Introduction to API Testing
API Testing is a software testing approach used to verify the functionality, reliability, performance, security, and behavior of Application Programming Interfaces (APIs). Unlike UI testing, which validates an application through its graphical interface, API testing directly communicates with backend services and validates requests, responses, status codes, headers, authentication, data, and business logic.
APIs act as a communication layer between different software components. For example, when a user logs into an application, searches for a product, adds an item to a cart, or completes a payment, the frontend often communicates with backend services through APIs.
API testing is an important part of modern software testing and automation because it allows testers to validate backend functionality independently of the user interface. It is also commonly integrated with UI automation, CI/CD pipelines, regression testing, and automation frameworks.
Course Resource: Selenium Training | Register for Course Demo
1. What is an API?
API stands for Application Programming Interface. An API is a set of rules and mechanisms that allows different software applications or components to communicate with each other.
For example, a mobile application may send a request to a backend API to retrieve user information. The backend processes the request and returns a response containing the requested data.
Client Application
|
| HTTP Request
v
API
|
v
Backend Application
|
v
Database
|
v
Backend Application
|
| HTTP Response
v
API
|
v
Client Application
2. What is API Testing?
API Testing is the process of testing APIs directly to verify that they behave according to their requirements and specifications.
API testing validates the request sent to the server and the response returned by the server. Testers can verify response status codes, response body, headers, response time, authentication, authorization, error handling, and business rules.
For example, if an API is responsible for creating a user, API testing can verify whether a valid request creates the user successfully and whether invalid requests return appropriate validation errors.
3. Why is API Testing Important?
- Validates backend functionality independently of the UI.
- Helps identify defects earlier in the development cycle.
- Provides faster feedback than many UI-based tests.
- Validates data exchanged between applications.
- Helps verify business logic.
- Supports automation and continuous testing.
- Can validate security and authentication behavior.
- Supports integration testing between services.
- Helps verify error handling.
- Can be integrated into CI/CD pipelines.
4. API Testing vs UI Testing
| Feature | API Testing | UI Testing |
| Testing Layer | Backend/API layer | Presentation/UI layer |
| Interaction | HTTP/API requests | Browser or application interface |
| Execution Speed | Generally faster | Generally slower |
| UI Dependency | Low or none | High |
| Main Validation | Request, response and business logic | UI behavior and user workflows |
| Common Tools | Postman, REST Assured | Selenium, Playwright |
| Automation | Highly suitable | Highly suitable |
5. How Does an API Work?
When a client wants to interact with a backend service, it sends an API request. The server receives the request, processes it, performs the required business operation, and returns an API response.
Client
|
| Request
| Method + URL + Headers + Body
v
API Server
|
| Authentication
| Validation
| Business Logic
| Database Operation
v
Response
|
| Status Code + Headers + Body
v
Client
6. Components of an API Request
An API request can contain several important components.
- HTTP Method: Defines the operation being requested.
- URL/Endpoint: Identifies the API resource.
- Headers: Provide additional request information.
- Query Parameters: Provide optional filtering or search information.
- Path Parameters: Identify a specific resource.
- Request Body: Contains data sent to the server.
- Authentication: Provides credentials or tokens when required.
7. API Endpoint
An endpoint is a specific URL through which an API resource or operation can be accessed.
https://example.com/api/users
For example, an application may expose the following endpoints:
| Endpoint | Purpose |
| /api/users | Get or create users |
| /api/products | Get or manage products |
| /api/orders | Manage orders |
| /api/login | Authenticate users |
8. HTTP Methods
REST APIs commonly use HTTP methods to indicate the requested operation.
| Method | Common Purpose | Example |
| GET | Retrieve data | Get users |
| POST | Create data | Create user |
| PUT | Replace/update data | Update user |
| PATCH | Partially update data | Update user email |
| DELETE | Delete data | Delete user |
9. GET Request
A GET request is generally used to retrieve information from a server.
GET /api/users/101
A successful response might contain:
{
"id": 101,
"name": "John",
"email": "[email protected]"
}
During API testing, testers can verify that the correct user data is returned for the requested ID.
10. POST Request
A POST request is commonly used to create a new resource.
POST /api/users
Example request body:
{
"name": "John",
"email": "[email protected]",
"role": "user"
}
The API may return the newly created resource and an appropriate HTTP status code.
11. PUT Request
PUT is commonly used to replace or update an existing resource.
PUT /api/users/101
{
"name": "John Smith",
"email": "[email protected]",
"role": "user"
}
12. PATCH Request
PATCH is commonly used when only part of an existing resource needs to be updated.
PATCH /api/users/101
{
"email": "[email protected]"
}
Only the specified field may be changed.
13. DELETE Request
A DELETE request is commonly used to remove a resource.
DELETE /api/users/101
The API should return an appropriate response indicating whether the deletion was successful.
14. HTTP Status Codes
HTTP status codes indicate the result of an API request.
| Status Code | Meaning | Typical Usage |
| 200 | OK | Successful request |
| 201 | Created | Resource successfully created |
| 202 | Accepted | Request accepted for processing |
| 204 | No Content | Successful request with no response body |
| 400 | Bad Request | Invalid request data |
| 401 | Unauthorized | Authentication required or invalid |
| 403 | Forbidden | Access is not permitted |
| 404 | Not Found | Resource does not exist |
| 409 | Conflict | Request conflicts with current state |
| 429 | Too Many Requests | Rate limit exceeded |
| 500 | Internal Server Error | Server-side error |
| 502 | Bad Gateway | Gateway received invalid response |
| 503 | Service Unavailable | Service temporarily unavailable |
15. API Response
An API response is the information returned by the server after processing an API request.
A response commonly contains:
- Status code
- Response headers
- Response body
- Response time
- Cookies when applicable
HTTP/1.1 200 OK
Content-Type: application/json
{
"id": 101,
"name": "John",
"status": "active"
}
16. Request Headers
Headers provide additional information about an API request.
Common request headers include:
- Content-Type
- Accept
- Authorization
- User-Agent
- Cache-Control
Content-Type: application/json
Accept: application/json
Authorization: Bearer <token>
17. Response Headers
Response headers provide metadata about the server response.
Content-Type: application/json
Content-Length: 250
Cache-Control: no-cache
API tests can verify that important response headers are present and have expected values.
18. Request Body
The request body contains data sent from the client to the server, particularly with POST, PUT, and PATCH requests.
{
"username": "john",
"password": "password123"
}
During API testing, the tester can verify how the server handles valid, invalid, missing, and unexpected request fields.
19. Response Body
The response body contains data returned by the API.
{
"id": 101,
"name": "John",
"role": "Admin"
}
Testers can validate individual fields, data types, values, arrays, nested objects, and business rules.
20. JSON in API Testing
JSON stands for JavaScript Object Notation. It is one of the most commonly used formats for exchanging data between clients and APIs.
{
"id": 101,
"name": "John",
"email": "[email protected]",
"active": true
}
JSON consists of key-value pairs and can also contain arrays and nested objects.
21. JSON Object
{
"name": "John",
"age": 30,
"active": true
}
API tests can verify whether each field exists and whether its value and data type are correct.
22. JSON Array
{
"users": [
{
"id": 1,
"name": "John"
},
{
"id": 2,
"name": "David"
}
]
}
API testing can validate array size, individual elements, ordering when applicable, and required fields.
23. REST API
REST stands for Representational State Transfer. REST is an architectural style commonly used for designing web APIs.
REST APIs commonly use HTTP methods and resources to perform operations.
GET /users
POST /users
GET /users/101
PUT /users/101
DELETE /users/101
24. REST API Testing
REST API testing validates REST endpoints by sending HTTP requests and checking their responses.
Typical validations include:
- Status code validation
- Response body validation
- Header validation
- Schema validation
- Response time validation
- Authentication validation
- Authorization validation
- Error handling validation
25. SOAP API
SOAP stands for Simple Object Access Protocol. SOAP is a protocol for exchanging structured information between systems and commonly uses XML messages.
<soap:Envelope>
<soap:Body>
<GetUser>
<UserId>101</UserId>
</GetUser>
</soap:Body>
</soap:Envelope>
SOAP testing involves validating XML requests, responses, operations, headers, faults, and service behavior.
26. REST vs SOAP
| Feature | REST | SOAP |
| Type | Architectural style | Protocol |
| Common Data Format | JSON, XML and others | XML |
| Transport | Commonly HTTP/HTTPS | Can operate over multiple protocols |
| Complexity | Generally simpler | More structured and formal |
| Testing | HTTP endpoint testing | XML/SOAP message testing |
27. Authentication in API Testing
Authentication verifies the identity of a user or client making an API request.
Common authentication approaches include:
- Basic Authentication
- Bearer Token Authentication
- API Keys
- OAuth 2.0
- Session-based authentication
- JWT-based authentication
28. Basic Authentication
Basic Authentication sends a username and password as part of the HTTP authentication mechanism.
Authorization: Basic <encoded-credentials>
Credentials should be transmitted only over secure HTTPS connections and should be handled carefully in automated tests.
29. Bearer Token Authentication
Bearer authentication uses a token to authorize API requests.
Authorization: Bearer <access-token>
The test framework can obtain a token from an authentication endpoint and use it in subsequent requests.
30. API Key Authentication
Some APIs use API keys to identify and authorize clients.
X-API-Key: <api-key>
API keys should be stored securely rather than being exposed in source-controlled automation code.
31. OAuth 2.0
OAuth 2.0 is a widely used authorization framework. It allows applications to obtain access tokens that can be used to access protected resources.
Client
|
v
Authorization Server
|
| Access Token
v
Client
|
| Bearer Token
v
Protected API
32. JWT Authentication
JWT stands for JSON Web Token. JWTs can carry claims that are digitally signed and can be used for authentication or authorization.
Authorization: Bearer eyJhbGciOi...
API tests can verify whether protected endpoints reject missing, expired, malformed, or unauthorized tokens.
33. API Functional Testing
Functional API testing verifies that the API performs its intended business operation correctly.
For example, a create-user API can be tested by sending valid user information and verifying that:
- The request is accepted.
- The expected status code is returned.
- A user ID is generated.
- The response contains the expected fields.
- The created data can be retrieved when appropriate.
34. Positive API Testing
Positive testing verifies that an API works correctly with valid inputs.
POST /api/users
{
"name": "John",
"email": "[email protected]"
}
The test verifies that the API accepts the valid request and returns the expected successful response.
35. Negative API Testing
Negative testing verifies how an API behaves when invalid, incomplete, unauthorized, or unexpected input is supplied.
Examples include:
- Missing required field
- Invalid email
- Invalid user ID
- Incorrect authentication token
- Unsupported HTTP method
- Invalid data type
- Duplicate resource
36. Boundary Value Testing for APIs
Boundary testing verifies behavior at the limits of accepted values.
For example, if a username must contain between 5 and 20 characters, tests may include:
- 4 characters
- 5 characters
- 20 characters
- 21 characters
37. API Validation
API validation involves verifying whether the actual response matches the expected behavior.
| Validation | Example |
| Status Code | Expected 200 |
| Response Field | name should exist |
| Data Type | id should be numeric |
| Header | Content-Type should be application/json |
| Response Time | Should remain within agreed threshold |
| Business Rule | Inactive user should not place an order |
38. API Schema Validation
Schema validation verifies whether the response structure, fields, data types, and required properties conform to the expected schema.
{
"id": 101,
"name": "John",
"active": true
}
A schema can define that id must be numeric, name must be a string, and active must be Boolean.
39. API Response Time Testing
Response time testing verifies how quickly an API responds to a request.
For example, an automated test may capture response time and compare it against a defined project threshold.
Request Sent
|
v
API Processing
|
v
Response Received
|
v
Calculate Response Time
|
v
Compare with Expected Threshold
Response-time checks in functional automation should not be confused with full performance or load testing.
40. API Security Testing
API security testing verifies whether APIs properly protect sensitive resources and enforce authentication and authorization requirements.
Security-oriented API tests can verify:
- Unauthorized access is rejected.
- Invalid tokens are rejected.
- Expired tokens are rejected.
- Users cannot access resources they are not authorized to access.
- Sensitive information is not unnecessarily exposed.
- Input validation is enforced.
41. API Authorization Testing
Authentication identifies who the user is, while authorization determines what that user is allowed to access.
For example:
Admin
|
+-- Create User
+-- Delete User
+-- View Reports
Regular User
|
+-- View Profile
+-- Update Profile
API tests should verify that users cannot perform operations outside their permitted roles.
42. API Error Handling
APIs should return predictable and meaningful responses when requests fail.
{
"error": "Invalid request",
"message": "Email is required"
}
Tests should verify both the HTTP status code and the relevant error response structure.
43. API Testing Tools
Several tools and libraries are commonly used for API testing.
| Tool | Common Usage |
| Postman | Manual and automated API testing |
| REST Assured | Java-based API automation |
| SoapUI | API and SOAP testing |
| JMeter | Performance and load testing |
| Newman | Command-line execution of Postman collections |
| PyTest | Python test framework that can be used for API automation |
44. Introduction to Postman
Postman is a popular API platform used to create, send, inspect, organize, and automate API requests.
Using Postman, testers can work with:
- GET requests
- POST requests
- PUT requests
- PATCH requests
- DELETE requests
- Headers
- Authentication
- Request bodies
- Variables
- Collections
- Tests
45. Creating a GET Request in Postman
A basic GET request can be created by selecting GET, entering the endpoint URL, and sending the request.
GET https://example.com/api/users
The response can then be inspected for status code, headers, response body, and response time.
46. Creating a POST Request in Postman
A POST request can be configured with a JSON request body.
POST https://example.com/api/users
{
"name": "John",
"email": "[email protected]"
}
The response can then be validated using the Postman test scripting capability.
47. Postman Variables
Variables make API collections easier to maintain across environments.
{{baseUrl}}/api/users/{{userId}}
For example:
baseUrl = https://qa.example.com
userId = 101
Variables help avoid hard-coding environment-specific values in every request.
48. Postman Environments
Different environments may have different URLs, credentials, tokens, and configuration values.
| Environment | Base URL |
| QA | https://qa.example.com |
| Stage | https://stage.example.com |
| Production | https://www.example.com |
Environment variables make it easier to execute the same API tests against different environments.
49. Postman Collections
A collection is a group of related API requests.
Users API Collection
|
|-- Login
|-- Create User
|-- Get User
|-- Update User
|-- Delete User
Collections help organize API tests and can be executed as a group.
50. API Test Automation
API automation means writing automated scripts that send API requests and verify their responses.
Typical automation flow:
Test Data
|
v
Create Request
|
v
Send API Request
|
v
Receive Response
|
v
Validate Status
|
v
Validate Headers
|
v
Validate Response Body
|
v
Generate Report
51. REST Assured
REST Assured is a Java library commonly used to automate REST API testing. It provides a readable syntax for creating requests and validating responses.
import static io.restassured.RestAssured.*;
import static org.hamcrest.Matchers.*;
import org.testng.annotations.Test;
public class ApiTest {
@Test
public void getUserTest() {
given()
.when()
.get("https://example.com/api/users/101")
.then()
.statusCode(200)
.body("id", equalTo(101));
}
}
52. REST Assured Request Structure
REST Assured commonly follows a Given-When-Then style.
given()
|
| Request setup
v
when()
|
| Send request
v
then()
|
| Validate response
v
Assertions
given() is used for request configuration, when() performs the action, and then() validates the response.
53. REST Assured GET Example
given()
.when()
.get("https://example.com/api/users")
.then()
.statusCode(200);
This example verifies that the endpoint returns HTTP status code 200.
54. REST Assured POST Example
String requestBody = "{"
+ "\"name\":\"John\","
+ "\"email\":\"[email protected]\""
+ "}";
given()
.header("Content-Type", "application/json")
.body(requestBody)
.when()
.post("https://example.com/api/users")
.then()
.statusCode(201);
55. API Testing with TestNG
API automation can be integrated with TestNG to organize test cases, execute suites, perform assertions, and generate reports.
import org.testng.Assert;
import org.testng.annotations.Test;
public class ApiTest {
@Test
public void statusCodeTest() {
int actualStatusCode = 200;
int expectedStatusCode = 200;
Assert.assertEquals(actualStatusCode, expectedStatusCode);
}
}
56. API Testing with Selenium Frameworks
Selenium primarily automates web browsers, while API testing validates backend services. Both can be combined in a broader automation framework.
API Testing
|
v
Create Test Data
|
v
UI Testing with Selenium
|
v
Validate Application
|
v
API Validation
|
v
Final Test Result
For example, an API can be used to create test data before a Selenium UI test starts.
57. API Testing and Database Testing
API tests can also be combined with database validation when the application requires verification of backend data.
API Request
|
v
Application Service
|
v
Database
|
+---- API Response
|
+---- Database Validation
This can help verify whether an API operation correctly creates, updates, or retrieves database records.
58. API Testing Lifecycle
Requirement Analysis
|
v
API Specification Review
|
v
Test Scenario Design
|
v
Test Data Preparation
|
v
API Request Creation
|
v
Test Execution
|
v
Response Validation
|
v
Defect Reporting
|
v
Regression Testing
|
v
Test Reporting
59. API Test Scenarios
Common API test scenarios include:
- Verify valid GET request.
- Verify valid POST request.
- Verify valid PUT request.
- Verify valid PATCH request.
- Verify DELETE operation.
- Verify invalid request data.
- Verify missing mandatory fields.
- Verify authentication.
- Verify authorization.
- Verify invalid tokens.
- Verify response headers.
- Verify response schema.
- Verify response time.
- Verify error messages.
- Verify duplicate data handling.
60. API Testing for Login
Login APIs are commonly tested using valid and invalid credentials.
POST /api/login
{
"username": "john",
"password": "password123"
}
Possible validations include:
- Valid credentials return a successful response.
- Invalid credentials are rejected.
- Missing username is handled correctly.
- Missing password is handled correctly.
- Authentication token is returned when appropriate.
- Sensitive information is not unnecessarily exposed.
61. API Testing for E-Commerce
E-commerce systems provide many opportunities for API testing.
Login API
|
v
Product API
|
v
Cart API
|
v
Order API
|
v
Payment API
|
v
Order Confirmation API
Each service can be tested independently and through end-to-end API workflows.
62. API Testing for User Management
A user-management API may support:
POST /users
GET /users
GET /users/101
PUT /users/101
PATCH /users/101
DELETE /users/101
Testers can create a user, retrieve the user, update the user, and finally delete the user as part of a controlled test workflow.
63. API Chaining
API chaining means using information returned by one API request in a subsequent API request.
Login API
|
| Returns token
v
Get User API
|
| Returns user ID
v
Get Orders API
|
| Returns order ID
v
Get Order Details API
API chaining is useful for testing realistic business workflows.
64. Extracting Values from API Responses
Automation tests often need to extract values such as IDs or tokens from responses.
{
"id": 101,
"token": "abc123"
}
The extracted ID or token can then be used in subsequent API requests.
65. API Contract Testing
Contract testing verifies that the communication contract between API consumers and providers remains compatible.
A contract can define expected:
- Endpoints
- HTTP methods
- Request fields
- Response fields
- Data types
- Status codes
Contract testing helps detect breaking API changes between services.
66. API Regression Testing
API regression testing verifies that changes to the application have not broken previously working API functionality.
A regression suite may contain tests for:
- Authentication
- User management
- Product APIs
- Order APIs
- Payment workflows
- Search APIs
- Reporting APIs
67. API Integration Testing
Integration testing verifies that multiple services communicate correctly with each other.
Order Service
|
v
Inventory Service
|
v
Payment Service
|
v
Notification Service
API integration tests can verify that information flows correctly between these services.
68. API Testing in CI/CD
API tests can be integrated into CI/CD pipelines so that automated tests execute whenever application changes are built or deployed.
Developer Commit
|
v
Build
|
v
API Tests
|
v
UI Tests
|
v
Reports
|
v
Deployment
Automated API tests can provide rapid feedback about backend regressions.
69. API Test Data Management
Good API automation requires reliable and maintainable test data.
Test data can come from:
- Java objects
- JSON files
- CSV files
- Excel files
- Databases
- Environment variables
- Configuration files
- Test data APIs
Sensitive credentials and tokens should be managed through appropriate secure mechanisms rather than committed as plain text.
70. API Testing Best Practices
- Understand the API specification before writing tests.
- Use meaningful test names.
- Validate both successful and unsuccessful scenarios.
- Validate status codes.
- Validate response body fields.
- Validate important response headers.
- Validate schemas where appropriate.
- Use reusable request utilities.
- Separate test data from test logic.
- Avoid hard-coding sensitive credentials.
- Use environment-specific configuration.
- Keep API tests independent whenever practical.
- Use API chaining for realistic workflows where required.
- Integrate automated API tests with CI/CD.
- Generate useful test reports.
- Log sufficient information for debugging without exposing secrets.
71. Common Mistakes in API Testing
- Checking only the status code and ignoring the response body.
- Not testing negative scenarios.
- Ignoring authentication and authorization.
- Hard-coding tokens and passwords.
- Using production data carelessly in test automation.
- Not validating required fields.
- Ignoring response headers.
- Not checking API error handling.
- Creating tightly coupled test cases.
- Not managing test data correctly.
- Ignoring environment differences.
- Not integrating API tests into regression execution.
72. API Testing vs API Automation
| API Testing | API Automation |
| Can be performed manually | Performed using automated scripts/tools |
| Useful for exploration | Useful for repeatable regression |
| May use Postman manually | Can use REST Assured, PyTest, Postman/Newman, etc. |
| Requires tester interaction | Can run automatically in CI/CD |
73. API Testing Project Structure
src
|-- test
| |-- java
| |-- tests
| | |-- LoginApiTest.java
| | |-- UserApiTest.java
| | |-- ProductApiTest.java
| | |-- OrderApiTest.java
| |
| |-- clients
| | |-- ApiClient.java
| |
| |-- data
| | |-- TestData.java
| |
| |-- utilities
| |-- ConfigReader.java
| |-- JsonUtility.java
| |-- TestDataUtility.java
|-- resources
|-- config
| |-- config.properties
|-- testdata
|-- users.json
|-- products.json
74. Complete Basic REST Assured Example
import static io.restassured.RestAssured.*;
import static org.hamcrest.Matchers.*;
import org.testng.annotations.Test;
public class UserApiTest {
@Test
public void getUserTest() {
given()
.when()
.get("https://example.com/api/users/101")
.then()
.statusCode(200)
.body("id", equalTo(101))
.body("name", notNullValue());
}
}
This example demonstrates the basic structure of an automated API test: configure the request, send the request, and validate the response.
75. Complete POST API Testing Example
import static io.restassured.RestAssured.*;
import org.testng.annotations.Test;
public class CreateUserApiTest {
@Test
public void createUserTest() {
String requestBody = "{"
+ "\"name\":\"John\","
+ "\"email\":\"[email protected]\","
+ "\"role\":\"user\""
+ "}";
given()
.header("Content-Type", "application/json")
.body(requestBody)
.when()
.post("https://example.com/api/users")
.then()
.statusCode(201);
}
}
76. API Test Execution Flow
Test Case
|
v
Prepare Test Data
|
v
Build Request
|
v
Add Headers
|
v
Add Authentication
|
v
Send Request
|
v
Receive Response
|
v
Validate Status Code
|
v
Validate Headers
|
v
Validate Response Body
|
v
Assertions
|
v
Generate Report
77. API Testing and Selenium Automation
API testing and Selenium UI testing complement each other. Selenium validates browser-level functionality, while API testing validates backend services.
| Scenario | Possible Testing Approach |
| Login backend | API testing |
| Login page appearance | Selenium UI testing |
| Create test user | API testing |
| Verify user profile in browser | Selenium UI testing |
| Validate order service | API testing |
| Verify checkout screen | Selenium UI testing |
78. Real-World API Testing Architecture
Test Data
|
+----------+----------+
| | |
JSON CSV DB
| | |
+----------+----------+
|
v
Test Framework
|
v
API Client
|
v
API Endpoint
|
v
Backend Services
|
v
Database
|
v
API Response
|
v
Validations
|
v
Report
79. API Testing Interview Questions
1. What is API Testing?
API testing is the process of validating an API's functionality, responses, data, authentication, error handling, and other expected behavior.
2. What does API stand for?
API stands for Application Programming Interface.
3. What is an endpoint?
An endpoint is a URL through which a specific API resource or operation can be accessed.
4. What is the difference between GET and POST?
GET is commonly used to retrieve resources, while POST is commonly used to create resources or submit data for processing.
5. What is PUT?
PUT is commonly used to replace or update an existing resource.
6. What is PATCH?
PATCH is commonly used to partially update an existing resource.
7. What is DELETE?
DELETE is commonly used to remove a resource.
8. What is a status code?
An HTTP status code indicates the result of an HTTP request.
9. What is JSON?
JSON is a lightweight data-interchange format commonly used in modern APIs.
10. What is REST?
REST is an architectural style commonly used to design web APIs around resources and HTTP operations.
11. What is SOAP?
SOAP is a protocol for exchanging structured information between systems, commonly using XML messages.
12. What is authentication?
Authentication verifies the identity of the client or user making an API request.
13. What is authorization?
Authorization determines whether an authenticated user or client is permitted to perform a particular operation.
14. What is API chaining?
API chaining is the process of using information from one API response in a subsequent API request.
15. What is REST Assured?
REST Assured is a Java library commonly used for automating REST API tests.
16. Can Selenium test APIs directly?
Selenium is primarily designed for browser automation. API testing is normally handled using dedicated API tools or libraries, which can be integrated into the same automation ecosystem.
17. What should be validated in an API response?
Status code, response body, headers, schema, data types, business rules, authentication behavior, and other project-specific requirements can be validated.
18. What is negative API testing?
Negative API testing verifies how an API behaves when invalid, incomplete, unauthorized, or unexpected data is provided.
19. Why is API testing useful in CI/CD?
API tests can execute automatically during builds and deployments, providing rapid feedback about backend regressions.
20. What is schema validation?
Schema validation verifies that the response structure and data types conform to an expected contract.
80. Quick Reference Table
| Concept | Description |
| API | Interface used for communication between software components |
| Endpoint | URL through which an API resource or operation is accessed |
| GET | Retrieve data |
| POST | Create or submit data |
| PUT | Replace or update a resource |
| PATCH | Partially update a resource |
| DELETE | Delete a resource |
| JSON | Common API data format |
| Status Code | Indicates the result of an HTTP request |
| Authentication | Verifies identity |
| Authorization | Controls access to resources |
| Postman | API development and testing platform |
| REST Assured | Java API automation library |
| API Chaining | Uses one API response in another API request |
| Schema Validation | Validates response structure and data types |
81. Learning Roadmap for API Testing
- Understand HTTP and web application fundamentals.
- Learn API concepts and client-server communication.
- Learn HTTP methods.
- Understand status codes.
- Learn request and response structure.
- Learn headers and authentication.
- Understand JSON and XML.
- Practice API testing using Postman.
- Learn variables and environments.
- Learn collections and API workflows.
- Practice positive and negative API testing.
- Learn API chaining.
- Learn schema validation.
- Learn REST Assured or another automation library.
- Integrate API tests with TestNG.
- Combine API testing with Selenium automation where appropriate.
- Integrate API tests with Maven and CI/CD.
- Build a reusable API automation framework.
82. Practical Exercises
- Create a GET request and validate status code 200.
- Create a POST request for user creation.
- Test PUT and PATCH operations.
- Test DELETE functionality.
- Validate response headers.
- Validate JSON response fields.
- Test invalid request data.
- Test missing mandatory fields.
- Test authentication using a token.
- Test authorization for different user roles.
- Create an API chain using multiple endpoints.
- Create a Postman collection for user management.
- Create automated API tests using REST Assured.
- Integrate REST Assured with TestNG.
- Execute API tests through Maven.
- Run API tests in a CI/CD pipeline.
83. Practical E-Commerce API Workflow
Login
|
v
Get Authentication Token
|
v
Get Products
|
v
Select Product
|
v
Add Product to Cart
|
v
Create Order
|
v
Process Payment
|
v
Verify Order
|
v
Logout
This workflow demonstrates how API testing can validate an entire business process rather than testing individual endpoints only.
84. Final Summary
API Testing is an important part of modern software quality assurance. It validates backend services directly by sending requests and verifying responses without depending entirely on the graphical user interface.
API testing covers HTTP methods, endpoints, request bodies, response bodies, headers, status codes, authentication, authorization, error handling, schema validation, business rules, and response behavior.
Tools such as Postman can be used for exploratory and manual API testing, while automation libraries such as REST Assured can be used to build maintainable automated API test suites in Java. API testing can also be combined with TestNG, Maven, Selenium, reporting systems, and CI/CD pipelines.
A well-designed API automation framework separates test data, API clients, test cases, configuration, validation, and reporting. This makes the framework easier to maintain and scale as the application grows.
85. Course Resources
Continue learning Selenium automation, API testing, TestNG, Page Object Model, data-driven testing, and automation framework development:
Final Takeaway: API Testing helps testers validate application services at the backend level by checking requests, responses, status codes, data, authentication, authorization, business rules, and error handling. When combined with UI automation and CI/CD, API testing becomes an important part of a complete modern test automation strategy.