Fields
The api block
How API tests use the server:
- Each API test gets a fresh server in its own sandbox.
- A test sends requests and checks the status, headers and body. It can capture values from a response body with
capture, or from its headers withcaptureHeaders, and reuse them in later steps. - Each test has its own cookie jar. A cookie the server sets is sent back on later requests, so a login is just a first step.
- Tests can also drive the server process itself, with
boot,signalandlogssteps.
The web block
A recipe that declares
web also declares entry or api, because web steps run inside an ordinary test.
Credentials
Each entry inapi.credentials names a request header and one source for its value: value, valueFromEnv or fromRequest. A test uses a credential by writing {{cred:<name>}} in a header value. An optional satisfies names the OpenAPI security scheme the credential fulfills, and an optional servers list limits it to the servers it authenticates against.
fromRequest logs in instead of storing a value:
capture is a path into the JSON body, and captureHeader reads a response header instead. When the login fails, the whole run stops as credential-request-failed rather than running unauthenticated.
Every resolved credential is masked in transcripts as «cred:<name>».
Next steps
Seeding
Create the data and principals tests need.
External services
Stubs, faults and real accounts for third parties.