Postman
Collections of saved HTTP requests, with variable stores, pre-request and test scripts, auth helpers and mock servers. Interviewers ask because sharing one is how a team stops trading curl commands.
part ofAPI & DB clientsoverview, primer and where to startread it →on this pageshowhide
explore
- Collection Document23 questions
- Stored Request11 questions
- File-Level Shape12 questions
- Variable Stores23 questions
- Scope Layers12 questions
- Value Provenance11 questions
- Sandbox Scripts16 questions
- Pre and Post Send4 questions
- Cascading from Parents4 questions
- Deprecated Globals4 questions
- Logging from Code4 questions
- Verifying a Reply14 questions
- Named Test Blocks5 questions
- Chained Matchers5 questions
- Validating Payload Shape4 questions
- Cross-Request Flow12 questions
- Passing Values Forward4 questions
- Redirecting the Sequence4 questions
- Firing Extra Calls4 questions
- Batch Execution13 questions
- Rows as Iterations4 questions
- Folder and Item Selection5 questions
- Terminal-Driven Runs4 questions
- Auth Helpers12 questions
- Inherited Credentials4 questions
- Built-In Scheme Types4 questions
- Fetching a Token First4 questions
- Transport Settings18 questions
- Certificate Attachment4 questions
- Proxy and Bypass5 questions
- Cookie Jar5 questions
- Per-Request Behaviour4 questions
- The Vendor's Side13 questions
- Mock Servers from Examples4 questions
- Scheduled Collection Runs5 questions
- Team Copies and Forks4 questions
questions
144 · 9 sectionsIn a saved Postman collection file, what does a request's body.mode field select, and where does the payload sit?
basics
~10 sbody.mode names one of raw, urlencoded, formdata, file or graphql, and the payload sits under a key spelled the same as the mode. Only that one key is read.
In a saved Postman collection file, what makes an entry in `item` a folder rather than a request?
basics
~10 sA Postman collection entry is a folder when it carries its own item list instead of a request. One array holds both kinds, so folders nest inside folders with no separate structure.
In a saved Postman collection, what two shapes can a request's url take, and why does the choice matter?
basics
~20 sA collection stores a request's url either as one flat string or as an object of raw, protocol, host, path, port, query, hash and variable. Only the object form lets a tool address and edit a single part.
In a Postman collection, what does body.options.raw.language do, and when does it not change the Content-Type sent?
basics
~10 sbody.options.raw.language labels what a raw payload is written in. From that label the runtime derives a Content-Type header marked system true, but only when the request declares no Content-Type of its own.
Why can a saved example's `originalRequest` disagree with the Postman item's own `request`?
basics
~20 sA saved example's originalRequest is a whole embedded request definition, not a pointer back at the item. Editing the item's own request never touches that copy, so the example keeps documenting a call the request no longer makes.
In an exported Postman collection file, where do collection variables live and how do scripts read them?
basics
~10 sCollection variables live in the collection document's own variable array, a field of the file itself, so they travel with every export and every commit. Scripts read them through the sandbox object pm.collectionVariables.
In a Postman request, what does a dollar-prefixed placeholder like {{$guid}} or {{$timestamp}} produce on each send?
basics
~20 sPostman's dollar-prefixed placeholders are generators supplied by the collection SDK: {{$guid}}, {{$timestamp}}, {{$isoTimestamp}} and {{$randomInt}} manufacture a value while the request is assembled. Nothing is read from a saved store and nothing is kept afterwards.
In Postman, what does an environment file contain, and how does a run read those values?
basics
~20 sA Postman environment file is a separate JSON document holding an id, a name and a values array of key, value, type and disabled entries. A run is pointed at one file and loads it as a variable scope.
When several Postman stores define the same variable name, which value does pm.variables.get return?
basics
~10 spm.variables walks a fixed chain and returns the first non-disabled match: its own local values, then iteration data, then the environment, then collection variables, then globals. An environment value therefore beats a collection variable.
A Postman request goes out with the literal text {{baseUrl}} still in its URL — what happened?
basics
~20 sNothing supplied a usable value for that name. The substitutor replaces a double-brace match only when the lookup yields a string, number or boolean; otherwise it returns the matched text unchanged, so the token itself is sent.
In a Postman collection, which requests does a script attached to a folder run for?
basics
~10 sA script attached to a Postman folder runs for every request nested beneath it, at any depth, including requests inside sub-folders. It never reaches requests outside that folder.
When a Postman sandbox script calls console.log, where does that output actually go?
basics
~20 sNowhere on its own. The sandbox's console dispatches an execution.console event carrying the cursor, the level and the serialised arguments out to whatever host runs the script, and the host decides whether to display it.
In a Postman run, in what order do collection, folder, and request scripts execute for one request?
basics
~10 sAncestors first: the collection's script, then each folder's from outermost inward, then the request's own. The Postman SDK's EventList.listeners orders inherited listeners ahead of the item's own, and all of them run.
Which parts of an outgoing Postman request can a pre-request script change so the edit actually reaches the wire?
basics
~10 sFive and only five: url, method, headers, body and auth. Those are the mutations the runtime reads back out of a pre-request script; anything else the script assigns is not carried into the send.
In a saved Postman collection, which values can an event's `listen` field take, and when does each script run?
basics
~10 sExactly two: prerequest, which runs just before the request is handed to the transport, and test, which runs after the reply arrives. No third, post-send listener name exists in the format.
In a Postman test script, what does `pm.response.to.have.status(200)` assert, and what else can `status` take?
basics
~20 sPostman's status matcher is polymorphic: hand it a number and it compares the reply's status code, hand it a string and it compares the reply's reason phrase instead. statusCode and statusReason are the single-purpose spellings.
In a Postman test script, how do the `body` and `jsonBody` matchers differ in what they read from the reply?
basics
~20 sPostman's body matcher reads the reply as raw text and takes a string or a regular expression; jsonBody parses the reply first and then takes a path, an expected value, or an object. Both hang off pm.response.to.have.
In a Postman test script, what does pm.response.to.have.jsonSchema(schema) assert, and what parses the body?
basics
~10 sPostman's jsonSchema assertion validates a value against a JSON Schema object using Ajv. Chained off pm.response it parses the reply body first; chained off pm.expect it validates whatever value you handed in.
In a Postman script, how many results does one pm.test block containing five pm.expect calls report?
basics
~20 sExactly one. A pm.test block is the reporting unit: it emits a single record carrying a name, a passed flag, a skipped flag, an error slot and an index, however many pm.expect calls sit inside it.
In a Postman test script, how does a throw inside a pm.test block differ from a throw outside one?
basics
~20 sContainment. A throw inside pm.test is caught by that block: the block is recorded as failed and the script keeps going. A throw outside any block escapes, ends the script execution and surfaces as an execution error, not an assertion.
In a Postman collection, how does a test script hand an id from one response to the next request?
basics
~10 sRead the value out of the reply in a test script, then write it into a tracked store with pm.environment.set, pm.collectionVariables.set or pm.globals.set. The next request refers to that same name.
In a Postman collection run, why can the next request not read a value written with `pm.variables.set`?
basics
~20 sPostman's runtime carries only three scopes back from a script - globals, environment and collectionVariables, the list its item command declares as trackContext. pm.variables.set writes a fourth, execution-local layer that is thrown away when the script ends.
In a Postman script, what does pm.execution.setNextRequest(name) do to a run, and when does it take effect?
basics
~10 spm.execution.setNextRequest records a target for the run's cursor rather than jumping. The current item finishes normally, then the runtime seeks to the named request. The last call made during that item wins.
How does a Postman run resolve the name given to pm.execution.setNextRequest, and what happens when nothing matches?
basics
~20 sThe runtime matches the value against the run's items, ids before names. A value matching neither — a typo — or an explicit null sets the position to the iteration end, so the run stops silently.
What does a call sent by pm.sendRequest in a Postman script not get that a stored collection request gets?
basics
~20 sIt gets no events and no place in the run. Because a script builds it rather than the collection holding it, no item exists, so no pre-request or test script fires for it and the sequence of requests is unchanged.
When a saved Postman collection is run from a terminal instead of the app, what must be supplied explicitly?
basics
~20 sA terminal run gets only the collection file plus what the command line hands it. The app's selected environment, its accumulated cookies and its transport settings are app-side state; anything the requests depend on must be passed explicitly.
In a Newman command line, what does the `-d` data file do to a collection run, and how does a script read the current row?
basics
~10 sNewman's -d flag takes a data file and runs the whole collection once per row. Each row becomes that iteration's pm.iterationData scope, so a script reads its columns with pm.iterationData.get('column').
In a Newman command line, what does the `--folder` option select from a collection?
basics
~10 sIn Newman, --folder narrows a run to one part of the collection: it takes the name or id of a folder or of a single request, and only that subtree executes.
In a Newman run, what happens when `-n` asks for more iterations than the `-d` data file has rows?
basics
~10 sNewman neither wraps nor fails: iterations past the data file's last row repeat that last row. A count smaller than the row count simply runs the leading rows and never reaches the rest.
Two folders in a Postman collection share a name — which one does Newman's `--folder` run?
basics
~10 sThe first match wins and only it runs. Newman's --folder lookup compares ids and names and takes own children before deeper ones, so a top-level folder beats a same-named folder nested further down.
In a saved Postman collection, where may an `auth` block be declared, and which declaration signs a request?
basics
~20 sThe collection format allows an auth block in three places: the collection document itself, a folder, and a single request. Resolution is nearest-wins, so a request's own block beats a folder's, and a folder's beats the collection's.
In a saved Postman collection, how does the `auth` object name a scheme and where do its settings live?
basics
~10 sThe auth object's required type field names the scheme, and that scheme's settings sit in a sibling array with the same name, holding auth attributes. Only key is required on each attribute.
How does the Postman SDK's `Item.getAuth()` choose a credential block when several ancestors declare one?
basics
~20 sItem.getAuth() extracts the request's own auth first, then calls findInParents to walk the parent chain outward. It returns the first ancestor declaring a block whose type is a usable name, and undefined if none does.
In a Postman collection, how does a token a pre-request script just fetched reach the oauth2 accessToken attribute?
basics
~20 sA pre-request script stores the fetched token in a variable scope; the collection's oauth2 accessToken attribute holds a brace token naming it. The runtime resolves auth variables before the handler signs, so signing sees the real value.
What happens when a Postman collection's `auth.type` names a scheme no signing handler is registered for?
basics
~20 sThe request goes out unsigned. The SDK stores almost any scheme name, the runtime's handler lookup misses, a console warning naming the type is triggered, and the run continues as if no credential had been configured.
In a Postman or Newman run, what does the cookie jar hold and how does a script reach it?
basics
~20 sA run keeps one cookie jar: the store every request in that run reads from and every response writes into. Scripts open it with pm.cookies.jar(), while pm.cookies lists what the jar holds for the current request's URL.
Why is a configured Postman client certificate never presented when the request URL uses http rather than https?
basics
~10 sPostman's Certificate.canApplyTo rejects any non-https URL before it ever tests the entry's match patterns, so a plain http call is short-circuited out of certificate selection no matter how well the patterns fit.
A Postman collection sets followRedirects false and a request inside sets it true; which value does the run use?
basics
~10 sThe request's value wins. Postman's SDK resolves an item's protocolProfileBehavior by walking every ancestor including the collection root and merging their blocks member by member, so the declaration nearest the request decides each member.
In Postman's SDK, why can a request whose URL matches a proxy entry's match pattern still be sent directly?
basics
~10 sProxyConfig.test checks the bypass list before the match pattern, so any bypass hit ends the evaluation and the request goes direct no matter what match says. Bypass is a veto, not a tie-breaker.
A Postman request that should present a client certificate sends none, so how do you diagnose it?
basics
~20 sCheck three things in order: the URL's scheme, since a non-https URL is rejected first; the list order, since the first matching entry wins; and the key and certificate paths, since a failed file read only warns.
In Postman, where does a mock server get the replies it serves, and who can change them?
basics
~20 sA Postman mock server replies with the examples already saved beside the requests in the collection it was created from. Those examples live in a Postman account, and anyone allowed to edit that collection can edit them.
What does a Postman mock server fuse when one collection is definition, documentation and stand-in at once?
basics
~20 sA Postman mock server fuses the documented reply and the served reply into one saved example, so a single edit by anyone with collection edit rights moves documentation and stand-in together, with no diff or review on the consumer's side.
When a Postman collection running on a hosted schedule fails, who finds out first, and what does that notice lack?
basics
~20 sWhoever holds the vendor account finds out first, not whoever caused the failure. The notice carries a time and a failed request but no commit, no author and no build, so attribution has to be reconstructed by hand.
In Postman, what does forking a shared collection give you that duplicating it does not?
basics
~20 sA Postman fork keeps a recorded link back to the collection it came from, so later work can be offered back and merged through a review held in the vendor's account. A duplicate is an orphan.