Skip to main content
Postman has a native MCP request type — it speaks the protocol directly and shows raw request/response data, with no AI model or chat layer in the way. That makes it the most direct way to confirm Perfai Cloud itself is healthy, independent of whichever AI client you eventually use day to day. Perfai Cloud connects as a remote streamable-http server.
Unlike every other page in this section, there’s no AI assistant here to type natural-language prompts into. You call each Perfai tool directly from Postman’s Tools tab, filling in its arguments yourself.

Generate your Bearer token

The value Postman needs is a Perfai Token (id_token which is a JWT).
read -s masks the password prompt so it never lands in your shell history. Copy the printed id_token value in full.
Copy the resulting string — you’ll paste it into Postman’s Authorization tab as the Bearer token value.

Installation

  1. In any Postman workspace, click Add → MCP.
  2. Set the transport: choose HTTP (Postman’s label for Streamable HTTP).
  3. URL: https://mcp-server.perfai.ai/mcp
  4. Open the Authorization tab → Auth Type: Bearer Token → paste the id_token from above.
  5. Click Run to connect.

Verify the server is connected

  1. A correct token gets you a green Connected status immediately after clicking Run — the handshake doesn’t require you to already be logged into a Perfai account, only to hold a valid token.
  2. Open the Tools tab and confirm all 19 tools are listed.
  3. If it fails, re-check the token value for trailing whitespace, and make sure it hasn’t expired (generate a fresh id_token if it has).
The Bearer token authenticates the connection. It does not log you into a Perfai account by itself — that’s the separate login step below.

Login

In the Tools tab, select login. For a production account, leave the email/password arguments blank and click Run — this triggers a browser-based login to Perfai’s own sign-in page instead of sending your password through the request body. Then run auth_status to confirm the session is active.

Register an app and run a scan

Run each of these from the Tools tab, filling in arguments as needed:
  1. register_app — set appUrl to https://your-app.example.com.
  2. check_app_status — run repeatedly until registrationStatus is COMPLETED. If it returns AWAITING_INPUT, that’s the target app’s own login, not your Perfai account — supply it via submit_app_credentials.
  3. run_security_test — returns a taskId.
  4. check_task_status — run with that taskId until it reports COMPLETED.
  5. get_vulnerabilities — lists findings with sequence numbers, used in the fix tools below.

Fix and verify

  1. auto_fix_all — returns a prioritized, critical-first fix plan. Postman won’t apply these changes for you; copy the instructions into your editor by hand.
  2. mark_vulnerability_fixed — run once per finding, after the corresponding code change is actually made.
  3. get_fix_summary — confirms the fixed/unfixed/dismissed counts moved as expected.
  4. logout, then auth_status again — confirms the session actually cleared.