Every save is a version you can go back to
Build a collection, save it, share the link. Each save keeps who saved it and when, so you can diff two versions, replay an old one, or restore it.
Save a request, capture a webhook, wire them into a flow. It's one shared workspace: invite your team, and every save is versioned so you can open any old version and put it back.
Built on formats you already use
What's in the box
Save and version a request, capture an inbound webhook, then chain both into a flow. The whole round trip of an API call, without leaving the page.
Build a collection, save it, share the link. Each save keeps who saved it and when, so you can diff two versions, replay an old one, or restore it.
Click once for a unique inbound URL, point Stripe or GitHub at it, and read every payload that arrives. Reshape it with a few lines of JS and forward to up to three places.
Pass one response into the next request, pull out the values you need, branch on the status code, and assert on what comes back. Run it in the app, on a schedule, or in CI.
GET /v1/charges - "limit": 10 + "limit": 50 + "expand[]": "customer"
The request that just broke? See who changed it six months ago and what they changed. Restoring an old version writes a new one on top, so you never lose the current state either.
Workspace-scoped vars with {{var}} substitution. Secrets encrypted at rest with per-workspace keys.
OAuth 2.0 with auto-refresh, AWS SigV4, HTTP Digest, Basic, Bearer — configured per request, cached per user.
Collections, environments, and history your whole team can see. Threaded comments with @mentions.
Cron-driven flow runs with Slack, Discord, webhook + email alerting on failure. Your smoke tests, on autopilot.
A tiny binary dispatches requests from your own network — hit internal APIs without firewall holes.
Postman v2.1, Insomnia v4, Bruno folders, and OpenAPI 3 — folder structure and auth carry over.
From inside the app
Three views of the actual UI. What you see here is what you get when you sign in.
Click once for an inbound URL and point any producer at it. Every event shows up with its full headers, body, and timing. Reshape it with a few lines of JS and forward to up to three destinations at once.
{ "id": "evt_3PaX9k…", "type": "checkout.session.completed", "data": { "object": { "customer": "cus_NJxQ…", "amount_total": 2199 } } }
Drag steps into order, then pass values between them with a JSON path — the token from step one becomes the auth header in step two. Branch on the status, assert on the result, and run it from the app, on a schedule, or from CI.
See who changed what and when. Restore an old version in one click; it's written as a new revision, so the version you're restoring from sticks around too.
GET /v1/charges query: - "limit": 10 + "limit": 50 + "expand[]": "customer" headers: Authorization: Bearer {{API_KEY}}
In your pipeline
The CLI runs the exact same code as the button in the app — no separate
export to keep in sync. Point apistash run at a request, a flow, or a whole
collection; it runs every step, checks your assertions, and exits non-zero when one fails
so the build goes red.
Why we built it
The requests live in one person's desktop app. Every save overwrites the last one. The env file is pasted in a Slack thread somewhere. And you're still emailing curl snippets like it's 2014.
A teammate "fixes" your saved request and the last working version is gone. Without history there's no rollback.
Your {{HOST}} works locally, theirs doesn't. The env file is on someone's laptop. Nobody knows whose.
Your API client has no CLI, so the integration tests you set up in the UI never run again after Monday.
One shared workspace, so the collection isn't stuck on anyone's laptop. Every save is versioned, so nothing gets overwritten. And one CLI runs that same collection in CI.
Who it's for
From the first curl at 2am to the regression suite that gates your deploy.
Skip the install. Open a tab, fire a request, share a link. Your collections follow you between machines because they live in your workspace, not your laptop.
One place for the collections, environments, and history everyone shares. Build a flow that creates a customer, catches the webhook that fires, and checks the side effects — then run it on every deploy.
Maintain a canonical collection that mirrors your public API. Import OpenAPI to stay in sync. Hand customers a single link instead of a 70MB export.
How we stack up
Here's where each one lands. If another tool fits your team better, use it.
| Postman | Bruno | Insomnia | ||
|---|---|---|---|---|
| Versioned history (every save) | Yes | Paid plan | Git only | Sync only |
| Browser-native | Yes | Web (paid) | Desktop | Desktop |
| Shared workspaces + comments | Built in | Workspaces (paid) | No | Sync only |
| Inbound webhook capture + forward | Built in | Mock servers | No | No |
| Multi-step flows (chain requests) | Visual + scripted | Test scripts | Runner | Test suites |
| Scheduled runs + alerting | Slack · Discord · webhook · email | Paid monitors | No | No |
| Import Postman / Insomnia / Bruno | All three | Own format | Postman | Postman |
| Local agent for internal APIs | Yes | Agent | Local | Local |
| CLI for CI | Yes | Newman | CLI | Inso |
| Try before you buy | 14-day full trial | Limited free tier | Free (OSS) | Limited free tier |
| Install required | None | Desktop / Web | Desktop | Desktop |
Comparison reflects vendor docs as of writing. Things change — re-check before you switch.
