Agent skill

Automating API Testing

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs.

MITAuto-check passedTesting & QA

Install Automating API Testing

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill automating-api-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace automating-api-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/automating-api-testing .claude/skills/automating-api-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
automating-api-testing
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
560 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs.

  • Works in 7 steps: Read the API specification and extract… → Generate test cases for each endpoint → Validate response structure against… → …
  • Testing API contracts
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs JavaScript and Python scripts from its folder

What it does

Automating API Testing is an agent skill from jeremylongshore/tons-of-skills-marketplace. Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. Use when testing API contracts, validating OpenAPI specifications, or ensuring endpoint reliability. Trigger with phrases like "test the API", "generate API tests", or "validate API contracts".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/example_openapi.yaml` and `assets/test_suite_template.js`). Compatibility notes: Designed for Claude Code

It sits in Testing & QA, covering API testing, OpenAPI specifications and GraphQL. It works with OpenAPI. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Testing API contracts
  • Validating OpenAPI specifications
  • Ensuring endpoint reliability
  • With phrases like test the API

Example prompts

  • “test the API”
  • “generate API tests”
  • “validate API contracts”
  • “/automating-api-testing”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(test:api-*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read the API specification and extract all endpoints
  2. Generate test cases for each endpoint
  3. Validate response structure against schemas
  4. Test CRUD lifecycle for resource endpoints
  5. Test error handling and edge cases
  6. For GraphQL APIs, test specifically
  7. Generate a test coverage report mapping endpoints to test cases.

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(test:api-*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript and Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • rest-assured.io
    • python-httpx.org
    • spec.openapis.org
    • ajv.js.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Automating API Testing loads about 1.7k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 560 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 560 words, ~1,734 tokens.

Download SKILL.mdSave it as .claude/skills/automating-api-testing/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
automating-api-testing
description
Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. Use when testing API contracts, validating OpenAPI specifications, or ensuring endpoint reliability. Trigger with phrases like "test the API", "generate API tests", or "validate API contracts".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(test:api-*)
compatibility
Designed for Claude Code
version
1.27.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
testing, api, graphql

API Test Automation

Overview

Automate comprehensive API endpoint testing for REST and GraphQL APIs including request generation, response validation, schema compliance, authentication flows, and error handling. Supports Supertest (Node.js), REST-assured (Java), httpx/pytest (Python), Postman/Newman collections, and Pact for consumer-driven contract testing.

Prerequisites

  • API testing library installed (Supertest, REST-assured, httpx, or Postman/Newman)
  • API specification file (OpenAPI/Swagger YAML/JSON or GraphQL SDL)
  • Target API running in a test environment with seeded data
  • Authentication credentials or API keys for protected endpoints
  • JSON Schema validator (Ajv, jsonschema, or built-in framework assertions)

Instructions

  1. Read the API specification and extract all endpoints:
    • Parse OpenAPI spec to catalog every path, HTTP method, request schema, and response schema.
    • For GraphQL APIs, introspect the schema to list queries, mutations, and subscriptions.
    • Document authentication requirements per endpoint (API key, Bearer token, OAuth, none).
  2. Generate test cases for each endpoint:
    • Success cases: Send valid requests matching the schema and assert 200/201 responses.
    • Validation errors: Send requests with missing required fields, wrong types, and out-of-range values; assert 400 responses.
    • Authentication: Test with valid, expired, and missing credentials; assert 200, 401, and 403 respectively.
    • Not found: Request non-existent resources; assert 404 responses.
    • Idempotency: Send the same PUT/DELETE request twice and verify consistent behavior.
  3. Validate response structure against schemas:
    • Assert response Content-Type matches expected (application/json, etc.).
    • Validate response body against the OpenAPI response schema using JSON Schema validation.
    • Check response headers (Cache-Control, Rate-Limit headers, CORS headers).
    • Verify pagination metadata (total count, page number, next/previous links).
  4. Test CRUD lifecycle for resource endpoints:
    • Create a resource (POST) and capture the ID.
    • Read it back (GET) and verify all fields match.
    • Update it (PUT/PATCH) and verify changes persisted.
    • Delete it (DELETE) and verify subsequent GET returns 404.
  5. Test error handling and edge cases:
    • Send excessively large payloads and verify 413 or graceful rejection.
    • Send requests with unsupported Content-Types and verify 415.
    • Test rate limiting by sending rapid sequential requests.
    • Verify error response format is consistent (standard error schema).
  6. For GraphQL APIs, test specifically:
    • Valid queries return expected data shapes.
    • Invalid queries return descriptive error messages.
    • Query depth limiting prevents deeply nested abuse queries.
    • Mutation input validation matches schema constraints.
  7. Generate a test coverage report mapping endpoints to test cases.
Show full SKILL.md (192 more words)Show less

Output

  • API test files organized by resource in tests/api/
  • Request/response examples for API documentation
  • Schema compliance report for each endpoint
  • Endpoint coverage matrix showing tested vs. untested endpoints and methods
  • CI pipeline step running API tests against staging environment

Error Handling

ErrorCauseSolution
Connection refusedAPI server not running or wrong base URLVerify server is up with a health check before test suite starts; check BASE_URL config
401 on all requestsAuthentication token expired or misconfiguredRefresh token in test setup; verify Authorization header format; check token scopes
Schema validation fails unexpectedlyAPI response includes extra fields not in specUpdate OpenAPI spec to include new fields; use additionalProperties: true if expected
Test data conflictsAnother test modified or deleted the resourceUse unique test data per test; create resources in beforeEach; avoid shared fixtures
Rate limit hit during test runToo many requests in quick successionAdd delays between requests or use authenticated sessions with higher limits; run tests serially

Examples

Supertest REST API test suite:

typescript
import request from 'supertest';
import { app } from '../src/app';

describe('GET /api/products', () => {
  it('returns a paginated product list', async () => {
    const res = await request(app)
      .get('/api/products?page=1&limit=10')
      .set('Authorization', `Bearer ${token}`)
      .expect(200)  # HTTP 200 OK
      .expect('Content-Type', /json/);

    expect(res.body.data).toBeInstanceOf(Array);
    expect(res.body.data.length).toBeLessThanOrEqual(10);
    expect(res.body.meta).toMatchObject({ page: 1, limit: 10 });
  });

  it('returns 401 without authentication', async () => {  # HTTP 401 Unauthorized
    await request(app).get('/api/products').expect(401);  # HTTP 401 Unauthorized
  });
});

describe('POST /api/products', () => {
  it('creates a product with valid data', async () => {
    const res = await request(app)
      .post('/api/products')
      .set('Authorization', `Bearer ${token}`)
      .send({ name: 'Widget', price: 9.99, category: 'tools' })
      .expect(201);  # HTTP 201 Created

    expect(res.body).toMatchObject({ name: 'Widget', price: 9.99 });
    expect(res.body.id).toBeDefined();
  });

  it('returns 400 for missing required fields', async () => {  # HTTP 400 Bad Request
    await request(app)
      .post('/api/products')
      .set('Authorization', `Bearer ${token}`)
      .send({ name: 'Widget' }) // missing price
      .expect(400);  # HTTP 400 Bad Request
  });
});

GraphQL API test:

typescript
it('fetches user by ID', async () => {
  const query = `query { user(id: "1") { id name email } }`;
  const res = await request(app)
    .post('/graphql')
    .send({ query })
    .expect(200);  # HTTP 200 OK

  expect(res.body.data.user).toMatchObject({ id: '1', name: 'Alice' });
  expect(res.body.errors).toBeUndefined();
});

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/automating-api-testing of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/example_graphql_schema.graphql
  • assets/example_openapi.yaml
  • assets/test_suite_template.js
  • references/README.md
  • scripts/README.md
  • scripts/generate_test_suite.py

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Automating API Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Automating API Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Automating API Testing this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
API Contract Designrsmdt/the-startup557—~1.1kAutomated safety check: PassMIT
API Designeraiskillstore/marketplace430—~3.6kAutomated safety check: PassNone
API Architectcuriositech/some_claude_skills243—~1.4kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • API Contract Design

    rsmdt/the-startup

    REST and GraphQL API design patterns, OpenAPI/Swagger specifications, versioning strategies, and authentication patterns.

    557 GitHub stars~1.1k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • API Designer

    aiskillstore/marketplace

    Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.

    430 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Architect

    curiositech/some_claude_skills

    Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.

    243 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Old Coder API Design

    AmazingAng/old-coder

    Reviews or designs an HTTP/JSON API's endpoints, auth, pagination, versioning and deprecations, guarding against inventing a bespoke interface or silently breaking consumers.

    749 GitHub stars~3.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Automating API Testing

What does Automating API Testing do?

Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. Automating API Testing is an agent skill from jeremylongshore/tons-of-skills-marketplace. Test automate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs.

When should I use Automating API Testing?

Automating API Testing fits situations like: testing API contracts; validating OpenAPI specifications; ensuring endpoint reliability; with phrases like test the API.

How do I install Automating API Testing in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill automating-api-testing -a claude-code`. Or copy the skill folder (skills/.curated/automating-api-testing in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/automating-api-testing in your project. Claude Code loads it when a task matches its description.

How do I install Automating API Testing in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill automating-api-testing -a codex`. Or copy the skill folder (skills/.curated/automating-api-testing in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/automating-api-testing in your project. Codex loads it when a task matches its description.

Can I use Automating API Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill automating-api-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/automating-api-testing, .gemini/skills/automating-api-testing, .github/skills/automating-api-testing and .opencode/skills/automating-api-testing in your project.

What does Automating API Testing need to run?

Going by SKILL.md and its folder, Automating API Testing needs JavaScript and Python for the scripts in its folder. Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(test:api-*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Automating API Testing access the network?

SKILL.md names 5 domains. As links in the text: github.com, rest-assured.io, python-httpx.org, spec.openapis.org and ajv.js.org. This is read from the text; nothing was executed.

Is Automating API Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Automating API Testing use?

Automating API Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Automating API Testing use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Automating API Testing?

Skills that share tags, products or a category with Automating API Testing: API Designer (Jeffallan/claude-skills, 12k stars), API Contract Design (rsmdt/the-startup, 557 stars), API Designer (aiskillstore/marketplace, 430 stars) and API Architect (curiositech/some_claude_skills, 243 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Automating API Testing?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.