Open source · Node 18+, no npm install
A Postman collection is a map. Gobiman draws it, runs it, and lets you search what came back.
Every API team has a Postman collection: a hundred requests in folders, each with a URL and a token. Postman shows it as a list. Gobiman shows it as what it is: a tree of calls that happen in an order, each one feeding the next, with the responses right there to read.
Two demo collections against public APIs are loaded, or drop your own on the page. Nothing you import or run is stored.

What you get
A mind map
The collection as a collapsible tree. After a run, each request shows status, time and size. Dashed arrows appear where an ID hard-coded in one request first appeared in an earlier response: the map shows which call feeds which.
A sequence diagram
Client ↔ API in call order, grouped by folder, with the path on the request arrow and the status on the response. Loops in a folder are drawn as loops. The whiteboard picture, drawn for you.
An inspector with a real JSON viewer
Resolved URL with variables highlighted, headers, body, scripts and the raw Postman JSON. The response opens as a collapsible tree: depth 1/2/3/all, search, copy value, copy JSONPath.
Search across everything
⌘K searches request names, URLs, descriptions and the full text of every response you have run, then jumps to the match inside the JSON.


Try it here, or run it on your machine
Try it here
- Pick a demo workspace, or drop your own collection and environment files on the page. They stay in your browser.
- Every browser gets its own in-memory session; nobody sees anybody else's. A session is dropped after two hours of silence. Nothing is ever stored.
- The hosted copy calls the public internet only: an API on your own network will not answer from here.
- A token you type into Variables lives in that session and nowhere else. Fine for an afternoon with a public API; not for credentials that matter.
Run it on your machine
- One HTML file and one Node file. No npm install, no account.
- The server binds to 127.0.0.1 only and rejects other origins; tokens are held in memory and never written to disk.
- Every folder of Postman files is a workspace; an environment file beside the collection fills its variables.
- This is the right choice for a private API, or any token you would not paste into a website.
git clone https://github.com/madhudream/gobiman
cd gobiman
node server.js # → http://localhost:4600
How it works
The server is a proxy, and only that. The browser cannot call most APIs directly because of CORS, so the page sends each request to the server, which makes the call and returns body, headers and timing. There is no database and no build step; the whole app is index.html, the whole server is server.js.
Data links are computed, not configured. After a run, Gobiman collects every ID-like value in every response and looks for the same values hard-coded in later request URLs; where it finds one it draws a dashed arrow from the response that produced it to the request that uses it.
Hosted mode is one flag. GOBIMAN_HOSTED=1 makes the same server listen on every interface, keep one session per browser, refuse private and link-local addresses on every redirect hop, cap a response at 8 MB and 30 seconds, and allow 90 runs a minute per client. The repository ships a Dockerfile and a Cloud Run deploy script, so you can host your own copy in minutes.
It reads Postman Collection v2 and v2.1: folders, raw, urlencoded and GraphQL bodies, collection- and request-level bearer and basic auth, collection and environment variables. Test scripts are shown but not executed. The URL hash is a shareable deep link: /app#ws=demo-jsonplaceholder&sel=1-2&view=seq.