Complete an OAuth2 client flow
Hard120 pts~45 min
- OAuth2
- Token lifecycle
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Run a full token lifecycle: obtain, use on a protected resource, refresh, and reject an invalid refresh token.
Your task
- 1POST BASE_URL + "/auth/token" with the admin fixture → assert token_type "Bearer", expires_in > 0 and a refresh_token.
- 2GET BASE_URL + "/admin/reports" with the Bearer token → assert 200 and a non-empty reports array.
- 3POST BASE_URL + "/auth/refresh" with the refresh_token → assert 200 and a different access_token.
- 4POST BASE_URL + "/auth/refresh" with { "refresh_token": "bogus" } → assert 401 INVALID_REFRESH_TOKEN.
Acceptance criteria
- POST /auth/token returns 200
- GET /admin/reports returns 200
- POST /auth/refresh returns 200 and 401 for an invalid token
- At least 4 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authentication