QA Jobs India
QA Jobs India – Top Menu Bar
Trusted by 50,000+ QA Professionals
API Fundamentals: A Tester’s Guide 2026 | QA Jobs India
🌐 API Fundamentals for QA Testers

πŸš€ API Fundamentals: A Tester’s Guide

The Ultimate Guide to API Testing by QA Jobs India β€” Master REST APIs, HTTP Methods, JSON/XML, Status Codes, Authentication, Postman Testing, and Java Automation with real-world examples.

7Sections
50+Topics
100%Practical
FreeReference
Section 1 β€” API & Web Service Basics
What is an API & Web Service?

Q1: What is a Web Service?

Ans: A Web Service is a service that is available over the internet. It allows different applications to communicate with each other regardless of the platform or programming language they are built on.

Q2: What is an API?

Ans: An API (Application Programming Interface) acts as an intermediary between two different applications, allowing them to communicate. It defines the methods and data formats that applications can use to request and exchange information.

Q3: Can you explain with a real-world example how APIs work?

Ans: Let’s take a bus ticketing application example. Bus tickets can be booked through either the Tamil Nadu Transport official website or the RedBus website.

These applications may access the same database, but they operate independently. They might even be built using different programming languages:

  • The Tamil Nadu Transport website could be created using Java.
  • The RedBus website could be created using Python.

However, both applications need to communicate. If a ticket is sold out for a route from Theni to Chennai on the RedBus website, it should be updated on the Tamil Nadu Transport website. Similarly, if a ticket is sold out or a seat is modified on the Tamil Nadu Transport website, it should reflect on RedBus in real-time.

So, how do they communicate, even though they are built using different programming languages? The answer is JSON/XML, which is used for data exchange. In most REST web services, JSON is used.

JSON acts like a “translator” between the two websites, ensuring the ticket details are transferred correctly and keeping both platforms updated.

πŸ’‘ INTERVIEW TIP: Always use real-world examples when explaining APIs in interviews. The bus ticketing example shows you understand practical API usage across different platforms.

Q4: What is a REST Web Service?

Ans: A REST (Representational State Transfer) web service is a type of web service that follows the principles of REST architecture. It allows applications to communicate using standard HTTP methods (GET, POST, PUT, DELETE), usually with JSON or XML as the data format.

Q5: What is JSON?

Ans: JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write, and easy for machines to parse and generate. JSON is commonly used in REST web services to transfer data between servers and clients.

🏒 ENTERPRISE: In enterprise applications, REST APIs are the backbone of microservices architecture. Companies like Amazon, Netflix, and Flipkart use REST APIs to connect hundreds of microservices that handle millions of requests per second.
Section 2 β€” Key API Terminologies
Understanding API Components

Q6: What is a Client in API terminology?

Ans: A Client is anyone or anything that makes a request. It could be a person using a website or a piece of software asking for information.

Q7: What is a Server?

Ans: A Server is a program that gets the client’s request, processes it, and sends back a response.

Q8: What is a URL (Uniform Resource Locator)?

Ans: A URL is the web address you type in a browser to find something on the internet (like www.example.com).

Q9: What is a Request in API?

Ans: A Request is a message from the client to the server asking for some data or action.

Q10: What is a Response?

Ans: The Response is the message the server sends back to the client after receiving the request. It could include the data you asked for or an error message.

Q11: What is a Request Body?

Ans: The Request Body is the information the client sends to the server (like when you fill out a form and submit it).

Q12: What is a Response Body?

Ans: The Response Body is the information the server sends back to the client after it processes the request (like showing the results of a search).

Q13: What are Headers in API?

Ans: Headers are extra information that comes with both the request and response, like the type of data being sent (e.g., JSON or HTML). It’s like the envelope of a letter that contains important details about the message inside.

Q14: What is Content Type?

Ans: Content Type tells the server what kind of data the client is sending or receiving. Some examples:

  • application/json β€” Means the data is in JSON format.
  • application/xml β€” Means the data is in XML format.
  • text/html β€” Means the data is in HTML format (like a web page).
βœ… QUICK RECALL: Remember: Client asks (Request), Server answers (Response). Headers are like the envelope, Body is the letter inside. Content-Type tells what language the letter is written in.
Section 3 β€” HTTP Methods Explained
GET, POST, PUT, DELETE

Q15: What is HTTP and why is it important for API testing?

Ans: HTTP (Hypertext Transfer Protocol) is the language that lets the website ask for something, and the server responds with what’s needed. When a client (like your browser) sends a request over the internet, it uses HTTP. The backbone of these requests is HTTP Methods, which define the action being requested.

