Contents

Engineering Craft › Testing · also in API Design

API Testing

Calling endpoints and checking status codes, bodies and side effects.

Also known as: REST API testing, endpoint testing, testing APIs

API testing means calling your endpoints the way a client would and checking the result: status code, response body and, just as important, what changed behind the scenes.

def test_create_order(client, db):
    res = client.post("/orders", json={"item_id": 7, "quantity": 2})

    assert res.status_code == 201
    body = res.json()
    assert body["quantity"] == 2
    assert db.query(Order).count() == 1          # side effect really happened

What to check

  • Status codes: 201 for created, 400 for bad input, 401/403 for auth problems, 404 for missing things.
  • Response body: the right fields and values, not just “it returned JSON”.
  • Side effects: rows written, emails queued, events published.
  • Errors: invalid or missing input, wrong types, duplicates and unauthorized users. The sad paths are where most bugs live.
  • Security basics: can user A read or change user B’s data? (see authentication vs authorization).

Ways to run them

ApproachNotes
Framework test client in your test suiteFast; runs in CI. Most backend tests use this
Against a running serverCloser to real, slower; good for a smoke test after deploy
Manual tools (curl, Postman, Insomnia)Good for exploring; saved collections can be automated

Use a separate test database so tests never touch real data, and make each test independent of the others. API tests are a kind of integration test: they exercise routing, validation and the database together.