Make sure to run them only in backend workflows or else the postmark API token will be exposed to the user