recurring revenue (ARR) of $120-150 million.
SI011 Tracxn Postman Postman has raised a total funding of $434M over 6 rounds.
SI012 PM Insights Postman Valuation | PM Insights Postman Valuation and Overview.
SI013 Premier Alternatives Postman Valuation: $2.2B (2026) Current Valuation $3.3B.
SI014 CompWorth Postman – Financial Footprint & Growth Factors – 2026
SI015 Postman Postman Workspaces | API Collaboration | Postman API Platform One place where teams collaborate to build, test, and distribute APIs.
SI016 Postman API Repository | Postman API Platform Postman provides a cloud-based, version-controlled, centralized repository for all API artifacts.
SI017 Postman Flows | Visual Workflow Documentation | Postman API Platform Flows gives your team something they can inspect, execute, debug, and clone, not just read.
SI018 Postman Agent Mode | Postman API Platform Agent Mode can help your team debug faster, generate test coverage, and build quality, AI-ready APIs.
SI019 U.S. Securities and Exchange Commission GitLab submissions JSON Gitlab Inc. is a Nasdaq-listed operating company and large accelerated filer.
SI020 U.S. Securities and Exchange Commission GitLab companyfacts JSON GitLab's SEC companyfacts include revenue, gross profit, R&D, and selling-and-marketing facts through the 2026 filing set.
SI021 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise TechCrunch reported Postman was valued at $5.6 billion in a $225 million fundraise.
SI022 LinkedIn Postman | LinkedIn Discover all 3,523 employees.
SI023 Business Wire Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation Postman Announces New San Francisco Headquarters to Accelerate Growth and Innovation.
SI024 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, as well as collaboration and test automation.
SI025 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SI026 Apidog Postman Pricing 2026: What They Changed & Why You Should Switch The Team plan at $19 per user monthly is the cheapest option for collaboration.
SI027 Dev Tools Postman's 2026 Pricing Changes: What They Mean for Your API Testing Workflow Postman Free is now limited to 1 user.
SI028 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts and collaboration tools.
SE001 Postman Postman API Platform - Build, Test & Manage Postman is a unified platform for designing, testing, distributing, documenting, and monitoring APIs.
SE002 Postman API Repository | Postman API Platform Postman provides a cloud-based, version-controlled, centralized repository for all API artifacts.
SE003 Postman Flows | Visual Workflow Documentation | Postman API Platform Flows gives your team something they can inspect, execute, debug, and clone, not just read.
SE004 Postman Agent Mode | Postman API Platform Agent Mode understands your collections, specs, environments, and history so every response is grounded in your actual APIs.
SE005 Postman Meet the AI Engineer | Postman Powered by an always-on, continuously updated context graph of your APIs and services across your organization.
SE006 Postman Docs Create and manage request collections in Postman | Postman Docs A collection is one of the fundamental elements in Postman.
SE007 Postman Docs Store and reuse values using variables | Postman Docs Variables enable you to store and reuse values in Postman.
SE008 Postman Postman Schemas Collections v2.1.0 is listed as stable on the schema site.
SE009 GitHub GitHub - postmanlabs/newman: Newman is a command-line collection runner for Postman Newman is a command-line collection runner for Postman.
SE010 npm newman Newman is a command-line collection runner for Postman.
SE011 npm postman-collection Postman Collection SDK is a NodeJS module that allows a developer to work with Postman Collections.
SE012 npm openapi-to-postmanv2 openapi-to-postmanv2 is a published package for converting OpenAPI definitions to Postman collections.
SE013 TechCrunch Postman launches an AI agent builder on top of its API platform TechCrunch reported Postman launched an AI agent builder on top of its API platform.
SE014 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing These features make AI and native Git workflows core parts of the Postman platform.
SE015 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Postman now lets teams organize HTTP, GraphQL, gRPC, MCP, MQTT, WebSockets, and AI requests in the same collection.
SE016 Postman Postman Security - Compliance, Privacy, & Reliability Audit logs track key activities related to security access and team management for the past 180 days.
SE017 Postman Postman Customer Trust Portal On June 13, Postman became aware of a potential data security incident after a third-party provider, Klue, notified us that it had been compromised.
SE018 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SE019 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, as well as collaboration and test automation.
SE020 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts, detailed request and response analysis, and easy organization of collections.
SE021 I Programmer Postman Launches AI Agent Builder Postman has launched an AI agent builder on top of its API platform.
SE022 QATechTools Postman AI Features: Real API Testing Scenario Scenario-based walkthrough of Agent Mode, Postbot, and Flows.
SE023 Postman Docs About Postbot | Postman Docs Your inputs and outputs will not be used for training Postman or Postman’s artificial intelligence models.
SE024 Postman Docs Run Postman Collections in your CI environment using Newman | Postman Docs You can use Newman and the Postman API to run Postman Collections in your continuous integration (CI) environment.
SE025 Postman Docs Install and run Newman | Postman Docs Newman is built on Node.js.
SE026 Postman Docs Integrate Postman into your development toolchain | Postman Docs Use the Postman API to programmatically manage your Postman assets and integrate Postman into your development toolchain.
SE027 Tayyab Akmal Postman Newman GitHub Actions: API Test CI/CD Setup (2026) Newman integrates seamlessly into GitHub Actions to execute your entire API test suite on every push, pull request, and deployment.
SE028 Postman Integrate Postman into your development toolchain | Postman Docs The API Catalog API enables you to programmatically manage your API Catalog.
SU001 Postman About Postman More than 500,000 organizations use Postman.
SU002 Postman API Customer Stories | Postman API Platform Learn why 40 million developers and 500,000 companies rely on Postman.
SU003 Postman PayPal API Case Study | Postman API Platform Time to first call reduced from hours to 1 minute.
SU004 Postman Announcing public workspace metrics Public workspace metrics help API publishers see engagement and quality signals.
SU005 Postman Docs View reports about workspaces | Postman Docs Workspace reports give insights into active users, active workspaces, API requests, and usage trends over time.
SU006 Postman Docs Get analytics data | Postman Docs Gets analytics data based on the specified resource, metrics, and given filters.
SU007 Postman Postman Insights | API Observability | Postman API Platform Postman Insights provides API observability and production visibility.
SU008 Landbase Postman As of 2026, 3,906 verified companies use Postman.
SU009 Ramp Postman Ramp Rate: A Data-Backed Look As of July 2026, 13% of organizations in the DevOps category use Postman.
SU010 LinkedIn Postman | LinkedIn More than 40 million developers and 500,000 organizations use Postman.
SU011 Postman Postman Enterprise | AI-native API Platform Trusted by over 40M developers and 98% of the Fortune 500.
SU012 Postman Postman’s Series D Funding and the API-First World There are now 17 million developers on the Postman API Platform.
SU013 Postman 2025 State of the API Report | Postman 65% of organizations generate revenue from their API programs.
SU014 Autodesk Platform Services Using APS OpenAPI Specs with Postman You can import Autodesk OpenAPI specs directly into Postman and instantly generate a collection.
SU015 Box Postman Collection - Box Dev Docs The Box Postman Collection includes over 170 API endpoints organized by resource type.
SU016 Microsoft Use Postman with the Microsoft Graph API - Microsoft Graph To use the Postman collection, fork it to your own Postman workspace.
SU017 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SU018 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, collaboration, and test automation.
SU019 Software Advice Postman Software Reviews, Demo & Pricing Postman simplifies API testing with automated scripts and collaboration tools.
SU020 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Reporting has been consolidated so internal, partner, and public workspace analytics live in a single destination.
SU021 Postman Postman Integrations | Postman API Platform Postman integrates with the tools teams already use every day.
SU022 Postman Postman | Postman API Network Explore official API references and public workspaces on the Postman API Network.
SU023 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing The new Team plan will support collaborative API development, testing, and distribution across shared workflows.
SU024 Postman Autodesk Case Study | Postman API Platform Partner API requests jumped from 40 million per year to 60 million per month.
SU025 Postman Medibank Case Study | Postman API Platform Testing cycle times have been reduced by 70% which has sped up feature releases by three weeks.
SU026 Postman HubSpot Case Study | Postman API Platform The total number of API calls on Postman increased by 104% in the six months from November 2023 to May 2024.
SU027 Postman The ZEISS Case Study | Postman API Platform Hundreds of test cases can now be run in one minute.
SU028 Postman Cover Genius Case Study | Postman API Platform Using Postman has doubled our efficiency in delivering key integration requirements to partners.
SU029 TheirStack Companies that use Postman (67,301) TheirStack lists more than 67,000 companies associated with Postman usage signals.
SU030 Postman Public Workspace Metrics report
SR001 Postman Postman Security - Compliance, Privacy, & Reliability Audit logs track key activities related to security access and team management for the past 180 days.
SR002 Postman Postman Customer Trust Portal On June 13, Postman became aware of a potential data security incident after a third-party provider, Klue, notified us that it had been compromised.
SR003 Postman Postman Legal Browse Postman’s legal documents, privacy policies, terms of service, and other legal resources.
SR004 Postman Postman Terms of Service
SR005 Postman Legal Archives | Postman Terms of Service and Product Terms were updated multiple times in 2025.
SR006 Postman Postman Status 100.0% uptime over the last 90 days is shown for the desktop platform view.
SR007 CloudSEK Postman Data Leaks: The Hidden Risks Lurking in Your Workspaces More than 30,000 publicly accessible Postman workspaces were disclosing sensitive information.
