Does the Postman API need an API key?

Does the Postman API need an API key?

Yes for the 26 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.

ERR-2026-1733, ERR-2026-1749, ERR-2026-1761, ERR-2026-1762, ERR-2026-1764, ERR-2026-1786, ERR-2026-1812, ERR-2026-1814, ERR-2026-1902, ERR-2026-1941, ERR-2026-1942, ERR-2026-2002

Every record behind those answers

26 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

credentials are required (observed) (26)

The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.

ERR-2026-1733Single CollectionHTTP 401checked 2026-09-15, 2 times
ERR-2026-1749All CollectionsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1761User safe scoring - Accumulated value - v1/Scorings/individualHTTP 401checked 2026-09-15, 2 times
ERR-2026-1762User statistice - Daily value - v1/Statistics/individual/dailyHTTP 401checked 2026-09-15, 2 times
ERR-2026-1764Get linked relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1786Get all APIsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1812User statistics - Accumulated value - /v1/Statistics/individualHTTP 401checked 2026-09-15, 2 times
ERR-2026-1814Get integration test relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1902User safe scoring - daily value - /v1/Scorings/individual/dailyHTTP 401checked 2026-09-15, 2 times
ERR-2026-1941Get documentation relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1942/v1/Scorings/consolidated/dailyHTTP 401checked 2026-09-15, 2 times
ERR-2026-2002API Key OwnerHTTP 401checked 2026-09-15, 2 times
ERR-2026-2016Get All API VersionsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2032/v1/Scorings/consolidatedHTTP 401checked 2026-09-15, 2 times
ERR-2026-2040/v1/Statistics/consolidated/dailyHTTP 401checked 2026-09-15, 2 times
ERR-2026-2044All MocksHTTP 401checked 2026-09-15, 2 times
ERR-2026-2066Get monitor relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2069Get SchemaHTTP 401checked 2026-09-15, 2 times
ERR-2026-2090Single EnvironmentHTTP 401checked 2026-09-15, 2 times
ERR-2026-2092All EnvironmentsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2116Get an API VersionHTTP 401checked 2026-09-15, 2 times
ERR-2026-2140Get contract test relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2152Get test suite relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2180/v1/Statistics/consolidatedHTTP 401checked 2026-09-15, 2 times
ERR-2026-2221Get environment relationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2235Single APIHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://api.getpostman.com/collections/errata-probe-not-a-real-identifier

Also filed as: Quick start - Telematics SDK, telematicssdk.com. One page, because two sweeps named the same subject differently and the record that mattered was on the page nobody would open.

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.