π API Fundamentals: A Tester’s Guide
The Ultimate Guide to API Testing by QA Jobs India β Master REST APIs, HTTP Methods, JSON/XML, Status Codes, Authentication, Postman Testing, and Java Automation with real-world examples.
π Table of Contents
Q1: What is a Web Service?
Ans: A Web Service is a service that is available over the internet. It allows different applications to communicate with each other regardless of the platform or programming language they are built on.
Q2: What is an API?
Ans: An API (Application Programming Interface) acts as an intermediary between two different applications, allowing them to communicate. It defines the methods and data formats that applications can use to request and exchange information.
Q3: Can you explain with a real-world example how APIs work?
Ans: Let’s take a bus ticketing application example. Bus tickets can be booked through either the Tamil Nadu Transport official website or the RedBus website.
These applications may access the same database, but they operate independently. They might even be built using different programming languages:
- The Tamil Nadu Transport website could be created using Java.
- The RedBus website could be created using Python.
However, both applications need to communicate. If a ticket is sold out for a route from Theni to Chennai on the RedBus website, it should be updated on the Tamil Nadu Transport website. Similarly, if a ticket is sold out or a seat is modified on the Tamil Nadu Transport website, it should reflect on RedBus in real-time.
So, how do they communicate, even though they are built using different programming languages? The answer is JSON/XML, which is used for data exchange. In most REST web services, JSON is used.
JSON acts like a “translator” between the two websites, ensuring the ticket details are transferred correctly and keeping both platforms updated.
Q4: What is a REST Web Service?
Ans: A REST (Representational State Transfer) web service is a type of web service that follows the principles of REST architecture. It allows applications to communicate using standard HTTP methods (GET, POST, PUT, DELETE), usually with JSON or XML as the data format.
Q5: What is JSON?
Ans: JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write, and easy for machines to parse and generate. JSON is commonly used in REST web services to transfer data between servers and clients.
Q6: What is a Client in API terminology?
Ans: A Client is anyone or anything that makes a request. It could be a person using a website or a piece of software asking for information.
Q7: What is a Server?
Ans: A Server is a program that gets the client’s request, processes it, and sends back a response.
Q8: What is a URL (Uniform Resource Locator)?
Ans: A URL is the web address you type in a browser to find something on the internet (like www.example.com).
Q9: What is a Request in API?
Ans: A Request is a message from the client to the server asking for some data or action.
Q10: What is a Response?
Ans: The Response is the message the server sends back to the client after receiving the request. It could include the data you asked for or an error message.
Q11: What is a Request Body?
Ans: The Request Body is the information the client sends to the server (like when you fill out a form and submit it).
Q12: What is a Response Body?
Ans: The Response Body is the information the server sends back to the client after it processes the request (like showing the results of a search).
Q13: What are Headers in API?
Ans: Headers are extra information that comes with both the request and response, like the type of data being sent (e.g., JSON or HTML). It’s like the envelope of a letter that contains important details about the message inside.
Q14: What is Content Type?
Ans: Content Type tells the server what kind of data the client is sending or receiving. Some examples:
- application/json β Means the data is in JSON format.
- application/xml β Means the data is in XML format.
- text/html β Means the data is in HTML format (like a web page).
Q15: What is HTTP and why is it important for API testing?
Ans: HTTP (Hypertext Transfer Protocol) is the language that lets the website ask for something, and the server responds with what’s needed. When a client (like your browser) sends a request over the internet, it uses HTTP. The backbone of these requests is HTTP Methods, which define the action being requested.
Q16: What is a GET Request?
Ans: GET is used to retrieve information (like a webpage or data) without changing anything on the server. That’s why it’s called a “safe method.”
- If the resource exists on the server, you’ll get a response along with a status code and the resource data (response body).
- If the resource isn’t found, you’ll get a relevant status code like 404.
Q17: What is a POST Request?
Ans: POST is used to create a new resource on the server. It modifies the server, so it’s not a “safe method.” For example, sending two identical POST requests creates two different resources with the same content but different IDs.
- If the resource is successfully created, the server returns a status code like 201.
- POST requests include a request body containing the data to create the resource.
Q18: What is a PUT Request?
Ans: PUT is used to update an existing resource on the server. If the resource doesn’t already exist, the server creates it. You must send the updated request body with the PUT request.
Q19: What is a DELETE Request?
Ans: DELETE is used to delete a resource from the server. If the resource exists, it deletes it and sends a relevant status code (like 200 for success).
Q20: What is the difference between POST and PUT?
Ans: POST is used to create a new resource, and each POST request creates a new resource with a new ID. PUT is used to update an existing resource. If the resource doesn’t exist, PUT may create it. POST is not idempotent (calling it multiple times creates multiple resources), while PUT is idempotent (calling it multiple times gives the same result).
Q21: What are HTTP Status Codes?
Ans: When the client submits a request, the server responds with a status code indicating whether the request was successful or not, along with resource data.
Q22: Explain 1xx Status Codes.
Ans: 1xx (Informational) β The server is still processing the request. These are rarely seen in normal API testing.
Q23: Explain 2xx Status Codes.
Ans: 2xx (Success) β The request was successful:
- 200 OK: The GET request was successful, and the resource was found.
- 201 Created: A POST request successfully created a resource.
Q24: Explain 3xx Status Codes.
Ans: 3xx (Redirection) β The client is redirected to another URL. For example, when a resource has moved to a new location.
Q25: Explain 4xx Status Codes.
Ans: 4xx (Client Error) β There’s an issue with the client’s request:
- 400 Bad Request: Wrong data sent in the request.
- 401 Unauthorized: You’re not logged in or don’t have valid credentials.
- 403 Forbidden: Employees can view only their details, but admins can see all. You don’t have permission.
- 404 Not Found: Broken or invalid link. The resource doesn’t exist.
Q26: Explain 5xx Status Codes.
Ans: 5xx (Server Error) β Something is wrong on the server side:
- 500 Internal Server Error: The server is down or encountered an unexpected condition. Only the server maintenance team can fix this.
Q27: What is an API Endpoint?
Ans: An Endpoint is where the API sends a request to get or send data. Think of it as the URL address for a specific feature.
Example (LinkedIn):
Q28: What is a Path Parameter?
Ans: A Path Parameter is a part of the URL used to identify specific data.
Example (LinkedIn):
Q29: What is a Query Parameter?
Ans: A Query Parameter is extra info added to the URL to filter results. It comes after a ? symbol.
Example (LinkedIn):
Q30: What is a Header in API?
Ans: A Header is additional info sent with a request, like login details or the type of data you want.
Example (LinkedIn):
Q31: What is Authentication in API?
Ans: Authentication confirms who you are so the server knows you’re allowed to use the API. Types of Authentication:
- No Auth: No login required (rare).
- Basic Auth: Username and password sent in the header.
Authorization: Basic <encoded_username_password>
- API Token: A key (like a password) to identify you.
Header: Authorization: Token <your_api_key>
- Bearer Token: A type of API token that’s more secure.
Authorization: Bearer <your_access_token>
- OAuth: Advanced method where you log in through a provider (like LinkedIn) to get access.
When you click “Sign in with LinkedIn” on other apps, that’s OAuth.
Q32: What is API Testing?
Ans: API testing ensures the APIs work as expected. We test the requests and responses between the client and server. In simple terms:
- We check if the API returns the correct data.
- We verify that the API handles errors gracefully (e.g., what happens if the resource doesn’t exist?).
- We validate the status codes, response times, and data formats (like JSON).
Q33: How do you manually test an API using a Browser?
Ans: Test Case: Verify if the Google homepage is successfully loaded.
- Open your browser and go to http://google.co.in.
- Right-click anywhere on the page and select Inspect.
- Navigate to the Network tab.
