Prompt
k6 login spike test
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Here’s a simple k6 spike test for a login endpoint.
1) Install k6
brew install k6
# or on Linux:
# sudo apt install k6
2) Spike test script: login-spike.js
Replace the URL, payload, and expected response checks with your app’s details.
import http from 'k6/http';
import { check, sleep } from 'k6';
export const options = {
stages: [
{ duration: '10s', target: 10 }, // small warm-up
{ duration: '5s', target: 500 }, // spike up quickly
{ duration: '15s', target: 500 }, // hold spike
{ duration: '10s', target: 0 }, // drop to zero
],
thresholds: {
http_req_failed: ['rate<0.01'],
http_req_duration: ['p(95)<1000'],
},
};
export default function () {
const url = 'https://your-api.example.com/login';
const payload = JSON.stringify({
username: 'testuser',
password: 'testpassword',
});
const params = {
headers: {
'Content-Type': 'application/json',
},
};
const res = http.post(url, payload, params);
check(res, {
'status is 200 or 401': (r) => r.status === 200 || r.status === 401,
'response time is acceptable': (r) => r.timings.duration < 1000,
});
sleep(1);
}
3) Run it
k6 run login-spike.js
4) If you need real login realism
For more realistic tests, use:
- multiple usernames/passwords
- tokens from a test user pool
- CSV data file
- login + follow-up authenticated request
Example using a CSV file with credentials:
import http from 'k6/http';
import { check } from 'k6';
import { SharedArray } from 'k6/data';
const users = new SharedArray('users', function () {
return open('./users.json').split('\n').filter(Boolean).map(JSON.parse);
});
export const options = {
stages: [
{ duration: '5s', target: 100 },
{ duration: '5s', target: 1000 },
{ duration: '10s', target: 1000 },
{ duration: '5s', target: 0 },
],
};
export default function () {
const user = users[__VU % users.length];
const res = http.post('https://your-api.example.com/login', JSON.stringify({
username: user.username,
password: user.password,
}), {
headers: { 'Content-Type': 'application/json' },
});
check(res, { 'login succeeded or rejected': (r) => r.status === 200 || r.status === 401 });
}
If you want, I can generate a spike test tailored to your exact login API (URL, headers, body, CSRF token, JWT/cookie flow, etc.).
Brands