API testing

Assert an unauthorized (401) response

Medium70 pts~25 min
  • 401 Unauthorized
  • Negative testing
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-assert-an-unauthorized-401-response

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Prove a protected endpoint rejects missing and invalid credentials with 401.

Your task

  1. 1GET BASE_URL + "/auth/me" with no Authorization header → assert 401 and error.code "UNAUTHORIZED".
  2. 2Repeat with Authorization: Bearer not-a-real-token → assert 401.
  3. 3GET BASE_URL + "/admin/reports" with no token → assert 401.

Acceptance criteria

  • GET /auth/me returns 401
  • GET /admin/reports returns 401
  • At least 3 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authorization & negative testing