SR008 Cyber Security News Postman Data Leak - 30,000 Publicly Accessible Workspaces Could Lead Massive Hack Cyber Security News summarized the 30,000-workspace exposure problem.
SR009 Truffle Security (The) Postman Carries Lots of Secrets At least 4,000 live secrets are currently leaking on Postman.
SR010 AppSentinels Postman Workspace Exposure: 30k+ Public Workspaces Exposed Public Postman workspaces can be indexed like any other webpage.
SR011 InfoSec Write-ups Postman Secret Scanning: A Practical Guide to Finding Exposed APIs Practical guide to finding exposed APIs and secrets.
SR012 UpGuard Postman Security Rating, Vendor Risk Report, and Data Breaches Vendor risk tracking page for Postman.
SR013 Panorays Postman
SR014 GitHub GitHub - usebruno/bruno: Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) Bruno stores your collections directly in a folder on your filesystem.
SR015 Bruno Bruno - The Git-Native API Client No cloud sync. No account. No login.
SR016 Insomnia The Collaborative API Development Platform Store data locally, via Git, or in the cloud.
SR017 Visual Studio Marketplace Thunder Client - Visual Studio Marketplace Thunder Client is a lightweight REST API client extension with local storage and Git sync.
SR018 GitHub GitHub Copilot · Your AI pair programmer GitHub Copilot is an AI pair programmer integrated into the GitHub platform.
SR019 California Office of the Attorney General California Consumer Privacy Act (CCPA) The CCPA gives consumers more control over the personal information that businesses collect about them.
SR020 Data Privacy Framework Data Privacy Framework Official Data Privacy Framework site.
SR021 Postman Docs Explore public APIs on the Postman API Network | Postman Docs Explore public APIs on the Postman API Network.
SR022 Postman Postman | Postman API Network Postman operates a public API network / reference library.
SR023 G2 Postman Reviews & Product Details The biggest frustration has been the gradual move of features behind the paid plan.
SR024 TrustRadius Postman Reviews & Ratings 2026 Higher tiers support API management, collaboration, and test automation.
SR025 Software Advice Postman Software Reviews, Demo & Pricing Some users report that the platform can become slow with large requests and team workspaces.
SR026 Postman Coming to Postman in March: AI-native capabilities, a new API Catalog, and updated plans and pricing AI and native Git workflows are becoming core parts of the platform.
SR027 Postman The New Postman is Here: AI-Native and Built for the Agentic Era Internal, partner, and public workspace analytics now live in a single destination.
SR028 Postman Docs Integrate Postman into your development toolchain | Postman Docs The Postman API exposes Audit Logs, Secret Scanner, SCIM, and Private API Network endpoints.
SR029 Postman Agent Mode | Postman API Platform Agent Mode understands your collections, specs, environments, and history so every response is grounded in your actual APIs.
SR030 The Economic Times Postman sees 30-40% cut in valuation in secondary deal People aware of Postman’s financials said it is estimated to be clocking annualised recurring revenue (ARR) of $120-150 million.
SR031 Apidog Postman Pricing 2026: What They Changed & Why You Should Switch The Team plan at $19 per user monthly is now the cheapest option for collaboration.
SR032 Dev Tools Postman's 2026 Pricing Changes: What They Mean for Your API Testing Workflow Postman Free is now limited to 1 user.
SR033 Postman Privacy Center
SV001 Postman Press and Media | Postman Postman Announces Collaboration with Microsoft to Expand AI Model Choice, Accelerate Developer Workflows, and Unify API Governance (2026-04-16).
SV002 Postman Postman's Series D Funding and the API-First World We've closed a Series D investment round of $225 million that values the company at $5.6 billion.
SV003 TechCrunch API platform Postman valued at $5.6 billion in $225 million fundraise Postman said on Wednesday it has raised $225 million in a new financing round that values it at $5.6 billion, up from $2 billion a year ago.
SV004 The Economic Times Postman sees secondaries at steep discount Postman ... has struck secondary deals at a 30-40% discount recently ... secondary transactions are typically finalised at 10-15% discount to the last primary valuation.
SV005 Latka (GetLatka) Postman Revenue, Valuation & Funding History In 2024, Postman's revenue reached $313.1M... Postman reached a $3.6B valuation in 2021, set during its $225M Series D.
SV006 Craft.co Postman Company Profile Market Valuation $2B (2020-06-11); Total Funding $433M.
SV007 Forge Global Invest and Sell Postman Stock - Forge Forge Price $7.00 (7/20/2026); Forge Price valuation $2.22B; total funding $352M across 4 priced rounds.
SV008 Tracxn Postman Company Profile
SV009 Public.com Postman (PSTM) Private Company Stock Postman's estimated secondary market share price is $7.64 as of June 2026.
