API testing verifies functional, non-functional and security aspects of interfaces independently from the user interface. It includes automated contract, integration and load tests plus dependency mocking. The aim is early defect detection, more stable integrations and faster feedback loops in CI/CD pipelines and measurable API quality indicators.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
API testing checks interfaces directly against their functional and technical expectations — from correct responses to load behavior and security risks — without involving the user interface.
As service-based architectures expanded, APIs became the actual contract between teams and systems. API testing emerged as a specialized form of software testing to examine that layer separately from the UI: specifications, status codes, and data formats can be automated, while security guidance such as the OWASP API Security Project shows that APIs also introduce their own attack patterns and misconfigurations.
Think of API testing as a verification chain wrapped around an interface. A first step compares request, response, status code, and required fields against the specification. Integration tests then exercise real interactions with authentication, data storage, and dependent services; mocks replace only the parts that are unavailable or too expensive to use. Load and security tests complete the picture for concurrency, failure scenarios, and abusive inputs.
The request and response schema, status codes, and required fields are checked against the expected specification.
The API is tested in combination with authentication, persistence, and dependent services.
Mocks or stubs replace dependencies so cases remain isolated, controllable, and repeatable.
Latency, throughput, concurrency, and failure behavior are assessed under realistic conditions.
Authorization, authentication, input validation, and common API attack surfaces are checked deliberately.
API testing is especially useful before releases, when endpoints change, in CI/CD, and for security-sensitive services. It shortens feedback loops and exposes interface defects early. It does not replace end-to-end or UI testing entirely; real operational problems, workflows, and data dependencies only become visible when the specification, test data, and coverage strategy are chosen well.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.