13 ms·
Show HN: I created Postwoman, an online, open-source API request builder
- dalbotex 7y agoDon't CORS restrictions basically render this whole tool useless?
- Vogtinator 7y agoIt indeed seems to be totally broken.
- jacobush 7y agoI don't understand. Plus it has 1700 stars on github.
- coldtea 7y agoWhat exactly is there to "understand"?
- lol768 7y agoI suppose it's useful for APIs with permissive CORS headers. Maybe there's also some way to run it locally as a separate app with SOP disabled? Maybe something like: $ chromium-browser --disable-web-security --user-data-dir="/tmp" --kiosk https://liyasthomas.github.io/postwoman/ Unrelated, meta note: why does indiehackers need a separate interstitial splash screen, visible for ~4-5 seconds to load a simple article page?
- ge96 7y agoload balancer /s
- oauea 7y agoThen you're launching a second chromium instance and practically recreating Electron.
- lol768 7y agoYes, indeed. Sort of defeats the point of Postwoman being more performant.. Still, this seems safer than the various extensions that have been recommended in order to disable the SOP. I'd rather the user's data wasn't on the line.
- oauea 7y agoRight, so I don't see any reason why I would ever want to use this tool when far superior alternatives (like postman) exist.
- ge96 7y ago~~Does Postman work with JS? I've used it with Python.~~ Oh nvm I'm thinking of a different service
- jamessb 7y agoIt seems the user created this because they thought that Postman required too many resources as an Electron app. I'm not sure why they didn't just use a commandline tool (e.g. httpie [1]) that would work with any API, rather than just those with permissive CORS headers. [1]: https://httpie.org/ https://httpie.org/
- batoure 7y agoSo Postman used to be a lightweight Chrome plugin. Then its developers turned it into an electron app with lots and lots and lots of features. They did this as a vehicle to begin offering paid features and enterprise plans. To your second point, despite years of writing Curl some times its nice to have an interface and for some people that is their personal preference.
- jannes 7y agoAnother reason why they moved to Electron may be that Google announced [0] in 2016 that they will discontinue Chrome Apps (outside of Chrome OS). [0]: https://blog.chromium.org/2016/08/from-chrome-apps-to-web.html https://blog.chromium.org/2016/08/from-chrome-apps-to-web.ht...
- ch_sm 7y agoit could proxy the requests through a server.
- deleted 7y ago[deleted]
- losvedir 7y agoI use Postman a fair bit, and looking through my history it's mostly playing with 3rd party APIs to see what format they return and how they respond to query params and such. So it works for that purpose, since those generally won't have CORS restrictions. It probably won't work for testing of your own API endpoints for, say, a SPA, though, which is likely to have CORS. But for local testing where I control the backend, I mostly just rely on printing responses to the terminal anyway.
- maddening 7y ago> I use a low-end PC and can't possibly afford to run another Electron app > That's why I created my own API request builder with pure JavaScript (I used Vue.js) + HTML + CSS So... the only differences are not running this as a separate process and NIH?
- nicoburns 7y agoPresumably lower memory usage due to not running in a separate process. On a low-end PC this is a completely valid concern. Chrome is memory hungry. Running one instance might be viable. Running 2, 3 or 6 probably isn't (and you can always choose a less memory-hungry browser).
- jmnicolas 7y agoIf performances are a concern I would build it in QT, not Javascript. Just opening Firefox eats like 400 MB ram on my PC !
- tumetab1 7y agoIt makes me question, is there any way to run a slim browser for these kind of tools? It would be cool to have a tool that would: * run a very slim browser tab for each tool * I cloud load/save sites into tools (So I can really run them offline) * Could have a shortcut or a starting page that's just links to my saved tools
- amrrs 7y agoGithub: https://github.com/liyasthomas/postwoman https://github.com/liyasthomas/postwoman Back Story: https://dev.to/liyasthomas/i-created-postwoman-an-online-open-source-api-request-builder-41md https://dev.to/liyasthomas/i-created-postwoman-an-online-ope...
