DEV Community

Cover image for API Testing Rule 6/10: APIs Must Fail Predictably
Liudas
Liudas

Posted on

API Testing Rule 6/10: APIs Must Fail Predictably

API failures are inevitable, but they should never be unpredictable. Invalid requests, missing resources, authentication failures, rate limits, dependency outages, and internal errors are different conditions. They should return different and meaningful HTTP status codes instead of collapsing into a generic 500 Internal Server Error.

Predictable API error handling allows clients to understand what happened and decide whether to fix the request, authenticate, retry later, or stop. Similar failures should produce consistent status codes, stable error structures, and useful messages without exposing sensitive implementation details.

For example, a missing resource should return 404 Not Found, a malformed request should return 400 Bad Request, and a rate-limited client should receive 429 Too Many Requests. A 500 Internal Server Error should indicate that the server failed while processing an otherwise valid request—not that the client submitted invalid data.

API testing should cover validation errors, missing resources, authentication and authorization failures, unsupported operations, rate-limit violations, timeouts, dependency failures, and unexpected internal errors. Testers should verify that error responses are consistent, actionable, secure, and easy for API clients to interpret.

Any reproducible request that consistently generates a 5xx response should be investigated as a potential defect. Reliable APIs are not defined only by successful responses. Predictable failure handling is a core part of API reliability, REST API design, and software quality.

Rentgen is an API discovery tool built to explore failure paths beyond the expected request and expose assumptions before they become production incidents.

Read the complete API testing white paper: https://qaontime.com/research/the-power-of-ten-rules-for-testing-http-apis.html

Automation Before Automation.

Top comments (0)