Verifying programmatic interfaces.
WHY IT IS VALUABLE
Faster and more stable than interface testing, while covering real behaviour.
WHAT TO VERIFY
Status codes Response structure and types Values, against expectation Headers Error responses
WHAT TO TEST FOR EVERY ENDPOINT
Valid requests Missing required fields Invalid types and formats Values at boundaries Unauthorised access Access to another user's resources
WHY THAT LAST ONE MOST
Authorisation on individual records is the commonest serious fault in interfaces.
HOW TO TEST IT
Authenticate as one user and request another's resource.
WHAT TO VERIFY ABOUT ERRORS
A meaningful status code A structured body No internal detail disclosed
WHAT TO TEST ABOUT STATE
That operations meant to be repeatable are That creating twice produces the expected result That deleting a missing item behaves sensibly
WHAT CONTRACT TESTING PROVIDES
Assurance that consumers and providers agree.
WHAT SCHEMA VALIDATION PROVIDES
Automatic checking of structure against a definition.
WHAT TO TEST ABOUT PAGINATION
Boundaries, empty results, and stability while data changes.
WHAT TO AUTOMATE
All of it, since it is fast and stable.