Popular Searches
Popular Course Categories
Popular Courses

Introduction to API Testing

Introduction to API Testing

API & Database Integration

Introduction to API Testing

API Testing is a software testing approach used to verify the functionality, reliability, performance, security, and behavior of Application Programming Interfaces (APIs). Unlike UI testing, which validates an application through its graphical interface, API testing directly communicates with backend services and validates requests, responses, status codes, headers, authentication, data, and business logic.

APIs act as a communication layer between different software components. For example, when a user logs into an application, searches for a product, adds an item to a cart, or completes a payment, the frontend often communicates with backend services through APIs.

API testing is an important part of modern software testing and automation because it allows testers to validate backend functionality independently of the user interface. It is also commonly integrated with UI automation, CI/CD pipelines, regression testing, and automation frameworks.

Course Resource: Selenium Training | Register for Course Demo


1. What is an API?

API stands for Application Programming Interface. An API is a set of rules and mechanisms that allows different software applications or components to communicate with each other.

For example, a mobile application may send a request to a backend API to retrieve user information. The backend processes the request and returns a response containing the requested data.

Client Application

        |

        | HTTP Request

        v

      API

        |

        v

Backend Application

        |

        v

    Database

        |

        v

Backend Application

        |

        | HTTP Response

        v

      API

        |

        v

Client Application


2. What is API Testing?

API Testing is the process of testing APIs directly to verify that they behave according to their requirements and specifications.

API testing validates the request sent to the server and the response returned by the server. Testers can verify response status codes, response body, headers, response time, authentication, authorization, error handling, and business rules.

For example, if an API is responsible for creating a user, API testing can verify whether a valid request creates the user successfully and whether invalid requests return appropriate validation errors.


3. Why is API Testing Important?

  • Validates backend functionality independently of the UI.
  • Helps identify defects earlier in the development cycle.
  • Provides faster feedback than many UI-based tests.
  • Validates data exchanged between applications.
  • Helps verify business logic.
  • Supports automation and continuous testing.
  • Can validate security and authentication behavior.
  • Supports integration testing between services.
  • Helps verify error handling.
  • Can be integrated into CI/CD pipelines.


4. API Testing vs UI Testing

FeatureAPI TestingUI Testing
Testing LayerBackend/API layerPresentation/UI layer
InteractionHTTP/API requestsBrowser or application interface
Execution SpeedGenerally fasterGenerally slower
UI DependencyLow or noneHigh
Main ValidationRequest, response and business logicUI behavior and user workflows
Common ToolsPostman, REST AssuredSelenium, Playwright
AutomationHighly suitableHighly suitable


5. How Does an API Work?

When a client wants to interact with a backend service, it sends an API request. The server receives the request, processes it, performs the required business operation, and returns an API response.

Client

  |

  | Request

  | Method + URL + Headers + Body

  v

API Server

  |

  | Authentication

  | Validation

  | Business Logic

  | Database Operation

  v

Response

  |

  | Status Code + Headers + Body

  v

Client


6. Components of an API Request

An API request can contain several important components.

  • HTTP Method: Defines the operation being requested.
  • URL/Endpoint: Identifies the API resource.
  • Headers: Provide additional request information.
  • Query Parameters: Provide optional filtering or search information.
  • Path Parameters: Identify a specific resource.
  • Request Body: Contains data sent to the server.
  • Authentication: Provides credentials or tokens when required.


7. API Endpoint

An endpoint is a specific URL through which an API resource or operation can be accessed.

https://example.com/api/users

For example, an application may expose the following endpoints:

EndpointPurpose
/api/usersGet or create users
/api/productsGet or manage products
/api/ordersManage orders
/api/loginAuthenticate users


8. HTTP Methods

REST APIs commonly use HTTP methods to indicate the requested operation.

MethodCommon PurposeExample
GETRetrieve dataGet users
POSTCreate dataCreate user
PUTReplace/update dataUpdate user
PATCHPartially update dataUpdate user email
DELETEDelete dataDelete user


9. GET Request

A GET request is generally used to retrieve information from a server.

