skip to content

Postman

Collections of saved HTTP requests, with variable stores, pre-request and test scripts, auth helpers and mock servers. Interviewers ask because sharing one is how a team stops trading curl commands.

part ofAPI & DB clientsoverview, primer and where to startread it →
on this pageshow

explore

questions

144 · 9 sections

In a saved Postman collection file, what does a request's body.mode field select, and where does the payload sit?

level: juniorimportance: must knowfreq 62%
basics
~10 s

body.mode names one of raw, urlencoded, formdata, file or graphql, and the payload sits under a key spelled the same as the mode. Only that one key is read.

open as a page

In a saved Postman collection file, what makes an entry in `item` a folder rather than a request?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A Postman collection entry is a folder when it carries its own item list instead of a request. One array holds both kinds, so folders nest inside folders with no separate structure.

open as a page

In a saved Postman collection, what two shapes can a request's url take, and why does the choice matter?

level: juniorimportance: must knowfreq 65%
basics
~20 s

A collection stores a request's url either as one flat string or as an object of raw, protocol, host, path, port, query, hash and variable. Only the object form lets a tool address and edit a single part.

open as a page

In a Postman collection, what does body.options.raw.language do, and when does it not change the Content-Type sent?

level: middleimportance: must knowfreq 48%
basics
~10 s

body.options.raw.language labels what a raw payload is written in. From that label the runtime derives a Content-Type header marked system true, but only when the request declares no Content-Type of its own.

open as a page

Why can a saved example's `originalRequest` disagree with the Postman item's own `request`?

level: middleimportance: must knowfreq 55%
basics
~20 s

A saved example's originalRequest is a whole embedded request definition, not a pointer back at the item. Editing the item's own request never touches that copy, so the example keeps documenting a call the request no longer makes.

open as a page

In an exported Postman collection file, where do collection variables live and how do scripts read them?

level: juniorimportance: must knowfreq 72%
basics
~10 s

Collection variables live in the collection document's own variable array, a field of the file itself, so they travel with every export and every commit. Scripts read them through the sandbox object pm.collectionVariables.

open as a page

In a Postman request, what does a dollar-prefixed placeholder like {{$guid}} or {{$timestamp}} produce on each send?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Postman's dollar-prefixed placeholders are generators supplied by the collection SDK: {{$guid}}, {{$timestamp}}, {{$isoTimestamp}} and {{$randomInt}} manufacture a value while the request is assembled. Nothing is read from a saved store and nothing is kept afterwards.

open as a page

In Postman, what does an environment file contain, and how does a run read those values?

level: juniorimportance: must knowfreq 76%
basics
~20 s

A Postman environment file is a separate JSON document holding an id, a name and a values array of key, value, type and disabled entries. A run is pointed at one file and loads it as a variable scope.

open as a page

When several Postman stores define the same variable name, which value does pm.variables.get return?

level: juniorimportance: must knowfreq 68%
basics
~10 s

pm.variables walks a fixed chain and returns the first non-disabled match: its own local values, then iteration data, then the environment, then collection variables, then globals. An environment value therefore beats a collection variable.

open as a page

A Postman request goes out with the literal text {{baseUrl}} still in its URL — what happened?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Nothing supplied a usable value for that name. The substitutor replaces a double-brace match only when the lookup yields a string, number or boolean; otherwise it returns the matched text unchanged, so the token itself is sent.

open as a page

In a Postman collection, which requests does a script attached to a folder run for?

level: juniorimportance: must knowfreq 72%
basics
~10 s

A script attached to a Postman folder runs for every request nested beneath it, at any depth, including requests inside sub-folders. It never reaches requests outside that folder.

open as a page

When a Postman sandbox script calls console.log, where does that output actually go?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Nowhere on its own. The sandbox's console dispatches an execution.console event carrying the cursor, the level and the serialised arguments out to whatever host runs the script, and the host decides whether to display it.

open as a page

In a Postman run, in what order do collection, folder, and request scripts execute for one request?

level: middleimportance: must knowfreq 66%
basics
~10 s

Ancestors first: the collection's script, then each folder's from outermost inward, then the request's own. The Postman SDK's EventList.listeners orders inherited listeners ahead of the item's own, and all of them run.

open as a page

Which parts of an outgoing Postman request can a pre-request script change so the edit actually reaches the wire?

level: middleimportance: must knowfreq 56%
basics
~10 s

Five and only five: url, method, headers, body and auth. Those are the mutations the runtime reads back out of a pre-request script; anything else the script assigns is not carried into the send.

open as a page

In a saved Postman collection, which values can an event's `listen` field take, and when does each script run?

level: middleimportance: must knowfreq 62%
basics
~10 s

Exactly two: prerequest, which runs just before the request is handed to the transport, and test, which runs after the reply arrives. No third, post-send listener name exists in the format.