- tumetab1 7y agoOpening the link I was hoping that this would be a postman with better support for file uploads. I have a long lived desired to be able to have postman request which embeds a file to upload. I really like postman features and UX but when I need a test suite for a file upload endpoint it doesn't match. Tried several hacks to achieve to embed files but none worked. If the endpoint supported Content-Transfer-Encoding it would be kind of easy to do.
- splatcollision 7y agoIf you're on macos, you want https://mmattozzi.github.io/cocoa-rest-client/ https://mmattozzi.github.io/cocoa-rest-client/
- scarface74 7y agoYou don’t need a hack. I do it all of the time. https://stackoverflow.com/questions/16015548/tool-for-sending-multipart-form-data-request https://stackoverflow.com/questions/16015548/tool-for-sendin...
- tumetab1 7y agoThat doesn't work for the test runner, just for one time off requests. Just closing and opening postman it looses the file you had choosen.
- scarface74 7y agoUse the export functionality to create a script in your language of choice? (c#, Java, Curl, etc.)?
- tumetab1 7y agoIn my opinion that would defeat the purpose of the tool. I like to have a postman suite file that I can share... using other tools and integrations would kind of break that. Postman best thing is that an easy enough tool for beginners and customizable enough to be a test suite for an API. The cost of leaving the tools for it's pretty high.
- oakesm9 7y agoI'm just a user of this, but if anyone is looking for a truly native MacOS version of Postman, you should take a look at Paw. https://paw.cloud/ https://paw.cloud/
- rvz 7y agoI never knew this existed, thanks! After looking for a Postman alternative (Due to Electron) I took a look at Paw and I am really enjoying using it on my MacBook and replaced Postman with Paw.
- dewey 7y agoUsing this for years already and the developer is very responsive if there are bugs. Can highly recommend it.
- girvo 7y agoAdding to the praise, I adore Paw and the developer is amazingly responsive. Highly recommended on my end.
- toomuchtodo 7y agoPaid for Paw years ago, no regrets. Only use it occasionally, but super pleased with the experience when needed.
- barnaclejive 7y agoPaw++
- fredsted 7y agoPaw is the gold standard for these kinds of utilities. If you're still using something else, you're missing out.
- OutsmartDan 7y agoPaw is fantastic- just missing GraphQL support to be even more fantastic.
- notus 7y agoCan it use postman collections?
- archie2 7y agoPrepare to get bombarded by politically correct crazy people.
- maxelerator 7y agoI'm pretty happy with the features of the vscode-restclient called VS Code extension. https://github.com/Huachao/vscode-restclient https://github.com/Huachao/vscode-restclient
- leandot 7y agoAfter Postman lost all my saved queries after an upgrade I switched to Insomnia - https://insomnia.rest/ https://insomnia.rest/ and am quite happy with it.
- stronglikedan 7y agoI'm curious to know what gives you the confidence that Insomnia won't lose your saved data? Are you paying the premium for the data sync?
- cerberusss 7y agoNot OP, but since Insomnia is a native app, it'll probably store its data and preferences in ~/Library. That is of course backed up via Time Machine.
- laurent123456 7y agoWhy wasn't the Postman data backed up by Time Machine?
- umen 7y agoIt is not nattive , very hard to find native apps https://github.com/getinsomnia/insomnia https://github.com/getinsomnia/insomnia
- peteforde 7y agoI'm surprised that nobody has mentioned Insomnia. https://insomnia.rest/ https://insomnia.rest/ It's an excellent tool that allows defining workspaces and even sharing sets of routes with members of your team. It's one of my favourite tools.
- dfsegoat 7y agoI've been using Insomnia since I had some issues with Postman, and I have not looked back.
- jgalentine007 7y agoAnother vote for insomnia!
- asdkhadsj 7y agoCan you comment on the I/O of documentation from it? Ie, I hate how Postman and friends want to be the nexus / saas of my products API documentation. I want to work with something in a common format, like OpenAPI, RAML or BlueprintAPI. These HTTP clients are nice, but I want them to be a tool, not required. Thoughts?
- Improvotter 7y agoI've used them all: Postman, Insomnia, Paw, and other online web apps. Unfortunately none come close to being usable for large APIs imo. Some of the problems I faced off the top of my head (it's almost 2 years ago now since I tried them all though, but I haven't seen much change to be honest): Insomnia: doesn't really have any support for documentation stuff. It is just an HTTP client that if you share your workspace with your team, is some kind of documentation. But you cannot share this outside of your organisation. Postman: their documentation implementation seems one of the better ones, but Postman itself just isn't very DRY. For example we have a slightly different authentication scheme which isn't supported so we had to add a simple Javascript snippet to each request, but keeping all of them updated is impossible. I personally also wasn't a big fan of their client and it's not very user-friendly imo. Paw: honestly pretty good. I asked them a few years ago to implement this and keep me posted. They eventually implemented some documentation stuff, but it's proprietary and using a plugin to convert to RAML or something else is a pain. When I used it, it also wasn't very expansive. It also faces the same problem as Insomnia: you are not able to share it outside your team. Though it also requires everyone to buy Paw and own a Mac. I switched to Linux a few years ago and so don't use my account anymore, that I paid for. OpenAPI/Swagger: OpenAPI itself is great, but the website GUI that Swagger converts it to is basically useless for large APIs. You cannot nest anything and it is not very good for public documentation. RAML: I personally love this syntax the most. Though there barely is any support for it. You cannot find any mature library or application that can convert it to actual usable documentation pages. It's also honestly a big pain to write all of the documentation at once. BlueprintAPI: this is just way too barebones. I immediately stopped using it after trying it. There were some others I tried, none really noteworthy. It's been a while as well so it's possible that some of my opinions are out of date.
- howiroll 7y agoWhy make this when CORS blocks your path? The app is completely useless.
- alperakgun 7y agoRested firefox extension is quite nice too.
- jgrpf 7y agoI like wuzz. An ncurses interfaces for HTTP requests that allows me to save my configuration. It's super lightweight and all I need. https://github.com/asciimoo/wuzz https://github.com/asciimoo/wuzz
- duiker101 7y agoSince it was added, my favourite way to do API requests is IntelliJ Http client https://www.jetbrains.com/help/idea/http-client-in-product-code-editor.html https://www.jetbrains.com/help/idea/http-client-in-product-c... You just write the requests. That's it. Not much of an interface or anything. It also supports creating requests from a cURL command (so in Chromium devtools you can copy the cURL request and then paste it in IntelliJ).
- sancha_ 7y agoThis is also what I use. Others mention insomnia, but it does not support testing responses (validating them) with a script. With the Http Client in IntelliJ you can do that, as well as with Postman. But with Postman you need to import/export everything and put it into you projects, so you can check it in with your source code. Using IntelliJ you don't need to do that anymore too. Having used Postman, Insomnia and the IntelliJ Http Client, the last one is the best out of them all.
- GordonS 7y agoThat's pretty nice! I'm a Rider user, which is based on IntelliJ... Will need to check if Rider has this!
- beardedwizard 7y agoDon't forget to paste your auth tokens into a random website today.
- edoceo 7y agoEveryone: don't use existing please make new, unique keys for services like this. Time-box and revoke!
- iandinwoodie 7y agoCan you please elaborate on what you mean by time-boxing and how you achieve it? I'm assuming it means to assign a time scope to a key and then revoke it's access outside of that time period. This would require access to the API authentication methods, correct? Otherwise, for API's that you don't have backend access to (e.g., GitHub API) you should just generate a token for testing and manually delete it when you are done?
- dennisnedry 7y agoThey mean to assign an expiration date to your tokens. Then when you're done testing, still revoke the token, even if you haven't reached the expiration date.
- edoceo 7y agoThis is exactly what I meant, thank you.
- oauea 7y agoHow does that stop the operator from watching the logs, and stealing all my data?
- vinylkey 7y agoIs it any safer than pasting your auth tokens into a standalone application like Postman? That can just as easily send that information somewhere else, but now you can't press F12, get a network tab, and look at outgoing requests.
- whoisthemachine 7y agoThat's a neat side project, and I like the idea of having a quick website I can go for testing quick requests rather than having to open a full-fledged app.
- JaceLightning 7y ago> this is not at all an alternative to Postman - it does the job very beautifully and minimally. -_- wow. Way to stereotype women
- AngeloAnolin 7y agoNavigating to the site[1] and asking me to install it on my Chrome browser without providing any relevant information is a big security no-no. I think the developer should have provided more information on the product and link to a trustworthy site where the binaries could be verified and added (safely) into the browser. [1] https://liyasthomas.github.io/postwoman/ https://liyasthomas.github.io/postwoman/
- lpcvoid 7y agoThis is probably the worst website I have ever used. Why does it have a progress bar, why is everything slow, why is it not simply a html page. What is going on with these people. Also, author quote : >I use a low-end PC and can't possibly afford to run another Electron app But proceeds to create more slow running web stuff. Okay. Is it just me or does this just seem like such a strange behavior?
- neotek 7y agoEven by HN standards this seems like an excessive level of cynicism for a bog standard blog post format.
- lpcvoid 7y agoI did not mean to come about as cynical, I simply do not understand this mindset. If you identified a problem, why not fix it? Why keep on making the same decision with the same deterministic outcome?
- jakelazaroff 7y agoIf you don't want to come across as cynical, you could probably have done without these superlatives: > This is probably the worst website I have ever used. > What is going on with these people.
- throwaway8941 7y agoWell, it _is_ 5.4 MB of data for a short text-only blog post. Even by today's web standards this seems like an excessive amount of bloat.
- klinskyc 7y agoAre you talking about the indiehackers website? That's not made by the author of the post
- lpcvoid 7y ago
- oauea 7y agoIs this affiliated with Postman? It seems disingenuous to reuse their name if not.
- dyeje 7y agoCame here to say the same. Seems needlessly antagonistic.
- pelasaco 7y agoIt's PC!
- JungleGymSam 7y agoBut inclusion!
- unicornAccount 7y agoPostman had a "man" in it so it needed a feminist touch with less toxic masculinity
- abtinf 7y agoHere is the definition of trademark infringement directly from USPTO [1]: "Trademark infringement is the unauthorized use of a trademark or service mark on or in connection with goods and/or services in a manner that is likely to cause confusion, deception, or mistake about the source of the goods and/or services." I'm not affiliated with Postman in any way. But if I was, I'd already have sent a note to my lawyers to collect evidence, issue a cease and desist letter, get your project kicked off of github, and prepare for the possibility of lawsuit. Given the nature of your project and the extreme similarity to the name "Postman", I would strongly urge you to change your project's name before you expose yourself and your family to potential financial ruin. [1] https://www.uspto.gov/page/about-trademark-infringement https://www.uspto.gov/page/about-trademark-infringement
- jjeaff 7y agoFirst, doesn't even look like it's a commercial product. Second, the creator says they don't have the money right now for a domain name. You can't squeeze blood from a turnip. And they may not even live in a country that respects US trademark law. Seems like a polite request from postman would be a good place to start.
- systematical 7y agoHow does performance compare to PostMans laughably bad performance? I'd love to drop postman.
- joshmn 7y agoPlenty of alternatives. Paw[0], Insomnia[1] to name a few. [0] https://paw.cloud/ https://paw.cloud/ [1] https://insomnia.rest/ https://insomnia.rest/
- RyJones 7y agothis is pretty cool! I've needed a tool like this all week to mess with the GitHub API
- queercode 7y agoThis is neat. One of the projects in my to-do list is to make a gender-neutral version of postman, postperson. I guess now I can just fork this. Thx!
- riston 7y agoWorking on integrating other companies APIs and find declarative approach easier like VSCode has this extension where you could write all API calls in code. https://marketplace.visualstudio.com/items?itemName=humao.rest-client https://marketplace.visualstudio.com/items?itemName=humao.re...
- ticmasta 7y agoIf you're already in VS Code I prefer the rest extension as well. It's great for making quick one-off calls but is a little under-powered for organizing larger sets of endpoints, credentials, etc
- riston 7y agoYou can create env variables, local variables, use response results in next request etc.
- unhammer 7y agoHm, web based so defeated by CORS (plus privacy issues unless you install it on your own server, but then Postman itself is closed source …). Fortunately there's an Emacs package for this =P http://emacsrocks.com/e15.html http://emacsrocks.com/e15.html
- Sree_Inventrust 7y agoGreat, You can host your open source API on www.inventrust.com as well. This is a blockchain enabled, collaborative Exchange for Trusted software code.