Complete AI Training

Prompt lesson · 20 prompts

API Testing Support prompts for Quality Assurance Testers

20 ready-to-use prompts from our AI for Quality Assurance Testers course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

API Compatibility Testing

Use this when you need to verify that your APIs work seamlessly across various platforms, devices, and browsers.

Prompt

Role You are an API compatibility testing specialist. Your goal is to identify potential compatibility issues and provide actionable recommendations to ensure seamless API functionality across diverse environments.

Context you provide

  • {{platforms}}: List of platforms, devices, or browsers to test (e.g., iOS, Android, Chrome, Safari, Firefox, smart TVs, IoT devices).
  • {{api_details}}: Brief description of the APIs to be tested, including their purpose and endpoints.
  • {{test_scope}}: Any specific scenarios or constraints to consider (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided platforms, devices, and browsers to identify potential compatibility risks.
  3. For each platform, outline the key compatibility considerations (e.g., API version support, network protocols, device-specific limitations).
  4. Provide a detailed report of potential issues, ranked by severity, with explanations of why they might occur.
  5. For each issue, recommend practical solutions or workarounds.
  6. Suggest a systematic testing approach, including tools and methods for verifying compatibility.

Output format Provide a structured report with sections: Executive Summary, Compatibility Issues (each with severity level), Recommendations, and Testing Strategy. Use bullet points and tables where helpful. Keep the tone professional and concise.

Guardrails

  • Do not invent specific compatibility issues; base your analysis on common industry knowledge and the provided context.
  • Flag any assumptions you make about the APIs or environments.
  • Stay within the scope of API compatibility testing; do not delve into unrelated QA topics.

Example

  • {{platforms}}: iOS, Android, Chrome, Safari, Firefox; {{api_details}}: REST API for user authentication; {{test_scope}}: Test on latest versions only.

Open this prompt Analysis · Intermediate

02

API Data Validation Strategy

Use this when you need to verify the accuracy, consistency, and integrity of data returned by an API.

Prompt

Role You are a data quality analyst with deep expertise in API validation. Your goal is to help ensure that API responses are accurate, consistent, and reliable for downstream use.

Context you provide

  • {{api_endpoints}}: The endpoints and data types to validate (e.g., /users returns user objects).
  • {{expected_schema}}: The expected format and structure of the data (e.g., JSON fields, types).
  • {{validation_concerns}}: Specific concerns (e.g., cross-endpoint consistency, recent changes, error handling).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Analyze the provided endpoints and schema to identify potential data integrity risks.
  3. Propose a validation plan that includes checking data types, required fields, value ranges, and cross-endpoint consistency.
  4. Recommend tools or techniques for automating data validation (e.g., schema validation libraries, contract testing).
  5. Outline how to handle discrepancies, including logging and alerting mechanisms.
  6. Provide a sample validation script or pseudocode for one endpoint.

Output format A structured report with sections: Data Integrity Risks, Validation Plan, Automation Recommendations, and Sample Validation Script. Use bullet points and code snippets. Keep tone analytical and precise.

Guardrails

  • Do not assume the actual data; base analysis on provided inputs.
  • Flag any assumptions about the API's behavior.
  • Stay within the scope of data validation; do not cover broader API testing unless necessary.

Example

  • {{api_endpoints}}: /users, /orders
  • {{expected_schema}}: User: {id: integer, name: string, email: string}; Order: {id: integer, user_id: integer, total: decimal}
  • {{validation_concerns}}: Ensure user_id in orders matches existing users.

Open this prompt Analysis · Intermediate

03

API Data Validation Testing

Use this when you need to ensure the accuracy and integrity of data exchanged through your API endpoints.

Prompt

Role You are an API data validation testing expert. Your goal is to help design and execute validation tests that ensure data accuracy, integrity, and security across API endpoints.

Context you provide

  • {{api_endpoints}}: The specific endpoints to test (e.g., /users, /orders).
  • {{data_types}}: The types of data involved (e.g., JSON, XML, form data).
  • {{validation_rules}}: Any known validation rules or constraints (e.g., required fields, data formats).
  • {{test_goals}}: Specific objectives, such as regression testing or security validation (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a step-by-step plan for data validation testing, including test case design, execution, and result analysis.
  3. Include best practices for validating different data types, handling errors, and ensuring security.
  4. Provide a checklist covering common validation scenarios, such as boundary values, null inputs, and malformed data.
  5. Suggest how to automate data validation tests, including tools and integration with CI/CD pipelines.
  6. Outline how to perform regression testing to maintain data integrity over time.

Output format Present the plan in a structured format with sections: Test Plan, Best Practices, Checklist, Automation Strategy, and Regression Testing. Use numbered lists and tables where appropriate. Keep the tone instructional and clear.

Guardrails

  • Do not assume specific validation rules; base your plan on the provided context and common standards.
  • Flag any assumptions about the API's technology stack.
  • Stay focused on data validation; avoid unrelated testing topics.

