New · Scheduled flows that ping Slack when they fail →

The API clientflow runnerwebhook inbox
your team opens in a browser tab.

Save a request, capture a webhook, wire them into a flow. It's one shared workspace: invite your team, and every save is versioned so you can open any old version and put it back.

  • 14-day free trial
  • Nothing to install
  • No credit card to start

Built on formats you already use

  • OpenAPI 3import + export
  • OAuth 2.0 + PKCEtokens encrypted at rest
  • AWS SigV4native request signing
  • WebSocketsreal-time agent dispatch
  • Postman · Insomnia · Brunoone-click import
  • GraphQLfirst-class body editor
  • JUnit / HTMLCI-ready reports
  • Markdownfirst-class docs
  • Cron schedulesSlack · Discord · webhook · email
  • OpenAPI 3import + export
  • OAuth 2.0 + PKCEtokens encrypted at rest
  • AWS SigV4native request signing
  • WebSocketsreal-time agent dispatch
  • Postman · Insomnia · Brunoone-click import
  • GraphQLfirst-class body editor
  • JUnit / HTMLCI-ready reports
  • Markdownfirst-class docs
  • Cron schedulesSlack · Discord · webhook · email

What's in the box

Requests, webhooks, and flows in one tab

Save and version a request, capture an inbound webhook, then chain both into a flow. The whole round trip of an API call, without leaving the page.

GET {{HOST}}/v1/charges
200 112ms
Saved · v23 · just now

Every save is a version you can go back to

Build a collection, save it, share the link. Each save keeps who saved it and when, so you can diff two versions, replay an old one, or restore it.

POST /i/wh_8f3a…
checkout.session.completed
charge.succeeded
customer.created
↳ Forwarded to api.example.com 200

Catch inbound webhooks and forward them

Click once for a unique inbound URL, point Stripe or GitHub at it, and read every payload that arrives. Reshape it with a few lines of JS and forward to up to three places.

POSTcustomers
→
POSTcharges
→
JSassert
5/5 pass 1.4s Last run · CI · main@a1b2c

Chain requests into a flow

Pass one response into the next request, pull out the values you need, branch on the status code, and assert on what comes back. Run it in the app, on a schedule, or in CI.

  GET /v1/charges
-   "limit": 10
+   "limit": 50
+   "expand[]": "customer"
v23 by chris · restore any revision

Nothing you save ever gets overwritten

The request that just broke? See who changed it six months ago and what they changed. Restoring an old version writes a new one on top, so you never lose the current state either.

Production3 variables
HOSTapi.stripe.com
API_KEY••••••••••••••

Environments + secrets

Workspace-scoped vars with {{var}} substitution. Secrets encrypted at rest with per-workspace keys.

OAuth 2.0auto-refresh
BearereyJhbGciOi•••••
Token valid · refreshes in 59m

OAuth, SigV4, and Digest, handled for you

OAuth 2.0 with auto-refresh, AWS SigV4, HTTP Digest, Basic, Bearer — configured per request, cached per user.

CT JD MK +4 7 members
@chris can you double-check the auth header here?

Invite your team, share everything

Collections, environments, and history your whole team can see. Threaded comments with @mentions.

*/5 * * * *passing
SlackDiscordEmail
Next run in 2m · alert on failure

Turn any flow into a monitor

Cron-driven flow runs with Slack, Discord, webhook + email alerting on failure. Your smoke tests, on autopilot.

$ apistash-agent run
connected · workspace ready
→ GET localhost:8080/health 200

Local agent

A tiny binary dispatches requests from your own network — hit internal APIs without firewall holes.

Postman Insomnia Bruno OpenAPI
↓42 requests · 6 folders imported

Imports

Postman v2.1, Insomnia v4, Bruno folders, and OpenAPI 3 — folder structure and auth carry over.

From inside the app

These are real screens, not mockups

Three views of the actual UI. What you see here is what you get when you sign in.

Webhooks

Every payload lands in an inbox you can read

Click once for an inbound URL and point any producer at it. Every event shows up with its full headers, body, and timing. Reshape it with a few lines of JS and forward to up to three destinations at once.

