Prompt
How do I automate endpoint tests for a REST API?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To automate endpoint tests for a REST API, you generally want to test:
- Status codes — e.g.
200,201,400,401,404 - Response body — fields, types, values, schema
- Headers — content type, auth headers, caching, etc.
- Behavior — auth, validation, pagination, sorting, filtering
- Error cases — invalid input, missing auth, nonexistent resources
A practical approach
1) Pick a test layer
Most teams automate API endpoint tests at the integration/API test layer, not just unit tests.
Common tools:
- JavaScript/TypeScript: Jest + Supertest, Playwright API, Axios + Jest
- Python: Pytest + Requests
- Java: RestAssured
- .NET: xUnit + HttpClient / Flurl
- Postman/Newman: good for quick automation and CI
- Python/Java/JS all work fine
2) Create a repeatable test setup
Your tests should not depend on manual steps.
Typical setup:
- Start with a known database state
- Seed test data
- Use a dedicated test environment
- Clean up data after tests, or reset the DB between runs
- Use test credentials / tokens
3) Write tests around endpoint behavior
For each endpoint, cover:
- Happy path
- Validation failures
- Unauthorized/forbidden
- Not found
- Edge cases
- Contract/schema checks
Example cases for GET /users/:id:
- returns
200for an existing user - returns
404for missing user - returns
401without token - returns
403for insufficient permission - returns expected JSON schema
4) Use assertions
A good API test checks more than just “it didn’t crash.”
Example assertions:
response.status == 200response.body.id === expectedIdresponse.body.nameis a stringresponse.headers["content-type"]containsapplication/json
5) Run in CI
Automate execution in:
- GitHub Actions
- GitLab CI
- Jenkins
- Azure DevOps
- CircleCI
Run tests:
- on every pull request
- on merge to main
- optionally nightly against staging
Example: Python + Pytest + Requests
import requests
BASE_URL = "https://api.example.com"
def test_get_user():
response = requests.get(f"{BASE_URL}/users/123", headers={
"Authorization": "Bearer test-token"
})
assert response.status_code == 200
data = response.json()
assert data["id"] == 123
assert "name" in data
Example: JavaScript + Jest + Supertest
const request = require('supertest');
const app = require('../app');
test('GET /users/123 returns a user', async () => {
const res = await request(app)
.get('/users/123')
.set('Authorization', 'Bearer test-token');
expect(res.statusCode).toBe(200);
expect(res.body.id).toBe(123);
expect(res.body.name).toBeDefined();
});
Best practices
- Keep tests independent
- Make test data explicit
- Don’t rely on test order
- Avoid mocking the system under test too much
- Test both success and failure paths
- Validate response schema, not just values
- Use separate environments for testing
- Keep tests fast enough to run in CI
Helpful additions
- OpenAPI/Swagger: generate or validate tests against your API spec
- JSON Schema validation: ensure response structure is correct
- Contract testing: e.g. Pact for consumer/provider contracts
- Postman collections: easy to maintain and run with Newman
If you want, I can give you:
- a complete example in Python, JavaScript, or Java
- a CI pipeline example
- or a test plan/template for REST endpoints