For AI agents: a documentation index is available at the root level at /llms.txt and /llms-full.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
Postman
PricingEnterprise
Contact SalesSign InSign Up for Free
HomeDocs
HomeDocs
      • Overview
      • Onboarding checklist
      • Roles and permissions
      • System service accounts
      • Free and Solo experience
      • Team migration
        • Overview
        • Create an organization
        • Create teams
        • Manage user groups
        • Manage resources
        • Manage product access
        • Configure team settings
        • Manage API keys
          • Overview
          • How the Secret Scanner works
          • The Secret Scanner dashboard
          • Secret Scanner patterns
        • BYOK Encryption
        • Audit logs
      • Admin FAQs
Postman API Platform

Product

  • Postman Overview
  • Enterprise
  • Spec Hub
  • Flows
  • Agent Mode
  • API Catalog
  • Fern
  • Postman CLI
  • Integrations
  • Workspaces
  • Plans and pricing

API Network

  • App Security
  • Artificial Intelligence
  • Communication
  • Data Analytics
  • Database
  • Developer Productivity
  • DevOps
  • Ecommerce
  • eSignature
  • Financial Services
  • Payments
  • Travel

Resources

  • Postman Docs
  • Academy
  • Community
  • Templates
  • Intergalactic
  • Videos
  • MCP Servers

Legal and Security

  • Legal Terms Hub
  • Terms of Service
  • Postman Product Terms
  • Security
  • Website Terms of Use

Company

  • About
  • Careers and culture
  • Contact us
  • Partner program
  • Customer stories
  • Student programs
  • Press and media
Twitter iconLinkedIn iconGithub iconYouTube iconInstagram iconDiscord icon
Download Postman
Privacy Policy

© 2026 Postman, Inc.

On this page
  • Benefits of Postman Secret Scanner
  • Manage your secrets with the Secret Scanner dashboard
  • Manage Secret Scanner findings with the Postman API
Administer PostmanTeam managementSecret Scanner

Postman Secret Scanner

||View as Markdown|
Was this page helpful?
Previous

Manage API keys

Next

How the Secret Scanner works

Built with

The Postman Secret Scanner scans public workspaces and published documentation to detect exposed secrets on all Postman plans. It monitors the collections, global variables, environment variables, and documentation in public workspaces. Secret Scanner helps safeguard your organization from potential threats and malicious users attempting to access any exposed secrets. It also scans the documentation your team has published, regardless of the type of workspace it’s found in.

You can also set up Postman’s integration for Slack to alert you in Slack if the Secret Scanner detects exposed secrets in your workspaces.

Benefits of Postman Secret Scanner

Secret Scanner helps protect your team’s sensitive information from accidental exposure, no matter which Postman plan you’re on. By scanning your team’s resources, it ensures that your data stays secure.

For Enterprise plans with the Advanced Security Administration add-on, Secret Scanner also delivers results for public workspace, internal workspace, and Partner Workspace scans in Secret Scanner dashboard. It also includes access to reporting and analytics on exposed secrets in Team and Public workspaces.

To learn more, see How the Postman Secret Scanner works.

Manage your secrets with the Secret Scanner dashboard

The Secret Scanner dashboard enables Admins and Super Admins review and manage your team’s detected secrets and view reports. It also lets your team customize and manage secret patterns that best fit your team’s specific needs.

To learn more, see The Secret Scanner dashboard. For information about Secret Scanner patterns, see Secret Scanner patterns.

Manage Secret Scanner findings with the Postman API

The Secret Scanner Postman API endpoints are available with the Postman Enterprise plan with the Advanced Security Administration add-on.

Admins, Super Admins, and Workspace Admins can access Secret Scanner findings through the Postman API. Using the Postman API enables you to create custom automated workflows to retrieve and resolve identified secrets. To learn more, see the Postman API documentation.