  • Unlimited inbound endpoints
  • Full headers + body inspection
  • Forward to up to 3 URLs in parallel
apistash.dev · webhooks · stripe-events
POST https://apistash.dev/i/wh_8f3ac1d2 200
Inbox3 events
checkout.session.completed just now
charge.succeeded 2m ago
customer.created 14m ago
BodyHeadersForwarded
{
  "id": "evt_3PaX9k…",
  "type": "checkout.session.completed",
  "data": {
    "object": {
      "customer": "cus_NJxQ…",
      "amount_total": 2199
    }
  }
}
Flows

Log in, grab the token, call the next endpoint

Drag steps into order, then pass values between them with a JSON path — the token from step one becomes the auth header in step two. Branch on the status, assert on the result, and run it from the app, on a schedule, or from CI.

  • Request, script, and delay steps
  • Per-step extract + expect
  • Cookies inherit across steps automatically
apistash.dev · flows · onboard-customer
Onboard customer ▶ Run
  1. 1 POST Create customer → customer.id
  2. 2 POST Create charge → charge.id
  3. 3 ⏱ Wait 2s
  4. 4 GET Webhook captured? expect 200
  5. 5 JS Assert payload shape pass
Versioned history

Every save is a snapshot you can diff.

See who changed what and when. Restore an old version in one click; it's written as a new revision, so the version you're restoring from sticks around too.

  • Author + timestamp on every revision
  • Side-by-side diff view
  • Restore writes a new revision
apistash.dev · history · v23 ↔ v22
47 revisions
v23 chris · just now
v22 alex · 3h ago
v21 jamie · yesterday
v20 chris · 2d ago
Diff · v23 vs v22
  GET /v1/charges
  query:
-   "limit": 10
+   "limit": 50
+   "expand[]": "customer"
  headers:
    Authorization: Bearer {{API_KEY}}

In your pipeline

The same runner your CI can call

The CLI runs the exact same code as the button in the app — no separate export to keep in sync. Point apistash run at a request, a flow, or a whole collection; it runs every step, checks your assertions, and exits non-zero when one fails so the build goes red.

  • JUnit + HTML reports for any CI
  • Environments resolved the same way as the UI
  • One binary, zero config files
Set up your pipeline →

Why we built it

Most API clients trap your work on one laptop

The requests live in one person's desktop app. Every save overwrites the last one. The env file is pasted in a Slack thread somewhere. And you're still emailing curl snippets like it's 2014.

Lost work

A teammate "fixes" your saved request and the last working version is gone. Without history there's no rollback.

Drifted environments

Your {{HOST}} works locally, theirs doesn't. The env file is on someone's laptop. Nobody knows whose.

Stuck in CI

Your API client has no CLI, so the integration tests you set up in the UI never run again after Monday.

How API Stash handles it

One shared workspace, so the collection isn't stuck on anyone's laptop. Every save is versioned, so nothing gets overwritten. And one CLI runs that same collection in CI.

Who it's for

Whether it's just you or the whole team

From the first curl at 2am to the regression suite that gates your deploy.

Solo developers

Skip the install. Open a tab, fire a request, share a link. Your collections follow you between machines because they live in your workspace, not your laptop.

  • Works from any browser
  • Capture a webhook in 10 seconds
  • Free 14-day trial

Platform + DevRel

Maintain a canonical collection that mirrors your public API. Import OpenAPI to stay in sync. Hand customers a single link instead of a 70MB export.

  • OpenAPI import + drift detection
  • Public docs export
  • CLI for CI regression

How we stack up

How it compares to Postman, Bruno, and Insomnia

Here's where each one lands. If another tool fits your team better, use it.

Postman Bruno Insomnia
Versioned history (every save)YesPaid planGit onlySync only
Browser-nativeYesWeb (paid)DesktopDesktop
Shared workspaces + commentsBuilt inWorkspaces (paid)NoSync only
Inbound webhook capture + forwardBuilt inMock serversNoNo
Multi-step flows (chain requests)Visual + scriptedTest scriptsRunnerTest suites
Scheduled runs + alertingSlack · Discord · webhook · emailPaid monitorsNoNo
Import Postman / Insomnia / BrunoAll threeOwn formatPostmanPostman
Local agent for internal APIsYesAgentLocalLocal
CLI for CIYesNewmanCLIInso
Try before you buy14-day full trialLimited free tierFree (OSS)Limited free tier
Install requiredNoneDesktop / WebDesktopDesktop

Comparison reflects vendor docs as of writing. Things change — re-check before you switch.

