REST API Testing: Beyond the Status Code 200
2 years ago
•8 min read
88
10

REST API Testing: Beyond the Status Code 200
When we think of API testing, the first thing that often comes to mind is verifying that we get a 200 OK response. While that's a good start, true API quality assurance goes much deeper. As an SDET, your goal is to ensure the API is secure, resilient, and correct under all conditions.
Why API Testing Matters
API tests are generally faster and more stable than UI tests. They allow you to test the core logic of your application without the overhead of a browser. In a microservices architecture, API testing is the primary way to ensure that different services can communicate correctly.
Essential Testing Levels
- Contract Testing: Verifying that the API adheres to its defined contract (e.g., OpenAPI/Swagger spec).
- Functional Testing: Ensuring the business logic is correct. If I create a user, can I fetch that user with the returned ID?
- Security Testing: Can I access resources I'm not authorized to see? What happens if I send a malformed token?
- Negative Testing: Sending invalid data to ensure the API returns appropriate error codes (
400 Bad Request,422 Unprocessable Entity) instead of crashing (500 Internal Server Error).
Tooling: REST Assured vs. Playwright
REST Assured (Java)
Perfect for teams already working in Java. It provides a highly readable DSL for testing APIs.
given()
.header("Content-Type", "application/json")
.body(userPayload)
.when()
.post("/api/users")
.then()
.statusCode(201)
.body("name", equalTo("Qumbar"))
.body("id", notNullValue());
Playwright API Testing (JavaScript/TypeScript)
If you're already using Playwright for UI tests, you can use the same framework for API tests. This allows for powerful end-to-end scenarios (e.g., create data via API, verify via UI).
const { test, expect } = require('@playwright/test');
test('should create a new user', async ({ request }) => {
const newUser = await request.post('/api/users', {
data: { name: 'Qumbar', email: 'qumbar@example.com' }
});
expect(newUser.ok()).toBeTruthy();
const body = await newUser.json();
expect(body.name).toBe('Qumbar');
});
Schema Validation
One of the most important aspects of API testing is validating the response schema. Even if the values are correct, if a field changes from a number to a string, it can break downstream consumers. Tools like JSON Schema are invaluable for this.
Conclusion
API testing is a fundamental pillar of modern QA. By moving "left" and testing APIs early and often, you can catch bugs before they ever reach the UI, saving time and improving the overall stability of your system.