Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>Local API Workbench — REST & GraphQL ClientNew to Visual Studio Code? Get it now.
Local API Workbench — REST & GraphQL Client

Local API Workbench — REST & GraphQL Client

The Craft Build

| (0) | Free
Thunder Client alternative for VS Code with a one-time purchase. No login, no cloud. Import your Thunder Client, Postman and Insomnia collections in one click. REST, GraphQL, WebSocket, gRPC. Saved work is always yours.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Local API Workbench — Thunder Client alternative for VS Code

A REST, GraphQL, WebSocket and gRPC client for VS Code. Buy once. No login. No cloud.

Looking for a Thunder Client alternative? Import your Thunder Client collections and environments in one step, and keep working the way you did. The features Thunder Client users rely on most are here: collections, environments, tests without code, tc.* scripts, request chaining, the collection runner and a CLI for CI.

  • One-time purchase. No subscription. No account. No usage limits.
  • Your work stays yours. Requests are plain files in your repo. They stay readable and exportable even if your license ends.
  • Works offline. The license is checked on your machine. There is no license server and no telemetry.
  • Also replaces Postman, Insomnia and REST Client for most day-to-day API testing inside VS Code.

Made by Vinay Solapurkar · Phone: +91 99164 67570

Independent product. Not affiliated with, endorsed by, or connected to Thunder Client, Postman, Insomnia or their makers. Product names are used only to describe import compatibility.

Pre-release build. Pricing and the purchase page are not final. Thunder Client import is built from public format knowledge and has not yet been verified against real exports. See Compatibility.

What you get

  • Requests, collections, folders and environments in a native VS Code sidebar, with an editor panel for each request.
  • Your files, in Git. Workspace collections are saved to .apiworkbench/ as one small, stable JSON file per request. If you save without changing anything, Git shows no diff.
  • Secrets stay on your machine. Tokens and passwords go into VS Code secret storage. The files hold only references such as {{$secret:req/…/auth.token}}.
  • Tests without scripts. You can check status, headers, JSONPath values and types, JSON Schema, response time and size. You can copy values from a response into variables and use them in the next request.
  • A command-line runner, apiwb. It uses the same engine as the editor, so a collection behaves the same in CI. It writes JUnit and JSON reports.
  • Import from Thunder Client (export files, or a copy of its data folder), Postman v2.1, cURL (Bash and PowerShell) and OpenAPI 3.0/3.1. You see a preview first and can roll the import back afterwards.
  • Export as a portable backup, Thunder Client, Postman v2.1 or OpenAPI 3.1, and code snippets in 20 languages (38 clients).
  • Thunder Client feature parity: WebSocket, SSE and gRPC requests; HTTP/2; auth types None, Basic, Bearer, OAuth 2 (all grants), NTLM, AWS SigV4 and Digest; {{#system}} variables and | filters; the tc.* scripting API with bundled libraries; request chaining; a parallel collection runner with HTML/JUnit/CSV/NUnit reports; Local, Global, .env and collection-attached environments; a Cookie Manager; chart view. See docs/thunder-parity.md for each feature's status and its gaps.
  • Works offline and with no account. A bought license is a signed file that is checked on your machine. The extension never contacts a license server.

Quick start

  1. Open the API Workbench icon in the activity bar.
  2. Click New Request (Cmd/Ctrl+Alt+N). Choose where the request lives:
    • Workspace: saved in .apiworkbench/ and shared through Git.
    • Personal: stays on this machine.
  3. Type a URL and press Enter, or press Cmd/Ctrl+Enter from anywhere in the editor. Cmd/Ctrl+S saves. Esc cancels.
  4. In the Environments view, create DEV and add variables. Mark tokens as Secret. Use them as {{name}}.
  5. In the Tests tab, add checks, for example status eq 200 or jsonpath $.id exists.
  6. Right-click a collection and choose Run Collection.

The status bar shows the active environment and where requests run, for example runs on: WSL: Ubuntu. In a remote window (WSL, SSH, dev container or Codespaces), localhost means that machine, not your desktop.

