Prompt
How do I test APIs with OAuth, API keys, and JWT in one tool?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Use an API client that supports authentication presets, environment variables, and scripted token handling—the most common choice is Postman, but Insomnia, Hoppscotch, and Thunder Client can also work.
Best approach
Pick a tool that can handle these three auth types in one place:
- API keys
Add them as headers or query params, e.g.x-api-key: ... - OAuth 2.0
Use the built-in OAuth flow to get/access refresh tokens - JWT
Usually sent as a Bearer token:Authorization: Bearer <JWT>
Recommended setup in one tool
1) Use variables
Create environment variables like:
base_urlapi_keyaccess_tokenjwt_token
Then reuse them in requests:
{{base_url}}/users- Header:
Authorization: Bearer {{access_token}} - Header:
x-api-key: {{api_key}}
2) Separate auth by request or collection
- For API key endpoints, set auth to API key
- For JWT endpoints, set auth to Bearer token
- For OAuth, configure the OAuth 2.0 authorization in the tool and let it populate the access token automatically
3) Automate token refresh
If the JWT or OAuth token expires:
- Use pre-request scripts or built-in token refresh
- Store the refreshed token back into a variable
Tool recommendations
Postman
Best all-around for:
- OAuth 2.0 flows
- API key auth
- Bearer/JWT
- Environments and scripting
- Teams and collections
Insomnia
Good for:
- Clean UI
- OAuth 2.0
- Bearer/API key handling
- Environment management
Hoppscotch
Good lightweight option:
- Easy testing
- Supports headers, bearer tokens, variables
- Less powerful for complex OAuth automation
Example strategy
If your API uses all three:
- OAuth for login/token acquisition
- JWT for secured endpoints after login
- API key for partner/admin endpoints
In your tool:
- Create one collection/project
- Store all credentials in environments
- Use per-request auth settings
- Use scripts to extract tokens from responses if needed
Security tips
- Don’t hardcode secrets in requests
- Use environment variables or vaults
- Avoid sharing exported collections with live credentials
- Rotate API keys and tokens regularly
If you want, I can show you a Postman setup step-by-step for OAuth, API keys, and JWT in the same workspace.