Unlike every other page in this section, there’s no AI assistant here to type natural-language prompts into. You call each Perfai tool directly from Postman’s Tools tab, filling in its arguments yourself.
Generate your Bearer token
The value Postman needs is a Perfai Token (id_token which is a JWT).- macOS / Linux
- Windows (PowerShell)
read -s masks the password prompt so it never lands in your shell history. Copy the printed id_token value in full.Installation
- In any Postman workspace, click Add → MCP.
- Set the transport: choose HTTP (Postman’s label for Streamable HTTP).
- URL:
https://mcp-server.perfai.ai/mcp - Open the Authorization tab → Auth Type: Bearer Token → paste the
id_tokenfrom above. - Click Run to connect.
Verify the server is connected
- A correct token gets you a green Connected status immediately after clicking Run — the handshake doesn’t require you to already be logged into a Perfai account, only to hold a valid token.
- Open the Tools tab and confirm all 19 tools are listed.
- If it fails, re-check the token value for trailing whitespace, and make sure it hasn’t expired (generate a fresh
id_tokenif it has).
The Bearer token authenticates the connection. It does not log you into a Perfai account by itself — that’s the separate
login step below.Login
In the Tools tab, selectlogin. For a production account, leave the email/password arguments blank and click Run — this triggers a browser-based login to Perfai’s own sign-in page instead of sending your password through the request body.
Then run auth_status to confirm the session is active.
Register an app and run a scan
Run each of these from the Tools tab, filling in arguments as needed:register_app— setappUrltohttps://your-app.example.com.check_app_status— run repeatedly untilregistrationStatusisCOMPLETED. If it returnsAWAITING_INPUT, that’s the target app’s own login, not your Perfai account — supply it viasubmit_app_credentials.run_security_test— returns ataskId.check_task_status— run with thattaskIduntil it reportsCOMPLETED.get_vulnerabilities— lists findings with sequence numbers, used in the fix tools below.
Fix and verify
auto_fix_all— returns a prioritized, critical-first fix plan. Postman won’t apply these changes for you; copy the instructions into your editor by hand.mark_vulnerability_fixed— run once per finding, after the corresponding code change is actually made.get_fix_summary— confirms the fixed/unfixed/dismissed counts moved as expected.logout, thenauth_statusagain — confirms the session actually cleared.

