API testing

Assert a forbidden (403) response

Medium70 pts~25 min
  • 403 Forbidden
  • Role-based access
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-assert-a-forbidden-403-response

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Show that an authenticated viewer is forbidden from an admin-only resource while an admin is allowed.

Your task

  1. 1Get a token for the viewer fixture (viewer@target.dev / Viewer@123) via POST BASE_URL + "/auth/token".
  2. 2GET BASE_URL + "/admin/reports" with the viewer token → assert 403 and error.code "FORBIDDEN".
  3. 3Repeat with an admin token (qa@target.dev / Test@123) → assert 200.

Acceptance criteria

  • GET /admin/reports returns 403 for the viewer
  • GET /admin/reports returns 200 for the admin
  • At least 2 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authorization & negative testing