GET /api/users/101

A successful response might contain:

{

  "id": 101,

  "name": "John",

  "email": "[email protected]"

}

During API testing, testers can verify that the correct user data is returned for the requested ID.


10. POST Request

A POST request is commonly used to create a new resource.

POST /api/users

Example request body:

{

  "name": "John",

  "email": "[email protected]",

  "role": "user"

}

The API may return the newly created resource and an appropriate HTTP status code.


11. PUT Request

PUT is commonly used to replace or update an existing resource.

PUT /api/users/101

{

  "name": "John Smith",

  "email": "[email protected]",

  "role": "user"

}


12. PATCH Request

PATCH is commonly used when only part of an existing resource needs to be updated.

PATCH /api/users/101

{

  "email": "[email protected]"

}

Only the specified field may be changed.


13. DELETE Request

A DELETE request is commonly used to remove a resource.

DELETE /api/users/101

The API should return an appropriate response indicating whether the deletion was successful.


14. HTTP Status Codes

HTTP status codes indicate the result of an API request.

Status CodeMeaningTypical Usage
200OKSuccessful request
201CreatedResource successfully created
202AcceptedRequest accepted for processing
204No ContentSuccessful request with no response body
400Bad RequestInvalid request data
401UnauthorizedAuthentication required or invalid
403ForbiddenAccess is not permitted
404Not FoundResource does not exist
409ConflictRequest conflicts with current state
429Too Many RequestsRate limit exceeded
500Internal Server ErrorServer-side error
502Bad GatewayGateway received invalid response
503Service UnavailableService temporarily unavailable


15. API Response

An API response is the information returned by the server after processing an API request.

A response commonly contains:

  • Status code
  • Response headers
  • Response body
  • Response time
  • Cookies when applicable

HTTP/1.1 200 OK

 

Content-Type: application/json

 

{

  "id": 101,

  "name": "John",

  "status": "active"

}


16. Request Headers

Headers provide additional information about an API request.

Common request headers include:

  • Content-Type
  • Accept
  • Authorization
  • User-Agent
  • Cache-Control

Content-Type: application/json

Accept: application/json

Authorization: Bearer <token>


17. Response Headers

Response headers provide metadata about the server response.

Content-Type: application/json

Content-Length: 250

Cache-Control: no-cache

API tests can verify that important response headers are present and have expected values.


18. Request Body

The request body contains data sent from the client to the server, particularly with POST, PUT, and PATCH requests.

{

  "username": "john",

  "password": "password123"

}

During API testing, the tester can verify how the server handles valid, invalid, missing, and unexpected request fields.


19. Response Body

The response body contains data returned by the API.

{

  "id": 101,

  "name": "John",

  "role": "Admin"

}

Testers can validate individual fields, data types, values, arrays, nested objects, and business rules.


20. JSON in API Testing

JSON stands for JavaScript Object Notation. It is one of the most commonly used formats for exchanging data between clients and APIs.

{

  "id": 101,

  "name": "John",

  "email": "[email protected]",

  "active": true

}

JSON consists of key-value pairs and can also contain arrays and nested objects.


21. JSON Object

{

  "name": "John",

  "age": 30,

  "active": true

}

API tests can verify whether each field exists and whether its value and data type are correct.


22. JSON Array

{

  "users": [

    {

      "id": 1,

      "name": "John"

    },

    {

      "id": 2,

      "name": "David"

    }

  ]

}

API testing can validate array size, individual elements, ordering when applicable, and required fields.


23. REST API

REST stands for Representational State Transfer. REST is an architectural style commonly used for designing web APIs.

REST APIs commonly use HTTP methods and resources to perform operations.

GET     /users

POST    /users

GET     /users/101

PUT     /users/101

DELETE  /users/101


24. REST API Testing

REST API testing validates REST endpoints by sending HTTP requests and checking their responses.

