Prompt

How do I test API auth flows with API keys, JWT, and OAuth?

Technology / Testing & QA1 observationLast seen Oct 6, 2026

Latest observation

Oct 6, 2026OpenAI APIWeb search: off

A good way to test auth flows is to separate them by what you’re validating:

  • API keys: simple client authentication / authorization
  • JWTs: token structure, signature, claims, expiration
  • OAuth: end-to-end grant flow, token issuance, refresh, and scope enforcement

Here’s a practical test strategy for each.


1) API keys

What to test

  • Missing key → 401 Unauthorized
  • Invalid key → 401 Unauthorized
  • Valid key but wrong permissions → 403 Forbidden
  • Key in the wrong place (header vs query vs body) → rejected
  • Key rotation / revocation works
  • Rate limits / quotas per key

Example request

curl -H "X-API-Key: your-key-here" https://api.example.com/v1/data

Good test cases

  • No header
  • Empty header
  • Random string
  • Expired/revoked key
  • Correct key, forbidden endpoint
  • Correct key, allowed endpoint

Tips

  • Use environment variables for secrets
  • Add negative tests for malformed headers and whitespace
  • Assert response body does not leak whether the key exists

2) JWT auth

JWT tests usually cover verification and claims.

What to test

  • Token missing → 401
  • Token expired (exp) → 401
  • Not valid before (nbf) → 401
  • Issuer (iss) mismatch → 401
  • Audience (aud) mismatch → 401
  • Signature invalid / tampered token → 401
  • Wrong algorithm rejected (for example, accept only RS256 if expected)
  • Scope/role claims enforced → 403
  • Clock skew tolerance behaves as expected

Example request

curl -H "Authorization: Bearer <jwt>" https://api.example.com/v1/data

Good test cases

  • Valid token
  • Expired token
  • Token with modified payload but same signature
  • Token signed with wrong key
  • Token with wrong aud
  • Token with wrong iss
  • Token lacking required scope
  • Token with alg: none if your system must reject it

Tips

  • Test with both real tokens from the identity provider and locally generated tokens for unit/integration tests
  • Verify the API checks signature + claims, not just “token exists”
  • Make sure the backend rejects tokens signed by untrusted keys

3) OAuth flows

OAuth testing depends on the grant type, but the most common is Authorization Code with PKCE.

What to test

  • Authorization redirect happens correctly
  • User login and consent flow works
  • Authorization code can be exchanged only once
  • Code expires quickly
  • PKCE verifier/challenge validation
  • Access token works at resource server
  • Refresh token flow works, if enabled
  • Scope requested vs granted is correct
  • Revocation/logout invalidates tokens if supported

Main flow to test

  1. Client sends user to authorization endpoint
  2. User authenticates and grants consent
  3. Authorization server returns code
  4. Client exchanges code + PKCE verifier for tokens
  5. API accepts access token
  6. Refresh token renews access token

Example checks

  • Authorization endpoint returns expected redirect URI
  • state is preserved and validated
  • Code exchange without correct PKCE verifier fails
  • Reusing the same code fails
  • Expired access token is rejected
  • Refresh token rotation works if enabled

Tips

  • Automate with a test identity provider or sandbox tenant
  • Use browser automation for the redirect/consent part if needed
  • Validate scopes on protected API endpoints
  • Mock OAuth only for unit tests; use real auth server for integration tests

4) Recommended test layers

Unit tests

  • JWT validation logic
  • Scope/role authorization checks
  • Header parsing
  • Token claim mapping

Integration tests

  • API key accepted/rejected by actual service
  • JWTs issued by real signing keys
  • OAuth token exchange against sandbox IdP

End-to-end tests

  • Full browser login for OAuth
  • Protected API call with token
  • Refresh and revocation scenarios

5) Common negative tests for all auth types

  • Missing auth header
  • Malformed auth header
  • Wrong content type
  • Expired credentials
  • Replay attempts
  • Insufficient scope/role
  • Invalid tenant/issuer
  • Accessing a different user’s resource

6) Useful tooling

  • curl / HTTPie for manual checks
  • Postman / Insomnia for exploratory auth testing
  • pytest / Jest / JUnit for automated tests
  • WireMock / mock servers for dependency isolation
  • OAuth sandbox / test IdP for real flows
  • JWT libraries to generate test tokens

7) Best practice checklist

  • Test both 401 and 403
  • Verify token expiry and claim validation
  • Use least-privileged scopes
  • Rotate/revoke secrets and tokens in tests
  • Keep auth tests separate from business-logic tests
  • Prefer real integration tests for OAuth

If you want, I can also give you:

  1. a sample test matrix for API key/JWT/OAuth auth, or
  2. example pytest/Postman test scripts for each flow.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as Circuit. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.