Test rate limiting behavior
Hard120 pts~45 min
- Rate limiting
- 429 Too Many Requests
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Exceed the 5-requests-per-10-seconds limit and assert the 429 response and its headers.
Your task
- 1Send GET BASE_URL + "/rate-limited" repeatedly (up to 7 times).
- 2Assert the successful responses carry X-RateLimit-Limit: 5 and a decreasing X-RateLimit-Remaining.
- 3Assert a later request returns 429 with error.code RATE_LIMITED and a Retry-After header.
Acceptance criteria
- GET /rate-limited returns 429
- At least 2 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authorization & negative testing