Typical validations include:

  • Status code validation
  • Response body validation
  • Header validation
  • Schema validation
  • Response time validation
  • Authentication validation
  • Authorization validation
  • Error handling validation


25. SOAP API

SOAP stands for Simple Object Access Protocol. SOAP is a protocol for exchanging structured information between systems and commonly uses XML messages.

<soap:Envelope>

  <soap:Body>

    <GetUser>

      <UserId>101</UserId>

    </GetUser>

  </soap:Body>

</soap:Envelope>

SOAP testing involves validating XML requests, responses, operations, headers, faults, and service behavior.


26. REST vs SOAP

FeatureRESTSOAP
TypeArchitectural styleProtocol
Common Data FormatJSON, XML and othersXML
TransportCommonly HTTP/HTTPSCan operate over multiple protocols
ComplexityGenerally simplerMore structured and formal
TestingHTTP endpoint testingXML/SOAP message testing


27. Authentication in API Testing

Authentication verifies the identity of a user or client making an API request.

Common authentication approaches include:

  • Basic Authentication
  • Bearer Token Authentication
  • API Keys
  • OAuth 2.0
  • Session-based authentication
  • JWT-based authentication


28. Basic Authentication

Basic Authentication sends a username and password as part of the HTTP authentication mechanism.

Authorization: Basic <encoded-credentials>

Credentials should be transmitted only over secure HTTPS connections and should be handled carefully in automated tests.


29. Bearer Token Authentication

Bearer authentication uses a token to authorize API requests.

Authorization: Bearer <access-token>

The test framework can obtain a token from an authentication endpoint and use it in subsequent requests.


30. API Key Authentication

Some APIs use API keys to identify and authorize clients.

X-API-Key: <api-key>

API keys should be stored securely rather than being exposed in source-controlled automation code.


31. OAuth 2.0

OAuth 2.0 is a widely used authorization framework. It allows applications to obtain access tokens that can be used to access protected resources.

Client

  |

  v

Authorization Server

  |

  | Access Token

  v

Client

  |

  | Bearer Token

  v

Protected API


32. JWT Authentication

JWT stands for JSON Web Token. JWTs can carry claims that are digitally signed and can be used for authentication or authorization.

Authorization: Bearer eyJhbGciOi...

API tests can verify whether protected endpoints reject missing, expired, malformed, or unauthorized tokens.


33. API Functional Testing

Functional API testing verifies that the API performs its intended business operation correctly.

For example, a create-user API can be tested by sending valid user information and verifying that:

  • The request is accepted.
  • The expected status code is returned.
  • A user ID is generated.
  • The response contains the expected fields.
  • The created data can be retrieved when appropriate.


34. Positive API Testing

Positive testing verifies that an API works correctly with valid inputs.

POST /api/users

 

{

  "name": "John",

  "email": "[email protected]"

}

The test verifies that the API accepts the valid request and returns the expected successful response.


35. Negative API Testing

Negative testing verifies how an API behaves when invalid, incomplete, unauthorized, or unexpected input is supplied.

Examples include:

  • Missing required field
  • Invalid email
  • Invalid user ID
  • Incorrect authentication token
  • Unsupported HTTP method
  • Invalid data type
  • Duplicate resource


36. Boundary Value Testing for APIs

Boundary testing verifies behavior at the limits of accepted values.

For example, if a username must contain between 5 and 20 characters, tests may include:

  • 4 characters
  • 5 characters
  • 20 characters
  • 21 characters


37. API Validation

API validation involves verifying whether the actual response matches the expected behavior.

ValidationExample
Status CodeExpected 200
Response Fieldname should exist
Data Typeid should be numeric
HeaderContent-Type should be application/json
Response TimeShould remain within agreed threshold
Business RuleInactive user should not place an order


38. API Schema Validation

Schema validation verifies whether the response structure, fields, data types, and required properties conform to the expected schema.

{

  "id": 101,

  "name": "John",

  "active": true

}

A schema can define that id must be numeric, name must be a string, and active must be Boolean.


39. API Response Time Testing

Response time testing verifies how quickly an API responds to a request.

For example, an automated test may capture response time and compare it against a defined project threshold.

Request Sent

     |

     v

API Processing

     |

     v

Response Received

     |

     v

Calculate Response Time

     |

     v

Compare with Expected Threshold

Response-time checks in functional automation should not be confused with full performance or load testing.


40. API Security Testing

API security testing verifies whether APIs properly protect sensitive resources and enforce authentication and authorization requirements.

Security-oriented API tests can verify:

  • Unauthorized access is rejected.
  • Invalid tokens are rejected.
  • Expired tokens are rejected.
  • Users cannot access resources they are not authorized to access.
  • Sensitive information is not unnecessarily exposed.
  • Input validation is enforced.


41. API Authorization Testing

Authentication identifies who the user is, while authorization determines what that user is allowed to access.

For example:

Admin

  |

  +-- Create User

  +-- Delete User

  +-- View Reports

 

Regular User

  |

  +-- View Profile

  +-- Update Profile

API tests should verify that users cannot perform operations outside their permitted roles.


42. API Error Handling

APIs should return predictable and meaningful responses when requests fail.

{

  "error": "Invalid request",

  "message": "Email is required"

}

Tests should verify both the HTTP status code and the relevant error response structure.


43. API Testing Tools

Several tools and libraries are commonly used for API testing.

ToolCommon Usage
PostmanManual and automated API testing
REST AssuredJava-based API automation
SoapUIAPI and SOAP testing
JMeterPerformance and load testing
NewmanCommand-line execution of Postman collections
PyTestPython test framework that can be used for API automation


44. Introduction to Postman

Postman is a popular API platform used to create, send, inspect, organize, and automate API requests.

Using Postman, testers can work with:

  • GET requests
  • POST requests
  • PUT requests
  • PATCH requests
  • DELETE requests
  • Headers
  • Authentication
  • Request bodies
  • Variables
  • Collections
  • Tests


45. Creating a GET Request in Postman

A basic GET request can be created by selecting GET, entering the endpoint URL, and sending the request.

GET https://example.com/api/users

The response can then be inspected for status code, headers, response body, and response time.


46. Creating a POST Request in Postman

A POST request can be configured with a JSON request body.

POST https://example.com/api/users

 

{

  "name": "John",

  "email": "[email protected]"

}

The response can then be validated using the Postman test scripting capability.


47. Postman Variables

Variables make API collections easier to maintain across environments.

{{baseUrl}}/api/users/{{userId}}

For example:

baseUrl = https://qa.example.com

userId = 101

Variables help avoid hard-coding environment-specific values in every request.


48. Postman Environments

Different environments may have different URLs, credentials, tokens, and configuration values.

EnvironmentBase URL
QAhttps://qa.example.com
Stagehttps://stage.example.com
Productionhttps://www.example.com

Environment variables make it easier to execute the same API tests against different environments.


49. Postman Collections

A collection is a group of related API requests.

Users API Collection

  |

  |-- Login

  |-- Create User

  |-- Get User

  |-- Update User

  |-- Delete User

Collections help organize API tests and can be executed as a group.


50. API Test Automation

API automation means writing automated scripts that send API requests and verify their responses.

Typical automation flow:

Test Data

    |

    v

Create Request

    |

    v

Send API Request

    |

    v

Receive Response

    |

    v

Validate Status

    |

    v

Validate Headers

    |

    v

Validate Response Body

    |

    v

Generate Report


51. REST Assured

REST Assured is a Java library commonly used to automate REST API testing. It provides a readable syntax for creating requests and validating responses.

import static io.restassured.RestAssured.*;

import static org.hamcrest.Matchers.*;

 

import org.testng.annotations.Test;

 

public class ApiTest {

 

    @Test

    public void getUserTest() {

 

        given()

        .when()

            .get("https://example.com/api/users/101")

        .then()

            .statusCode(200)

            .body("id", equalTo(101));

    }

}


52. REST Assured Request Structure

REST Assured commonly follows a Given-When-Then style.

given()

    |

    | Request setup

    v

when()

    |

    | Send request

    v

then()

    |

    | Validate response

    v

Assertions

given() is used for request configuration, when() performs the action, and then() validates the response.


