Prompt
How do I validate response status codes, headers, and payloads in API tests?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
To validate API responses in tests, check three main parts:
1) Status code
Verify the HTTP status matches what you expect.
Examples:
200 OKfor successful GET201 Createdfor successful POST400 Bad Requestfor invalid input401 Unauthorizedwhen auth is missing404 Not Foundwhen resource doesn’t exist
Assertion idea:
- “Response status should be 200”
2) Headers
Validate important response headers such as:
Content-Type→ e.g.application/jsonCache-ControlAuthorization/WWW-AuthenticateLocationfor creation responses (201)Content-Lengthif relevant
Examples:
- Ensure JSON responses return
Content-Type: application/json - Ensure a
201 Createdresponse includes aLocationheader
3) Payload/body
Validate the response body content and structure.
For JSON responses, check:
- Required fields exist
- Field values are correct
- Data types are correct
- Nested objects/arrays have expected structure
- Optional fields behave correctly
- Error responses contain proper error codes/messages
Examples:
idis present and is a number/stringnameequals"John"itemsis an array with 3 elementserror.messageis not empty for invalid requests
Good validation strategy
A strong API test usually combines:
- Status code
- Header checks
- Schema validation (structure of payload)
- Specific field assertions (exact values/business rules)
- Negative cases (invalid input, unauthorized, missing fields)
Example test flow
- Send request
- Assert status code
- Assert response headers
- Parse body
- Assert fields and structure
Example pseudo-test
Send GET /users/1
Assert status == 200
Assert Content-Type == application/json
Assert body.id == 1
Assert body.name is not empty
Assert body.email contains "@"
If you want, I can also show you how to do this in Postman, REST Assured, Python (pytest), or JavaScript (Jest/Supertest).