API testing

Test rate limiting behavior

Hard120 pts~45 min
  • Rate limiting
  • 429 Too Many Requests
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-test-rate-limiting-behavior

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Exceed the 5-requests-per-10-seconds limit and assert the 429 response and its headers.

Your task

  1. 1Send GET BASE_URL + "/rate-limited" repeatedly (up to 7 times).
  2. 2Assert the successful responses carry X-RateLimit-Limit: 5 and a decreasing X-RateLimit-Remaining.
  3. 3Assert a later request returns 429 with error.code RATE_LIMITED and a Retry-After header.

Acceptance criteria

  • GET /rate-limited returns 429
  • At least 2 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authorization & negative testing