An API client your whole team works in.
Build and send HTTP requests, keep environments and secrets in one place, and see every teammate’s change and every send as it happens.
Build any HTTP request. Send it with Ctrl+Enter.
Requests live in your workspace, not in a file on someone’s laptop. Save one and everyone on the workspace can send it.
- method · url
Params and headers
GET, POST, PUT, PATCH and DELETE. The URL and the params table stay in sync, and any row can be switched off without deleting it.
- path variables
Path variables
Write /users/:id in the URL and fill in the value on the Params tab. OpenAPI imports set them up for you.
- body
JSON, XML, text and forms
Raw bodies with pretty-printing, form data and URL-encoded fields. Content-Type is set from the body unless you set your own.
- auth
Auth that inherits
Basic, Bearer token or API key, set on a request, a collection or the whole workspace. A request uses the nearest level that sets one.
- response
Read what came back
Pretty or raw JSON, response headers, the request as it went out, and a timing breakdown from connection to download. Right-click a JSON value to copy its path.
- watchers
Watch a value
Add a value from a JSON response to the request’s watchers to keep an eye on it across sends.
Staging to production in one click.
Write {{baseUrl}} once. Switch the environment and the same request goes to another server, with that environment’s tokens.
- variables
Variables everywhere
Use {{variables}} in the URL, params, headers, auth and body. Type {{ for suggestions, and hold Ctrl+E to preview the resolved request.
- types
Know where you’re sending
Tag environments Local, Development, Test, QA, Staging or Production. The Send button takes the environment’s colour, and Production asks before every send.
- secrets
Secrets stay secret
Secret values are stored encrypted, can’t be read back in the app, not even by you, and never end up in execution history. In the web app they’re filled in on Collapy’s servers at send time.
- overrides
Try a value just for you
Override a variable for one request, on your device, without touching the team’s environment. Push it back as the shared value when it’s right.
Bring your API in. Keep it tidy.
Import what you already have from Postman or an OpenAPI spec, then organise it in collections the whole team shares.
- collections
Nested collections
Folders for your requests, as deep as you need, each with its own auth. Move, duplicate, or undo a delete for a few seconds after.
- search
Find anything
Filter the Explorer tree, pin favourites to their own panel, or press Ctrl+K to search collections, requests and environments.
- postman
Import from Postman
Bring a Postman Collection v2.1 export. Folders become collections, saved examples become presets, and collection variables can become an environment, secrets included.
- openapi
Import from OpenAPI
Turn an OpenAPI 3 JSON spec into one request per operation, grouped by tag, with a {{baseUrl}} environment and example bodies generated from the schema.
Shared by default. Private when you need it.
Organizations hold your plan and your people. Workspaces hold the work, and everyone in one sees the same requests, environments and history.
- live
One live workspace
When a teammate creates, renames or saves something, it appears on your screen without a reload. No exports, no files to pass around.
- executions
Shared execution history
Every send is recorded with its response, timing and who sent it, so a teammate can open the exact response you saw. Credentials are redacted in the stored copy.
- roles
Owner, Admin, Editor
Roles at the organization and in each workspace. Invite people by email and choose their workspaces in the same step.
- private
Private work in progress
Mark a request, collection or environment Private to keep it out of everyone else’s way. Its executions stay private too. Workspace admins and owners can still see it.
- offboarding
Disable, don’t delete
Disable a member to cut their access to every workspace at once. Enable them again and their roles come back.
Turn requests into test scenarios.
Chain saved requests, pass values between them and check every response, on every plan.
- scenarios
Chain requests
Build a scenario from saved requests. Extract values from one response and use them in later steps as {{steps.<step>.<key>}}.
- assertions
Assert on the response
Check the status code, response time, headers or any body value: equals, contains, regex, comparisons, ranges or a JSON schema.
- runs
See what failed
Run a scenario and see every step and assertion pass or fail, in a run you can open again later.
Laid out like your editor. Driven from the keyboard.
Panels around the edges, your open requests in tabs, a status bar at the bottom, and a shortcut for everything you do all day.
- CtrlEnter
- Send request
- CtrlS
- Save
- CtrlK
- Global search
- CtrlP
- Command palette
- CtrlE
- Hold to preview variables
- panels
Panels where you want them
Explorer, Environments, Request Variables, Executions and Response dock left, right or bottom, or float over the editor. Your layout is remembered on your device.
- tabs
Tabs that scale
Horizontal or vertical tabs, coloured tab groups, a searchable tab switcher, and a quick way back to the tab you just closed.
- palette
Command palette
Press Ctrl+P and run any command by name. The ones you used last come first.
More history, more automation.
Everything above is on every plan, Free included. Plans differ in seats, workspaces, cloud executions and how much history is kept, and a few features depend on the plan.
- change logUltra
Every save, with a diff
Each saved version of a request is kept. The Change Log tab shows who changed it, when, and exactly what changed, side by side.
- synced workspacesUltra
Your OpenAPI spec, kept in sync
Point a workspace at an OpenAPI URL. Click Sync now, or let your CI call the workspace’s webhook, and the requests are re-imported, stamped with the spec’s API version.
- test runsUltra
One run, several environments
Run a test scenario against several environments at once and compare the results side by side.
- audit logUltra
Audit log
See the privileged actions in your organization, such as member and workspace changes.
In your browser today. On your desktop soon.
The web app sends requests through Collapy’s cloud, so CORS never gets in the way. The desktop app will send them straight from your machine.