open as a page

In a Postman test script, what does `pm.response.to.have.status(200)` assert, and what else can `status` take?

level: juniorimportance: must knowfreq 82%
basics
~20 s

Postman's status matcher is polymorphic: hand it a number and it compares the reply's status code, hand it a string and it compares the reply's reason phrase instead. statusCode and statusReason are the single-purpose spellings.

open as a page

In a Postman test script, how do the `body` and `jsonBody` matchers differ in what they read from the reply?

level: middleimportance: must knowfreq 60%
basics
~20 s

Postman's body matcher reads the reply as raw text and takes a string or a regular expression; jsonBody parses the reply first and then takes a path, an expected value, or an object. Both hang off pm.response.to.have.

open as a page

In a Postman test script, what does pm.response.to.have.jsonSchema(schema) assert, and what parses the body?

level: middleimportance: must knowfreq 58%
basics
~10 s

Postman's jsonSchema assertion validates a value against a JSON Schema object using Ajv. Chained off pm.response it parses the reply body first; chained off pm.expect it validates whatever value you handed in.

open as a page

In a Postman script, how many results does one pm.test block containing five pm.expect calls report?

level: middleimportance: must knowfreq 76%
basics
~20 s

Exactly one. A pm.test block is the reporting unit: it emits a single record carrying a name, a passed flag, a skipped flag, an error slot and an index, however many pm.expect calls sit inside it.

open as a page

In a Postman test script, how does a throw inside a pm.test block differ from a throw outside one?

level: middleimportance: must knowfreq 68%
basics
~20 s

Containment. A throw inside pm.test is caught by that block: the block is recorded as failed and the script keeps going. A throw outside any block escapes, ends the script execution and surfaces as an execution error, not an assertion.

open as a page

In a Postman collection, how does a test script hand an id from one response to the next request?

level: juniorimportance: must knowfreq 76%
basics
~10 s

Read the value out of the reply in a test script, then write it into a tracked store with pm.environment.set, pm.collectionVariables.set or pm.globals.set. The next request refers to that same name.

open as a page

In a Postman collection run, why can the next request not read a value written with `pm.variables.set`?

level: middleimportance: must knowfreq 60%
basics
~20 s

Postman's runtime carries only three scopes back from a script - globals, environment and collectionVariables, the list its item command declares as trackContext. pm.variables.set writes a fourth, execution-local layer that is thrown away when the script ends.

open as a page

In a Postman script, what does pm.execution.setNextRequest(name) do to a run, and when does it take effect?

level: middleimportance: must knowfreq 62%
basics
~10 s

pm.execution.setNextRequest records a target for the run's cursor rather than jumping. The current item finishes normally, then the runtime seeks to the named request. The last call made during that item wins.

open as a page

How does a Postman run resolve the name given to pm.execution.setNextRequest, and what happens when nothing matches?

level: middleimportance: must knowfreq 54%
basics
~20 s

The runtime matches the value against the run's items, ids before names. A value matching neither — a typo — or an explicit null sets the position to the iteration end, so the run stops silently.

open as a page

What does a call sent by pm.sendRequest in a Postman script not get that a stored collection request gets?

level: middleimportance: must knowfreq 62%
basics
~20 s

It gets no events and no place in the run. Because a script builds it rather than the collection holding it, no item exists, so no pre-request or test script fires for it and the sequence of requests is unchanged.

open as a page

When a saved Postman collection is run from a terminal instead of the app, what must be supplied explicitly?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A terminal run gets only the collection file plus what the command line hands it. The app's selected environment, its accumulated cookies and its transport settings are app-side state; anything the requests depend on must be passed explicitly.

open as a page

In a Newman command line, what does the `-d` data file do to a collection run, and how does a script read the current row?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Newman's -d flag takes a data file and runs the whole collection once per row. Each row becomes that iteration's pm.iterationData scope, so a script reads its columns with pm.iterationData.get('column').

open as a page

In a Newman command line, what does the `--folder` option select from a collection?

level: juniorimportance: must knowfreq 70%
basics
~10 s

In Newman, --folder narrows a run to one part of the collection: it takes the name or id of a folder or of a single request, and only that subtree executes.

open as a page

In a Newman run, what happens when `-n` asks for more iterations than the `-d` data file has rows?

level: middleimportance: must knowfreq 52%
basics
~10 s

Newman neither wraps nor fails: iterations past the data file's last row repeat that last row. A count smaller than the row count simply runs the leading rows and never reaches the rest.

open as a page

Two folders in a Postman collection share a name — which one does Newman's `--folder` run?

level: middleimportance: must knowfreq 55%
basics
~10 s

The first match wins and only it runs. Newman's --folder lookup compares ids and names and takes own children before deeper ones, so a top-level folder beats a same-named folder nested further down.

