# Secure collaboration and sharing of non-public APIs [Between 2 Devs LIVE]

Source: https://www.youtube.com/watch?v=6IUPRtspR_g
Recap page: https://rapidrecap.app/video/6IUPRtspR_g
Generated: 2025-11-11T13:06:11.184+00:00

---
## Quick Overview

The video demonstrates how to securely collaborate with external partners on private Postman APIs by utilizing Partner Workspaces, showcasing the ability to fork collections, assign specific roles (like Editor or Viewer), and maintain granular control over what partners can see or modify, ensuring internal API details remain protected.

**Key Points:**
- The demonstration focuses on using Postman's Partner Workspaces for secure collaboration with external entities like CreditMaker and PayPie.
- Ashutosh walks through forking a collection from an internal workspace to a new partner workspace, ensuring the original internal API remains unaffected.
- The host revealed that Swagger (Option B) was the correct answer to the trivia question: "What animal is commonly associated with API design and documentation?"
- Partner roles (Editor, Viewer) provide granular access control, allowing publishers to control what partners can see or modify within the shared workspace.
- The platform allows partners to view and interact with APIs (like the 'Knock Knock' health check API) without necessarily having access to the entire internal collection structure.
- The session highlights that collaboration is streamlined as partners can work in a shared space without needing to switch between entirely separate environments.

![Screenshot at 1:09: The trivia slide asking "What animal is commonly associated with API design and documentation?" with options Octopus, Swagger, Postman, and Python snake, which is immediately followed by the answer reveal.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-01-09.png)

**Context:** This segment is part of a 'Between 2 Devs LIVE' session hosted by Talia Kohan and featuring Ashutosh Kaushik from the Postman team, focusing on secure API collaboration features available within Postman, specifically demonstrating Partner Workspaces and collection forking capabilities. The discussion centers on how internal API development teams can safely share specific API collections with external partners without exposing sensitive internal details.

## Detailed Analysis

The session transitions into a practical demonstration of secure external collaboration using Postman's Partner Workspaces, hosted by Ashutosh Kaushik. After addressing a trivia question where 'Swagger' was identified as the correct answer (a real bird species, unlike the other options which are Postman-related or other animals), Ashutosh moves to the Postman interface to show how to share specific API assets securely. He starts by demonstrating how to fork a collection from an internal workspace into a newly created 'HBI Partner Workspace'. This action creates a copy, ensuring the original internal collection remains untouched. He emphasizes that this process is crucial for security, especially when dealing with sensitive APIs like the 'Payment Gateway APIs' shown, where internal details must be shielded from external partners. He demonstrates how to invite partners, assigning them an 'Editor' role, which grants them the ability to view and modify the forked collection but keeps the original internal collection private. The key benefit highlighted is that partners only see what is explicitly shared, streamlining onboarding and collaboration without exposing the entire internal API landscape. He concludes by showing the resulting partner workspace where only the forked collection is visible, proving the isolation between internal and external development efforts.

### Introduction & Trivia

- Talia welcomes Ashutosh and the audience; Ashutosh correctly answers a trivia question, identifying Swagger (a bird species) as the animal associated with API design/documentation.

### Partner Workspace Creation

- Ashutosh demonstrates creating a new 'Partner Workspace' from the workspace dropdown menu, naming it 'HBI Partner Workspace' and selecting the 'Partner' workspace type for secure external sharing.

### Collection Forking

- Ashutosh forks the 'HBI Demo Payment Gateway [1.0]' collection from the internal workspace into the new partner workspace, naming the fork 'Ashutosh Kaushik (Partner)'.

### Role-Based Access Control

- The host shows the invitation modal, setting the partner's role to 'Editor' and noting that partners can be granted granular access rights, controlling visibility of collections, environments, etc.

### Security Isolation

- Ashutosh navigates to the Partner Workspace settings to confirm that only the forked collection is visible to the partner, demonstrating that internal APIs remain secure and inaccessible to external collaborators.

### Demonstration of Use

- Ashutosh quickly tests the 'Knock Knock' API within the partner workspace, proving that the partner can use the shared API endpoints without needing full internal access.

![Screenshot at 0:00: Promotional graphic for the 'Between 2 Devs LIVE' event featuring the two hosts.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-00-00.png)
![Screenshot at 1:09: The trivia slide asking "What animal is commonly associated with API design and documentation?"](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-01-09.png)
![Screenshot at 1:25: The trivia answer slide revealing 'B\) Swagger' as the correct answer.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-01-25.png)
![Screenshot at 5:29: Talia Kohan welcomes the audience to the live stream, identifying the hosts and event name.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-05-29.png)
![Screenshot at 6:44: The screen splits to show both Talia Kohan and Ashutosh Kaushik, as Ashutosh prepares to share his screen.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-06-44.png)
![Screenshot at 11:03: Ashutosh clicks the 'Workspaces' dropdown and selects 'Create Fork' to begin duplicating the collection.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-11-03.png)
![Screenshot at 15:28: The 'Invite partners to this workspace' modal appears, showing options for role assignment \(Editor/Viewer\) and partner management.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-15-28.png)
![Screenshot at 17:37: Ashutosh navigates to the 'Settings' tab of the Partner Workspace to show collaboration control options.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-17-37.png)
![Screenshot at 22:47: The Postman interface shows the 'Knock Knock' API request open with authorization and header configuration visible.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-22-47.png)
![Screenshot at 25:28: The 'Invite partners to this workspace' modal reappears, showing the option to invite specific users or teams with defined roles.](https://ss.rapidrecap.app/screens/6IUPRtspR_g/00-25-28.png)
