top of page

Welcome
to NumpyNinja Blogs

NumpyNinja: Blogs. Demystifying Tech,

One Blog at a Time.
Millions of views. 

Beyond the Status Code, Test the Logic of API

May 1, 2025
5 min read
"Real Testing means checking more than 200 OK"

In API testing, just checking the status code is like judging a book by its cover. Status codes may show if something passed or failed, but they don't confirm whether the API did what it was supposed to do. It's the difference between "building the product right" which ensures on quality and "building the right product" which ensures whether the actual business needs are met. Testing the actual logic of an API helps to find bugs at various levels, provides comprehensive test coverage, and confirms that the functionality aligns with business goals. In this blog, let's explore the importance of logic validation and explore various methods to implement it.


Why Logic Testing of an API is Important:

Testing API logic helps to find issues that the status code failed to show. Status code only indicates the success or failure of an API request. For example, an API might return status code 200 for a get request even if the data fetched is wrong or incomplete.


Real-world Logic Failures of an API:

Some of the real-world logic failures of an API are

1.     Payment Processed but Order Not Created

  • Status Code: 200 OK

  • Issue: Payment API succeeds with a returned 200 OK status code, but the order fails leaving the customer charged without an order confirmation.


2.     Inventory Not Updated After Order

  • Status Code: 201 Created

  • Issue: An order is placed successfully, but the inventory is not updated due to some background issue or integration issue.


How to Test API Logic:

Here are some of the methods to test the logic of an API beyond the status code,

  1. Response Time Validation:

    Response Time Validation is the process of checking how long the API takes to respond a request and verifying that API returns the response within an acceptable limit.


    Syntax in Postman

	pm.test("Validate Response Time is less than 5ooms", () => {
	pm.expect(pm.response.responseTime).to.be.below(500);
	});

Syntax in Rest Assured


 	given()
		.baseUri("https://sample.com")
	.when()
		.get("/endpoint")
	.then()
		.time(lessthan(500L));
	

  1. Data Validation:

    Data Validation is the process of checking the data returned by the API in the response matches the expected values.


      Syntax in Postman

pm.test("Data Validation", () => {
const ExpFirstName = pm.iterationData.get("userfirstsname");
pm.expect(jsonData.user_first_name).to.eql(ExpFirstName);
});

Syntax in Rest Assured

 given()
	.baseUri("https://sample.com")
 .when()
 	.get("/endpoint")
.then()
	.statusCode(200)
	.body("name", equalTo("Ajith Kumar"))
	.body("email", equalTo("ajith@gmail.com"));

  1. Header Validation:

    Header Validation is the process of checking that the HTTP headers in the response contains the correct values, matches the expected formats, and include all required information. Even if the body is correct, missing or incorrect header can cause bugs, security risks and performance issues. Some of the common headers to validate are,

    • Content Type

    • Authorization

    • Content - Encoding

    • Cookies

    • Cache - Control


Example of Header Validation

Syntax in Postman

pm.test("Content-Type Validation", () => {
pm.response.to.have.header("Content-Type", "application/json; charset=utf-8");
});

pm.test("Authorization Validation", () => {
pm.expect(pm.request.headers.has("Authorization")).to.be.true;
});

Syntax in Rest Assured


 given()
	.baseUri("https://sample.com")
	.header("Authorization", "Bearer abc123")
	.header("Content-Type", "application/json")
.when()
  	.statusCode(200)
    .header("Content-Type", equalTo("application/json"))
    .header("Authorization", notNullValue())

  1. Schema Validation:

    Schema Validation is the process of checking Json schema that defines the expected data types, required fields, nested object structures and format of each field in the response.


    Syntax in Postman

const schema = {
  "type": "object",
  "required": ["id", "name", "email"],
  "properties": {
    "id": {"type": "integer"},
    "name": {"type": "string"},
    "email": {"type": "string", "format": "email"}
  }
};

pm.test("Schema Validation", () => {
   pm.response.to.have.jsonSchema(schema);
});


Syntax in Rest Assured

 given()
    .baseUri("https://sample.com")
  .when()
	.get("/users/123")
 .then()
 	.statusCode(200)
	.body(matchesJsonSchemaInClasspath("schema/user-schema.json"));

Note: Ensure your schema file is in the classpath (i.e., inside src/test/resources/).


  1. Error Message / Success Message Validation

    Error Message / Success Message validation is the process of checking that an API returns the HTTP status code along with a clear and meaningful message for both successful and failed operations.

    For successful responses, the message should confirm the action clearly. For example,

    • Login Successful

    • User Created Successfully

    For error responses, the message should provide a clear explanation of the issue. For example,

    • Email Required

    • Invalid Password

    This validation helps to ensure a better user experience, simplifies error debugging, and ensures reliable communication between the frontend and backend systems.


    Syntax in Postman

	var jsonData = pm.response.json (); 
	pm.test("Validate Message", () => { 
	pm.expect(jsonData.message).to.eql("The Actual Message");
	});

Syntax in Rest Assured

	 given()
		.baseUri("https://sample.com")
	.when()
		.get("/users/123")
	 .then()
		  .statusCode(404)
		  .body("message", equalTo("User not found"));

  1. Date and Time Validation 

    Date and Time validation is the process of verifying that the date and time sent to or received from API are in the correct format, and logically consistent like having a start date before an end date, within valid ranges like birthday dates are not set in the future. Date and Time validation is important because the error can cause users to book wrong time slots, make transactions at the wrong time, and so on. Some of the types of Date and Time Validations are,


  • Format Validation: Ensures the data and time follows a specific format.

  • Logical Validation: Ensures that the date and time values make sense. For example,

    • Start date should be before the end date

    • Appointment or booking date should not be in the past

    • CreatedAt should not be in the future

  • Time Zone Validation: Ensures that the time includes information about the time zone.

  • Boundary or Range Validation: Ensures that the data and time values are within the acceptable range. For example,

    • The birthday date is not in the future

    • An appointment or booking date cannot be scheduled for a past date


7. State Change Validation

State Change validation is the process of verifying that an API request is made to create, update, or delete, and the actual backend data is modified accordingly. For example,

  1. Post Request (Create a User)

    • Request: Create a new user with a POST request.

    • Expected: A new user should be created, and the record should exist in the database.

    • State Validation: After the POST request, create a GET request with the created user ID from the POST request to confirm the user was actually created and stored.

  2. Put/Patch Request (Update an order)

    • Request: Update the order request to be shipped

    • Expected; The order should reflect the new status from the order placed to shipped.

    • State Validation: Following the PUT request, the GET request should return the status "shipped"


8. Business Rule Validation

Business Rule Validation is the process of verifying the response follows the specific rules and conditions defined by the business. These rules reflect how the system is expected to behave in real-world situations based on the rules set by the business. For example,

  • Coupons code can be applied after the minimum purchase.

  • Refund request is allowed within 30 days of purchase.


I hope this blog provided clarity on why validating the logic of an API along with status code validation is important. A combination of status code validation and logic testing is essential for scalable and reliable API. Together they help prevent hidden failures, maintain data integrity and deliver consistent performance.


"Test the code. Test the logic. Deliver better APIs"

 
 

+1 (302) 200-8320

NumPy_Ninja_Logo (1).png

Numpy Ninja Inc. 8 The Grn Ste A Dover, DE 19901

© Copyright 2025 by Numpy Ninja Inc.

  • Twitter
  • LinkedIn
bottom of page