This API testing checklist is the list to run through for every endpoint you test, whether manually in Postman or in an automated suite. It starts with the core per-endpoint checks, adds a catalogue of negative and edge cases, and ends with a senior-level checklist for reviewing an entire API test suite.

Checklist for Every Endpoint

CategoryTests to Write
Happy PathValid input → correct 2xx, correct response body, schema matches
AuthNo token → 401; wrong role → 403; expired token → 401; valid → 200
ValidationMissing required fields → 400/422; wrong types → 400/422; out of range → 422
Not FoundNon-existent ID → 404 (never 500)
DuplicatesDuplicate unique field (email) → 409 Conflict
BOLAAccess another user's resource → 403 (not 200!)
Rate LimitingExceed limit → 429 with Retry-After header
SchemaResponse structure matches JSON Schema
Response TimeResponse < defined SLA (e.g., 2 seconds)
Error FormatAll errors have consistent structure (code + message)
No Sensitive DataPassword, secrets, CVV never in response body
IdempotencyPUT/DELETE same request twice → same result
Final Advice for API Interview Rounds

"Always ask: What does success look like? What does failure look like?"

"Think in test categories: functional → security → performance → contract"

"Negative tests matter MORE than positive tests at senior level"

"Mention: schema validation, BOLA, rate limit, idempotency — these show depth"

"For every endpoint: draw the test matrix — who can do what, what inputs are valid"

Your RestAssured + Pact + security testing knowledge from this guide

puts you in the top 5% of API testing candidates. Now practise writing it. 🚀

Advertisement

Negative and Edge-Case Catalogue

CategoryTest ScenarioExpected Behaviour
Missing fieldsPOST /users without required "email" field400 or 422 with field-level error message
Wrong data typePOST /orders with "quantity": "two" (string not int)400 with type validation error
Out of rangePOST /user with "age": -5 or age: 999422 with range validation error
Invalid formatPOST /users with "email": "not-an-email"422 with format validation error
DuplicatePOST /users with email that already exists409 Conflict
Wrong IDGET /users/999999 (non-existent)404 Not Found
Empty bodyPOST /users with no body or empty {}400 Bad Request
Null valuesPUT /users/42 with { "name": null }422 or 400 if name is required
Too longPOST /users with 10,000-char name422 or 400 field length violation
SQL injectionGET /users?name='; DROP TABLE users;--400 or 200 with sanitised input (NOT 500)
XSS payloadPOST /users with name: "<script>alert(1)</script>"Stored sanitised or 400 rejected
UnauthorisedGET /admin/users with customer token403 Forbidden
No authGET /api/private without any token401 Unauthorized
Method not allowedDELETE /api/products/1 (read-only endpoint)405 Method Not Allowed
Rate limitPOST /auth/login 10 times rapidly429 Too Many Requests + Retry-After header
Large payloadPOST /orders with 1,000 items in array413 Payload Too Large or 400
Concurrent updatesTwo simultaneous PUT /orders/1 with different dataOne succeeds, one gets 409 Conflict (optimistic lock)

Status Codes to Expect

2xx Success3xx Redirect4xx Client Error5xx Server Error
200 OK301 Moved Permanently400 Bad Request500 Internal Server Error
201 Created302 Found (temp)401 Unauthorized502 Bad Gateway
204 No Content304 Not Modified403 Forbidden503 Service Unavailable
206 Partial307 Temp Redirect404 Not Found504 Gateway Timeout
405 Method Not Allowed
409 Conflict
422 Unprocessable
429 Too Many Requests

Senior Review Checklist for an API Test Suite

#Skill / TopicCan You Do It?
1Write GET/POST/PUT/PATCH/DELETE tests with RestAssured☐ Ready
2Implement RequestSpec/ResponseSpec and BaseTest pattern☐ Ready
3Extract values with JsonPath (nested, list, conditional)☐ Ready
4Validate JSON Schema with matchesJsonSchemaInClasspath()☐ Ready
5Test OAuth2 password grant + cache tokens with TokenManager☐ Ready
6Build RBAC test matrix with @DataProvider — all role/endpoint combos☐ Ready
7Write 5+ negative test scenarios for any endpoint☐ Ready
8Write Pact consumer test + provider verification☐ Ready
9Test GraphQL queries AND check "errors" field (never trust HTTP 200)☐ Ready
10Write BOLA test (user A accesses user B's resource → must get 403)☐ Ready
11Test OWASP Top 10 — name all 10 risks from memory☐ Ready
12Stub a payment API with WireMock (success + decline + timeout + fault)☐ Ready
13Run Postman collection with Newman in a CI pipeline☐ Ready
14Test file upload (multipart), wrong MIME, too-large file☐ Ready
15Set up webhook receiver with WireMock, verify HMAC signature☐ Ready
16Test idempotency — same key = same result, no duplicate resource☐ Ready
17Test ETag caching — first request 200 with ETag, second request 304☐ Ready
18Test CORS preflight OPTIONS → correct Access-Control-Allow-* headers☐ Ready
19Validate API responses against OpenAPI spec using swagger-request-validator☐ Ready
20Write JDBC assertions to verify DB state after API call☐ Ready
21Test Kafka event published after API call using Testcontainers + Awaitility☐ Ready
22Write a BDD API test in Karate DSL (or Cucumber + RestAssured)☐ Ready
23Attach AllureRestAssured filter and annotate tests with @Feature/@Story☐ Ready
24Design a complete API test framework from scratch — explain layer by layer☐ Ready
25Answer all 30 advanced interview Q&As from Section 12 without looking☐ Ready
Final Message

You now have the most complete API testing guide available for SDET interview preparation.

The 3 things that will get you hired at FAANG / top product companies:

1. Security mindset — BOLA, OWASP, RBAC matrix. Most candidates skip this entirely.

2. Contract testing (Pact) — shows you think at system architecture level.

3. Communication — explain your test design decisions clearly during the interview.

Practice exercise before every interview:

"Design API tests for a POST /payments endpoint."

Write: happy path → auth tests → RBAC matrix → negative → security → performance.

Time yourself. Full answer in under 4 minutes. That is the FAANG interview pace.

Go build something great, Naveed. The offer is closer than you think. 🚀

FAQs

What should be tested in an API?

Status codes, response body and schema, headers, data persistence, error handling for invalid input, authentication and authorisation, performance under load, and behaviour on retries and edge cases.

What are negative test cases in API testing?

Requests that should be rejected: missing or invalid fields, wrong data types, invalid IDs, missing or expired tokens, wrong HTTP methods and oversized payloads. Each should return the right 4xx code with a clear error, never a 500.

Is this checklist useful for manual API testing?

Yes. Use it in Postman when exploring an endpoint, then automate the checks that matter most in REST Assured or Newman.