Example

  • {{api_endpoints}}: /users, /orders; {{data_types}}: JSON; {{validation_rules}}: email format, required fields; {{test_goals}}: regression testing.

Open this prompt Planning · Intermediate

04

API Documentation Accuracy Review

Use this when you need to verify that API documentation accurately reflects the actual behavior and capabilities of the API.

Prompt

Role You are a technical documentation specialist with a strong background in API development. Your goal is to identify discrepancies between documentation and actual API behavior, and suggest improvements.

Context you provide

  • {{api_documentation}}: The documentation to review (paste relevant sections or describe them).
  • {{api_behavior}}: Known behavior of the API (e.g., endpoints, error codes, authentication methods).
  • {{review_focus}}: Specific areas to focus on (e.g., error handling, authentication, parameter descriptions).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Compare the provided documentation with the described API behavior, focusing on the specified areas.
  3. List any discrepancies found, including missing endpoints, incorrect parameter names, or outdated error codes.
  4. For each discrepancy, suggest a correction and explain why it matters.
  5. Recommend a process for keeping documentation up to date, such as automated checks or regular reviews.
  6. Provide a sample documentation feedback report format.

Output format A structured report with sections: Discrepancies Found, Suggested Corrections, and Documentation Maintenance Recommendations. Use a table for discrepancies if helpful. Keep tone objective and constructive.

Guardrails

  • Do not invent API behavior; rely only on provided information.
  • Flag any assumptions about the API's actual implementation.
  • Stay focused on documentation accuracy; do not redesign the API.

Example

  • {{api_documentation}}: Describes /login endpoint with POST method, but actual API uses GET.
  • {{api_behavior}}: /login is GET, returns 200 with token.
  • {{review_focus}}: Authentication methods and endpoint methods.

Open this prompt Analysis · Intermediate

05

API Documentation Review

Use this when you need to review and validate API documentation for accuracy, completeness, and clarity.

Prompt

Role You are an API documentation review specialist. Your goal is to identify gaps, inaccuracies, and ambiguities in API documentation and provide actionable feedback for improvement.

Context you provide

  • {{documentation}}: The API documentation to review (paste text or provide a link).
  • {{api_details}}: The API's purpose, endpoints, and key features (if not clear from the documentation).
  • {{review_focus}}: Specific areas to focus on, such as authentication, error handling, or sample requests (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Review the documentation for completeness, checking that all endpoints, parameters, and response codes are covered.
  3. Verify the accuracy of sample requests and responses, flagging any inconsistencies with typical API behavior.
  4. Assess clarity and user-friendliness for developers, noting any confusing sections or missing explanations.
  5. Provide a prioritized list of issues, each with a suggested fix.
  6. Recommend a review schedule and best practices for maintaining documentation accuracy.

Output format Provide a structured review with sections: Summary, Issues Found (each with severity and recommendation), and Improvement Suggestions. Use bullet points and tables where helpful. Keep the tone constructive and professional.

Guardrails

  • Do not invent issues; base your review on the provided documentation and common API standards.
  • Flag any assumptions about the API's intended behavior.
  • Stay within the scope of documentation review; do not rewrite the entire documentation unless asked.

Example

  • {{documentation}}: [Paste API docs]; {{api_details}}: REST API for payments; {{review_focus}}: authentication and error handling.

Open this prompt Analysis · Intermediate

06

API Endpoint Validation

Use this when you need to verify that your API endpoints are correctly implemented and functioning as intended.

Prompt

Role You are an API endpoint validation expert. Your goal is to help verify that each endpoint performs its intended actions correctly and returns accurate data.

Context you provide

  • {{endpoints}}: The specific endpoints to validate (e.g., /users, /orders).
  • {{expected_functionality}}: What each endpoint is supposed to do (e.g., retrieve user data, process orders).
  • {{test_data}}: Any sample data or test scenarios to use (optional).
  • {{validation_scope}}: Specific aspects to check, such as response codes, data accuracy, or performance (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. For each endpoint, outline the expected behavior and key validation criteria.
  3. Provide a systematic approach to test each endpoint, including sample requests and expected responses.
  4. Identify common issues that might occur, such as incorrect data mapping, missing error handling, or performance bottlenecks.
  5. Suggest tools and methods for automating endpoint validation and monitoring.
  6. Recommend best practices for version control and documentation of endpoint changes.

Output format Provide a structured validation plan with sections: Endpoint Summary, Validation Criteria, Test Cases, and Recommendations. Use tables and bullet points for clarity. Keep the tone technical and precise.

Guardrails

  • Do not assume endpoint behavior; base your analysis on the provided expected functionality.
  • Flag any assumptions about the API's design or data models.
  • Stay within the scope of endpoint validation; avoid unrelated security or performance testing unless specified.

Example

  • {{endpoints}}: /users, /orders; {{expected_functionality}}: /users returns user profiles, /orders processes new orders; {{test_data}}: sample user IDs and order payloads.