How it works

From a single request to a CI check

Three steps, all in the same workspace: save something, catch what comes back, then wire it into a flow you can run anywhere.

  1. GET {{HOST}}/v1/charges
    200 112ms
    Saved · v23 · just now
    01

    Save your first request

    Build a request, hit Save, share the URL with your teammates. Every save is a snapshot you can diff, restore, or replay.

  2. POST /i/wh_8f3a…
    checkout.session.completed
    charge.succeeded
    customer.created
    ↳ Forwarded to api.example.com 200
    02

    Capture inbound traffic

    Mint a webhook URL in one click. Point Stripe, GitHub, or your own producer at it. Transform on the fly, forward downstream.

  3. POSTcustomers
    →
    POSTcharges
    →
    JSassert
    5/5 pass 1.4s Last run · CI · main@a1b2c
    03

    Chain it into a flow

    Wire requests, scripts, and delays into a single workflow. Run from the UI — or from CI with apistash run.

Pricing

One plan. It's $19 a month per workspace

Free for 14 days, then $19 a month for the whole workspace — not per seat. Add your entire team and the price doesn't move. Every feature is in the one plan; there's nothing to upgrade to.

Straight talk

It's one developer, and it's bootstrapped

No investors, no board, no plan to flip it. Before you put a card in, here are the three things you're probably wondering about — answered straight.

Questions

Questions we get a lot

How much does it cost?

$19/mo per workspace — one flat price, billed per workspace rather than per seat, with every feature included. There are no locked tiers or add-ons. New workspaces start with a 14-day free trial (no credit card to start) so you can evaluate the whole product before you pay.

Where does my data live?

Your workspace data lives in an isolated tenant on our managed backend, deployed to a global edge network for low latency. Secrets — OAuth tokens, environment values marked as secret, MFA seeds, agent credentials — are encrypted at rest with workspace-scoped keys, separate from the data they protect. We never touch your request payloads beyond the round-trip needed to dispatch them.

Can I hit internal APIs that aren't on the public internet?

Yes — the local agent is a small Node binary you run on a developer machine or a build runner. The web app dispatches requests to it over an authenticated WebSocket; the agent calls your private API and returns the response. No firewall holes, no VPN-into-prod.

What are flows?

Flows let you chain multiple API requests into a single workflow. Each step can be a request (with extracted values piped to the next), a JS script, or a delay. Branch on status codes, assert on responses, retry on failure. Session cookies inherit across steps automatically. The same flow runs in the UI, on a cron schedule, and in CI via apistash run.

How do webhooks work?

Create a webhook in one click and we mint you a unique inbound URL. Point any service at it — Stripe, GitHub, your own producer — and we capture every payload with full headers and body in your inbox. Inspect them, optionally transform with a tiny JS function, and forward to up to 3 downstream URLs in parallel.

Does API Stash run in CI?

Yes, via the apistash run CLI. Point it at a request, a flow, or a whole collection plus an environment, and it dispatches every step, runs assertions, and emits a JUnit/HTML report. Exit code is non-zero on assertion failure, so it slots into any CI pipeline.

How is this different from Postman or Bruno?

Postman spreads collaboration, history, and monitors across several paid tiers. Bruno is genuinely good and open-source, but each collection lives in a git repo, so there's no live collaboration. API Stash sits between them: it's web-native, shared the moment you invite someone, and versioning and webhook capture are on by default rather than bolted on. And there's one price for everything instead of a tier ladder.

Do you import existing Postman, Insomnia, or Bruno collections?

Yes — all three, plus OpenAPI 3. Postman v2.1 exports, Insomnia v4 exports, and Bruno folders of .bru files import with folder structure and auth configuration carried over.

How does versioning work?

Every time you hit Save, API Stash writes a revision row with the full snapshot — method, URL, headers, body, scripts — plus author and timestamp. Flows version the same way. You can diff, restore, or run any past revision; restoring writes a new revision so nothing is destroyed.

What's the catch?

It's a small operation — really just one developer. Support is email, and Pro workspaces get answered first. There's no big enterprise sales motion, no phone tree. The upside of small: fixes and features tend to land in days, not quarters (the changelog is the receipt).

Move one collection over this afternoon

Import from Postman, Insomnia, Bruno, or OpenAPI and your folders and auth come across. Requests, webhooks, and flows, shared in one workspace. Free for 14 days, no card.