Q16: What is a GET Request?

Ans: GET is used to retrieve information (like a webpage or data) without changing anything on the server. That’s why it’s called a “safe method.”

  • If the resource exists on the server, you’ll get a response along with a status code and the resource data (response body).
  • If the resource isn’t found, you’ll get a relevant status code like 404.
GET http://www.linkedin.com/users

Q17: What is a POST Request?

Ans: POST is used to create a new resource on the server. It modifies the server, so it’s not a “safe method.” For example, sending two identical POST requests creates two different resources with the same content but different IDs.

  • If the resource is successfully created, the server returns a status code like 201.
  • POST requests include a request body containing the data to create the resource.
POST http://www.linkedin.com/users Body: { “name”: “Yogesh Pandian”, “email”: “yogeshpandian@mail.com” }

Q18: What is a PUT Request?

Ans: PUT is used to update an existing resource on the server. If the resource doesn’t already exist, the server creates it. You must send the updated request body with the PUT request.

PUT http://www.linkedin.com/users/123 Body: { “name”: “Yogesh Pandian”, “email”: “yogeshchandran@mail.com” }

Q19: What is a DELETE Request?

Ans: DELETE is used to delete a resource from the server. If the resource exists, it deletes it and sends a relevant status code (like 200 for success).

DELETE http://www.linkedin.com/users/123
πŸ’‘ INTERVIEW TIP: Remember the CRUD analogy: Create = POST, Read = GET, Update = PUT, Delete = DELETE. This is the most common interview question on HTTP methods!

Q20: What is the difference between POST and PUT?

Ans: POST is used to create a new resource, and each POST request creates a new resource with a new ID. PUT is used to update an existing resource. If the resource doesn’t exist, PUT may create it. POST is not idempotent (calling it multiple times creates multiple resources), while PUT is idempotent (calling it multiple times gives the same result).

Section 4 β€” HTTP Status Codes
Understanding Response Codes

Q21: What are HTTP Status Codes?

Ans: When the client submits a request, the server responds with a status code indicating whether the request was successful or not, along with resource data.

Q22: Explain 1xx Status Codes.

Ans: 1xx (Informational) β€” The server is still processing the request. These are rarely seen in normal API testing.

Q23: Explain 2xx Status Codes.

Ans: 2xx (Success) β€” The request was successful:

  • 200 OK: The GET request was successful, and the resource was found.
  • 201 Created: A POST request successfully created a resource.

Q24: Explain 3xx Status Codes.

Ans: 3xx (Redirection) β€” The client is redirected to another URL. For example, when a resource has moved to a new location.

Q25: Explain 4xx Status Codes.

Ans: 4xx (Client Error) β€” There’s an issue with the client’s request:

  • 400 Bad Request: Wrong data sent in the request.
  • 401 Unauthorized: You’re not logged in or don’t have valid credentials.
  • 403 Forbidden: Employees can view only their details, but admins can see all. You don’t have permission.
  • 404 Not Found: Broken or invalid link. The resource doesn’t exist.

Q26: Explain 5xx Status Codes.

Ans: 5xx (Server Error) β€” Something is wrong on the server side:

  • 500 Internal Server Error: The server is down or encountered an unexpected condition. Only the server maintenance team can fix this.
Status Code Quick Reference: 1xx β†’ Informational (Processing) 2xx β†’ Success (200=OK, 201=Created) 3xx β†’ Redirection 4xx β†’ Client Error (400=Bad, 401=Auth, 403=Forbidden, 404=Not Found) 5xx β†’ Server Error (500=Server Down)
⚠️ INTERVIEW TIP: Always know the difference between 401 and 403. 401 means “You need to login” (Unauthorized), while 403 means “You are logged in but don’t have permission” (Forbidden). This is a very common interview trap question!
Section 5 β€” API Components
Endpoint, Path, Query, Header & Authentication

Q27: What is an API Endpoint?

Ans: An Endpoint is where the API sends a request to get or send data. Think of it as the URL address for a specific feature.

Example (LinkedIn):

https://api.linkedin.com/v2/users This endpoint is used to get LinkedIn user data.

Q28: What is a Path Parameter?

Ans: A Path Parameter is a part of the URL used to identify specific data.

Example (LinkedIn):

https://api.linkedin.com/v2/users/{userId} Replace {userId} with the actual user ID like 12345: https://api.linkedin.com/v2/users/12345 This gets the profile of user ID 12345.