53. REST Assured GET Example

given()

.when()

    .get("https://example.com/api/users")

.then()

    .statusCode(200);

This example verifies that the endpoint returns HTTP status code 200.


54. REST Assured POST Example

String requestBody = "{"

        + "\"name\":\"John\","

        + "\"email\":\"[email protected]\""

        + "}";

 

given()

    .header("Content-Type", "application/json")

    .body(requestBody)

.when()

    .post("https://example.com/api/users")

.then()

    .statusCode(201);


55. API Testing with TestNG

API automation can be integrated with TestNG to organize test cases, execute suites, perform assertions, and generate reports.

import org.testng.Assert;

import org.testng.annotations.Test;

 

public class ApiTest {

 

    @Test

    public void statusCodeTest() {

 

        int actualStatusCode = 200;

        int expectedStatusCode = 200;

 

        Assert.assertEquals(actualStatusCode, expectedStatusCode);

    }

}


56. API Testing with Selenium Frameworks

Selenium primarily automates web browsers, while API testing validates backend services. Both can be combined in a broader automation framework.

API Testing

    |

    v

Create Test Data

    |

    v

UI Testing with Selenium

    |

    v

Validate Application

    |

    v

API Validation

    |

    v

Final Test Result

For example, an API can be used to create test data before a Selenium UI test starts.


57. API Testing and Database Testing

API tests can also be combined with database validation when the application requires verification of backend data.

API Request

    |

    v

Application Service

    |

    v

Database

    |

    +---- API Response

    |

    +---- Database Validation

This can help verify whether an API operation correctly creates, updates, or retrieves database records.


58. API Testing Lifecycle

Requirement Analysis

       |

       v

API Specification Review

       |

       v

Test Scenario Design

       |

       v

Test Data Preparation

       |

       v

API Request Creation

       |

       v

Test Execution

       |

       v

Response Validation

       |

       v

Defect Reporting

       |

       v

Regression Testing

       |

       v

Test Reporting


59. API Test Scenarios

Common API test scenarios include:

  • Verify valid GET request.
  • Verify valid POST request.
  • Verify valid PUT request.
  • Verify valid PATCH request.
  • Verify DELETE operation.
  • Verify invalid request data.
  • Verify missing mandatory fields.
  • Verify authentication.
  • Verify authorization.
  • Verify invalid tokens.
  • Verify response headers.
  • Verify response schema.
  • Verify response time.
  • Verify error messages.
  • Verify duplicate data handling.


60. API Testing for Login

Login APIs are commonly tested using valid and invalid credentials.

POST /api/login

 

{

  "username": "john",

  "password": "password123"

}

Possible validations include:

  • Valid credentials return a successful response.
  • Invalid credentials are rejected.
  • Missing username is handled correctly.
  • Missing password is handled correctly.
  • Authentication token is returned when appropriate.
  • Sensitive information is not unnecessarily exposed.


61. API Testing for E-Commerce

E-commerce systems provide many opportunities for API testing.

Login API

   |

   v

Product API

   |

   v

Cart API

   |

   v

Order API

   |

   v

Payment API

   |

   v

Order Confirmation API

Each service can be tested independently and through end-to-end API workflows.


62. API Testing for User Management

A user-management API may support:

POST   /users

GET    /users

GET    /users/101

PUT    /users/101

PATCH  /users/101

DELETE /users/101

Testers can create a user, retrieve the user, update the user, and finally delete the user as part of a controlled test workflow.


63. API Chaining

API chaining means using information returned by one API request in a subsequent API request.

