API testing

Authenticate with a bearer token

Medium70 pts~25 min
  • Bearer tokens
  • OAuth2
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-authenticate-with-a-bearer-token

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Obtain an access token and use it as a Bearer token to read the current user.

Your task

  1. 1POST BASE_URL + "/auth/token" with { "username": "qa@target.dev", "password": "Test@123" } → assert 200 and token_type "Bearer".
  2. 2GET BASE_URL + "/auth/me" with Authorization: Bearer <access_token> → assert 200.
  3. 3Assert email "qa@target.dev", role "admin", tenant "acme".

Acceptance criteria

  • POST /auth/token returns 200
  • GET /auth/me returns 200
  • A Bearer Authorization header is sent
  • At least 3 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication