Postman Credential Verification

A scan only reaches the endpoints its credentials can open. If a token in your Postman collection has expired or an environment variable is wrong, scans miss your authenticated endpoints and pentests stall until you send updated files. You can now check your Postman credentials before testing starts.
What's new
Verify Before You Scan – Upload your Postman collection and environment file, then click Run Verification. Astra checks whether your credentials can authenticate against your API, usually within a few minutes.
No Pentest Delays – Confirm your files work before the engagement starts, so testing doesn't wait on a fresh collection or environment file.
Every Credential Source, Together – Credentials from your collection, your environment file, and the target's saved authentication are checked as one setup, so you see how your scan will actually behave.
Clear Result for Every Endpoint – Each endpoint shows a clear result, along with which credential worked. A short summary explains the overall result.
Safe to Run – Verification is read-only. It doesn't change any data on your API, and credential values never appear in the report.
Re-verify in One Click – Rotated a token or replaced a file? Click Retry verification to check again.
Catch broken credentials before testing starts, not after. Available for API and Web targets on selected plans. Give it a try and tell us what you think.

