---
title: Postman
canonical: https://saasranked.com/software/postman/
category: API Clients
points: 78
rank: 3 of 11
facts_checked: 2026-10-08
---

# Postman

API platform with a free plan, a desktop app, a web app and a command-line tool.

78 points out of 100. #3 of 11 API clients. Vendor: Postman, Inc.. Website: https://www.postman.com/

- The Free plan covers 1 user; Solo costs $9 a month, billed yearly [1].
- Team costs $19 per user a month, billed yearly; single sign-on needs the Team plan's Simple Security add-on at $6 per user a month [1][6].
- Built-in request types include GraphQL, gRPC and WebSocket [4].
- Postman names SOC 2 Type II and ISO 27001 certification [5].
- The app's source code is not public; the GitHub repository holds issues and release notes [11].

Verdict: Postman suits teams that want shared cloud workspaces, mock servers and published docs behind one login [1]. Solo at $9 a month and Free both include the CLI and mock servers [1]. The catch: the app is closed source, Server-Sent Events are not listed as a request type, and single sign-on is an extra purchase on Team [4][6][11]. Best for: Teams that want shared workspaces, mock servers and published docs in one place.

## Points

| Criterion | Line | Value | Points | Note |
|---|---|---|---|---|
| Systems | Other systems | macOS, Linux, Web app | 6/6 | Desktop app for Mac and Linux, plus Postman on the web [2]. |
| Systems | Command-line runner | Yes | 4/4 | Postman CLI is listed on all plans and installs with npm [1][2]. |
| Requests and protocols | Built-in protocols | GraphQL, gRPC, WebSocket | 9/12 | Docs list HTTP, GraphQL, gRPC, WebSocket and MQTT; Server-Sent Events are not named [4]. |
| Requests and protocols | Imports OpenAPI | Yes | 4/4 | Collections can be generated in one click from OpenAPI schemas [3]. |
| Requests and protocols | Scripts and tests | Yes | 8/8 | Scripts run before a request or after a response, with test scripts that validate the response [8]. |
| Requests and protocols | Collection runner | Yes | 3/3 | The Collection Runner chains requests together to test workflows [3]. |
| Requests and protocols | Mock servers | Yes | 3/3 | Mock servers are listed on all plans [1]. |
| Requests and protocols | Publishes API docs | Yes | 3/3 | Docs publishing is listed on all plans; free docs are Postman-branded [1]. |
| Your data | Works without an account | Not published | 0/8 | Not published on the vendor's installation page [7]: it says only that the lightweight client sends requests when signed out. |
| Your data | Collections as plain files | Yes | 8/8 | Native Git keeps collections as files in a project folder, on every plan; file format is not stated [1][9][10]. |
| Your data | Open-source apps | No | 0/6 | The public GitHub repository holds issues and release notes, not the app's source code [11]. |
| Teams and trust | Shared team workspaces | Yes | 7/7 | Team plan adds collaboration in shared workspaces [1]. |
| Teams and trust | SAML or OIDC single sign-on | Yes | 4/4 | SAML 2.0 single sign-on on Enterprise, or Team with the Simple Security add-on [6]. |
| Teams and trust | SOC 2 Type II or ISO 27001 | Yes | 5/5 | The trust page says SOC 2 Type II certified and ISO 27001 certified [5]. |
| Price | Free plan | Yes | 10/10 | Free plan for 1 user at $0 [1]. |
| Price | Cheapest paid plan | $9/mo | 4/9 | Solo, $9 a month billed annually [1]. |

## Plans

| Plan | Price | Per month (USD) |
|---|---|---|
| Free | Free [1] | $0 |
| Solo | $9/month [1] | $9 |
| Team | $19/user/month [1] | $19 |
| Enterprise | Contact sales [1] | - |

Prices are shown billed annually; the pricing page shows no monthly-billed price [1].

## Strengths

- Mock servers, the Postman CLI and Native Git are listed on every plan, including Free [1].
- Imports OpenAPI files into a collection in one click [3].
- Pre-request and post-response scripts with test checks are documented [8].
- Names SOC 2 Type II and ISO 27001 certification [5].
- Collections can live as files in a Git project folder through Native Git [9][10].

## Limits

- The app's source code is not public [11].
- Server-Sent Events are not named among the request types [4].
- Single sign-on needs the Simple Security add-on on Team, or an Enterprise plan [6].
- Free docs carry Postman branding and cannot use custom domains [1].

## Sources

1. [Postman pricing](https://www.postman.com/pricing/), Postman, accessed 2026-10-08
2. [Download Postman](https://www.postman.com/downloads/), Postman, accessed 2026-10-08
3. [Postman API client](https://www.postman.com/api-platform/api-client/), Postman, accessed 2026-10-08
4. [Request basics](https://learning.postman.com/docs/sending-requests/create-requests/request-basics/), Postman Docs, accessed 2026-10-08
5. [Postman trust and security](https://www.postman.com/trust/), Postman, accessed 2026-10-08
6. [Intro to SSO](https://learning.postman.com/docs/administration/sso/intro-sso/), Postman Docs, accessed 2026-10-08
7. [Installation and updates](https://learning.postman.com/docs/getting-started/installation/installation-and-updates/), Postman Docs, accessed 2026-10-08
8. [Scripts and tests](https://learning.postman.com/docs/tests-and-scripts/tests-and-scripts/), Postman Docs, accessed 2026-10-08
9. [Sync local and cloud elements](https://learning.postman.com/docs/use/native-git/sync/), Postman Docs, accessed 2026-10-08
10. [Native Git overview](https://learning.postman.com/docs/use/native-git/overview/), Postman Docs, accessed 2026-10-08
11. [postmanlabs/postman-app-support](https://github.com/postmanlabs/postman-app-support), GitHub, accessed 2026-10-08
