Insomnia review: free Git Sync for 3 users, Pro at $12 a seat, Enterprise at $45. Account rules, local storage, export limits, CVE-2025-1087, and Postman vs Bruno.
Insomnia is Kong's open-source desktop API client, and it undercuts Postman exactly where small teams feel the price. The free Essentials plan lets up to three people share Git Sync projects, with unlimited collection runs. On Postman, sharing requests means the Team plan at $19 per user per month billed annually. For three developers that is $684 a year against nothing.
The catch sits at the edges. A fourth Git Sync user moves the team to Pro at $12 a seat, mock servers stop at 1,000 requests a month, and the app exports only its own YAML format or HAR. There is no button that gives you a Postman collection back. This review covers Insomnia 13.3.0, the stable release Kong shipped on September 23, 2026. Prices were checked on insomnia.rest/pricing on September 30, 2026.
There are three plans, each priced per user per month. The page offers an annual toggle but cannot agree on the discount. The toggle says "Save 17%", the Pro card says "15% savings", and no annual per-user price appears anywhere. Budget on the monthly figures.
| Plan | Price | Git Sync | Mock requests / month | What it adds |
|---|---|---|---|---|
| Essentials | $0 | Up to 3 users | 1,000 | Unlimited cloud and local projects, Inso CLI, unlimited runs and environments, end-to-end encryption, custom lint rules, plugins |
| Pro | $12 | All users | 10,000 | Unlimited users and organizations, role-based access control, email support |
| Enterprise | $45 | All users | Unlimited | SSO (SAML/OIDC) and SCIM, rules on where projects are stored, domain capture, AWS/GCP/HashiCorp/Azure vaults, Kong Konnect, SOC 2 reports |
Mock traffic beyond the monthly allowance costs $10 per 25,000 requests on Essentials and Pro. Pro is paid by credit card only. Enterprise is self-serve only up to 50 users; past that you talk to sales. The 14-day trial needs no card.
The free plan is less restrictive than it first looks. Cloud and local projects allow unlimited users, and the three-person ceiling applies only to Git Sync. That still hurts, because Git Sync is the mode most teams want: the collection lives in the same repository as the code it tests. So a ten-person team can share cloud projects for free, but it cannot share one Git-backed project without paying for every seat.
Enterprise is mostly about control. It is the only tier where an admin can require that projects stay local or in Git and never go to Kong's cloud, which is the first thing a security team will ask for.
For most of it, yes. That history explains why people still ask. Insomnia 8.0, released September 27, 2023, suddenly required a login, and some users who upgraded found their requests gone. GitHub issue #6585, "Upgrading to Insomnia 8 has deleted or hidden all of my queries and configuration", drew 74 comments, and the account complaint thread (#6577) collected 346 reactions. A Hacker News post about the change reached 180 points the same day. A local-only fork called Insomnium scored even higher. Kong partly reversed course in 8.3 on October 16, 2023, when it brought local-only projects back as Local Vault.
Today there are two ways to stay out of the cloud. The Scratch Pad needs no account at all; it is a link at the bottom of the login screen. Local Vault projects need a login, but in Kong's words "no data is sent to or stored in the cloud." The README admits that the no-account path is limited: "to access most capabilities of the product we require an account." Use the Scratch Pad to test an endpoint. Do not keep a team's work in it.
Two lines in Kong's own security docs matter for regulated teams. Cloud Sync encrypts data with AES-GCM-256 under a passphrase that each user sets and Kong never stores. The data then sits in Postgres on GCP in the US Central region, and the docs name no other region. Local data, meanwhile, "is not encrypted on disk", so a Local Vault on an unencrypted laptop is only as safe as the laptop.
Protocol coverage is the strongest reason to choose Insomnia over a leaner client. One app handles REST, GraphQL, gRPC, SOAP, WebSocket, Socket.IO and server-sent events. Since version 12.0 (November 2025) it also works as a Model Context Protocol client, so you can call an MCP server's tools the way you would call an endpoint. OAuth support includes Dynamic Client Registration, which MCP servers increasingly expect.
