API testing

Use HTTP basic auth

Medium70 pts~25 min
  • Basic auth
  • WWW-Authenticate
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-use-http-basic-auth

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Authenticate with HTTP Basic credentials and assert the challenge returned for bad credentials.

Your task

  1. 1GET BASE_URL + "/secure/basic" with Basic auth admin / secret → assert 200.
  2. 2Repeat with the wrong password → assert 401.
  3. 3Assert the 401 has a WWW-Authenticate header that starts with "Basic".

Acceptance criteria

  • GET /secure/basic returns 200
  • GET /secure/basic returns 401 with bad credentials
  • At least 3 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication