What a collection can hold
A collection stores requests, variables and scripts. If a request depends on values computed at send time, the collection needs a script that computes them, or that request fails every time it is sent from a saved state. Sorting your endpoints into groups early saves rework later.
- Static and parameterised requests translate directly into collection items.
- Requests authenticated with a bearer token translate with a collection level auth setting and a variable.
- Requests with signatures, encrypted bodies or device identifiers need a pre-request script that reproduces the derivation.
Build the endpoint inventory first
Collect endpoints from the app before opening Postman. Retrofit interfaces list paths and methods together. An OkHttp interceptor or a logging build reveals full URLs and headers. Where the app obfuscates both, the strings table and a traffic capture fill the gaps.
Record the method, path, required headers, content type and body shape for each endpoint. The body shape matters even where you hold a working sample, because fields that were absent in that sample may be required in other cases.
Move derived values into scripts
The Postman pre-request sandbox runs JavaScript, which covers hashing, HMAC, AES and base64 through its bundled crypto library. A signature computed with those primitives can be reproduced in a script, provided the key is available as a variable.
Some derivations do not survive the move. A value produced inside a native library, a key held in the Android keystore, or a signature over bytes the app assembles in C cannot be recreated in the sandbox. For those endpoints the honest options are a small local helper that signs and returns the value, or a note on the request explaining that the value comes from outside. A collection that pretends otherwise wastes the time of everyone who uses it.
Where the derivation involves a timestamp, keep the window short and read the server clock. A script that signs with the local machine time will work on your laptop and fail on a build machine in another region.
Chain requests with variables
Stateful flows become a folder of requests that pass values forward. The login or establishment request writes tokens and identifiers into variables, and the requests after it read them.
- Set variables from the response in a test script, so later requests can use them.
- Keep the session identifier separate from the access token, because the two expire independently.
- Use an environment for values you change often and collection variables for values that belong to the flow.
- Update the stored refresh token whenever a refresh call returns a new one.
Order inside a folder is a real dependency rather than a convenience. Someone who runs one request on its own should find that documented instead of discovering it through an opaque error. Name the folder after the workflow it represents, not after the screen that triggers it.
Cookies
Postman keeps a cookie jar per domain, which handles many session based APIs without any work on your part. Check whether the app also copies a cookie into a header or persists one to disk, because the jar will not cover either case. Where the API sets a cookie during login and expects it on every later call, verify the jar before you debug anything else. Confirm it with two calls in a row rather than one, because a jar that drops cookies while following a redirect fails in the middle of a flow rather than at the start.
Document what stays dynamic
A collection that hides its weak points is worse than one that names them. Describe each dynamic field, which script fills it, and what happens when it goes stale. Mark the endpoints that need an external signer, and note which requests depend on an earlier call in the folder.
That documentation is also the seed of an API description the team can maintain. The endpoint inventory you built at the start already holds the paths, methods and parameter shapes, so writing it down costs little and answers most of the questions a new client author would otherwise ask you directly.
Related work
Reviewed 28 September 2026 · SReverse research desk