Automate API Regression Testing with Postman Environments and Collection Runner
Learn how to use Postman environment variables, pre‑request scripts, and the Collection Runner to run the same API collection against multiple environments and validate end‑to‑end workflows.
24 Jun 2026, 23:42 UTC

The Problem: Manual API Validation at Scale
Testing a single API endpoint manually is simple, but validating an entire workflow across Development, Staging and Production is error‑prone. Manually updating URLs and authentication tokens for every request leads to configuration drift and missed regressions. The goal is to create a single portable test suite that can be executed against any target environment with one click.
Prerequisites
- Postman Desktop Application installed, version 10 or newer.
- A Postman Collection that contains the API requests you want to test.
- Valid credentials for the environments you intend to target (e.g., dev, staging, prod).
Step 1 – Create Environment Variables
Environment variables let you change the target server without editing each request.
- Open the Environments tab in the left sidebar and click **Create Environment**.
- Name it, for example **Staging**.
- Add a variable named
base_urland set its **Initial Value** to the server address (e.g.,https://api.staging.example.com). Use **Current Value** for any secrets that must stay local. - In each request replace the hard‑coded host with the variable syntax:
{{base_url}}/v1/resource.
Security note: Values placed in **Initial Value** are synced to Postman servers; keep tokens or keys in **Current Value** only.
Step 2 – Pass Data Between Requests with Pre‑request Scripts
Many workflows need a token from a login endpoint before calling protected resources. Store the token in an environment variable so later requests can reuse it.
In the **Pre‑request Script** tab of the login request add:
// Send login payload
pm.sendRequest({
url: {{base_url}}/auth/login,
method: 'POST',
header: {'Content-Type':'application/json'},
body: {mode:'raw', raw: JSON.stringify({username: 'testuser', password: 'secret'})}
}, function (err, res) {
if (err) { console.error('Login failed', err); return; }
const data = res.json();
if (data.access_token) {
pm.environment.set('jwt_token', data.access_token);
console.log('JWT token stored');
} else {
console.error('Token not found in login response');
}
});
Then, in any subsequent request set the Authorization header to Bearer {{jwt_token}}.
Step 3 – Define Test Assertions with pm.test
Use the Tests tab to verify each response. Each pm.test block creates a pass/fail entry in the Runner report.
pm.test('Status code is 200', function () {
pm.response.to.have.status(200);
});
pm.test('Response time under 800ms', function () {
pm.expect(pm.response.responseTime).to.be.below(800);
});
pm.test('JSON payload contains expected field', function () {
const json = pm.response.json();
pm.expect(json).to.have.property('id');
});
Step 4 – Run the Collection with Collection Runner
The Runner executes requests in the order they appear, passing environment variables between them.
- Open the Collection Runner (the **Runner** button at the top).
- Drag the target collection into the right pane.
- From the **Environment** dropdown select the environment you created (e.g., Staging).
- Keep **Iterations** at 1 and click **Run Collection Name**.
Verification and Diagnostics
| Check | Expected Result | Diagnostic Action |
|---|---|---|
| Environment resolution | Request URL shows the substituted base_url value. | Look at the request preview before sending; ensure no {{base_url}} remains. |
| Token propagation | After the login request, the environment variable jwt_token holds a non‑empty string. | Open **Environment Quick Look** (eye icon) during the run to confirm the value changed. |
| Test results | All pm.test blocks appear green in the Runner report. | Open the **Postman Console** (View → Show Postman Console) to see console.log output from scripts. |
Limitations and Recovery
Limitations: The Runner runs requests synchronously; long‑running asynchronous processes can cause timeouts unless you add delays in Pre‑request scripts, which may slow large collections. Storing secrets in Initial Value exposes them to Postman’s sync service; always use Current Value for tokens, API keys, or passwords.
Recovery: This workflow only modifies Postman metadata (environments, collection scripts). To roll back, delete the created environment via the Environments sidebar or revert the collection to a previous version using Postman’s version control (fork → restore). No server‑side state is changed.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.