Agent skill

API Testing Patterns

by proffesor-for-testing in proffesor-for-testing/agentic-qe

Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.

MITAuto-check passedTesting & QA

Install API Testing Patterns

skills CLI
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/assets/skills/api-testing-patterns .claude/skills/api-testing-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-testing-patterns
GitHub stars
494
Token cost
~2.4k tokens
SKILL.md length
458 words
Files
6 (incl. scripts)
Skills in repo
95
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.

  • Works in 5 steps: IDENTIFY testing level: contract,… → TEST the contract, not implementation… → VALIDATE auth, input, errors,… → …
  • Designing API test strategies
  • SKILL.md covers Quick Reference Card, Contract Testing, Critical Test Patterns and REST CRUD Pattern, plus 6 more sections
  • Tasks that involve API testing

What it does

API Testing Patterns is an agent skill from proffesor-for-testing/agentic-qe. Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. Use when testing APIs or designing API test strategies.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `config.json`, `evals/api-testing-patterns.yaml` and `schemas/output.json`).

It sits in Testing & QA, covering API testing and Integration testing. It works with GraphQL. The repository describes itself as: Agentic QE Fleet is an open-source AI-powered QA/QE platform designed for use with Coding Agents (works best with Claude Code) featuring specialized agents and skills to support… The licence is MIT.

When your agent uses it

  • Designing API test strategies
  • Tasks that involve API testing
  • Tasks that involve Integration testing

Example prompts

  • “/api-testing-patterns”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. IDENTIFY testing level: contract, integration, or component
  2. TEST the contract, not implementation (consumer perspective)
  3. VALIDATE auth, input, errors, idempotency, concurrency
  4. AUTOMATE in CI/CD with schema validation
  5. MONITOR production APIs for contract drift

What it can do on your machine

Read from SKILL.md and the folder at commit 829d030. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Testing Patterns loads about 2.4k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from proffesor-for-testing/agentic-qe at commit 829d030, republished under its MIT licence (© proffesor-for-testing). 458 words, ~2,371 tokens.

Download SKILL.mdSave it as .claude/skills/api-testing-patterns/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
api-testing-patterns
description
Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. Use when testing APIs or designing API test strategies.
category
testing-methodologies
priority
high
tokenEstimate
1200
agents
qe-api-contract-validator, qe-test-generator, qe-performance-tester, qe-security-scanner
implementation_status
optimized
optimization_version
1
last_optimized
2025-12-02
quick_reference_card
true
tags
api, rest, graphql, contract-testing, pact, integration, microservices
trust_tier
3

API Testing Patterns

<default_to_action> When testing APIs or designing API test strategy:

  1. IDENTIFY testing level: contract, integration, or component
  2. TEST the contract, not implementation (consumer perspective)
  3. VALIDATE auth, input, errors, idempotency, concurrency
  4. AUTOMATE in CI/CD with schema validation
  5. MONITOR production APIs for contract drift

Quick Pattern Selection:

  • Microservices → Consumer-driven contracts (Pact)
  • REST APIs → CRUD + pagination + filtering tests
  • GraphQL → Query validation + complexity limits
  • External deps → Mock with component testing
  • Performance → Load test critical endpoints

Critical Success Factors:

  • APIs are contracts - test from consumer perspective
  • Always test error scenarios, not just happy paths
  • Version your API tests to prevent breaking changes </default_to_action>

Quick Reference Card

When to Use
  • Testing REST or GraphQL APIs
  • Validating microservice contracts
  • Designing API test strategies
  • Preventing breaking API changes
Testing Levels
LevelPurposeDependenciesSpeed
ContractProvider-consumer agreementNoneFast
ComponentAPI in isolationMockedFast
IntegrationReal dependenciesDatabase, servicesSlower
Critical Test Scenarios
ScenarioMust TestExample
Auth401/403 handlingExpired token, wrong user
Input400 validationMissing fields, wrong types
Errors500 graceful handlingDB down, timeout
IdempotencyDuplicate preventionSame idempotency key
ConcurrencyRace conditionsParallel checkout
Tools
  • Contract: Pact, Spring Cloud Contract
  • REST: Supertest, REST-assured, Playwright
  • Load: k6, Artillery, JMeter
Agent Coordination
  • qe-api-contract-validator: Validate contracts, detect breaking changes
  • qe-test-generator: Generate tests from OpenAPI spec
  • qe-performance-tester: Load test endpoints
  • qe-security-scanner: API security testing

Contract Testing

Pattern: Consumer-Driven Contracts

javascript
// Consumer defines expectations
const contract = {
  request: { method: 'POST', path: '/orders', body: { productId: 'abc', quantity: 2 } },
  response: { status: 201, body: { orderId: 'string', total: 'number' } }
};

// Provider must fulfill
test('order API meets contract', async () => {
  const response = await api.post('/orders', { productId: 'abc', quantity: 2 });

  expect(response.status).toBe(201);
  expect(response.body).toMatchSchema({
    orderId: expect.any(String),
    total: expect.any(Number)
  });
});

