Secure collaboration and sharing of non-public APIs [Between 2 Devs LIVE]
Quick Overview
The video demonstrates how to securely collaborate with external partners on private Postman APIs by utilizing Partner Workspaces, showcasing the ability to fork collections, assign specific roles (like Editor or Viewer), and maintain granular control over what partners can see or modify, ensuring internal API details remain protected.
Key Points: The demonstration focuses on using Postman's Partner Workspaces for secure collaboration with external entities like CreditMaker and PayPie. Ashutosh walks through forking a collection from an internal workspace to a new partner workspace, ensuring the original internal API remains unaffected. The host revealed that Swagger (Option B) was the correct answer to the trivia question: "What animal is commonly associated with API design and documentation?" Partner roles (Editor, Viewer) provide granular access control, allowing publishers to control what partners can see or modify within the shared workspace. The platform allows partners to view and interact with APIs (like the 'Knock Knock' health check API) without necessarily having access to the entire internal collection structure. The session highlights that collaboration is streamlined as partners can work in a shared space without needing to switch between entirely separate environments.
Context: This segment is part of a 'Between 2 Devs LIVE' session hosted by Talia Kohan and featuring Ashutosh Kaushik from the Postman team, focusing on secure API collaboration features available within Postman, specifically demonstrating Partner Workspaces and collection forking capabilities. The discussion centers on how internal API development teams can safely share specific API collections with external partners without exposing sensitive internal details.
Detailed Analysis
The session transitions into a practical demonstration of secure external collaboration using Postman's Partner Workspaces, hosted by Ashutosh Kaushik. After addressing a trivia question where 'Swagger' was identified as the correct answer (a real bird species, unlike the other options which are Postman-related or other animals), Ashutosh moves to the Postman interface to show how to share specific API assets securely. He starts by demonstrating how to fork a collection from an internal workspace into a newly created 'HBI Partner Workspace'. This action creates a copy, ensuring the original internal collection remains untouched. He emphasizes that this process is crucial for security, especially when dealing with sensitive APIs like the 'Payment Gateway APIs' shown, where internal details must be shielded from external partners. He demonstrates how to invite partners, assigning them an 'Editor' role, which grants them the ability to view and modify the forked collection but keeps the original internal collection private. The key benefit highlighted is that partners only see what is explicitly shared, streamlining onboarding and collaboration without exposing the entire internal API landscape. He concludes by showing the resulting partner workspace where only the forked collection is visible, proving the isolation between internal and external development efforts.