Importing
Import from Postman collections/environments, OpenCollection (Bruno) YAML, OpenAPI/Swagger specs, and cURL commands.
Bring existing work into Impostor by importing Postman collections and environments, OpenCollection (Bruno) YAML collections, OpenAPI/Swagger API specifications, or by pasting a cURL command.
Postman compatibility
Impostor provides first-class support for importing Postman v2.1 collections. The importer accurately maps folders, requests, headers, body modes (including binary file bodies), and scripts. It also correctly handles Postman’s authentication and script inheritance, ensuring your setup remains intact.
You can import Postman environments directly; any variables marked as secret will be securely migrated to Impostor’s encrypted secret storage. The Environments section’s ⋮ menu offers Import from Postman as a shortcut, with the environment kind pre-selected.
Importing several files at once
The import dialog accepts multiple files in one batch — Postman JSON exports, OpenCollection YAML, or OpenAPI/Swagger specs — browse for several files (or add paths one by one) and each is auto-detected. Files are imported independently, so a problem with one file never aborts the rest of the batch.
After an import, each file gets its own result row with counts and warnings for any features that couldn’t be mapped.
OpenCollection (Bruno)
OpenCollection is the open YAML format Bruno 3.x
writes natively — the successor to its .bru DSL. Impostor imports it in every shape it
comes in:
- A collection folder on disk — pick its
opencollection.ymland the whole tree comes with it: one.ymlper request, each sub-folder’sfolder.yml, and everything underenvironments/. Picking a nestedfolder.ymlimports just that subtree. - A bundled single file — one document carrying the tree in a nested
itemsarray, with environments inline underconfig. Detected by content, so the file name doesn’t matter. - A single request file — imports as one request into the folder you picked, with no wrapper folder around it.
- A standalone environment file — the shape Bruno writes under
environments/, added to the workspace’s environments.
Only a picked opencollection.yml or folder.yml speaks for its directory. A bundled
file under any other name is read on its own, so dropping one into a folder of unrelated
YAML never sweeps that folder up.
What maps across
- Folders and requests — with
info.seqpreserved, so the sidebar keeps the order you had in Bruno. - Auth —
inherit,none, basic, bearer, API key (header/query), digest, AWS SigV4, and OAuth 2.0 (client credentials and authorization code, with PKCE). Collection- and folder-levelrequest.authbecomes folder auth that descendants inherit, exactly as they did in Bruno. - Bodies —
json,text,xml,sparql,form-urlencoded,multipart-form,file, and GraphQL (query + variables). Where a request carries several body variants, the selected one is imported. - Protocols — HTTP and GraphQL, plus WebSocket and gRPC requests (a
grpc://target, its fully-qualified method, metadata, and the message draft). - Headers, query and path params — disabled rows stay disabled. Path parameters are
substituted into the URL, since Impostor addresses them with
{{variables}}rather than a separate table. - Variables and environments — including typed values and
secretvariables, which land in Impostor’s encrypted vault rather than on disk. - Settings —
timeout,followRedirects, andmaxRedirects, at both request and folder level.
Scripts and assertions
Script code is imported verbatim, so nothing is lost — but Bruno’s scripts use a bru/req/res API while Impostor’s use im.* (with pm.* as a Postman-compatible
alias), so expect to port them. before-request becomes the pre-request script; after-response and tests are concatenated into the post-request script.
Declarative runtime.assertions have no Impostor equivalent. Rather than dropping them,
the importer appends them to the post-request script as an inert comment block so you can
port them to im.test(...).
Known limitations
oauth1, ntlm and wsse auth import as No Auth with a warning, as do the OAuth 2.0
implicit and resource-owner-password flows. WebSocket draft messages and docs blocks
aren’t imported. Anything that couldn’t be mapped is listed in the import’s warnings.
OpenAPI & Swagger
Impostor imports OpenAPI 3.0/3.1 specifications, with best-effort support for Swagger 2.0. Specs can be either JSON or YAML — the format is detected automatically.
Each spec becomes a collection folder named after the API’s title. Operations are grouped into sub-folders by their first tag (the Swagger-UI convention); untagged operations land at the collection root. The importer maps:
- Servers → a
baseUrlvariable every request is built on ({{baseUrl}}/path). Server-URL template variables (and Swagger 2.0’shost/basePath/schemes) are resolved into folder variables you can point at different environments. - Path/query/header parameters — path templating like
/users/{id}becomes{{id}}, and required parameters are imported enabled. - Request bodies — a representative JSON body is generated from the operation’s schema (using declared
examples where present), with local$refs resolved. Form and multipart bodies map to their field lists. - Security schemes —
httpbearer/basic,apiKey(header/query), andoauth2flows map to the matching auth type. Because a spec never contains credentials, these are imported as empty placeholders for you to fill in. Spec-wide security becomes the collection’s auth; per-operation security overrides it.
Known limitations
External or remote $refs (to other files or URLs) are skipped, oneOf/anyOf compositions import using their first option, and response examples aren’t imported. Anything that couldn’t be mapped is listed in the import’s warnings.
cURL commands
For quick ad-hoc requests, you can import a request directly by pasting a cURL command. Impostor will parse the command and populate a new tab with the corresponding URL, method, headers, and body.