- Reload the page (press F5) to capture the requests.
- Check the status code for the request to http://google.co.in.
Expected Output:
- Status Code: 200 (OK)
- Response: HTML content for the Google homepage.
Q34: How do you perform a GET Request in Postman?
Ans: Purpose: To retrieve the Google homepage.
Prerequisites:
- Header: Content-Type: application/json
- Request Method: GET
- Endpoint: http://google.co.in
Steps:
- Open Postman and select GET.
- Enter the URL: http://google.co.in.
- Add a header: Key: Content-Type, Value: application/json.
- Click Send.
Expected Output:
Response Body: HTML code of the Google homepage.
Q35: How do you perform a POST Request in Postman?
Ans: Purpose: To create a new resource on the server.
Dummy Example: Let’s say we are creating a new user on a dummy API.
Prerequisites:
- Header: Content-Type: application/json
- Request Method: POST
- Endpoint: http://dummyapi/users
- Request Body:
Steps:
- Open Postman and select POST.
- Enter the URL: http://dummyapi/users.
- Add a header: Key: Content-Type, Value: application/json.
- Add the Request Body.
- Click Send.
Expected Output:
Q36: How do you perform a PUT Request in Postman?
Ans: Purpose: To update an existing resource.
Dummy Example: Let’s say we are updating a user’s email address.
Prerequisites:
- Header: Content-Type: application/json
- Request Method: PUT
- Endpoint: http://dummyapi/users/123 (This 123 is unique id)
- Request Body:
Steps:
- Open Postman and select PUT.
- Enter the URL: http://dummyapi/users/123.
- Add a header: Key: Content-Type, Value: application/json.
- Add the Request Body.
- Click Send.
Expected Output:
Q37: How do you perform a DELETE Request in Postman?
Ans: Purpose: To delete a resource from the server.
Dummy Example: Let’s say we are deleting a user.
Prerequisites:
- Header: Content-Type: application/json
- Request Method: DELETE
- Endpoint: http://dummyapi/users/123
Steps:
- Open Postman and select DELETE.
- Enter the URL: http://dummyapi/users/123.
- Add a header: Key: Content-Type, Value: application/json.
- Click Send.
Expected Output:
Q38: Why is Postman testing considered manual API testing?
Ans: When using Postman, you’re manually:
- Selecting the request method (GET, POST, PUT, DELETE).
- Entering headers, request body, and endpoint.
- Clicking “Send” to view the response.
Since no scripts or automation tools (like Selenium or REST Assured) are used to repeat these tests, it’s manual testing.
Q39: Can Selenium be used for API Testing?
Ans: There is a common misconception that Selenium is the solution for all types of automation. However, Selenium is specifically designed for automating web applications (UI/browser automation), not API testing. Selenium cannot directly test APIs.
Q40: How do we automate API testing in Java?
Ans: We can automate API tests using native Java or third-party libraries. Here are some options:
- HttpURLConnection (java.net): This is a built-in class in Java that allows you to send HTTP requests and handle responses. It’s simple but not as feature-rich as other libraries.
- UniRest: A third-party library that simplifies sending HTTP requests and handling responses. It provides a more concise API than HttpURLConnection.
- RestAssured: A popular and widely used library for automating RESTful API tests. It has many built-in features for validating responses, setting headers, and making requests in a more readable way.
Q41: What is HttpURLConnection?
Ans: HttpURLConnection is a built-in Java class (java.net package) that allows you to send HTTP requests and handle responses. It is simple but requires more boilerplate code compared to third-party libraries.
Q42: What is UniRest and how do you add it to your project?
Ans: UniRest is a third-party library that simplifies sending HTTP requests and handling responses. It provides a more concise API than HttpURLConnection.
Maven Dependency:
Q43: What is RestAssured and how do you add it to your project?
Ans: RestAssured is the most popular and widely used library for automating RESTful API tests in Java. It has many built-in features for validating responses, setting headers, and making requests in a more readable way. It uses a BDD-style syntax (Given-When-Then) which makes tests very readable.
