Private desktop API workbench

Post APIs.
Not your data.

Send HTTP requests, open WebSocket and Socket.IO connections, organize reusable workflows, and safely author them with AI agents—without an account or cloud workspace.

Free and open source under Apache-2.0.

  • Your workspace stays localSQLite data on your machine
  • Networking runs nativelyHTTP · WebSocket · Socket.IO
  • Your data stays portablePostman, OpenAPI, cURL, and JSON
Request workspace

A dense desktop workspace, available in Light, Dark, and Forest themes.

The complete workflow

Everything important stays close to the request or connection

PostNot covers HTTP and live API workflows without turning your local workspace into a hosted service.

Workflow 01

Send and inspect requests

Compose requests in restored tabs, preview the fully resolved outgoing request with private values masked, cancel native sends, and inspect complete response bodies.

  • GET, QUERY, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS methods
  • Headers, query, auth, multipart files, and body editing
  • OAuth2 client-credentials helper
  • Searchable response and local request history
Inspect resolved URL, headers, auth, and body before anything leaves your machine.

Workflow 02

Open live API connections

Select a standalone WebSocket or Socket.IO connection profile, then compose and switch collection messages while one live tab session and its transcript stay intact.

  • Headers, cookies, auth, query parameters, subprotocols, and namespaces
  • Text, tokenized JSON, binary payloads, events, acknowledgements, ping, and pong
  • Reusable connection profiles selected independently from saved collection messages
  • One continuous session while messages are selected, edited, and sent

Transcript boundary: session-only and cleared when the app closes.

Reuse one connection and transcript while composing or selecting multiple compatible messages.

Workflow 03

Organize and automate

Build nested collections, find saved requests quickly, and run repeatable Playbooks with delays, scripts, stop-on-failure behavior, and grouped logs.

  • Folders, search, reorder, and drag-and-drop moves
  • Inherited collection, folder, and request scripts
  • Sequential Playbooks that reuse the normal send path
Explore the scripting API
Run saved requests in order while preserving scripts, environments, and history.

Workflow 04

Author API resources with local AI agents

Connect a compatible MCP client to inspect your workspace and prepare reusable HTTP requests, realtime connection profiles, and collection messages while PostNot keeps execution in your hands.

  • Read masked request details and resolved previews
  • Create hierarchies and atomically create or update HTTP requests
  • Manage standalone realtime profiles and messages with revision checks
  • Review every mutation in the persistent MCP Integration feed

Execution boundary: agents cannot execute requests or scripts, open realtime connections, or send traffic.

Connect over local stdio, keep network execution unavailable, and review recorded changes.

Workflow 05

Import, export, and migrate

Bring existing work from Postman, OpenAPI 3, or cURL. Export collections and environments in familiar formats, or share a single redacted request as cURL or PostNot JSON.

  • Postman collection and environment round trips
  • OpenAPI 3 collection and request-draft import
  • Broad cURL flag coverage and portable JSON exports
Keep imported work organized and ready to move again when you choose.

Workflow 06

Protect local data and secrets

Use environment variables without storing secret values in plain SQLite. PostNot masks private previews, keeps unresolved secret references in history, and redacts exports by default.

  • OS-backed secret storage
  • Built-in dynamic variables and script-driven updates
  • Explicit control over non-secret variable inclusion
Choose which values are ordinary local data and which belong in the OS credential store.

Why developers choose PostNot

A smaller boundary around your API work

In cloud-first workflows

The hosted service is part of the boundary

  • An identity or workspace may be required
  • Synchronization can be coupled to normal use
  • Storage and portability depend on service behavior
  • Browser networking constraints may shape the client

Data & privacy

Local by default, explicit when data moves

Where PostNot stores workspace data, how it protects secrets, and what agents can see.

  1. 1

    Workspace

    Requests, standalone connection profiles, collection messages, environments, settings, and HTTP history live under the Tauri app data directory in SQLite. Live transcripts remain session-only.

  2. 2

    Secrets

    Secret environment values go to the operating system credential store, not the application database.

  3. 3

    Agents

    MCP discovery omits secret values, masks credential-looking literals, and records mutation metadata without retaining request or realtime values in its integration log.

  4. 4

    Network and exports

    Data leaves when you send a request, open a live connection, or export. Previews mask private values and single-request exports redact credentials by default.

A workbench that fits

Compact in every theme

Try the site palette—the desktop app uses the same Light, Dark, and Forest direction.

Download

Choose the build for your machine

Free and open source under Apache-2.0. No account, trial, paid tier, or cloud workspace.

Latest stable Loading current release…
Published Checking GitHub Releases

Installer details load from the public GitHub release. Every download link still opens the latest release if that lookup is unavailable.

View all release assets

Runtime baselines follow the Tauri 2 platform prerequisites; Linux library availability varies by distribution.

Open development

Follow the project in public

PostNot does not need invented social proof. Its code, changes, issues, and builds are available to inspect.

Built in the open, by AI agents. PostNot is a fully AI-generated software project; repository code is produced end-to-end by AI agents.

Built with AI agents100% AI-generated code

Ready when you are

Keep the client. Keep the data.