Enforce API governance rules for your team in Postman

View as Markdown

Configurable API governance rules are available with Postman Enterprise plans. Learn more about Postman plans.

There’s a new API governance experience in Postman that includes a new look, feel, and functionality. For more information, see New API governance experience.

You can customize the API governance rules that Postman applies to your API specifications. Postman notifies team members if their API specifications violate the configured governance rules. This enables team members to keep APIs consistent and secure in your team.

API governance dashboard

Configure governance rules

You can configure API Governance rules that Postman applies to your API specifications in Spec Hub. You can use existing governance rules from the rule library or create custom governance rules. Then you can apply those rules to specific workspaces in your team.

You can also create custom governance functions and use them in your custom governance rules that Postman applies to your API specifications in Spec Hub.

Custom governance rule and function guidelines

Postman supports Spectral for custom governance rules and functions. For more information about using Spectral in Postman, see the following:

New API governance experience

Postman offers a new API governance experience that includes a new look, feel, and functionality. The new experience provides a more streamlined way to manage your team’s API governance rules and functions. With the new experience, you can:

  • Create rulesets and functions in a single workbench instead of managing them across interfaces.
  • Use a ruleset-based authoring experience instead of managing individual rules.
  • Catch schema errors, broken references, and invalid configurations while editing with live validation.
  • View rulesets in a rendered documentation view instead of reading raw YAML.
  • Assign rulesets across multiple workspaces from a single workbench instead of managing them in each workspace.
  • Manage permissions for rulesets and functions with more granularity.

API Catalog Managers and API Governance Managers can migrate their team’s existing rulesets and functions to the new experience to access the configurable API Governance rulesets. When you migrate to the new experience, existing functions are preserved, and rules are bundled into rulesets. Click Move to New Experience in the banner to migrate your team’s existing rulesets and functions to the new experience.

For information about the new API governance experience, see Define and enforce API standards with governance groups in Postman.