Moving from Thunder Client

  1. Export your collections and environments from Thunder Client. Or copy its data folder somewhere safe, such as a thunder-tests/ folder.
  2. Run API Workbench: Import and pick the files or the copied folder.
  3. Read the preview. It shows:
    • how many collections, folders, requests, environments and history entries were found;
    • each item's result: exact, adapted, needs manual rewrite, or rejected;
    • the secrets that were found.
  4. Choose how to handle the secrets, then confirm.
  5. A migration report opens. It lists every source record and the SHA-256 of every source file, recorded before and after the import, which proves the originals were not changed.
  6. API Workbench: Roll Back an Import can undo it at any time.

Imported scripts are kept but disabled until you review them. Nothing is executed during import. Thunder Client itself is never modified or uninstalled.

Command line

apiwb run . --collection "My API" --env DEV --reporter cli,junit --out reports
apiwb run . --collection "My API" --data users.csv --bail
apiwb import ./exports/*.json --workspace . --dry-run
apiwb export . --collection "My API" --format openapi --out api.json

Secrets can be passed in three ways:

  • --secret NAME=VALUE
  • --secrets-file f.json or --secrets-stdin
  • environment variables APIWB_SECRET_<NAME>

Exit codes:

Code Meaning
0 Everything passed
1 A request or assertion failed
2 Error
3 Usage error
4 A license is needed to run

A license is read from --license, APIWB_LICENSE or APIWB_LICENSE_FILE. Reading, listing and exporting never need one.

Pricing and trial (proposed — not final)

  • Trial: 14 days of full use, with no account. The days are counted from your first request.
  • After the trial: sending requests pauses. Everything you saved stays readable, copyable, exportable and backed up. That is never a paid feature.
  • One purchase per person: a one-time price covers all your devices and commercial work. You keep using the version you bought, offline, with no renewal. That version gets maintenance and security updates for 24 months.
  • Price: not decided yet. Purchasing is not open in this build.

Privacy

  • No telemetry, no analytics, no cloud. Requests go only to the endpoints you configure.
  • License checks are local, and license files contain no collection data.
  • History is local and adjustable. It is kept for 30 days or 1,000 runs by default. You can change those limits or turn history off. You are asked before old entries are removed.
  • Response bodies may hold sensitive data. Redaction only covers well-known fields (authorization headers, cookies, token-like names). It cannot find arbitrary secrets inside API bodies.

Security

  • Untrusted workspaces: you can view, copy and export. Scripts don't run, and requests cannot read local files.
  • Scripts (hooks) run in a separate short-lived process. The process is limited by Node's permission model: no file writes, no child processes, no file reads except its own code. It also has an empty environment, a memory cap and a time limit.
  • Network access from scripts is not blocked. Only enable scripts you trust.
  • Full Node.js mode: the optional setting apiWorkbench.scripts.mode = full, for trusted workspaces only, gives scripts full Node.js. That allows any require, fs, tc.exec and tc.loadModule, as in Thunder Client.
  • TLS verification is always on. You can turn it off for specific hosts in settings. An import never turns it off.
  • Response HTML is shown in a sandboxed frame with scripts disabled.

Compatibility

Area Status
VS Code desktop Tested on VS Code 1.140 / macOS (arm64). Minimum declared: 1.120. Windows and Linux are not yet qualified.
Remote (WSL, SSH, dev containers, Codespaces) Designed to run on the remote host and label it. Not yet tested.
VSCodium / Cursor Not qualified.
VS Code for the Web (browser only) Not supported in this version.
Thunder Client import Built from public knowledge of the formats. Not verified against real exports yet.
Postman v2.1, Insomnia v4/v5, Hoppscotch, cURL, OpenAPI 3.x, .env Supported, with fixtures. The Insomnia and Hoppscotch fixtures were written by hand.
Protocols HTTP/1.1, HTTP/2, GraphQL, WebSocket, SSE and gRPC. Each was tested live against a public server.

Where data lives

What Where
Workspace collections and environments <workspace>/.apiworkbench/ (commit this)
Personal collections VS Code global storage (not in Git)
Drafts, earlier versions, history, cookies, trash, import snapshots VS Code storage for this workspace (never in Git)
Secrets, license, OAuth tokens VS Code secret storage on the machine where requests run

The file format is documented in docs/format.md.

Contact

Built and supported by Vinay Solapurkar.

  • Phone: +91 99164 67570
  • Questions, bugs and feature requests are welcome.
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft