What to check on every endpoint
- Correct status codes (200, 201, 400, 401, 403, 404, 429, 500)
- Response structure matches the documented schema
- Required fields validated; bad input rejected
- Authentication: no token, expired token, wrong token
- Authorisation: user A cannot access user B’s data
- Pagination, filters and sorting
- Idempotency for payments and webhooks
- Rate limiting and sensible error messages
Starter test list
| Test | Expected |
|---|---|
| GET resource without login | 401 |
| GET another user’s resource | 403 or 404 |
| POST with missing required field | 400 with clear message |
| POST same payment twice | Only one charge |
| Very large payload | Rejected safely |
| 100 requests in a few seconds | 429 or graceful slowdown |
Tools and process
- Collect your API in Postman or an OpenAPI file.
- Write checks for each endpoint above.
- Run them in CI on every pull request.
- Add a case for every production bug.
- Review logs for errors after each release.
Why it matters for AI-built apps
AI tools often generate endpoints that trust the client. API tests that try other users’ IDs catch broken access control early. See penetration testing for AI-built apps.
Get your app tested QA from $20/h
Tell us your app, platforms and release date. We scope the hours and quote.
Frequently asked questions
Do I need to know how to code to test APIs?
Basic tests can be done in Postman without code; automation is easier with some scripting.
Is API testing enough?
No. Combine it with UI, security and performance testing.
Can you set up API test automation?
Yes, with CI so tests run on every change.
Get a free quote in 24 hours
Tell us what you need. We reply with scope, timeline and a fixed price.