open as a page

In a saved Postman collection, where may an `auth` block be declared, and which declaration signs a request?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The collection format allows an auth block in three places: the collection document itself, a folder, and a single request. Resolution is nearest-wins, so a request's own block beats a folder's, and a folder's beats the collection's.

open as a page

In a saved Postman collection, how does the `auth` object name a scheme and where do its settings live?

level: juniorimportance: must knowfreq 68%
basics
~10 s

The auth object's required type field names the scheme, and that scheme's settings sit in a sibling array with the same name, holding auth attributes. Only key is required on each attribute.

open as a page

How does the Postman SDK's `Item.getAuth()` choose a credential block when several ancestors declare one?

level: middleimportance: must knowfreq 52%
basics
~20 s

Item.getAuth() extracts the request's own auth first, then calls findInParents to walk the parent chain outward. It returns the first ancestor declaring a block whose type is a usable name, and undefined if none does.

open as a page

In a Postman collection, how does a token a pre-request script just fetched reach the oauth2 accessToken attribute?

level: middleimportance: must knowfreq 62%
basics
~20 s

A pre-request script stores the fetched token in a variable scope; the collection's oauth2 accessToken attribute holds a brace token naming it. The runtime resolves auth variables before the handler signs, so signing sees the real value.

open as a page

What happens when a Postman collection's `auth.type` names a scheme no signing handler is registered for?

level: seniorimportance: must knowfreq 52%
basics
~20 s

The request goes out unsigned. The SDK stores almost any scheme name, the runtime's handler lookup misses, a console warning naming the type is triggered, and the run continues as if no credential had been configured.

open as a page

In a Postman or Newman run, what does the cookie jar hold and how does a script reach it?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A run keeps one cookie jar: the store every request in that run reads from and every response writes into. Scripts open it with pm.cookies.jar(), while pm.cookies lists what the jar holds for the current request's URL.

open as a page

Why is a configured Postman client certificate never presented when the request URL uses http rather than https?

level: middleimportance: must knowfreq 55%
basics
~10 s

Postman's Certificate.canApplyTo rejects any non-https URL before it ever tests the entry's match patterns, so a plain http call is short-circuited out of certificate selection no matter how well the patterns fit.

open as a page

A Postman collection sets followRedirects false and a request inside sets it true; which value does the run use?

level: middleimportance: must knowfreq 42%
basics
~10 s

The request's value wins. Postman's SDK resolves an item's protocolProfileBehavior by walking every ancestor including the collection root and merging their blocks member by member, so the declaration nearest the request decides each member.

open as a page

In Postman's SDK, why can a request whose URL matches a proxy entry's match pattern still be sent directly?

level: middleimportance: must knowfreq 44%
basics
~10 s

ProxyConfig.test checks the bypass list before the match pattern, so any bypass hit ends the evaluation and the request goes direct no matter what match says. Bypass is a veto, not a tie-breaker.

open as a page

A Postman request that should present a client certificate sends none, so how do you diagnose it?

level: seniorimportance: must knowfreq 42%
basics
~20 s

Check three things in order: the URL's scheme, since a non-https URL is rejected first; the list order, since the first matching entry wins; and the key and certificate paths, since a failed file read only warns.

open as a page

In Postman, where does a mock server get the replies it serves, and who can change them?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A Postman mock server replies with the examples already saved beside the requests in the collection it was created from. Those examples live in a Postman account, and anyone allowed to edit that collection can edit them.

open as a page

In Postman, where does a collection in a shared team workspace live, and who can change it?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A collection in a shared Postman workspace lives in the vendor's hosted account, not in your repository. Anyone the workspace admits can edit it, and the edit takes effect immediately, with no commit and no review.

open as a page

What does a Postman mock server fuse when one collection is definition, documentation and stand-in at once?

level: middleimportance: must knowfreq 55%
basics
~20 s

A Postman mock server fuses the documented reply and the served reply into one saved example, so a single edit by anyone with collection edit rights moves documentation and stand-in together, with no diff or review on the consumer's side.

open as a page

When a Postman collection running on a hosted schedule fails, who finds out first, and what does that notice lack?

level: middleimportance: must knowfreq 55%
basics
~20 s

Whoever holds the vendor account finds out first, not whoever caused the failure. The notice carries a time and a failed request but no commit, no author and no build, so attribution has to be reconstructed by hand.

open as a page

In Postman, what does forking a shared collection give you that duplicating it does not?

level: middleimportance: must knowfreq 54%
basics
~20 s

A Postman fork keeps a recorded link back to the collection it came from, so later work can be offered back and merged through a review held in the vendor's account. A duplicate is an orphan.

open as a page