SV010 Premier Alternatives Postman Valuation Page title states 'Postman Valuation: $2.2B (2026)' while body text states 'Current Valuation $3.3B' and a 9.46x capital-efficiency ratio against $352.0M raised.
SV011 Yahoo Finance Postman (POSM.PVT) Private Company Quote Estimated Valuation $2.22B; Total Amount Raised $352M; Latest Amount Raised $145M; Total Funding Rounds 4.
SV012 Notice.co Postman Stock $8.07 | How to Buy, Valuation, Stock Price, IPO Page title metadata shows a $8.07 valuation figure; body content did not render (JavaScript-only page).
SV013 Inc42 Postman - Total Funding, Funding Over Time, Funding By Rounds and More Total funding: $433.00 Mn+; Revenue: Rs185.7 Cr+ (FY24) [Postdot Technologies Private Limited]; Employee count: 3,490.
SV014 UpMarket Postman Stock | Pre-IPO Private Markets Latest Price $5.6B (Series D, Aug 2021); UpMarket Estimate $4.8B, based on UpMarket valuation model.
SV015 ipos.fyi Postman IPO Tracker Fetch returned HTTP 429 (Vercel security checkpoint); no page content could be retrieved.
SV016 Kong Inc. Kong Secures $175 Million in New Financing Kong Inc. ... today announced it has closed a $175 million in up-round Series E financing ... at a $2 billion valuation ... This brings Kong's total capital raised to $345 million.
SV017 Balderton Capital Kong Secures $175M New Financing at $2Bn Valuation to Power the API World The round was co-led by Tiger Global and Balderton ... Balderton Partner Rana Yared joins the Kong board.
SV018 U.S. Securities and Exchange Commission EDGAR filer browse - CIK 1653482 (GitLab Inc.)
SV019 U.S. Securities and Exchange Commission EDGAR 10-K filings list - CIK 0001653482 (GitLab Inc.) Annual report [Section 13 and 15(d)] filed 2026-03-17, Acc-no 0001628280-26-018731.
SV020 GitLab Inc. GitLab Reports Fourth Quarter and Full Year Fiscal Year 2026 Financial Results Fiscal Year 2026 ... Total revenue of $955.2 million, up 26% year-over-year ... Fiscal year 2026 saw GitLab cross $1 billion in ARR.
SV021 CompaniesMarketCap.com GitLab Market Cap On Jul 19th, 2026 the market cap of GitLab was reported to be $5.52 Billion USD (-13.27% YoY).
SV022 Stock Analysis Atlassian (TEAM) Market Cap & Net Worth Atlassian has a market cap of $23.67 billion as of July 17, 2026 ... decreased by -52.65% in one year.
SV023 Francisco Partners SmartBear Announces Investment From Vista Equity Partners Francisco Partners ... will continue as an investor with Vista and Francisco Partners as equal owners of the company ... more than 15 million developers, testers and operations engineers at over 24,000 organizations.
SV024 Constellation Research IBM buys Confluent for $11 billion IBM said it will acquire data streaming company Confluent in a deal valued at $11 billion ... an annual revenue run rate topping $1 billion ... Big Blue's latest large deal being the $6.5 billion purchase of HashiCorp.
SV025 Multiples.vc Public software valuations in July 2026 Horizontal SaaS public comps in July 2026 show wide valuation dispersion ... Design and engineering software commands premium multiples, as companies like Autodesk and Adobe successfully integrate AI features.
SV026 Capstone Partners Middle Market M&A Poised to See Steady, Gradual Reopening in 2026 Private equity reemerged as a dominant force, ending a three-year lull with five consecutive quarters of platform acquisition growth.
SV027 EY M&A activity report Technology: M&A momentum remained strong, with deal value doubling YoY and volume rising 29%, reflecting sustained appetite for AI, software and digital infrastructure assets.
SV028 CompaniesMarketCap.com Datadog Revenue Revenue in 2026 (TTM): $3.67 Billion USD.
SV029 CompaniesMarketCap.com Datadog Market Cap On Jul 19th, 2026 the market cap of Datadog was reported to be $92.08 Billion USD (89.85% YoY).
SV030 PitchBook Top 10 startups now control record 51.8% of total unicorn value 2021-vintage unicorns trade at an average markdown near 68.2% to their last round, while 2022-vintage unicorns average a 52.1% markdown.
SV031 U.S. Securities and Exchange Commission EDGAR company search: 'postman' + Form S-1 EDGAR company-name search for 'postman' restricted to Form S-1 returned no matching filer/filing rows as of the access date.
SV032 Stock Analysis Atlassian (TEAM) Revenue Revenue (ttm) $6.19B, up 24.74% year-over-year; P/S Ratio 3.82.