API testing

Test a token refresh race

Expert190 pts~70 min
  • Concurrency
  • Refresh token rotation
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-test-a-token-refresh-race

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Fire two concurrent refreshes with the same refresh token and prove exactly one wins.

Your task

  1. 1POST BASE_URL + "/auth/token" with the admin fixture and keep refresh_token.
  2. 2Send two POST BASE_URL + "/auth/refresh" requests with that same token concurrently.
  3. 3Assert exactly one returned 200 and the other 401 INVALID_REFRESH_TOKEN.
  4. 4Use the winner's access_token on GET BASE_URL + "/auth/me" → assert 200.

Acceptance criteria

  • POST /auth/refresh returns 200 once
  • POST /auth/refresh returns 401 once
  • GET /auth/me returns 200
  • At least 3 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication