Access Postman Vault
With Postman Vault, you can store secrets in several different vault types, including Postman Local Vault and Postman Shared Vault. When you first open your local vault, Postman generates a vault key for you to save in a secure location to unlock it later. Your vault key isn’t synced to the Postman cloud.
Postman Local Vault and Postman Shared Vault are supported on the Postman desktop and web apps. Both vault types are supported in Local View and Cloud View on the Postman desktop app.
Postman Local Vault
Your local vault is created by default and you can’t delete it. With your local vault, you can store vault secrets in your local instance of Postman. Only you can access vault secrets in your local vault, and they aren’t synced to the Postman cloud. Local vault is supported in all workspace types.
To access your local vault, do the following:
- Open a workspace.
- Click Vault in the footer, and select
Local Vault.
- Create a vault key, if you haven’t already.
Once you create your vault key, you’ll use it to unlock your local vault each time you sign in to Postman. Learn more about unlocking your local vault.
With your local vault, you can also link vault secrets with secrets stored in an external vault, like 1Password. Learn more about Postman Vault integrations.
Vault secrets aren’t preserved in your Postman Local Vault when you sign out of Postman, switch between the Postman desktop and web apps, or switch to a different machine. Your vault secrets can’t be recovered with your vault key.
To save your vault secrets for later, learn how to export and import vault secrets.
Create your vault key
Save or download your vault key to a secure location so you can unlock your Postman Vault later. Your vault key isn’t synced to the Postman cloud. You can store your vault key in your system’s password manager, such as Keychain Access on macOS, so Postman automatically enters your vault key when you sign in. You can reset your vault key if you lose it.
To save your vault key, do the following:
-
When you open your local vault for the first time, save or download your vault key to a secure location. You can do the following to save your vault key:
- Click
Copy Vault key to copy your vault key to your clipboard.
- Click
Download Vault key to download your vault key.
- Click
-
By default, Postman stores your vault key to your system’s password manager. If you don’t want to store your vault key in your system’s password manager, clear the checkbox next to Save this key to native password manager.
If you’re using the Postman web app, you must use the Postman Desktop Agent to save your vault key to your system’s password manager.
-
Click Open Vault.
You can copy and download your vault key again later. Click Settings in the upper right corner, then copy or download your vault key from the Settings tab.
Once your vault key is generated, you’ll use it to unlock your local vault when you sign in.
Reset your vault key
You can reset your vault key if you lose it. Vault secrets are deleted from your Postman Local Vault when you reset your vault key.
To reset your vault key, do the following:
- Sign out and sign back in to Postman.
- Open your local vault.
- Click Reset vault.
- Click Reset Vault to generate a new vault key.
- Save your vault key.
Unlock your local vault
Each time you sign in to Postman, you must enter your vault key to unlock your Postman Local Vault. You can enter your vault key in the following ways, depending on how you saved your vault key:
- If you stored your vault key in your system’s password manager, Postman automatically retrieves and enters your vault key when you sign in. Make sure to use the Postman Desktop Agent if you’re using the Postman web app.
- If you stored your vault key to your own secure location, you must manually enter your vault key and click Open Vault.
Postman recommends you use the latest version of the Postman Desktop Agent to receive recent changes and improvements to Postman Vault.
Postman Shared Vault
Postman Shared Vault is available on Postman Solo, Team, and Enterprise plans. To learn more about Postman plans, see Postman pricing.
Each internal workspace and Partner Workspace has one shared vault that your teammates can access. With a shared vault, your vault secrets are synced to the Postman cloud so you can share vault secrets across Postman apps and machines. This also enables you to use vault secrets in cloud-based Postman features such as monitors and flows.
Postman Shared Vault is turned on by default for your team’s workspaces, making it available in internal workspaces and Partner Workspaces. Shared vault isn’t available in public workspaces. Admins on Enterprise plans can manage which workspaces have a shared vault. Learn how to manage access to shared vault.
Postman generates and manages encryption keys for shared vaults. Vault secrets stored in a shared vault are end-to-end encrypted.
To access your workspace’s shared vault, do the following:
- Open a workspace.
- Click Vault in the footer, and select
Shared Vault.
Manage access to shared vault
As an Admin on an Enterprise plan, you can manage which workspaces have a shared vault. Shared vault is on by default. When shared vault is turned on for a workspace, all members of that workspace can access the shared vault.
If shared vault was previously turned off, you can turn it back on for all your internal workspaces and Partner Workspaces:
- Select Organization or Team > Organization or Team settings in the Postman header.
- Click Shared Vault in the sidebar.
- Click Turn on in the upper right corner.
This turns on shared vault across all your team’s workspaces. To turn it on or off for specific workspaces instead, use the per-workspace toggles described in the next steps.
To manage which workspaces have a shared vault, do the following:
-
Select Organization or Team > Organization or Team settings in the Postman header.
-
Click Shared Vault in the sidebar.
-
You can take the following actions to locate a workspace:
- Use the search bar to search for a workspace by name.
- Click the Type dropdown to filter workspaces by type.
- Click the Created by dropdown to filter workspaces by creator.
-
Click the toggle next to a workspace to turn its shared vault on or off.
-
To turn shared vault on or off for several workspaces at once, select the checkbox next to each workspace, or select the checkbox next to the Workspace column to select all workspaces. Then click Turn on or Turn off.
-
To turn shared vault on or off for your entire team at once, click Turn on or Turn off in the upper right corner.
For any workspace with an active Move to Shared Vault Local Secret Protection policy, you can’t turn off its shared vault for a single, several, or entire team’s workspaces. This is because that policy automatically moves detected secrets into the shared vault and needs it to remain available. To turn off shared vault for those workspaces, change the policy first. Learn more about Local Secret Protection policies.
The team-level and per-workspace controls work together:
- Turning off shared vault for your team turns it off in all workspaces, no matter their individual settings.
- Turning it back on returns each workspace to its own setting, so a workspace you turned off individually stays off until you turn it back on for that workspace.