How it works
Three steps, all in the same workspace: save something, catch what comes back, then wire it into a flow you can run anywhere.
Build a request, hit Save, share the URL with your teammates. Every save is a snapshot you can diff, restore, or replay.
Mint a webhook URL in one click. Point Stripe, GitHub, or your own producer at it. Transform on the fly, forward downstream.
Wire requests, scripts, and delays into a single workflow.
Run from the UI — or from CI with apistash run.
Pricing
Free for 14 days, then $19 a month for the whole workspace — not per seat. Add your entire team and the price doesn't move. Every feature is in the one plan; there's nothing to upgrade to.
$19/mo per workspace
Free for 14 days. No credit card to start.
14 days free, then $19/mo. Cancel anytime from workspace settings.
Straight talk
No investors, no board, no plan to flip it. Before you put a card in, here are the three things you're probably wondering about — answered straight.
One flat $19 a month. Invite the whole team into a workspace and it stays $19 — nobody's counting seats, and there's no wall that pops up when the tenth person joins.
Export whenever you want, in formats Postman and the OpenAPI world already read. And if this ever shuts down, you'll get warning and a working export before anything goes read-only. Leaving is always an option.
Nothing you use today gets fenced off into a higher tier tomorrow. If the price ever moves, existing workspaces hear it from us first, in plain language — and grandfathering is on the table, not a surprise bill.
Questions
$19/mo per workspace — one flat price, billed per workspace rather than per seat, with every feature included. There are no locked tiers or add-ons. New workspaces start with a 14-day free trial (no credit card to start) so you can evaluate the whole product before you pay.
Your workspace data lives in an isolated tenant on our managed backend, deployed to a global edge network for low latency. Secrets — OAuth tokens, environment values marked as secret, MFA seeds, agent credentials — are encrypted at rest with workspace-scoped keys, separate from the data they protect. We never touch your request payloads beyond the round-trip needed to dispatch them.
Yes — the local agent is a small Node binary you run on a developer machine or a build runner. The web app dispatches requests to it over an authenticated WebSocket; the agent calls your private API and returns the response. No firewall holes, no VPN-into-prod.
Flows let you chain multiple API requests into a single workflow. Each step can be a request (with extracted values piped to the next), a JS script, or a delay. Branch on status codes, assert on responses, retry on failure. Session cookies inherit across steps automatically. The same flow runs in the UI, on a cron schedule, and in CI via apistash run.
Create a webhook in one click and we mint you a unique inbound URL. Point any service at it — Stripe, GitHub, your own producer — and we capture every payload with full headers and body in your inbox. Inspect them, optionally transform with a tiny JS function, and forward to up to 3 downstream URLs in parallel.
Yes, via the apistash run CLI. Point it at a request, a flow, or a whole collection plus an environment, and it dispatches every step, runs assertions, and emits a JUnit/HTML report. Exit code is non-zero on assertion failure, so it slots into any CI pipeline.
Postman spreads collaboration, history, and monitors across several paid tiers. Bruno is genuinely good and open-source, but each collection lives in a git repo, so there's no live collaboration. API Stash sits between them: it's web-native, shared the moment you invite someone, and versioning and webhook capture are on by default rather than bolted on. And there's one price for everything instead of a tier ladder.
Yes — all three, plus OpenAPI 3. Postman v2.1 exports, Insomnia v4 exports, and Bruno folders of .bru files import with folder structure and auth configuration carried over.
Every time you hit Save, API Stash writes a revision row with the full snapshot — method, URL, headers, body, scripts — plus author and timestamp. Flows version the same way. You can diff, restore, or run any past revision; restoring writes a new revision so nothing is destroyed.
It's a small operation — really just one developer. Support is email, and Pro workspaces get answered first. There's no big enterprise sales motion, no phone tree. The upside of small: fixes and features tend to land in days, not quarters (the changelog is the receipt).
Import from Postman, Insomnia, Bruno, or OpenAPI and your folders and auth come across. Requests, webhooks, and flows, shared in one workspace. Free for 14 days, no card.