Test a token refresh race
Expert190 pts~70 min
- Concurrency
- Refresh token rotation
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Fire two concurrent refreshes with the same refresh token and prove exactly one wins.
Your task
- 1POST BASE_URL + "/auth/token" with the admin fixture and keep refresh_token.
- 2Send two POST BASE_URL + "/auth/refresh" requests with that same token concurrently.
- 3Assert exactly one returned 200 and the other 401 INVALID_REFRESH_TOKEN.
- 4Use the winner's access_token on GET BASE_URL + "/auth/me" → assert 200.
Acceptance criteria
- POST /auth/refresh returns 200 once
- POST /auth/refresh returns 401 once
- GET /auth/me returns 200
- At least 3 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authentication