---
kind: guide
zz: "0.8.0"
updated: 2026-10-10
state: live
rules: https://zriz.io/llms.txt
---
# Test an API status code and response body

Check the status code and the fields of the result in one zriz pipeline. A test that reads only the status code misses a wrong body.

## The problem {#problem}

An API can answer `201` and send a wrong body. A field is absent, or it holds the data of a different user. A test that reads only the status code passes, and the client breaks.

## The test {#test}

The example is a shop API. `POST /api/auth/register` makes a user and answers `201` with a token.

Start from a project that `zz init` made: the [quick start](https://zriz.io/docs.md) gives the commands. Add the action `register` to the resource file. Keep the action `check` as it is.

`.zriz/resources/target.json`:

```json
{
  "type": "http",
  "description": "Your app under test",
  "base-url": "${env.TARGET_URL}",
  "headers": { "Content-Type": "application/json" },
  "actions": {
    "check": { "method": "GET", "path": "/api/health" },
    "register": { "method": "POST", "path": "/api/auth/register" }
  }
}
```

`.zriz/pipelines/register-reply.json`:

```json
{
  "description": "Sign up: check the status code and the body",
  "steps": [
    { "set": { "email": "u-${gen.uuid}@test.com" } },
    {
      "call": "target/register",
      "body": { "email": "${ctx.email}", "password": "secret123", "name": "Ann" },
      "expect": [
        ["status", "==", 201],
        ["body.email", "==", "${ctx.email}"],
        ["body.name", "==", "Ann"],
        ["body.user_id", "not-empty"],
        ["body.token", "not-empty"]
      ]
    }
  ]
}
```

## Run it {#run}

```sh
zz run register-reply
```

```text
"status":"pass"
```

## What it proves {#proves}

- `status == 201`: the API made the user. A `200` or a `500` fails the test.
- `body.email == ${ctx.email}`: the result has the e-mail that the test sent, not a different one.
- `body.name == Ann`: the API stored the name.
- `not-empty` on `body.user_id` and `body.token`: the client gets the id and the token that it needs.

> Common mistake: A fixed e-mail passes one time, then fails as a duplicate. `${gen.uuid}` makes a new e-mail for each run.

## Next {#next}

- [Test that a bad request returns 400](https://zriz.io/learn/test-api-400-bad-request.md)
- [Pipelines](https://zriz.io/docs/pipelines.md) lists each operator of a check.
