API developers juggle authentication across request tools
Developers testing or integrating APIs often have to acquire, copy, refresh, and reuse credentials by hand, or work around missing authentication support in their client tools. OAuth flows, expiring tokens, and cloud credentials can behave differently across tools, making requests cumbersome and sometimes less secure. Some reports also concern fixes only the service or platform owner can make, so an independent product would need to focus on the client-side workflow.
For developers testing and integrating authenticated APIs. Mentioned from Aug 2016 to Feb 2026 on Bluesky, GitHub and Hacker News.
24 different people described this problem in 20 separate discussions.
- Indie fit
- 4.0/10
- Pain
- 6.3/10
- Frequency
- 10.0/10
- Willingness to pay
- 0.0/10
- Momentum
- 5.0/10
- Who pays
- Professionals
- Competition
- High
- Build difficulty
- Medium
What people said
Quoted word for word. Follow a link to read the whole discussion.
But since our API is using Keycloak JWT tokens which are expiring after 5 minutes its is nearly impossible to use Postman without copying a new token each 5 minutes to the client
BirknerAlex on GitHub (postmanlabs/postman-app-support)Feb 2023+31 upvotesAsked for a toolHas a workaroundNow our IDS changed and the login form is submitted via javascript. This - similar to the topics mentioned above - does not work anymore now. Not able to complete the auth code flow with postman
Build brief
See what to build and who will buy it
- 2 product ideas with the smallest useful version and pricing
- 5 places to find your first customers
- 23 more quotes from people who have this problem
- Current workarounds, existing solutions and risks