Login API

    |

    | Returns token

    v

Get User API

    |

    | Returns user ID

    v

Get Orders API

    |

    | Returns order ID

    v

Get Order Details API

API chaining is useful for testing realistic business workflows.


64. Extracting Values from API Responses

Automation tests often need to extract values such as IDs or tokens from responses.

{

  "id": 101,

  "token": "abc123"

}

The extracted ID or token can then be used in subsequent API requests.


65. API Contract Testing

Contract testing verifies that the communication contract between API consumers and providers remains compatible.

A contract can define expected:

  • Endpoints
  • HTTP methods
  • Request fields
  • Response fields
  • Data types
  • Status codes

Contract testing helps detect breaking API changes between services.


66. API Regression Testing

API regression testing verifies that changes to the application have not broken previously working API functionality.

A regression suite may contain tests for:

  • Authentication
  • User management
  • Product APIs
  • Order APIs
  • Payment workflows
  • Search APIs
  • Reporting APIs


67. API Integration Testing

Integration testing verifies that multiple services communicate correctly with each other.

Order Service

     |

     v

Inventory Service

     |

     v

Payment Service

     |

     v

Notification Service

API integration tests can verify that information flows correctly between these services.


68. API Testing in CI/CD

API tests can be integrated into CI/CD pipelines so that automated tests execute whenever application changes are built or deployed.

Developer Commit

       |

       v

Build

       |

       v

API Tests

       |

       v

UI Tests

       |

       v

Reports

       |

       v

Deployment

Automated API tests can provide rapid feedback about backend regressions.


69. API Test Data Management

Good API automation requires reliable and maintainable test data.

Test data can come from:

  • Java objects
  • JSON files
  • CSV files
  • Excel files
  • Databases
  • Environment variables
  • Configuration files
  • Test data APIs

Sensitive credentials and tokens should be managed through appropriate secure mechanisms rather than committed as plain text.


70. API Testing Best Practices

  • Understand the API specification before writing tests.
  • Use meaningful test names.
  • Validate both successful and unsuccessful scenarios.
  • Validate status codes.
  • Validate response body fields.
  • Validate important response headers.
  • Validate schemas where appropriate.
  • Use reusable request utilities.
  • Separate test data from test logic.
  • Avoid hard-coding sensitive credentials.
  • Use environment-specific configuration.
  • Keep API tests independent whenever practical.
  • Use API chaining for realistic workflows where required.
  • Integrate automated API tests with CI/CD.
  • Generate useful test reports.
  • Log sufficient information for debugging without exposing secrets.


71. Common Mistakes in API Testing

  • Checking only the status code and ignoring the response body.
  • Not testing negative scenarios.
  • Ignoring authentication and authorization.
  • Hard-coding tokens and passwords.
  • Using production data carelessly in test automation.
  • Not validating required fields.
  • Ignoring response headers.
  • Not checking API error handling.
  • Creating tightly coupled test cases.
  • Not managing test data correctly.
  • Ignoring environment differences.
  • Not integrating API tests into regression execution.


72. API Testing vs API Automation

API TestingAPI Automation
Can be performed manuallyPerformed using automated scripts/tools
Useful for explorationUseful for repeatable regression
May use Postman manuallyCan use REST Assured, PyTest, Postman/Newman, etc.
Requires tester interactionCan run automatically in CI/CD


73. API Testing Project Structure

src

|-- test

|   |-- java

|       |-- tests

|       |   |-- LoginApiTest.java

|       |   |-- UserApiTest.java

|       |   |-- ProductApiTest.java

|       |   |-- OrderApiTest.java

|       |

|       |-- clients

|       |   |-- ApiClient.java

|       |

|       |-- data

|       |   |-- TestData.java

|       |

|       |-- utilities

|           |-- ConfigReader.java

|           |-- JsonUtility.java

|           |-- TestDataUtility.java

|-- resources

    |-- config

    |   |-- config.properties

    |-- testdata

        |-- users.json

        |-- products.json


74. Complete Basic REST Assured Example

import static io.restassured.RestAssured.*;

import static org.hamcrest.Matchers.*;

 

import org.testng.annotations.Test;

 

public class UserApiTest {

 

    @Test

    public void getUserTest() {

 

        given()

        .when()

            .get("https://example.com/api/users/101")

        .then()

            .statusCode(200)

            .body("id", equalTo(101))

            .body("name", notNullValue());

    }

}

This example demonstrates the basic structure of an automated API test: configure the request, send the request, and validate the response.


75. Complete POST API Testing Example

import static io.restassured.RestAssured.*;

 

import org.testng.annotations.Test;

 

public class CreateUserApiTest {

 

    @Test

    public void createUserTest() {

 

        String requestBody = "{"

                + "\"name\":\"John\","

                + "\"email\":\"[email protected]\","

                + "\"role\":\"user\""

                + "}";

 

        given()

            .header("Content-Type", "application/json")

            .body(requestBody)

        .when()

            .post("https://example.com/api/users")

        .then()

            .statusCode(201);

    }

}


76. API Test Execution Flow

Test Case

    |

    v

Prepare Test Data

    |

    v

Build Request

    |

    v

Add Headers

    |

    v

Add Authentication

    |

    v

Send Request

    |

    v

Receive Response

    |

    v

Validate Status Code

    |

    v

Validate Headers

    |

    v

Validate Response Body

    |

    v

Assertions

    |

    v

Generate Report


77. API Testing and Selenium Automation

API testing and Selenium UI testing complement each other. Selenium validates browser-level functionality, while API testing validates backend services.

ScenarioPossible Testing Approach
Login backendAPI testing
Login page appearanceSelenium UI testing
Create test userAPI testing
Verify user profile in browserSelenium UI testing
Validate order serviceAPI testing
Verify checkout screenSelenium UI testing


78. Real-World API Testing Architecture

                    Test Data

                        |

             +----------+----------+

             |          |          |

            JSON       CSV        DB

             |          |          |

             +----------+----------+

                        |

                        v

                  Test Framework

                        |

                        v

                   API Client

                        |

                        v

                  API Endpoint

                        |

                        v

                Backend Services

                        |

                        v

                     Database

                        |

                        v

                   API Response

                        |

                        v

                  Validations

                        |

                        v

                     Report


79. API Testing Interview Questions

1. What is API Testing?

API testing is the process of validating an API's functionality, responses, data, authentication, error handling, and other expected behavior.

2. What does API stand for?

API stands for Application Programming Interface.

3. What is an endpoint?

An endpoint is a URL through which a specific API resource or operation can be accessed.

4. What is the difference between GET and POST?

GET is commonly used to retrieve resources, while POST is commonly used to create resources or submit data for processing.

5. What is PUT?

PUT is commonly used to replace or update an existing resource.

6. What is PATCH?

PATCH is commonly used to partially update an existing resource.

7. What is DELETE?

DELETE is commonly used to remove a resource.

8. What is a status code?

An HTTP status code indicates the result of an HTTP request.

9. What is JSON?

JSON is a lightweight data-interchange format commonly used in modern APIs.

10. What is REST?

REST is an architectural style commonly used to design web APIs around resources and HTTP operations.

11. What is SOAP?

SOAP is a protocol for exchanging structured information between systems, commonly using XML messages.

12. What is authentication?

Authentication verifies the identity of the client or user making an API request.

13. What is authorization?

Authorization determines whether an authenticated user or client is permitted to perform a particular operation.

14. What is API chaining?

API chaining is the process of using information from one API response in a subsequent API request.

15. What is REST Assured?

REST Assured is a Java library commonly used for automating REST API tests.

16. Can Selenium test APIs directly?

Selenium is primarily designed for browser automation. API testing is normally handled using dedicated API tools or libraries, which can be integrated into the same automation ecosystem.

