API testing & workflow platform

Test your APIs, on autopilot.

API Hub is a collaborative workspace for designing, testing and automating API requests. Paste a cURL, build requests in your browser, chain them into workflows with sandboxed formulas, stand up mock servers — all across teams with fine-grained access control.

  • REST · SOAP · GraphQL
  • Paste-cURL auto-parse
  • Scratchpad testing
  • Multipart & file uploads
  • Mock servers
  • Sandboxed formulas
  • Workflow automation
  • Teams & RBAC
  • Audit & retention
The workspace

One place to design, test and automate every request

Everything a team needs to ship working APIs — a full request editor, instant cURL parsing, safe execution, organised collections and automation that runs on your behalf.

Build any request

A Postman-style editor for REST, SOAP, GraphQL and auth requests. Query params, headers, auth providers and rich bodies live in one focused panel.

  • All methods: GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS
  • Bodies: JSON, XML, form-urlencoded, raw text, GraphQL and multipart with file uploads
  • Folder-level auth providers and environment variable substitution
  • Syntax-highlighted JSON / XML / JS editors with formatting

Paste cURL, get structure

Stop rebuilding requests by hand. Drop a cURL command anywhere and API Hub parses the method, URL, query params, headers and body for you.

  • Auto-detected in the create request modal and straight into the URL field
  • Scratchpad to test a cURL without saving anything to your collection
  • Save the parsed request into any collection or nested folder when ready

Send before you save

Every edit updates the working copy the instant you type — Send runs exactly what you see, and the stored request only changes when you hit Save.

  • Ephemeral run engine — no stored request required to fire a call
  • Dirty-state dot flags unsaved edits on tabs and the Save button
  • Per-request undo/redo and back-to-previous for every open request

Organise collections & folders

Nested folder trees keep your API catalog tidy as it grows. Move, duplicate and rename rows without leaving the keyboard.

  • Nested folders with drag-and-drop moves for requests and folders
  • Duplicate requests or whole folders instantly (Ctrl/Cmd + C)
  • Import and export collections in a portable JSON format
  • Inline rename with F2 and shortcuts for everything else

Automate with workflows

Turn individual requests into reliable pipelines. Extract values, transform payloads, assert results and trigger runs on your schedule.

  • Sandboxed formula engine evaluates expressions server-side
  • Assertions and tests per request with clear pass/fail feedback
  • Schedule automations on cron or fire them instantly via webhook
  • Multi-step workflows feed one request’s output into the next

Mock servers & generated code

Let frontend and partner teams build against endpoints that do not exist yet — then hand them ready-to-run client code in minutes.

  • Per-project mock server with realistic routing and response data
  • Mock data store preloaded and editable at runtime
  • Generate request code for Node, Axios, Python, Go, PHP, Laravel and more
Workflow

From idea to integration in four steps

The same flow powers a quick sanity check and a production-grade automation pipeline — no setup ceremony in between.

01

Create

Paste a cURL or type a method and URL. Params, headers and body are structured into editable fields instantly.

02

Send & inspect

Run the request with environment variables and encrypted secrets injected. Inspect a clean, readable response.

03

Assert & automate

Add formulas and assertions, then chain requests into scheduled or webhook-driven workflows.

04

Share & ship

Generate client code, share collection links, stand up a mock server and watch history across the team.

Environments & history

Reuse the same requests across staging, test and production without editing every URL by hand.

  • Workspace environment variables substitute into URLs, headers and bodies
  • Encrypted secret values never leave the vault in plain text
  • Every send is recorded in run history — for a request or the whole project
  • Response viewer shows status, headers and pretty-printed bodies

Safe by default

Testing means touching real systems — API Hub makes sure only intended data moves, and everything is sandboxed.

  • Sandboxed execution for formulas and workflows — isolated-vm, never the host
  • Secret variables are encrypted at rest in a server-side vault
  • Sensitive responses can be redacted before they reach the screen
  • Retention policies prune history and data on your schedule
Teams & workspaces

Built for teams that ship together

From a solo side-project to an organisation with many teams, API Hub keeps the right requests in front of the right people.

  • Organise work across organisations → teams → workspaces → projects, each with its own collections and requests.
  • Self-service membership management on every project — add members and change roles as the project manager.
  • Share workspaces and collections, and invite collaborators by role so everyone works from the same source of truth.
  • A project overview that shows collections, requests, automations and recent runs at a glance.
  • Full run history and notifications keep the whole team aware of what happened and when.
Security & access

Enterprise-ready controls on every tier

Access is enforced at the API and the database, secrets are protected, and everything sensitive is recorded for review.

  • Every route checks access — roles VIEWER · EDITOR · MANAGER · ADMIN (plus SUPPORT in the portal) gate every operation.
  • Secret environment values are stored encrypted in a server-side vault and only decrypted for a run.
  • Formula execution runs in an isolated sandbox (isolated-vm), never on the host process.
  • Per-request response redaction, row-level DB security and a complete audit log.
  • Configurable retention policies keep history and data under your control.
Pricing

Plans for every stage

From a single workspace to organisation-wide control — workspaces, projects, seats and storage grow with your team. Your first recharge of Starter, Pro or Team adds 5, 10 or 15 extra days of validity.

FAQ

Frequently asked questions

What exactly is API Hub?

API Hub is a collaborative, Postman-style platform for designing, testing and automating API requests. You build requests in a browser workspace, run them against live or mock endpoints, assert the results, and chain them into workflows — with teams, workspaces, projects and role-based access on top.

Do I need a credit card to try a paid plan?

No card is required to sign up — the Free plan is free to use forever. Paid plans do not come with a separate trial: instead, your first recharge of Starter, Pro or Team adds 5, 10 or 15 extra days of validity on top of the paid period. If a paid plan is not for you, you can always drop back to the Free plan without losing your data.

Can I really paste a cURL and start without saving?

Yes. Paste a cURL into the create modal or the URL field of any request and it is parsed into method, URL, params, headers and body automatically. The scratchpad lets you fire that request immediately, with nothing saved until you choose to.

How are formulas and workflows kept safe?

Formula expressions run in an isolated sandbox server-side, with limits that stop runaway work. Workflows chain request outputs through that engine, and every run is recorded in history with retention policies you control.

What are the plan limits?

Plans scale the number of workspaces, projects and seats plus storage. Free is one workspace and project; paid tiers add more (and unlimited on Team/Enterprise). See the pricing grid above for the current limits.

Can I switch, cancel or get enterprise terms?

Yes. Upgrade, downgrade or cancel anytime — changes apply at the end of the current billing period, and yearly billing saves roughly 17%. The Enterprise plan adds unlimited seats, SAML SSO, an SLA and a dedicated customer success manager; contact sales for custom pricing.

How is my data secured?

Secret values are encrypted in a server-side vault, database access is enforced row-by-row, request responses can be redacted, and sensitive operations are written to an audit log. Formula runs are sandboxed and data retention is configurable per workspace.

Ready to test your APIs on autopilot?

Start free today — paste your first cURL in under a minute. When your team grows, pick a paid plan and earn extra validity days on your first recharge.