The 13.x releases changed how it feels day to day. Version 13.0 in June 2026 replaced the flat request list with a tree sidebar and moved templating from Nunjucks to LiquidJS, so check your old template tags after upgrading. 13.1 added the new QUERY HTTP method. 13.3 merged Document and Collection workspaces into a single API Collection, so a spec and the requests that exercise it no longer live apart. It also added an SSE Summary tab for reading event streams.
For CI, the Inso CLI comes with the free plan. It runs collections and tests, lints OpenAPI specs against your own rules and exports specs, so the collection a developer clicks through can also gate a pull request. Since 12.6, Git Sync projects are ordinary files on disk that git, or a coding agent, can edit directly.
User reviews are fewer than you might expect. G2 reviewers give it 4.4 out of 5, but there are only 17 reviews. The complaints that recur are slowness with large collections, thin documentation and panels that cannot be collapsed.
Import is generous: Postman v2.0 and v2.1, OpenAPI 3.0 and 3.1, Swagger, WSDL, HAR, cURL, and Insomnia's own JSON and YAML. Export is not. The app writes only Insomnia YAML (v5) and HAR, and the CLI adds an OpenAPI spec. There is no Postman export. If you later move from Insomnia to Postman, you rebuild your collections from a HAR or OpenAPI file, and neither format carries your pre-request scripts or environment variables.
Moving in costs nothing. Moving out costs a weekend. If your collections live in Git Sync, the YAML files at least sit in your own repository in a form you can read.
In 2025 Insomnia had a serious template-injection bug. CVE-2025-1087, scored 9.3, let an attacker run arbitrary code through template tags. NVD published it on May 9, 2025 and lists versions before 11.0.2 as affected. Tanto Security disagreed in a June 19, 2025 write-up, saying the flaw was "still remotely exploitable" in 11.2.0.
Kong has since tightened things in stages. In 11.5, scripts and template tags that access files were restricted to an allowlist. Templating moved into a QuickJS sandbox in 13.1, and pre- and post-request scripts were sandboxed in 13.3. We found no source confirming that these changes close the hole Tanto described. The practical rule stands: do not import collections or specs from people you do not trust, and stay on the current release.
A smaller 13.x change helps with secrets. Private sub-environments stay on your machine and are never exported, synced or committed, which makes them the right place for API keys in a shared Git Sync project.
Postman and Bruno sit on either side of Insomnia on price. Figures come from each vendor's pricing page.
| Insomnia | Postman | Bruno | |
|---|---|---|---|
| Free plan | Git Sync for 3 users; cloud and local projects for everyone | 1 user | Open source, free, no account |
| First paid tier | $12 per user / month (Pro) | $9 / month Solo; $19 per user / month Team, billed annually | $6 per user / month Pro, billed annually |
| Top tier | $45 per user / month Enterprise | Enterprise, contact sales | $11 per user / month Ultimate, billed annually |
| Where collections live | Your machine, your Git repo, or Kong's cloud | Postman's cloud | Plain files in your repo |
Against Postman, a four-person team pays $48 a month on Insomnia Pro against $76 on Postman Team, and a three-person team using Git Sync pays nothing. Postman keeps the bigger ecosystem, with hosted monitoring, public workspaces and more integrations. Our Postman review covers what that costs. Against Bruno, Insomnia loses on principle: Bruno needs no account and costs half as much per seat. Insomnia's case there is breadth, with MCP, Socket.IO and SSE in one client, plus the Kong gateway tie-in. Check Bruno's protocol list against the APIs you actually call before you decide.
Buy Insomnia if you are a team of three or fewer and want shared, Git-backed collections for free. It also fits anyone who moves between gRPC, SSE, Socket.IO and MCP and wants one client for all of them. Teams of four or more still come out ahead, paying $12 a seat against Postman's $19.
Skip it if you want collections as plain files and never want to make an account. Bruno does that for free, with paid seats at $6. Skip it too if your team already relies on Postman's monitors and public workspaces. And if your data policy rules out US-hosted cloud storage, remember that forcing projects to stay local takes the $45 Enterprise tier.
Visit the official website to see the latest plans, pricing, and special offers.
Get Started - Insomnia* Affiliate link - we may earn a commission at no extra cost to you.