Prompt
How do I test API auth flows with API keys, JWT, and OAuth?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
A good way to test auth flows is to separate them by what you’re validating:
- API keys: simple client authentication / authorization
- JWTs: token structure, signature, claims, expiration
- OAuth: end-to-end grant flow, token issuance, refresh, and scope enforcement
Here’s a practical test strategy for each.
1) API keys
What to test
- Missing key →
401 Unauthorized - Invalid key →
401 Unauthorized - Valid key but wrong permissions →
403 Forbidden - Key in the wrong place (header vs query vs body) → rejected
- Key rotation / revocation works
- Rate limits / quotas per key
Example request
curl -H "X-API-Key: your-key-here" https://api.example.com/v1/data
Good test cases
- No header
- Empty header
- Random string
- Expired/revoked key
- Correct key, forbidden endpoint
- Correct key, allowed endpoint
Tips
- Use environment variables for secrets
- Add negative tests for malformed headers and whitespace
- Assert response body does not leak whether the key exists
2) JWT auth
JWT tests usually cover verification and claims.
What to test
- Token missing →
401 - Token expired (
exp) →401 - Not valid before (
nbf) →401 - Issuer (
iss) mismatch →401 - Audience (
aud) mismatch →401 - Signature invalid / tampered token →
401 - Wrong algorithm rejected (for example, accept only RS256 if expected)
- Scope/role claims enforced →
403 - Clock skew tolerance behaves as expected
Example request
curl -H "Authorization: Bearer <jwt>" https://api.example.com/v1/data
Good test cases
- Valid token
- Expired token
- Token with modified payload but same signature
- Token signed with wrong key
- Token with wrong
aud - Token with wrong
iss - Token lacking required
scope - Token with
alg: noneif your system must reject it
Tips
- Test with both real tokens from the identity provider and locally generated tokens for unit/integration tests
- Verify the API checks signature + claims, not just “token exists”
- Make sure the backend rejects tokens signed by untrusted keys
3) OAuth flows
OAuth testing depends on the grant type, but the most common is Authorization Code with PKCE.
What to test
- Authorization redirect happens correctly
- User login and consent flow works
- Authorization code can be exchanged only once
- Code expires quickly
- PKCE verifier/challenge validation
- Access token works at resource server
- Refresh token flow works, if enabled
- Scope requested vs granted is correct
- Revocation/logout invalidates tokens if supported
Main flow to test
- Client sends user to authorization endpoint
- User authenticates and grants consent
- Authorization server returns code
- Client exchanges code + PKCE verifier for tokens
- API accepts access token
- Refresh token renews access token
Example checks
- Authorization endpoint returns expected redirect URI
stateis preserved and validated- Code exchange without correct PKCE verifier fails
- Reusing the same code fails
- Expired access token is rejected
- Refresh token rotation works if enabled
Tips
- Automate with a test identity provider or sandbox tenant
- Use browser automation for the redirect/consent part if needed
- Validate scopes on protected API endpoints
- Mock OAuth only for unit tests; use real auth server for integration tests
4) Recommended test layers
Unit tests
- JWT validation logic
- Scope/role authorization checks
- Header parsing
- Token claim mapping
Integration tests
- API key accepted/rejected by actual service
- JWTs issued by real signing keys
- OAuth token exchange against sandbox IdP
End-to-end tests
- Full browser login for OAuth
- Protected API call with token
- Refresh and revocation scenarios
5) Common negative tests for all auth types
- Missing auth header
- Malformed auth header
- Wrong content type
- Expired credentials
- Replay attempts
- Insufficient scope/role
- Invalid tenant/issuer
- Accessing a different user’s resource
6) Useful tooling
- curl / HTTPie for manual checks
- Postman / Insomnia for exploratory auth testing
- pytest / Jest / JUnit for automated tests
- WireMock / mock servers for dependency isolation
- OAuth sandbox / test IdP for real flows
- JWT libraries to generate test tokens
7) Best practice checklist
- Test both
401and403 - Verify token expiry and claim validation
- Use least-privileged scopes
- Rotate/revoke secrets and tokens in tests
- Keep auth tests separate from business-logic tests
- Prefer real integration tests for OAuth
If you want, I can also give you:
- a sample test matrix for API key/JWT/OAuth auth, or
- example pytest/Postman test scripts for each flow.