FetchBeta

Fetch docs

Fetch is an AI-first API client. Everything you make lives in your organization: workspaces, collections, folders, requests, environments, specs, mocks and monitors. Fetch is an invite-only beta.

Getting started

  1. Accept the invite you were emailed, or ask an admin of your organization for one. Sign-ups are closed during the beta.
  2. Open the app. Install it from your browser's menu (Install Fetch) to get its own window and offline start.
  3. Create a collection in the sidebar, add a request, type a URL and press ⌘/Ctrl + Enter.
  4. Create an environment for values like {{baseUrl}} and pick it at the top right.

Members, invites, API keys, your own bucket and usage are under Settings.

Where requests run

ModeUse it forNotes
BrowserPublic APIs that allow CORSFree. Only CORS-exposed headers are visible; cookies are hidden.
Agentlocalhost, private networks, mTLS, proxies, HTTP/3, gRPC, WebSocket, MQTT, SQL, stdio MCPFree. Runs on your computer.
CloudPublic APIs without CORS, collection runs, monitorsSent from Cloudflare's network; public internet only. Metered as cloud requests (pricing).

Auto (the default) uses the agent for localhost and private hosts when it's paired, the browser for APIs known to allow it, then the agent, then the cloud.

Limits for cloud sends, runs and monitors:

  • HTTP(S) and GraphQL only. Other protocols run in your browser or the Fetch Agent.
  • No pre-request or test scripts (no-code assertions work). Auth: none, basic, bearer, API key, and OAuth 2.0 with a stored token or client credentials. Digest, NTLM, Hawk, AWS Signature, Akamai EdgeGrid, OAuth 1.0 and JWT run in your browser or the agent.
  • 30 seconds and 10 MB per response. No client certificates or proxies. Cookies aren't carried between the steps of a run.
  • Up to 1,000 steps per collection run. Monitors run every 5 minutes at most.

History

History lists the requests you sent, newest first. Only you see it.

  • Browser and agent sends stay on your device: this browser keeps them (your last 500, up to 30 days) and never syncs them.
  • Cloud sends are kept 30 days: a summary (method, URL with secrets redacted, status, time, size, tests, error) in your organization's database, and the request and response, with up to 256 KB of the body, in Cloudflare R2, or in your own bucket when you set one (where your bucket's rules decide how long they stay). Opening one loads its response, as do history.get and the MCP tool history_get. The requests of cloud collection runs and monitors are kept the same way: open them from the run, which everyone in your organization sees.
  • Deleting an entry removes it from History at once; a cloud send's stored copy still expires on its own.

The Fetch Agent

The agent is the fetch command-line tool running on your computer. It sends requests the browser can't (localhost, your LAN, client certificates, proxies), keeps vault secrets in your OS keychain, launches stdio MCP servers and proxies AI providers that don't allow browser calls. It listens only on 127.0.0.1:47823.

Download fetch for macOS, Linux or Windows, or install it from a terminal:curl -fsSL https://fetch.nightroll.app/install.sh | sh (macOS, Linux) orirm https://fetch.nightroll.app/install.ps1 | iex (Windows PowerShell).

fetch agent        # start it (keep it running)
fetch agent pair   # prints a 6-digit code

In the app, open Agent from the send menu or the command palette (⌘K → "Pair the Fetch Agent") and enter the code. The pairing token stays on this device.

The CLI

The same fetch program (see Download):

fetch login                         # paste an API key from Settings → API keys
fetch run <collection> -e <env>      # run a collection; JUnit, JSON, HTML and CTRF reports for CI
fetch mock <collection>             # serve a collection's examples locally
fetch --help                        # every other command: items, requests, import…

fetch run also runs Postman collections, so you can switch CI before switching people.

MCP and API keys

Fetch is a remote MCP server at https://fetch.nightroll.app/mcp (Streamable HTTP). Connect with an API key fromSettings → API keys, or sign in with OAuth in your browser. AI & MCPlists every tool, and QuickStart walks through the first connection.

Claude Code

claude mcp add --transport http fetch https://fetch.nightroll.app/mcp --header "Authorization: Bearer $KEY"

Claude (claude.ai and Claude Desktop)

Settings → Connectors → Add custom connector, name it Fetch and paste https://fetch.nightroll.app/mcp. You sign in with OAuth.

ChatGPT

Settings → Apps & Connectors → enable developer mode → Create, then use https://fetch.nightroll.app/mcp with OAuth.

Cursor

// ~/.cursor/mcp.json
{ "mcpServers": { "fetch": { "url": "https://fetch.nightroll.app/mcp", "headers": { "Authorization": "Bearer <key>" } } } }

VS Code (Copilot agent mode)

// .vscode/mcp.json
{ "servers": { "fetch": { "type": "http", "url": "https://fetch.nightroll.app/mcp", "headers": { "Authorization": "Bearer <key>" } } } }

The same key works on the REST API: POST https://fetch.nightroll.app/v1/call/<command> with a JSON body (see QuickStart).

Bring your own AI key

The in-app assistant uses your own key for Anthropic, OpenAI, OpenRouter or any OpenAI-compatible endpoint. Keys stay on your device; calls go straight from your browser (or through the agent for providers that don't allow browser calls). The assistant uses the same commands as the API and MCP server, shows a diff and asks before it changes anything. We sell no AI.

Variables and secrets

Use {{name}} anywhere in a request. Scopes, narrowest first: local, data (collection runs), environment, collection, global. Dynamic values like {{$guid}}, {{$timestamp}} and {{$randomEmail}} work as in Postman.

  • Default: stored and synced as typed.
  • Secret: encrypted at rest, redacted from history, logs and MCP output.
  • Vault: the value never leaves your device; only the name syncs.

Scripts and tests

Pre-request and post-response scripts run on QuickJS, in your browser or the agent, with Postman's pm.* API and Fetch's typed fx.* API, plus chai, lodash, crypto-js, moment, uuid, ajv, tv4, xml2js, cheerio and csv-parse. No-code assertions cover status, headers, JSON paths, time and size, and also run in the cloud.

Sync and offline

The app keeps a full copy of your organization in your browser (SQLite on OPFS). Every edit is applied locally first, then synced in real time over a WebSocket; teammates see changes and presence live. Offline, keep working: edits wait in an outbox and sync when you're back, merging per field (the most recent edit to each field wins). The status at the top shows offline, syncing or synced. The server keeps 30 days of changes: a device away longer reloads your organization's current state, then puts its own unsynced edits back on top.

Importing from Postman

  1. In Postman, export the collection (Collection v2.1) and your environments.
  2. In Fetch, open the command palette (⌘K) and run Import with the file contents.

Fetch also imports OpenAPI 3.x, Swagger 2.0 and cURL. Scripts using pm.* run unchanged in almost every case.

Keyboard shortcuts

Send⌘/Ctrl Enter
Save⌘/Ctrl S
Command palette⌘/Ctrl K
New requestAlt N
Close tabAlt W
Toggle sidebar⌘/Ctrl B
All shortcuts?