17. What should be validated in an API response?

Status code, response body, headers, schema, data types, business rules, authentication behavior, and other project-specific requirements can be validated.

18. What is negative API testing?

Negative API testing verifies how an API behaves when invalid, incomplete, unauthorized, or unexpected data is provided.

19. Why is API testing useful in CI/CD?

API tests can execute automatically during builds and deployments, providing rapid feedback about backend regressions.

20. What is schema validation?

Schema validation verifies that the response structure and data types conform to an expected contract.


80. Quick Reference Table

ConceptDescription
APIInterface used for communication between software components
EndpointURL through which an API resource or operation is accessed
GETRetrieve data
POSTCreate or submit data
PUTReplace or update a resource
PATCHPartially update a resource
DELETEDelete a resource
JSONCommon API data format
Status CodeIndicates the result of an HTTP request
AuthenticationVerifies identity
AuthorizationControls access to resources
PostmanAPI development and testing platform
REST AssuredJava API automation library
API ChainingUses one API response in another API request
Schema ValidationValidates response structure and data types


81. Learning Roadmap for API Testing

  1. Understand HTTP and web application fundamentals.
  2. Learn API concepts and client-server communication.
  3. Learn HTTP methods.
  4. Understand status codes.
  5. Learn request and response structure.
  6. Learn headers and authentication.
  7. Understand JSON and XML.
  8. Practice API testing using Postman.
  9. Learn variables and environments.
  10. Learn collections and API workflows.
  11. Practice positive and negative API testing.
  12. Learn API chaining.
  13. Learn schema validation.
  14. Learn REST Assured or another automation library.
  15. Integrate API tests with TestNG.
  16. Combine API testing with Selenium automation where appropriate.
  17. Integrate API tests with Maven and CI/CD.
  18. Build a reusable API automation framework.


82. Practical Exercises

  1. Create a GET request and validate status code 200.
  2. Create a POST request for user creation.
  3. Test PUT and PATCH operations.
  4. Test DELETE functionality.
  5. Validate response headers.
  6. Validate JSON response fields.
  7. Test invalid request data.
  8. Test missing mandatory fields.
  9. Test authentication using a token.
  10. Test authorization for different user roles.
  11. Create an API chain using multiple endpoints.
  12. Create a Postman collection for user management.
  13. Create automated API tests using REST Assured.
  14. Integrate REST Assured with TestNG.
  15. Execute API tests through Maven.
  16. Run API tests in a CI/CD pipeline.


83. Practical E-Commerce API Workflow

Login

  |

  v

Get Authentication Token

  |

  v

Get Products

  |

  v

Select Product

  |

  v

Add Product to Cart

  |

  v

Create Order

  |

  v

Process Payment

  |

  v

Verify Order

  |

  v

Logout

This workflow demonstrates how API testing can validate an entire business process rather than testing individual endpoints only.


84. Final Summary

API Testing is an important part of modern software quality assurance. It validates backend services directly by sending requests and verifying responses without depending entirely on the graphical user interface.

API testing covers HTTP methods, endpoints, request bodies, response bodies, headers, status codes, authentication, authorization, error handling, schema validation, business rules, and response behavior.

Tools such as Postman can be used for exploratory and manual API testing, while automation libraries such as REST Assured can be used to build maintainable automated API test suites in Java. API testing can also be combined with TestNG, Maven, Selenium, reporting systems, and CI/CD pipelines.

A well-designed API automation framework separates test data, API clients, test cases, configuration, validation, and reporting. This makes the framework easier to maintain and scale as the application grows.


85. Course Resources

Continue learning Selenium automation, API testing, TestNG, Page Object Model, data-driven testing, and automation framework development:

Final Takeaway: API Testing helps testers validate application services at the backend level by checking requests, responses, status codes, data, authentication, authorization, business rules, and error handling. When combined with UI automation and CI/CD, API testing becomes an important part of a complete modern test automation strategy.

whatsapp