When: Microservices, distributed systems, third-party integrations


Critical Test Patterns

Authentication & Authorization
javascript
describe('Auth', () => {
  it('rejects without token', async () => {
    expect((await api.get('/orders')).status).toBe(401);
  });

  it('rejects expired token', async () => {
    const expired = generateExpiredToken();
    expect((await api.get('/orders', { headers: { Authorization: `Bearer ${expired}` } })).status).toBe(401);
  });

  it('blocks cross-user access', async () => {
    const userAToken = generateToken({ userId: 'A' });
    expect((await api.get('/orders/user-B-order', { headers: { Authorization: `Bearer ${userAToken}` } })).status).toBe(403);
  });
});
Input Validation
javascript
describe('Validation', () => {
  it('validates required fields', async () => {
    const response = await api.post('/orders', { quantity: 2 }); // Missing productId
    expect(response.status).toBe(400);
    expect(response.body.errors).toContain('productId is required');
  });

  it('validates types', async () => {
    expect((await api.post('/orders', { productId: 'abc', quantity: 'two' })).status).toBe(400);
  });

  it('validates ranges', async () => {
    expect((await api.post('/orders', { productId: 'abc', quantity: -5 })).status).toBe(400);
  });
});
Idempotency
javascript
it('prevents duplicates with idempotency key', async () => {
  const key = 'unique-123';
  const data = { productId: 'abc', quantity: 2 };

  const r1 = await api.post('/orders', data, { headers: { 'Idempotency-Key': key } });
  const r2 = await api.post('/orders', data, { headers: { 'Idempotency-Key': key } });

  expect(r1.body.orderId).toBe(r2.body.orderId); // Same order
});
Concurrency
javascript
it('handles race condition on inventory', async () => {
  const promises = Array(10).fill().map(() =>
    api.post('/orders', { productId: 'abc', quantity: 1 })
  );
  const responses = await Promise.all(promises);
  const successful = responses.filter(r => r.status === 201);

  const inventory = await db.inventory.findById('abc');
  expect(inventory.quantity).toBe(initialQuantity - successful.length);
});

REST CRUD Pattern

javascript
describe('Product CRUD', () => {
  let productId;

  it('CREATE', async () => {
    const r = await api.post('/products', { name: 'Widget', price: 10 });
    expect(r.status).toBe(201);
    productId = r.body.id;
  });

  it('READ', async () => {
    const r = await api.get(`/products/${productId}`);
    expect(r.body.name).toBe('Widget');
  });

  it('UPDATE', async () => {
    const r = await api.put(`/products/${productId}`, { price: 12 });
    expect(r.body.price).toBe(12);
  });

  it('DELETE', async () => {
    expect((await api.delete(`/products/${productId}`)).status).toBe(204);
    expect((await api.get(`/products/${productId}`)).status).toBe(404);
  });
});

Best Practices

✅ Do This
  • Test from consumer perspective
  • Use schema validation (not exact values)
  • Test error scenarios extensively
  • Version API tests
  • Automate in CI/CD
Show full SKILL.md (186 more words)Show less
❌ Avoid This
  • Testing implementation, not contract
  • Ignoring HTTP semantics (status codes)
  • No negative testing
  • Asserting on field order or extra fields
  • Slow tests (mock external services)

Agent-Assisted API Testing

typescript
// Validate contracts
await Task("Contract Validation", {
  spec: 'openapi.yaml',
  endpoint: '/orders',
  checkBreakingChanges: true
}, "qe-api-contract-validator");

// Generate tests from spec
await Task("Generate API Tests", {
  spec: 'openapi.yaml',
  coverage: 'comprehensive',
  include: ['happy-paths', 'input-validation', 'auth-scenarios', 'error-handling']
}, "qe-test-generator");

// Load test
await Task("API Load Test", {
  endpoint: '/orders',
  rps: 1000,
  duration: '5min'
}, "qe-performance-tester");

// Security scan
await Task("API Security Scan", {
  spec: 'openapi.yaml',
  checks: ['sql-injection', 'xss', 'broken-auth', 'rate-limiting']
}, "qe-security-scanner");

Agent Coordination Hints

Memory Namespace
aqe/api-testing/
├── contracts/*        - API contract definitions
├── generated-tests/*  - Generated test suites
├── validation/*       - Contract validation results
└── performance/*      - Load test results
Fleet Coordination
typescript
const apiFleet = await FleetManager.coordinate({
  strategy: 'contract-testing',
  agents: ['qe-api-contract-validator', 'qe-test-generator', 'qe-test-executor'],
  topology: 'mesh'
});

await apiFleet.execute({
  services: [
    { name: 'orders-api', consumers: ['checkout-ui', 'admin-api'] },
    { name: 'payment-api', consumers: ['orders-api'] }
  ]
});


Remember

API testing = verifying contracts and behavior, not implementation. Focus on what matters to consumers: correct responses, proper error handling, acceptable performance.

With Agents: Agents automate contract validation, generate comprehensive test suites from specs, and monitor production APIs for drift. Use agents to maintain API quality at scale.

Gotchas

  • Agent generates tests against documented API, not actual API — always validate against running service first
  • Auth tokens expire between test runs — use fixtures with long-lived tokens or refresh before each suite
  • Rate limiting in CI causes intermittent failures — add retry with exponential backoff for 429 responses
  • GraphQL introspection may be disabled in production — test against staging schema, not production endpoint
  • Idempotency tests need unique request IDs per run — hardcoded IDs cause false passes on retry

© proffesor-for-testing, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in assets/skills/api-testing-patterns of proffesor-for-testing/agentic-qe.

  • SKILL.md
  • config.json
  • evals/api-testing-patterns.yaml
  • schemas/output.json
  • scripts/validate-config.json
  • templates/api-test-scaffold.md

Open the folder on GitHubat commit 829d030

Compare with similar skills

API Testing Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Testing Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Testing Patterns this skillproffesor-for-testing/agentic-qe494—~2.4kAutomated safety check: PassMIT
API Testingpetrkindlmann/qa-skills165—~2.7kAutomated safety check: PassMIT
API Testingcosmicstack-labs/mercury-agent-skills476—~449Automated safety check: PassMIT
Integration Tests for pRESTprest/prest4.6k—~1.1kAutomated safety check: PassMIT
Reasoning Serialization Teststailcallhq/forgecode7.6k—~1kAutomated safety check: PassApache-2.0
Syncable Entity Integration Teststwentyhq/twenty58k—~3.4kAutomated safety check: PassCustom licence

Similar skills

  • API Testing

    petrkindlmann/qa-skills

    Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.

    165 GitHub stars~2.7k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • API Testing

    cosmicstack-labs/mercury-agent-skills

    REST and GraphQL testing, Postman/Insomnia patterns, contract testing, schema validation, and monitoring

    476 GitHub stars~449 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Guides writing and reviewing pREST Docker-based integration tests so every HTTP request is explained by step comments or table-driven descriptions.

    4.6k GitHub stars~1.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Reasoning Serialization Tests

    tailcallhq/forgecode

    Checks that ReasoningConfig fields are serialized into the right provider-specific JSON for OpenRouter, Anthropic, GitHub Copilot and Codex requests.

    7.6k GitHub stars~1k tokensUpdated today
    Testing & QAAuto-check passed
  • Step-by-step guide to writing the mandatory integration tests for syncable metadata entities in Twenty's server, covering failures and CRUD success cases.

    58k GitHub stars~3.4k tokensUpdated today
    Testing & QAAuto-check passed
  • API Testing

    fugazi/test-automation-skills-agents

    Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).

    247 GitHub stars~1.5k tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from proffesor-for-testing/agentic-qe

All 95 skills in this repo
  • Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • Mutation Testing

    proffesor-for-testing/agentic-qe

    Test quality validation through mutation testing, assessing test suite effectiveness by introducing code mutations and measuring kill rate.

    494 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Performance Testing

    proffesor-for-testing/agentic-qe

    Profiles application performance under load using k6, Artillery, or JMeter to measure latency, throughput, and error rates.

    494 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed
  • Code Review Quality

    proffesor-for-testing/agentic-qe

    Conduct context-driven code reviews focusing on quality, testability, and maintainability.

    494 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Security Testing

    proffesor-for-testing/agentic-qe

    Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology.

    494 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check: notes
  • Database Testing

    proffesor-for-testing/agentic-qe

    Database schema validation, data integrity testing, migration testing, transaction isolation, and query performance.

    494 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed

Works with

Categories

Questions about API Testing Patterns

What does API Testing Patterns do?

Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. API Testing Patterns is an agent skill from proffesor-for-testing/agentic-qe. Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.

When should I use API Testing Patterns?

API Testing Patterns fits situations like: designing API test strategies; tasks that involve API testing; tasks that involve Integration testing.

How do I install API Testing Patterns in Claude Code?

Run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a claude-code`. Or copy the skill folder (assets/skills/api-testing-patterns in proffesor-for-testing/agentic-qe) into .claude/skills/api-testing-patterns in your project. Claude Code loads it when a task matches its description.

How do I install API Testing Patterns in Codex?

Run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a codex`. Or copy the skill folder (assets/skills/api-testing-patterns in proffesor-for-testing/agentic-qe) into .agents/skills/api-testing-patterns in your project. Codex loads it when a task matches its description.

Can I use API Testing Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-testing-patterns, .gemini/skills/api-testing-patterns, .github/skills/api-testing-patterns and .opencode/skills/api-testing-patterns in your project.

What does API Testing Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: API Testing Patterns is instructions for the agent only.

Does API Testing Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Testing Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does API Testing Patterns use?

API Testing Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Testing Patterns use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Testing Patterns?

Skills that share tags, products or a category with API Testing Patterns: API Testing (petrkindlmann/qa-skills, 165 stars), API Testing (cosmicstack-labs/mercury-agent-skills, 476 stars), Integration Tests for pREST (prest/prest, 4.6k stars) and Reasoning Serialization Tests (tailcallhq/forgecode, 7.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Testing Patterns?

proffesor-for-testing (a GitHub user) maintains it in proffesor-for-testing/agentic-qe, which has 494 GitHub stars. The repository holds 95 skills in this directory. The repository was last updated on October 4, 2026.

Source: proffesor-for-testing/agentic-qe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.