Beyond the Status Code, Test the Logic of API
"Real Testing means checking more than 200 OK"
In API testing, just checking the status code is like judging a book by its cover. Status codes may show if something passed or failed, but they don't confirm whether the API did what it was supposed to do. It's the difference between "building the product right" which ensures on quality and "building the right product" which ensures whether the actual business needs are met. Testing the actual logic of an API helps to find bugs at various levels, provides comprehensive test coverage, and confirms that the functionality aligns with business goals. In this blog, let's explore the importance of logic validation and explore various methods to implement it.
Why Logic Testing of an API is Important:
Testing API logic helps to find issues that the status code failed to show. Status code only indicates the success or failure of an API request. For example, an API might return status code 200 for a get request even if the data fetched is wrong or incomplete.
Real-world Logic Failures of an API:
Some of the real-world logic failures of an API are
1. Payment Processed but Order Not Created
Status Code: 200 OK
Issue: Payment API succeeds with a returned 200 OK status code, but the order fails leaving the customer charged without an order confirmation.
2. Inventory Not Updated After Order
Status Code: 201 Created
Issue: An order is placed successfully, but the inventory is not updated due to some background issue or integration issue.
How to Test API Logic:
Here are some of the methods to test the logic of an API beyond the status code,
Response Time Validation:
Response Time Validation is the process of checking how long the API takes to respond a request and verifying that API returns the response within an acceptable limit.
Syntax in Postman
pm.test("Validate Response Time is less than 5ooms", () => {
pm.expect(pm.response.responseTime).to.be.below(500);
});Syntax in Rest Assured
given()
.baseUri("https://sample.com")
.when()
.get("/endpoint")
.then()
.time(lessthan(500L));
Data Validation:
Data Validation is the process of checking the data returned by the API in the response matches the expected values.
Syntax in Postman
pm.test("Data Validation", () => {
const ExpFirstName = pm.iterationData.get("userfirstsname");
pm.expect(jsonData.user_first_name).to.eql(ExpFirstName);
});Syntax in Rest Assured
given()
.baseUri("https://sample.com")
.when()
.get("/endpoint")
.then()
.statusCode(200)
.body("name", equalTo("Ajith Kumar"))
.body("email", equalTo("ajith@gmail.com"));
Header Validation:
Header Validation is the process of checking that the HTTP headers in the response contains the correct values, matches the expected formats, and include all required information. Even if the body is correct, missing or incorrect header can cause bugs, security risks and performance issues. Some of the common headers to validate are,
Content Type
Authorization
Content - Encoding
Cookies
Cache - Control
Example of Header Validation
Syntax in Postman
pm.test("Content-Type Validation", () => {
pm.response.to.have.header("Content-Type", "application/json; charset=utf-8");
});
pm.test("Authorization Validation", () => {
pm.expect(pm.request.headers.has("Authorization")).to.be.true;
});
Syntax in Rest Assured
given()
.baseUri("https://sample.com")
.header("Authorization", "Bearer abc123")
.header("Content-Type", "application/json")
.when()
.statusCode(200)
.header("Content-Type", equalTo("application/json"))
.header("Authorization", notNullValue())Schema Validation:
Schema Validation is the process of checking Json schema that defines the expected data types, required fields, nested object structures and format of each field in the response.
Syntax in Postman
const schema = {
"type": "object",
"required": ["id", "name", "email"],
"properties": {
"id": {"type": "integer"},
"name": {"type": "string"},
"email": {"type": "string", "format": "email"}
}
};
pm.test("Schema Validation", () => {
pm.response.to.have.jsonSchema(schema);
});
Syntax in Rest Assured
given()
.baseUri("https://sample.com")
.when()
.get("/users/123")
.then()
.statusCode(200)
.body(matchesJsonSchemaInClasspath("schema/user-schema.json"));
Note: Ensure your schema file is in the classpath (i.e., inside src/test/resources/).
Error Message / Success Message Validation
Error Message / Success Message validation is the process of checking that an API returns the HTTP status code along with a clear and meaningful message for both successful and failed operations.
For successful responses, the message should confirm the action clearly. For example,
Login Successful
User Created Successfully
For error responses, the message should provide a clear explanation of the issue. For example,
Email Required
Invalid Password
This validation helps to ensure a better user experience, simplifies error debugging, and ensures reliable communication between the frontend and backend systems.
Syntax in Postman
var jsonData = pm.response.json ();
pm.test("Validate Message", () => {
pm.expect(jsonData.message).to.eql("The Actual Message");
});
Syntax in Rest Assured
given()
.baseUri("https://sample.com")
.when()
.get("/users/123")
.then()
.statusCode(404)
.body("message", equalTo("User not found"));
Date and Time Validation
Date and Time validation is the process of verifying that the date and time sent to or received from API are in the correct format, and logically consistent like having a start date before an end date, within valid ranges like birthday dates are not set in the future. Date and Time validation is important because the error can cause users to book wrong time slots, make transactions at the wrong time, and so on. Some of the types of Date and Time Validations are,
Format Validation: Ensures the data and time follows a specific format.
Logical Validation: Ensures that the date and time values make sense. For example,
Start date should be before the end date
Appointment or booking date should not be in the past
CreatedAt should not be in the future
Time Zone Validation: Ensures that the time includes information about the time zone.
Boundary or Range Validation: Ensures that the data and time values are within the acceptable range. For example,
The birthday date is not in the future
An appointment or booking date cannot be scheduled for a past date
7. State Change Validation
State Change validation is the process of verifying that an API request is made to create, update, or delete, and the actual backend data is modified accordingly. For example,
Post Request (Create a User)
Request: Create a new user with a POST request.
Expected: A new user should be created, and the record should exist in the database.
State Validation: After the POST request, create a GET request with the created user ID from the POST request to confirm the user was actually created and stored.
Put/Patch Request (Update an order)
Request: Update the order request to be shipped
Expected; The order should reflect the new status from the order placed to shipped.
State Validation: Following the PUT request, the GET request should return the status "shipped"
8. Business Rule Validation
Business Rule Validation is the process of verifying the response follows the specific rules and conditions defined by the business. These rules reflect how the system is expected to behave in real-world situations based on the rules set by the business. For example,
Coupons code can be applied after the minimum purchase.
Refund request is allowed within 30 days of purchase.
I hope this blog provided clarity on why validating the logic of an API along with status code validation is important. A combination of status code validation and logic testing is essential for scalable and reliable API. Together they help prevent hidden failures, maintain data integrity and deliver consistent performance.
"Test the code. Test the logic. Deliver better APIs"


