Documentation
Learn the protocols, not just the product.
Practical guides on authentication, REST, GraphQL, WebSocket, gRPC, and the workflow features (variables, scripting, assertions) that tie a request chain together.
Authentication
API Authentication Methods: A Practical Overview A comparison of the common ways APIs authenticate requests — API keys, bearer tokens, and OAuth 2.0 — and how to pick the right one. What Is a Bearer Token? A Practical Guide to Bearer Authentication How bearer tokens work, the Authorization: Bearer header format, how they differ from API keys and Basic auth, and common mistakes to avoid. What Is an API Key? How API Key Authentication Works How API keys work, where they go in a request (header vs. query parameter), how they differ from bearer tokens, and how to keep them from leaking. What Is OAuth 2.0? A Practical Guide to the Authorization Framework How OAuth 2.0 works — the actors involved, the common grant types, access vs. refresh tokens, and how it relates to bearer tokens and API keys.
Protocols
What Is a REST API? Principles, Methods, and Conventions REST explained in practical terms — resources, HTTP methods, status codes, statelessness, and the conventions most real-world "RESTful" APIs actually follow. What Is GraphQL? A Practical Introduction How GraphQL works — a single endpoint, a typed schema, queries and mutations, and how it compares to REST for over-fetching and under-fetching. What Is a WebSocket? A Practical Guide How WebSocket connections work — the handshake, sending and receiving frames on one open connection, and when to reach for it instead of REST polling. What Is gRPC? A Practical Introduction How gRPC works — Protocol Buffers, the four call types, server reflection, and when it makes more sense than REST or GraphQL.
Workflow features
API Client Variables: Scopes, Precedence, and Secrets Explained How variables work in an API client — the {{variable}} syntax, environment vs. collection scope, precedence rules, and keeping secrets out of plain text. Request Scripting: Pre-Request and Post-Response Scripts Explained How scripting works in an API client — pre-request scripts that modify outgoing requests, post-response scripts for assertions, and what a sandboxed JS runtime can and cannot do. Writing API Assertions: Testing Responses with pm.test and pm.expect How to write assertions in a post-response script — pm.test, pm.expect matchers, response shortcuts, and how test results get reported. Pre-Request and Post-Response Workflows: Chaining Requests Together How to use pre-request and post-response scripts together to chain requests, refresh auth dynamically, and pass data from one response into the next request.