API testing

Check what your API actually returns.

An endpoint can return the expected status and still return the wrong business result. Test approved response expectations, input rules and supported access scenarios, then inspect the actual observations behind each outcome.

Connect assertions to expected behaviour.

Define the operation, allowed actions, inputs and expected response in the approved testing scope. Supported assertions examine response status and declared values or schemas. This gives developers a specific comparison to investigate: what the API should have returned and what the executed check observed. The source revision and target remain part of that result.

Exercise a reviewed set of invalid inputs.

Supported schema campaigns prepare a finite set of valid and schema-invalid JSON requests before review. Execution uses that approved set and preserves case identities, response observations and completion counts. A missing response, redirect or exhausted limit remains incomplete. A completed case with the wrong expected value fails, even when its HTTP status looks correct.

  • Review the operation and expected rejection behaviour.
  • Retain the request corpus identity and execution evidence.
  • Investigate or replay the exact case associated with a failure.

Agree the target before sending traffic.

An evaluation should identify a suitable environment, synthetic data, allowed effects and spending limit. Schema campaigns support a bounded schema and operation subset; broader workflows, authentication matrices and performance workloads have separate requirements. Production writes require explicit authority. We review those boundaries with you before a scoped run starts.

Questions about this testing method

01Is schema testing a complete security assessment?

Schema checks establish how the approved cases behaved. Security assessment needs its own scope and expectations, including relevant roles, tenant boundaries and authorised actions.

02Can a response teach the agent what should pass?

The expected result is approved before execution. Observed responses cannot silently rewrite that expectation or expand the reviewed request campaign.

Meet your AI testing workhorse

Bring your toughest code.
Set your highest bar.

See how the AI testing team would challenge your next release. We’ll scope the methods, automation and evidence around your software.

Request a walkthrough

Discuss an evaluation. No purchase commitment.