Anime, manga, and games, with a take · A Yukimedia publication

← all stories otherannouncement 1 sources · 1h ago ·

Postman Gives Passport General Release For Secretless API Access

Postman is pushing beyond developer tooling into API security, betting that credentials kept inside the customer's own environment will win out over key distribution and gateway models as AI agents multiply the number of API calls.

Reporting from 1 source: ASCII.jp.

Postman Gives Passport General Release For Secretless API Access

Postman announced the general availability of Passport by Postman on September 15, 2026. The product lets developers and AI agents call authorized APIs through reference tokens instead of holding real credentials, which stay in the customer's own VPC or vault. Permissions can be scoped to exact actions, hosts, and paths, and access can be revoked in seconds. Postman says it is used by more than 40 million developers and over 500,000 organizations.

Passport replaces the credential with a reference token, an encrypted pointer tied to the requesting identity. The token does not work without the proxy, and the underlying API key stays in the customer's VPC or vault rather than on a developer's laptop.

Agents are handled as identities rather than exceptions. Each one gets a temporary, task-scoped identity issued from a persistent parent, and sub-agents inherit only a subset of the parent's permissions. Access grants can be narrowed to specific actions, hosts, and paths before a request reaches the vault.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources