API testing

Authenticate with an API key header

Easy30 pts~12 min
  • API keys
  • Authentication
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-authenticate-with-an-api-key-header

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Call a protected endpoint with an API key header and prove requests without it are rejected.

Your task

  1. 1GET BASE_URL + "/secure/api-key" with header x-api-key: tqa_live_key_123 → assert 200 and a data object.
  2. 2Send the same request without the header → assert 401 and error.code INVALID_API_KEY.

Acceptance criteria

  • GET /secure/api-key returns 200 with the key
  • GET /secure/api-key returns 401 without it
  • At least 2 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication