API testing

Complete an OAuth2 client flow

Hard120 pts~45 min
  • OAuth2
  • Token lifecycle
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-complete-an-oauth2-client-flow

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Run a full token lifecycle: obtain, use on a protected resource, refresh, and reject an invalid refresh token.

Your task

  1. 1POST BASE_URL + "/auth/token" with the admin fixture → assert token_type "Bearer", expires_in > 0 and a refresh_token.
  2. 2GET BASE_URL + "/admin/reports" with the Bearer token → assert 200 and a non-empty reports array.
  3. 3POST BASE_URL + "/auth/refresh" with the refresh_token → assert 200 and a different access_token.
  4. 4POST BASE_URL + "/auth/refresh" with { "refresh_token": "bogus" } → assert 401 INVALID_REFRESH_TOKEN.

Acceptance criteria

  • POST /auth/token returns 200
  • GET /admin/reports returns 200
  • POST /auth/refresh returns 200 and 401 for an invalid token
  • At least 4 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication