Managing data dynamically in Postman allows API requests to work with values that change during testing. Instead of manually entering values for every request, data such as resource IDs, tokens, timestamps, and test inputs can be generated, updated, and reused throughout an API workflow.
- Reduces hardcoded values in API workflows.
- Allows dependent requests to work with changing data.
- Makes repeated API testing easier to maintain.
Variable Resolution and Value Substitution
Variable resolution is the process by which Postman identifies a variable reference in a request and replaces it with the variable's current value when the request is executed. This allows requests to use changing data without modifying the request definition.
Example: if a variable is defined as:
user_id = 101
It can be referenced in a request as:
/users/{{user_id}}
When the request is sent, Postman resolves {{user_id}} and substitutes its value:
/users/101
The same concept can be applied to different request components:
- URL paths for dynamic resource identifiers.
- Query parameters for changing input values.
- Headers for values such as tokens or request identifiers.
- Request bodies for dynamic test data.
Variable substitution is particularly useful when a value is obtained or changed during an API workflow. For example, a user ID returned by one request can be stored in a variable and then referenced by a subsequent request.
const response = pm.response.json();
pm.environment.set("user_id", response.id);
The next request can use:
/users/{{user_id}}
This creates a dynamic flow in which the second request uses data produced by the first request rather than relying on a hardcoded value.
- Postman resolves {{variable_name}} references when a request is executed.
- The current value of the referenced variable is substituted into the request.
- Variable substitution helps connect dependent API requests.
- Updating a variable changes the value used by requests that reference it.
- Dynamic substitution reduces hardcoded data and supports reusable API workflows.
Extracting Data from API Responses
Postman can extract values from an API response and store them in variables for use in later requests. This is useful when a response contains dynamic data such as a user ID, order ID, authentication token, or other resource details.
Example: suppose an API returns the following response:
{
"id": 101,
"name": "John",
"email": "john@example.com"
}
The response data can be accessed in a post-response script using pm.response.json():
const response = pm.response.json();
pm.environment.set("user_id", response.id);
Here, response.id extracts the id value from the JSON response and stores it in the user_id variable.
The stored value can then be used in another request:
{{base_url}}/users/{{user_id}}
When the next request is executed, Postman substitutes {{user_id}} with the value obtained from the previous response.
Extracting Nested Data
For nested JSON responses, use the appropriate property path to access the required value.
Example:
{
"user": {
"id": 101,
"profile": {
"email": "john@example.com"
}
}
}
The values can be extracted as follows:
const response = pm.response.json();
pm.environment.set("user_id", response.user.id);
pm.environment.set("user_email", response.user.profile.email);
This approach allows specific response fields to be reused without manually copying them.
Extracting Data from Arrays
When the response contains an array, access the required element using its index.
{
"users": [
{
"id": 101,
"name": "John"
},
{
"id": 102,
"name": "Alice"
}
]
}
To store the first user's ID:
const response = pm.response.json();
pm.environment.set("user_id", response.users[0].id);
The extracted value can then be used by subsequent requests.
Benefits
- Automatically captures changing values from API responses.
- Eliminates manual copying of IDs, tokens, and other response data.
- Enables dependent requests to use data generated by earlier requests.
- Supports reusable and automated API testing workflows.
Passing Data Between Requests
Once a value has been stored, it can be referenced by another request using its variable name
Example:
GET {{base_url}}/users/{{user_id}}
If user_id contains 101, Postman sends the request using:
GET {{base_url}}/users/101
This is useful when a later request requires a value produced during an earlier operation.
Common examples include:
- Using a user ID to retrieve user details.
- Using an order ID to check an order.
- Using a product ID to update a product.
- Using an authentication value for a protected endpoint.
This approach allows related requests to use changing data without manually entering the values.
Chaining Dependent API Requests
Chaining dependent API requests means organizing multiple API operations so that one operation must successfully complete before the next operation can be performed. This is useful for testing workflows where later actions depend on resources created or modified earlier.
For example, an e-commerce workflow may follow:
Create User -> Create Order -> Get Order -> Cancel Order
In these workflows, the requests are logically connected because the outcome of one operation determines whether the next operation can proceed.
Chained workflows are useful for:
- Testing complete business processes.
- Verifying interactions between related API operations.
- Detecting failures in the middle of multi-step workflows.
- Automating end-to-end API scenarios.
Managing Authentication and Session Data
Authentication and session data are required when testing protected API endpoints. Postman variables can be used to manage values that change during an authenticated workflow.
Common authentication and session data include:
- Access tokens
- Refresh tokens
- Session IDs
- CSRF tokens
A typical authentication workflow is:
Login -> Authenticate -> Access Protected API -> Refresh Session -> Logout
Example: After login, an access token can be used to authorize subsequent protected requests:
Authorization: Bearer {{access_token}}
This helps test:
- Successful authentication
- Expired or invalid tokens
- Token refresh
- Session expiration
- Logout and session termination
Updating Variables During API Execution
Variable values may need to change while a request or workflow is being executed. Postman scripts can update values when new information becomes available or when a calculated value is required.
Example: A pre-request script can generate a current timestamp:
pm.variables.set("request_time", new Date().toISOString());
A script can also update a value according to the current response state:
const response = pm.response.json();
pm.environment.set("status", response.status);
Runtime updates are useful for:
- Current timestamps.
- Counters.
- Calculated values.
- Current application states.
- Values that change during repeated execution.
This allows the workflow to respond to its current execution state instead of relying only on fixed values.
Data-Driven Testing with External Files
Data-driven testing allows the same API test to run with multiple sets of input data. In Postman, CSV and JSON files can provide different values for each collection-run iteration.
Example: CSV file can contain
username,email
john,john@example.com
alice,alice@example.com
david,david@example.com
The request can reference the data using:
{{username}}
{{email}}
During the collection run, Postman uses the values from each row for the corresponding iteration.
Example:
Iteration 1 -> john -> john@example.com
Iteration 2 -> alice -> alice@example.com
Iteration 3 -> david -> david@example.com
Approach
- Testing the same API with different input values.
- Running multiple test cases without modifying the request.
- Testing different combinations of valid and invalid data.
- Handling large test datasets efficiently.
External files are especially useful when test data needs to be maintained separately from the API request and reused across collection runs.
Validating Dynamic Data
Dynamic data should be validated to confirm that the API returns values that meet the expected conditions. Validation can be performed on generated or changing values without manually checking each response.
Example: An API may return:
{
"id": 101,
"email": "john@example.com"
}
The response can be validated with:
const response = pm.response.json();
pm.test("Response contains valid data", function () {
pm.expect(response.id).to.be.a("number");
pm.expect(response.email).to.be.a("string");
});
Dynamic values can be checked for:
- Required fields
- Expected data types
- Valid formats
- Acceptable ranges or values
- Expected relationships between response fields
Best Practices for Dynamic Data Management
- Use clear and consistent variable names.
- Avoid hardcoding values that change during testing.
- Store only the values required by the workflow.
- Update variables when their underlying data changes.
- Use external files for large or reusable test datasets.
- Validate important dynamic values before using their results.
- Protect authentication and other sensitive data.
- Remove temporary values when they are no longer needed.
- Keep API workflows simple enough to identify where dynamic data changes.