> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Postman

> Connect the Perfai Cloud MCP server to Postman via its native MCP request type.

Postman has a native **MCP** request type — it speaks the protocol directly and shows raw request/response data, with no AI model or chat layer in the way. That makes it the most direct way to confirm Perfai Cloud itself is healthy, independent of whichever AI client you eventually use day to day. Perfai Cloud connects as a remote streamable-http server.

<Note>
  Unlike every other page in this section, there's no AI assistant here to type natural-language prompts into. You call each Perfai tool directly from Postman's **Tools** tab, filling in its arguments yourself.
</Note>

***

## Generate your Bearer token

The value Postman needs is a Perfai Token (id\_token which is a JWT).

<Tabs>
  <Tab title="macOS / Linux">
    ```bash theme={null}
    read -s -p "PerfAI password: " PERFAI_PASSWORD; echo
    curl -s -X POST "https://api.perfai.ai/api/v1/auth/token" \
      -H "Content-Type: application/json" \
      -d "{\"username\":\"you@example.com\",\"password\":\"$PERFAI_PASSWORD\"}" \
      | grep -o '"id_token":"[^"]*"' | cut -d'"' -f4
    ```

    `read -s` masks the password prompt so it never lands in your shell history. Copy the printed `id_token` value in full.
  </Tab>

  <Tab title="Windows (PowerShell)">
    ```powershell theme={null}
    $cred = Get-Credential -UserName "you@example.com" -Message "PerfAI password"
    $body = @{ username = $cred.UserName; password = $cred.GetNetworkCredential().Password } | ConvertTo-Json
    $resp = Invoke-RestMethod -Uri "https://api.perfai.ai/api/v1/auth/token" -Method Post -Body $body -ContentType "application/json"
    $resp.id_token
    ```

    `Get-Credential` masks the password prompt and, unlike a plain double-quoted string, won't let PowerShell mangle special characters (`$`, `` ` ``, `"`) in your password. Copy the printed `id_token` value in full — it wraps across multiple terminal lines, but that's just visual wrapping, not truncation.
  </Tab>
</Tabs>

Copy the resulting string — you'll paste it into Postman's Authorization tab as the Bearer token value.

***

## Installation

1. In any Postman workspace, click **Add** → **MCP**.
2. Set the transport: choose **HTTP** (Postman's label for Streamable HTTP).
3. **URL**: `https://mcp-server.perfai.ai/mcp`
4. Open the **Authorization** tab → **Auth Type**: **Bearer Token** → paste the `id_token` from above.
5. Click **Run** to connect.

***

## Verify the server is connected

1. A correct token gets you a green **Connected** status immediately after clicking Run — the handshake doesn't require you to already be logged into a Perfai account, only to hold a valid token.
2. Open the **Tools** tab and confirm all 19 tools are listed.
3. If it fails, re-check the token value for trailing whitespace, and make sure it hasn't expired (generate a fresh `id_token` if it has).

<Note>
  The Bearer token authenticates the **connection**. It does not log you into a Perfai account by itself — that's the separate `login` step below.
</Note>

***

## Login

In the **Tools** tab, select **`login`**. For a production account, leave the `email`/`password` arguments blank and click **Run** — this triggers a browser-based login to Perfai's own sign-in page instead of sending your password through the request body.

Then run **`auth_status`** to confirm the session is active.

***

## Register an app and run a scan

Run each of these from the **Tools** tab, filling in arguments as needed:

1. **`register_app`** — set `appUrl` to `https://your-app.example.com`.
2. **`check_app_status`** — run repeatedly until `registrationStatus` is `COMPLETED`. If it returns `AWAITING_INPUT`, that's the target app's own login, not your Perfai account — supply it via **`submit_app_credentials`**.
3. **`run_security_test`** — returns a `taskId`.
4. **`check_task_status`** — run with that `taskId` until it reports `COMPLETED`.
5. **`get_vulnerabilities`** — lists findings with sequence numbers, used in the fix tools below.

***

## Fix and verify

1. **`auto_fix_all`** — returns a prioritized, critical-first fix plan. Postman won't apply these changes for you; copy the instructions into your editor by hand.
2. **`mark_vulnerability_fixed`** — run once per finding, after the corresponding code change is actually made.
3. **`get_fix_summary`** — confirms the fixed/unfixed/dismissed counts moved as expected.
4. **`logout`**, then **`auth_status`** again — confirms the session actually cleared.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.