Maven Dependency:
Q44: Why is RestAssured preferred over HttpURLConnection?
Ans: RestAssured is preferred because:
- It uses BDD-style syntax (Given-When-Then) which is more readable.
- It has built-in methods for validating JSON/XML responses.
- It handles headers, cookies, and authentication easily.
- It supports JSON Path and XML Path for extracting data from responses.
- It integrates well with TestNG and JUnit for test execution.
- It requires much less boilerplate code compared to HttpURLConnection.
Q45: What is the difference between manual and automated API testing?
Ans:
- Manual API Testing: Using tools like Postman where you manually select methods, enter data, and click Send. Good for exploratory testing and one-time checks.
- Automated API Testing: Writing scripts using libraries like RestAssured, UniRest, or HttpURLConnection. Good for regression testing, CI/CD integration, and repeated execution.
Q46: What are the common types of API testing?
Ans:
- Functional Testing: Verifying the API works as per requirements.
- Validation Testing: Checking data format, schema, and structure.
- Load Testing: Testing API performance under heavy load.
- Security Testing: Checking authentication, authorization, and data protection.
- Integration Testing: Verifying APIs work together correctly.
- Error Handling Testing: Checking how APIs handle invalid inputs and errors.
Q47: What is the difference between SOAP and REST APIs?
Ans:
- SOAP (Simple Object Access Protocol): Uses XML only, follows strict standards, supports WS-* standards, requires more bandwidth, and is more secure. Used in enterprise/banking applications.
- REST (Representational State Transfer): Uses JSON/XML/HTML, follows architectural principles (not strict standards), lightweight, faster, easier to implement. Most commonly used in modern web applications.
Q48: What is JSON Schema Validation in API Testing?
Ans: JSON Schema Validation ensures that the API response matches the expected structure. For example, if the API should return a user object with “id” (number), “name” (string), and “email” (string), schema validation checks that the response contains these fields with the correct data types. This is crucial for catching API contract violations early.
Q49: What tools can be used for API Testing besides Postman?
Ans:
- Postman β Most popular for manual and some automation.
- SoapUI β Best for SOAP API testing.
- JMeter β For API performance and load testing.
- REST Assured β Java library for REST API automation.
- Karate β BDD-style API testing framework.
- Insomnia β Alternative to Postman with better UX.
- Swagger β For API documentation and testing.
Q50: What are the key things to verify in API Testing?
Ans: The key things to verify in API Testing are:
- Status Code: Verify the correct HTTP status code is returned.
- Response Body: Verify the data returned is correct and in expected format (JSON/XML).
- Response Time: Verify the API responds within acceptable time limits.
- Headers: Verify correct headers are returned (Content-Type, Authorization, etc.).
- Error Handling: Verify proper error messages for invalid requests.
- Data Integrity: Verify data is correctly stored in the database after POST/PUT.
- Authentication: Verify unauthorized access is blocked (401/403).
π― Complete API Testing Guide by QA Jobs India
Welcome to the API Fundamentals: A Tester’s Guide β the most comprehensive API testing preparation guide by QA Jobs India. This guide covers everything from basic API concepts to advanced automation with Java libraries like RestAssured, UniRest, and HttpURLConnection.
Perfect for Freshers, Junior QA Engineers, Manual Testers, QA Analysts, Automation Testers, and anyone preparing for API testing interviews. Covers REST APIs, HTTP Methods, JSON/XML, Status Codes, Authentication types, Postman Testing, and Java Automation.
All content is 100% free and regularly updated for 2026. Bookmark this page and revisit before every interview!
Get direct HR emails, priority alerts & exclusive job access before anyone else!
π Upgrade to Premium NowGet instant job alerts, interview tips, resume feedback, and connect with 5000+ QA professionals. Never miss an opportunity!
π± Join WhatsApp Group