Requestly
FeaturesHTTP InterceptorPricingRequestly vs PostmanBlogDocsDownload

Home / API Client / Enterprise Security

Built to pass your security review

SOC 2 Type II, SAML single sign-on with Okta and Microsoft Entra ID, role-based access control, encryption in transit and at rest, and audit logs.

Used by 300,000+ developers at 50,000+ companies

Security review, answered

An API client sees your staging tokens, your production headers and your customers’ payloads. It is reasonable for a security team to have questions about it.

SOC 2, encryption and audit logs

Requestly holds SOC 2 Type II certification, which covers the controls around how data is handled, who can reach it, and how that is monitored over time. Data is encrypted in transit and at rest.

SSO and role-based access

SAML single sign-on integrates with your existing identity provider — setup is documented for Okta and Microsoft Entra ID. Inside a shared project, role-based access control assigns Admin, User or Viewer, so edit rights follow responsibility. Audit logs record activity across your organization’s workspaces.

Where secrets actually live

The controls above matter, but so does the everyday path a credential takes. Two things are worth knowing:

  • Vault encrypts secrets through the operating system keychain and stores only a {{vault:key}} reference in the collection. The value never appears in an export, in console output, or in cloud sync.
  • Local projects keep an individual’s collections and environments on their own machine, with nothing synced at all.

Together those mean a shared collection can be genuinely shareable without the credentials riding along.

Contact us about an Enterprise plan →

Read the documentation →

Enterprise-ready security and compliance

Requestly meets enterprise security requirements with SOC 2 Type II compliance, SSO integration and role-based access control. Read the compliance announcement

SOC 2 compliant

SOC-II Compliance

Adheres to rigorous security standards for data protection and privacy.

Single Sign-On (SSO)

Simplifies user access with secure, centralized authentication.

Role-based access control

Ensures precise control over user permissions and data access.

Data encryption

Protects your data in transit and at rest with advanced encryption protocols.

Audit logs

Keeps a record of activity across your organization's workspaces.

Regular security updates

Keeps your environment secure with timely updates and patches.

How teams keep credentials contained

Security is not only a compliance checklist — it is where secrets end up day to day.

Secrets never in exports

Vault values are encrypted via the OS keychain and never appear in exports or cloud sync.

Roles per project

Admin, User and Viewer roles control who can change shared collections.

Local-only option

Local projects keep collections on the individual's machine, with nothing synced.

SSO with your IdP

Set up SAML SSO with Okta or Microsoft Entra ID.

Enterprise-ready security and compliance

Requestly ensures top-tier security with SOC-II compliance, SSO integration, and role-based access control. We protect your data and secure your workflows, making us the ideal choice for enterprises.

SOC-II Compliance

Adheres to rigorous security standards for data protection and privacy.

Single Sign-On (SSO)

Simplifies user access with secure, centralized authentication.

Role-based access control

Ensures precise control over user permissions and data access.

Data encryption

Protects your data in transit and at rest with advanced encryption protocols.

Audit logs

Tracks and records user actions and system events, giving you complete visibility.

Regular security updates

Keeps your environment secure with timely updates and patches.

Why developers switched

★★★★★ verified user

Requestly is the first API client that has genuinely replaced Postman for me. Everything runs locally, so my API data never goes through a cloud server. No bloat, no pressure to upgrade.

Hasan Toor
Hasan Toor
AI & Tech Educator
★★★★★ verified user

Postman stopped fitting the way our team works. We wanted our API collections in Git, not locked inside another tool. Requestly stores everything as plain JSON files, giving us full control over versioning and reviews.

NIJ Ruvos
NIJ Ruvos
Engineering Lead
★★★★★ verified user

We migrated from Postman to Requestly's API Client and it has been a great experience. Storing collections locally, keeping them in Git, and working with simple JSON files made the transition seamless.

Harry S
Harry S
Principal Engineer at Tapistro

Related features

More of what the Requestly API Client does.

Import from Postman

Migrate collections in one click

Local Projects

Keep collections on your machine

Team Workspaces

Shared projects with roles

Vault

Encrypted secrets, never in exports

AI Test Case Generator

Write tests from a plain-English prompt

Collections

Group requests into folders

See all features →

Frequently Asked Questions

Yes — Requestly holds SOC 2 Type II certification. See the compliance announcement.

Requestly documents SAML SSO setup for Okta and Microsoft Entra ID.

Shared projects use role-based access control with Admin, User and Viewer roles. See Team projects.

Yes. A local project stores all collections, requests and environment data on the individual machine, with nothing synced. See Local projects.

Unlimited usage, API access, SSO and SAML, GDPR and SOC 2 compliance, user access management, SLAs for support and uptime, invoice-based billing, and priority support. Contact us to discuss it.

Talk to us about your requirements

Enterprise plans add SSO, SAML, user access management, SLAs and priority support.

macOS, Windows & Linux