# Postman Integration

The Postman integration lets you import Aikido API security findings into Postman.

You can review vulnerabilities next to the collection you are testing. This is useful when your team already works in Postman and wants scan results in the same place.

This integration works best when your API is already set up for scanning in Aikido. If you still need that, see [REST API & Web App Scanning](https://help.aikido.dev/dast-surface-monitoring/api-scanning/rest-api-scanning).

{% hint style="info" %}
Use a staging or test environment for active API scanning. Avoid running API fuzzing against production systems.
{% endhint %}

### Use Cases

* Review Aikido API findings without leaving Postman
* Triage issues while testing or updating a collection
* Share findings with API owners who work in Postman
* Check recent scan results before release

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FnLKLeYp4jRaulzqF0hAG%2Fimage.png?alt=media&#x26;token=25173cf7-4831-474c-8f39-7d65480eead1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FHO9SCMporwMWdjQ0eWhg%2Fimage.png?alt=media&#x26;token=5bbfdfae-bbc2-448a-8b75-2b15a3939439" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FZfRcT3RtHeoNnDIETblU%2Fimage.png?alt=media&#x26;token=72e58293-02cd-4d4d-ab40-107c38dcfaa9" alt=""><figcaption></figcaption></figure>

### Setup

{% stepper %}
{% step %}

#### Install the app in Postman

In Postman, go to **Settings** and open **Installed Apps**.

Add **Aikido** as an installed app.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FzBG6p7rbBsh3lBHpSFMN%2Fimage.png?alt=media&#x26;token=5307f503-0d87-407e-9999-b8b0600b7fcd" alt=""><figcaption></figcaption></figure>

Approve the install when Postman asks for permission.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FYnjn4T4UgIRZq8qcoDyy%2Fimage.png?alt=media&#x26;token=44cf9102-b1d0-4e33-b530-b7f75b86162c" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Generate an API key in Aikido

Open the [Postman integration settings](https://app.aikido.dev/settings/integrations/postman) in Aikido.

Generate an API key.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FLWCMpB9DCsgjuryM053W%2Fimage.png?alt=media&#x26;token=592a774d-0f17-4655-b7e6-40d3618e81dd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Paste the API key into Postman

Go back to Postman and paste the Aikido API key.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FRmxg8wspzyqN6E4GMbwQ%2Fimage.png?alt=media&#x26;token=2248b4eb-1d3b-4220-9a83-2fef86f883a0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Copy the Postman credentials into Aikido

Copy the **Client ID** and **Client Secret** from Postman.

Paste both values into the Aikido integration settings.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FiJTwjDx7ASRvX2j4e7Ej%2Fimage.png?alt=media&#x26;token=9445abc9-93a5-4e8d-8a4d-2954070b1dff" alt=""><figcaption></figcaption></figure>

Save the settings to finish the connection.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FqFP4MfVFahveq6k9FwjH%2Fimage.png?alt=media&#x26;token=2aa5833b-6361-4724-911e-2746699ca6d1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Import findings into a collection

Open a Postman collection.

Click the three-dot menu and select **Import Vulnerabilities**.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FfnBwdkxc1VrlhF5lpoIl%2Fimage.png?alt=media&#x26;token=d2969f9a-326b-4e07-b2cc-a5aafe613286" alt=""><figcaption></figcaption></figure>

The imported issues appear in the side panel.

<figure><img src="https://3149773201-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2FL7GNUc1uTRTj9as08kH9%2Fimage.png?alt=media&#x26;token=0aa35432-1959-46eb-80b7-62ad98de9abd" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

### Data handling

This integration exchanges vulnerability data only.

It does not transfer source code. It does not rely on stored exploitation data.
