Learn API testing
Short lessons on API and database tests. Each lesson solves one test problem with one zriz pipeline that you can copy.
- Test an API status code and response body Check the status code and the fields of the result in one zriz pipeline. A test that reads only the status code misses a wrong body.
- Test that a bad request returns 400 Send a broken request on purpose in a zriz pipeline. Check for status 400 and the exact error text, so a bad input never gets a 500 or a 201.
- Test that an API returns 401 without a token Call a protected endpoint with no token and with a bad token in one zriz pipeline. Each call must get status 401 and no data.
- Test API authorization between two users Make two users in one zriz pipeline. User A creates an order, then user B asks for it. The API must refuse user B: this finds broken access control.
- Test that duplicate requests create one row Send one request three times in a zriz pipeline, then count the rows in the database. One row proves that a retry makes no duplicate.
- Test that a failed request writes no row Send a bad request in a zriz pipeline, then query the database. Status 400 and zero rows prove that a refused request stores nothing.
- Test a login flow from sign-up to token Chain three calls in one zriz pipeline: sign up, log in, then use the token of the login. The flow passes only when each part works with the next.
- Test that a password is stored as a hash Sign up in a zriz pipeline, then read the user row. The test fails if a result holds the password or the database holds it as plain text.
- Test an async API with polling, not sleep Use the poll step of a zriz pipeline to wait for an async result. The test ends when the result comes, and fails if it never does.
- Test that a missing record returns 404 Ask for a record that does not exist in a zriz pipeline. The API must answer 404 with an error, not 500 and not 200 with an empty body.