Q29: What is a Query Parameter?

Ans: A Query Parameter is extra info added to the URL to filter results. It comes after a ? symbol.

Example (LinkedIn):

https://api.linkedin.com/v2/users?location=India&jobTitle=Engineer This searches for LinkedIn users in India with the job title Engineer.

Q30: What is a Header in API?

Ans: A Header is additional info sent with a request, like login details or the type of data you want.

Example (LinkedIn):

A header might look like this: Authorization: Bearer It tells LinkedIn you’re logged in and allowed to access the data.

Q31: What is Authentication in API?

Ans: Authentication confirms who you are so the server knows you’re allowed to use the API. Types of Authentication:

  1. No Auth: No login required (rare).
  2. Basic Auth: Username and password sent in the header.
    Authorization: Basic <encoded_username_password>
  3. API Token: A key (like a password) to identify you.
    Header: Authorization: Token <your_api_key>
  4. Bearer Token: A type of API token that’s more secure.
    Authorization: Bearer <your_access_token>
  5. OAuth: Advanced method where you log in through a provider (like LinkedIn) to get access.
    When you click “Sign in with LinkedIn” on other apps, that’s OAuth.
πŸ” SECURITY: In production environments, never hardcode API tokens in your code. Use environment variables or secure vaults like AWS Secrets Manager or Azure Key Vault. Bearer tokens should have expiration times and be refreshed regularly.
Section 6 β€” Manual API Testing with Postman
GET, POST, PUT, DELETE with Examples

Q32: What is API Testing?

Ans: API testing ensures the APIs work as expected. We test the requests and responses between the client and server. In simple terms:

  • We check if the API returns the correct data.
  • We verify that the API handles errors gracefully (e.g., what happens if the resource doesn’t exist?).
  • We validate the status codes, response times, and data formats (like JSON).

Q33: How do you manually test an API using a Browser?

Ans: Test Case: Verify if the Google homepage is successfully loaded.

  1. Open your browser and go to http://google.co.in.
  2. Right-click anywhere on the page and select Inspect.
  3. Navigate to the Network tab.
  4. Reload the page (press F5) to capture the requests.
  5. Check the status code for the request to http://google.co.in.

Expected Output:

  • Status Code: 200 (OK)
  • Response: HTML content for the Google homepage.

Q34: How do you perform a GET Request in Postman?

Ans: Purpose: To retrieve the Google homepage.

Prerequisites:

  • Header: Content-Type: application/json
  • Request Method: GET
  • Endpoint: http://google.co.in

Steps:

  1. Open Postman and select GET.
  2. Enter the URL: http://google.co.in.
  3. Add a header: Key: Content-Type, Value: application/json.
  4. Click Send.

Expected Output:

Response Body: HTML code of the Google homepage.

<!doctype html> <html> <head>…</head> <body> <h1>Google</h1> </body> </html> Status Code: 200 (OK)

Q35: How do you perform a POST Request in Postman?

Ans: Purpose: To create a new resource on the server.

Dummy Example: Let’s say we are creating a new user on a dummy API.

Prerequisites:

  • Header: Content-Type: application/json
  • Request Method: POST
  • Endpoint: http://dummyapi/users
  • Request Body:
{ “name”: “Yogesh Pandian”, “email”: “yogeshchandran@mail.com” }

Steps:

  1. Open Postman and select POST.
  2. Enter the URL: http://dummyapi/users.
  3. Add a header: Key: Content-Type, Value: application/json.
  4. Add the Request Body.
  5. Click Send.

Expected Output:

{ “id”: 123, “name”: “Yogesh Pandian”, “email”: “yogeshchandran@mail.com”, “message”: “User created successfully” } Status Code: 201 (Created)

Q36: How do you perform a PUT Request in Postman?

Ans: Purpose: To update an existing resource.

Dummy Example: Let’s say we are updating a user’s email address.

Prerequisites:

  • Header: Content-Type: application/json
  • Request Method: PUT
  • Endpoint: http://dummyapi/users/123 (This 123 is unique id)
  • Request Body:
{ “email”: “yogeshchandran@mail.com” }

Steps:

  1. Open Postman and select PUT.
  2. Enter the URL: http://dummyapi/users/123.
  3. Add a header: Key: Content-Type, Value: application/json.
  4. Add the Request Body.
  5. Click Send.

