Prompt

How do I validate response status codes, headers, and payloads in API tests?

Technology / Testing & QA1 observationLast seen Oct 6, 2026

Latest observation

Oct 6, 2026OpenAI APIWeb search: off

To validate API responses in tests, check three main parts:

1) Status code

Verify the HTTP status matches what you expect.

Examples:

  • 200 OK for successful GET
  • 201 Created for successful POST
  • 400 Bad Request for invalid input
  • 401 Unauthorized when auth is missing
  • 404 Not Found when resource doesn’t exist

Assertion idea:

  • “Response status should be 200”

2) Headers

Validate important response headers such as:

  • Content-Type → e.g. application/json
  • Cache-Control
  • Authorization / WWW-Authenticate
  • Location for creation responses (201)
  • Content-Length if relevant

Examples:

  • Ensure JSON responses return Content-Type: application/json
  • Ensure a 201 Created response includes a Location header

3) Payload/body

Validate the response body content and structure.

For JSON responses, check:

  • Required fields exist
  • Field values are correct
  • Data types are correct
  • Nested objects/arrays have expected structure
  • Optional fields behave correctly
  • Error responses contain proper error codes/messages

Examples:

  • id is present and is a number/string
  • name equals "John"
  • items is an array with 3 elements
  • error.message is not empty for invalid requests

Good validation strategy

A strong API test usually combines:

  • Status code
  • Header checks
  • Schema validation (structure of payload)
  • Specific field assertions (exact values/business rules)
  • Negative cases (invalid input, unauthorized, missing fields)

Example test flow

  1. Send request
  2. Assert status code
  3. Assert response headers
  4. Parse body
  5. Assert fields and structure

Example pseudo-test

Send GET /users/1
Assert status == 200
Assert Content-Type == application/json
Assert body.id == 1
Assert body.name is not empty
Assert body.email contains "@"

If you want, I can also show you how to do this in Postman, REST Assured, Python (pytest), or JavaScript (Jest/Supertest).

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.