k6 load testing

Correlate a dynamic token

Hard120 pts~45 min
  • Correlation
  • Dynamic values
Practice app · Checkout Service

A load-testable checkout service with realistic latency that degrades under concurrency, plus a live metrics view.

BASE_URL
/api/practice
Console app
/lab/sdet-correlate-a-dynamic-token

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Extract the session token and CSRF value from login and send them on the next request.

Your task

  1. 1POST BASE_URL + "/perf/login" with JSON.stringify({ username: "qa@target.dev", password: "Test@123" }) with Content-Type: application/json.
  2. 2const { token, csrf } = res.json().
  3. 3POST BASE_URL + "/perf/cart" with { sku: "TQA-200", qty: 2 } and headers Authorization: Bearer <token>, X-CSRF-Token: <csrf>, Content-Type: application/json.
  4. 4check the cart returns 200 with a cartId. Use { vus: 3, iterations: 9 }.

Acceptance criteria

  • POST /perf/login returns 200
  • POST /perf/cart returns 200
  • The X-CSRF-Token header is sent
  • At least 9 check() calls pass

k6 load testing · SDET · Scripting basics