Skip to content
routebase

3.0 API Testing

API testing that proves reality against the spec

Routebase builds API testing on your OpenAPI contract, so test suites, security scans, and CI automation all enforce the same spec.

14-day Pro trial — no credit card required.

New to API testing? Read the complete guide →

The Routebase API testing runner: suites and scenarios on the left, the nine ordered steps of the "Browse and order flow" scenario in the centre, and the run result on the right — nine steps passed in 858 ms, with the token, product and order id each extracted from one step and carried into the next.

API testing breaks down when the tests live in scripts that nobody updates, so they keep passing while the API quietly changes underneath them. Routebase treats your OpenAPI spec as the contract to enforce, so API tests are declarative suites of chained requests with assertions on status, headers, body, JSON paths, latency, and schema. The same suite runs against staging and production with ten auth schemes resolved per environment, and fixtures, seeds, and snapshots put the API in a known state before every run. Security is part of API testing as well, with OWASP API Top 10 scans and multi-identity personas beside the functional suites. From there, the CLI, cron schedules, and signed webhooks run the suites where your pipeline already lives.

API test suites that assert everything

Suites of chained requests — assert on status, JSON paths, headers, body, latency, and schema with 10 operators.

  • 6 assertion types with 10 operators, drag-and-drop suites
  • Chained requests: extract values, reuse them downstream
  • Pre-request and post-response JavaScript

Auth like production

Ten auth schemes resolved per environment — run the same suite against staging and prod.

  • OAuth2, Bearer, API Key, JWT, AWS SigV4, and more
  • Environment variables in requests and assertions

Test data, managed

Fixtures, seeds, and snapshots put the API in a known state before every run.

  • Fixtures with per-suite scope control
  • Pre/post-run seeds with loops and captures
  • Logical snapshots restore known state

Security is a test, too

OWASP API Top 10 scanning with multi-identity personas, finding triage, and a security score.

  • 13 scanners: BOLA, broken auth, SSRF, fuzzing, and more
  • Personas for multi-identity access testing
  • Triage workflow with audit trail and score dashboard

API testing in your pipeline

CLI for CI, API triggers, schedules, and signed webhooks — testing that fits your pipeline.

  • CLI runner with CI exit codes
  • Cron schedules and API-key triggers
  • HMAC-signed webhooks on completion

Frequently asked questions

Do I need an OpenAPI spec for API testing in Routebase?

No. A test case is a plain HTTP request with assertions, and linking it to an endpoint is optional. If you do have a spec, schema assertions check every response against the contract.

Which assertions and auth schemes are supported?

Assertions cover status, headers, body, JSON paths, latency, and schema with ten operators, and requests chain by extracting values for later steps. Auth resolves per environment across ten schemes, from Bearer and API key to OAuth2, JWT, and AWS SigV4.

Can I run API tests in CI?

Yes. The CLI and the GitHub Action run suites with CI exit codes and JUnit or SARIF output, cron schedules run them unattended, API-key triggers start them from your own pipeline, and HMAC-signed webhooks report completion.

Does API testing include security scanning?

Yes. OWASP API Top 10 scans run beside the functional suites, with personas for multi-identity access testing, a triage workflow with an audit trail, and a security score.

One living spec

The rest of the lifecycle

Every stage below works from the same spec, so a change is made once and published once.

Ready to ship on it?

Routebase is live. Design your API once — docs, mocks, tests, and monitoring all follow from the same source.

14-day Pro trial — no credit card required.