Authenticate with an API key header
Easy30 pts~12 min
- API keys
- Authentication
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Call a protected endpoint with an API key header and prove requests without it are rejected.
Your task
- 1GET BASE_URL + "/secure/api-key" with header x-api-key: tqa_live_key_123 → assert 200 and a data object.
- 2Send the same request without the header → assert 401 and error.code INVALID_API_KEY.
Acceptance criteria
- GET /secure/api-key returns 200 with the key
- GET /secure/api-key returns 401 without it
- At least 2 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authentication