Django → Postman collection
Not every Django API uses DRF. routeman also handles plain Django views, forms, JSON endpoints and session logins with CSRF, and writes a Postman collection you can send straight away.
Plain Django has no schema, and routeman doesn't need one
OpenAPI tools for Django mostly assume Django REST framework. A classic Django project, with function views returning JsonResponse, FormViews and a login page, has nothing for those tools to read. routeman works from the URLconf and the view code itself.
What routeman reads
- URLconf:
path(),re_path()and nestedinclude(), with converters (<int:pk>,<uuid:id>,<slug:slug>) turned into typed Postman variables. Admin and static routes are skipped. - Methods:
require_http_methods,require_POST/require_GET, theget/post/put/deletehandlers of class-based views, andif request.method == "POST"branches. - Bodies:
form_classand ModelForms (field types, choices, required),request.POST[...],request.FILES(multipart file pickers) andjson.loads(request.body)(JSON body). - Query parameters: anything read from
request.GET. - Auth: session logins, plus Bearer/Token auth if the project also uses DRF. Form requests send an
X-CSRFTokenheader filled from thecsrftokencookie. - WebSockets: Django Channels routes are listed in the collection description.
Example
# accounts/views.py
@require_POST
def signup(request):
data = json.loads(request.body)
user = User.objects.create_user(
email=data["email"], password=data["password"], name=data.get("name", "")
)
return JsonResponse({"id": user.id}, status=201)
def search(request):
q = request.GET.get("q")
page = int(request.GET.get("page", 1))
...
class ProfileUpdateView(LoginRequiredMixin, UpdateView):
form_class = ProfileForm # first_name, last_name, avatar (ImageField)
# accounts/urls.py
urlpatterns = [
path("signup/", signup),
path("search/", search),
path("profile/<int:pk>/edit/", ProfileUpdateView.as_view()),
]
$ routeman routes
GET /accounts/profile/{pk}/edit/
POST /accounts/profile/{pk}/edit/ form: first_name, last_name, avatar
PUT /accounts/profile/{pk}/edit/ form: first_name, last_name, avatar
GET /accounts/search/
POST /accounts/signup/ json: email, password, name
This is real output. The Accounts folder contains:
- Signup: a JSON body
{"email": "user@example.com", "password": "Str0ngPassw0rd!", "name": ""}, found by reading the view code. The description notes that the list was inferred. - Search: query parameters
q(string) andpage(integer, from theint(...)cast). - Profile update (GET, POST, PUT):
multipart/form-datawithfirst_name=John,last_name=Doe, a file picker foravatar,{{profile_id}}in the path, and a field table showing which fields are required.
Session + CSRF in Postman, solved
Django form views are hard to call from Postman because of CSRF. routeman handles it in two parts. A collection-level script saves the csrftoken cookie into a {{csrftoken}} variable after each response, and form requests send it as an X-CSRFToken header. Send any GET once so Django sets the cookie, and your POST and PUT requests pass CSRF validation.
Running it
$ source .venv/bin/activate
$ pip install routeman
$ routeman generate # uses manage.py's DJANGO_SETTINGS_MODULE
$ routeman generate -a config.settings.dev -b http://localhost:8000
Settings that read environment variables work as long as they are in .env (loaded automatically) or a file passed with --env-file.
Using Django REST framework too? See DRF to Postman. Both are handled in the same run. For a full walkthrough, read Export every Django URL to Postman.