Glostarep

Postman and Wiz Just Closed a Major API Security Gap

Postman and Wiz Just Closed a Major API Security Gap

Quick Reads
  • Wiz’s runtime security is now embedded inside Postman’s API Catalog
  • The integration covers both deployed and undeployed APIs in one dashboard
  • It targets the API security gap that exists before APIs ship to production
  • The feature is available now for Postman Enterprise customers
  • Teams get a unified risk scorecard without switching tools

Postman and Wiz have joined forces to tackle a long-standing API security gap, and the result is already live. Wiz’s runtime security is now embedded directly in the Postman API Catalog, giving teams a unified view of API risk before it becomes a breach.

The partnership addresses something most organisations quietly overlook. Security tools like Wiz do a solid job of surfacing risk in what’s already deployed. However, APIs that are still in design or development, before they ever reach production, largely remain invisible to those same tools. That blind spot is exactly what this integration targets.

Until now, the handoff between security and engineering was clunky at best. A security engineer would pull risk signals from the Wiz dashboard, then manually track down the right developer across Slack threads, emails, and multiple tools. Context got lost. Fixes moved slowly. The API security gap widened with every handoff.

The new integration changes that workflow entirely. Instead of security signals sitting outside a developer’s workspace, risk now surfaces directly inside Postman, the tool developers already use every day. The Wiz dashboard is embedded natively inside the Postman platform through the Postman API Catalog, so there is no separate tab to remember or context to chase down.

What makes this integration particularly powerful is its full-spectrum coverage. Deployed APIs benefit from Wiz’s runtime risk analysis, including misconfigurations and cloud exposure. Undeployed APIs, meanwhile, get policy and design-time checks through Postman’s API Governance tools. Both categories of risk live in one actionable view.

Teams also gain a unified scorecard showing operational health alongside a complete inventory of every known service. That matters because, as the integration makes clear, you cannot enforce security policy on services you cannot see. Visibility has to come first, and it now lives where engineers already work.

The “shift left” principle has been a talking point in security circles for years. This integration, though, makes it practical. When a developer opens an API inside the Postman API Catalog, they see a risk scorecard right alongside everything else, not because they went searching for it, but because the signal came directly to them. That kind of frictionless experience is what actually changes developer behaviour.

As Postman puts it: “The new dashboard shows risks based on APIs that aren’t deployed yet, before they become a problem. That’s how we move from reactive to preventive.”

The Wiz API Catalog dashboard is available now for customers on Postman’s Enterprise plan. Teams can activate the integration through their API Catalog settings or by contacting their Postman account team. Postman has also signalled that deeper workflows and expanded coverage are on the way in the coming weeks.

For engineering and security teams still managing risk across disconnected tools, this integration is a direct answer to the API security gap, and it is already running.

Leave a Comment

Your email address will not be published. Required fields are marked *