Expected Output:

{ “id”: 123, “name”: “Yogesh Pandian”, “email”: “yogeshchandran@mail.com”, “message”: “User updated successfully” } Status Code: 200 (OK)

Q37: How do you perform a DELETE Request in Postman?

Ans: Purpose: To delete a resource from the server.

Dummy Example: Let’s say we are deleting a user.

Prerequisites:

  • Header: Content-Type: application/json
  • Request Method: DELETE
  • Endpoint: http://dummyapi/users/123

Steps:

  1. Open Postman and select DELETE.
  2. Enter the URL: http://dummyapi/users/123.
  3. Add a header: Key: Content-Type, Value: application/json.
  4. Click Send.

Expected Output:

{ “message”: “User deleted successfully” } Status Code: 200 (OK)

Q38: Why is Postman testing considered manual API testing?

Ans: When using Postman, you’re manually:

  1. Selecting the request method (GET, POST, PUT, DELETE).
  2. Entering headers, request body, and endpoint.
  3. Clicking “Send” to view the response.

Since no scripts or automation tools (like Selenium or REST Assured) are used to repeat these tests, it’s manual testing.

πŸ’‘ INTERVIEW TIP: When asked “How do you test APIs?” in an interview, always mention both manual (Postman) and automation approaches. This shows you have end-to-end API testing knowledge.
Section 7 β€” API Automation with Java
HttpURLConnection, UniRest & RestAssured

Q39: Can Selenium be used for API Testing?

Ans: There is a common misconception that Selenium is the solution for all types of automation. However, Selenium is specifically designed for automating web applications (UI/browser automation), not API testing. Selenium cannot directly test APIs.

Q40: How do we automate API testing in Java?

Ans: We can automate API tests using native Java or third-party libraries. Here are some options:

  1. HttpURLConnection (java.net): This is a built-in class in Java that allows you to send HTTP requests and handle responses. It’s simple but not as feature-rich as other libraries.
  2. UniRest: A third-party library that simplifies sending HTTP requests and handling responses. It provides a more concise API than HttpURLConnection.
  3. RestAssured: A popular and widely used library for automating RESTful API tests. It has many built-in features for validating responses, setting headers, and making requests in a more readable way.

Q41: What is HttpURLConnection?

Ans: HttpURLConnection is a built-in Java class (java.net package) that allows you to send HTTP requests and handle responses. It is simple but requires more boilerplate code compared to third-party libraries.

Q42: What is UniRest and how do you add it to your project?

Ans: UniRest is a third-party library that simplifies sending HTTP requests and handling responses. It provides a more concise API than HttpURLConnection.

Maven Dependency:

<dependency> <groupId>com.konghq</groupId> <artifactId>unirest-java</artifactId> <version>3.11.11</version> </dependency>

Q43: What is RestAssured and how do you add it to your project?

Ans: RestAssured is the most popular and widely used library for automating RESTful API tests in Java. It has many built-in features for validating responses, setting headers, and making requests in a more readable way. It uses a BDD-style syntax (Given-When-Then) which makes tests very readable.

Maven Dependency:

<dependency> <groupId>io.rest-assured</groupId> <artifactId>rest-assured</artifactId> <version>5.2.0</version> </dependency>

Q44: Why is RestAssured preferred over HttpURLConnection?

Ans: RestAssured is preferred because:

  • It uses BDD-style syntax (Given-When-Then) which is more readable.
  • It has built-in methods for validating JSON/XML responses.
  • It handles headers, cookies, and authentication easily.
  • It supports JSON Path and XML Path for extracting data from responses.
  • It integrates well with TestNG and JUnit for test execution.
  • It requires much less boilerplate code compared to HttpURLConnection.
// RestAssured Example (BDD Style): given() .header(“Content-Type”, “application/json”) .body(“{“name”:”Yogesh”,”email”:”test@mail.com”}”) .when() .post(“http://dummyapi/users”) .then() .statusCode(201) .body(“message”, equalTo(“User created successfully”));
βœ… INTERVIEW GOLD: In interviews, always mention RestAssured as your primary API automation tool. It is the industry standard for Java API testing. Know the Given-When-Then syntax by heart!

Q45: What is the difference between manual and automated API testing?

Ans:

  • Manual API Testing: Using tools like Postman where you manually select methods, enter data, and click Send. Good for exploratory testing and one-time checks.
  • Automated API Testing: Writing scripts using libraries like RestAssured, UniRest, or HttpURLConnection. Good for regression testing, CI/CD integration, and repeated execution.

Q46: What are the common types of API testing?

Ans:

  • Functional Testing: Verifying the API works as per requirements.
  • Validation Testing: Checking data format, schema, and structure.
  • Load Testing: Testing API performance under heavy load.
  • Security Testing: Checking authentication, authorization, and data protection.
  • Integration Testing: Verifying APIs work together correctly.
  • Error Handling Testing: Checking how APIs handle invalid inputs and errors.

Q47: What is the difference between SOAP and REST APIs?

Ans:

  • SOAP (Simple Object Access Protocol): Uses XML only, follows strict standards, supports WS-* standards, requires more bandwidth, and is more secure. Used in enterprise/banking applications.
  • REST (Representational State Transfer): Uses JSON/XML/HTML, follows architectural principles (not strict standards), lightweight, faster, easier to implement. Most commonly used in modern web applications.

Q48: What is JSON Schema Validation in API Testing?

Ans: JSON Schema Validation ensures that the API response matches the expected structure. For example, if the API should return a user object with “id” (number), “name” (string), and “email” (string), schema validation checks that the response contains these fields with the correct data types. This is crucial for catching API contract violations early.

Q49: What tools can be used for API Testing besides Postman?

Ans:

  • Postman β€” Most popular for manual and some automation.
  • SoapUI β€” Best for SOAP API testing.
  • JMeter β€” For API performance and load testing.
  • REST Assured β€” Java library for REST API automation.
  • Karate β€” BDD-style API testing framework.
  • Insomnia β€” Alternative to Postman with better UX.
  • Swagger β€” For API documentation and testing.

Q50: What are the key things to verify in API Testing?

Ans: The key things to verify in API Testing are:

  1. Status Code: Verify the correct HTTP status code is returned.
  2. Response Body: Verify the data returned is correct and in expected format (JSON/XML).
  3. Response Time: Verify the API responds within acceptable time limits.
  4. Headers: Verify correct headers are returned (Content-Type, Authorization, etc.).
  5. Error Handling: Verify proper error messages for invalid requests.
  6. Data Integrity: Verify data is correctly stored in the database after POST/PUT.
  7. Authentication: Verify unauthorized access is blocked (401/403).
πŸŽ‰ CONGRATULATIONS! You’ve completed the API Fundamentals Guide! Practice these concepts with real APIs like jsonplaceholder.typicode.com or reqres.in. Good luck with your interviews!

🎯 Complete API Testing Guide by QA Jobs India

Welcome to the API Fundamentals: A Tester’s Guide β€” the most comprehensive API testing preparation guide by QA Jobs India. This guide covers everything from basic API concepts to advanced automation with Java libraries like RestAssured, UniRest, and HttpURLConnection.

Perfect for Freshers, Junior QA Engineers, Manual Testers, QA Analysts, Automation Testers, and anyone preparing for API testing interviews. Covers REST APIs, HTTP Methods, JSON/XML, Status Codes, Authentication types, Postman Testing, and Java Automation.

All content is 100% free and regularly updated for 2026. Bookmark this page and revisit before every interview!

API Testing API Fundamentals REST API HTTP Methods JSON Postman API Automation QA Jobs India Software Testing API Interview Questions GET POST PUT DELETE Status Codes Bearer Token OAuth API Endpoint API Testing Interview REST Assured UniRest HttpURLConnection SOAP vs REST Path Parameter Query Parameter Content Type API Headers Authentication JSON Schema API Performance Testing Manual API Testing Automated API Testing QA Career
πŸ‘‘ Get Daily 100+ Jobs

Get direct HR emails, priority alerts & exclusive job access before anyone else!

πŸ‘‘ Upgrade to Premium Now
πŸ’¬ Join Our WhatsApp Community

Get instant job alerts, interview tips, resume feedback, and connect with 5000+ QA professionals. Never miss an opportunity!

πŸ“± Join WhatsApp Group

Β© 2026 QA Jobs India | API Fundamentals: A Tester’s Guide by QA Jobs India

Keywords: API Testing, API Fundamentals, REST API, HTTP Methods, JSON, Postman, API Automation, QA Jobs India, Software Testing, API Interview Questions, GET POST PUT DELETE, Status Codes, Bearer Token, OAuth, API Endpoint, API Testing Interview, REST Assured, UniRest, HttpURLConnection, SOAP vs REST, Path Parameter, Query Parameter, Content Type, API Headers, Authentication, JSON Schema, API Performance Testing, Manual API Testing, Automated API Testing, QA Career

βœ“ You're subscribed! Job alerts arrive daily at 9 AM.
Scroll to Top