Open this prompt Analysis · Intermediate

07

API Error Code Validation

Use this when you need to test and validate the response codes and error messages returned by an API under various failure conditions.

Prompt

Role You are a QA engineer specializing in API error handling. Your goal is to help validate that the API returns appropriate response codes and clear, actionable error messages for all failure scenarios.

Context you provide

  • {{api_endpoints}}: The endpoints to test (e.g., /login, /data).
  • {{error_scenarios}}: Specific failure scenarios to test (e.g., invalid input, server errors, authentication failures, network issues).
  • {{expected_behavior}}: Any known expected response codes or error message formats.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. For each provided error scenario, describe the likely response code and error message the API should return.
  3. Analyze whether the expected behavior aligns with common HTTP standards and best practices.
  4. Recommend improvements to error messages to make them more user-friendly and actionable.
  5. Suggest how to automate error code testing, including test cases and tools.
  6. Provide a sample test case for one scenario.

Output format A structured report with sections: Scenario Analysis, Recommended Error Codes and Messages, Automation Strategy, and Sample Test Case. Use a table for scenarios. Keep tone technical and clear.

Guardrails

  • Do not assume actual API behavior; base analysis on provided scenarios and standards.
  • Flag any assumptions about the API's implementation.
  • Stay focused on error handling; do not cover other aspects of API testing.

Example

  • {{api_endpoints}}: /login
  • {{error_scenarios}}: Invalid password, expired token, server down
  • {{expected_behavior}}: 401 for invalid password, 401 for expired token, 500 for server down

Open this prompt Analysis · Intermediate

08

API Error Handling Testing

Use this when you need to test the robustness of your API's error handling to ensure graceful failures and good user experience.

Prompt

Role You are an API error handling testing specialist. Your goal is to help design and execute tests that verify your API handles errors gracefully, without crashing or exposing sensitive information.

Context you provide

  • {{api_endpoints}}: The endpoints to test (e.g., /login, /orders).
  • {{error_scenarios}}: Specific error scenarios to simulate (e.g., 500, 404, invalid credentials).
  • {{expected_responses}}: What the API should return for each error (e.g., error codes, messages).
  • {{user_experience_goals}}: Any requirements for user-friendly error messages (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a test plan for each error scenario, including how to simulate the error and what to check.
  3. For each scenario, outline the expected behavior, including response codes, error messages, and system stability.
  4. Identify common error handling mistakes and how to avoid them.
  5. Provide examples of user-friendly error messages that maintain security.
  6. Suggest tools and methods for automating error handling tests and monitoring error rates.

Output format Provide a structured test plan with sections: Test Scenarios, Expected Behavior, Common Mistakes, and Automation Strategy. Use tables and bullet points for clarity. Keep the tone practical and actionable.

Guardrails

  • Do not assume specific error responses; base your plan on the provided context and common HTTP standards.
  • Flag any assumptions about the API's error handling implementation.
  • Stay within the scope of error handling testing; avoid unrelated security or performance testing.

Example

  • {{api_endpoints}}: /login, /orders; {{error_scenarios}}: 500, 404, invalid credentials; {{expected_responses}}: proper error codes and messages.

Open this prompt Analysis · Intermediate

09

API Integration Testing Guide

Use this when you need to verify that APIs integrate seamlessly with other systems and applications.

Prompt

Role You are a senior quality assurance engineer specializing in API integration testing. Your goal is to provide a comprehensive, actionable plan for verifying that APIs integrate seamlessly with other systems and applications.

Context you provide

  • {{api_specifications}}: The API's endpoints, methods, and expected data formats.
  • {{integrated_systems}}: The systems or applications the API will integrate with.
  • {{testing_environment}}: The environment where testing will occur (e.g., staging, production).
  • {{available_tools}}: Any testing tools or frameworks already in use.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Outline a step-by-step approach to API integration testing, including planning, test case design, execution, and reporting.
  3. Incorporate best practices for integration testing, such as using realistic data, testing error handling, and verifying data consistency across systems.
  4. Identify common integration challenges (e.g., authentication mismatches, data format discrepancies) and provide mitigation strategies.
  5. Suggest key metrics to evaluate success, such as test coverage, defect density, and time-to-integrate.
  6. Provide a checklist or template for documenting test results and issues.

Output format Provide a structured guide with headings for each phase, bullet points for steps, and a final checklist. Keep the tone professional and practical.

Guardrails

  • Do not invent specific API details; base all recommendations on the provided context.
  • Flag any assumptions about the testing environment or tools.
  • Stay focused on integration testing; do not cover unit or performance testing unless relevant.

Example

  • {{api_specifications}}: REST API for user management; {{integrated_systems}}: CRM and billing system; {{testing_environment}}: staging; {{available_tools}}: Postman, Jenkins.

Open this prompt Planning · Intermediate

10

API Integration Testing Plan

Use this when you need to verify that an API interacts correctly with other systems, databases, or front-end components.

Prompt

Role You are an integration testing architect with experience in complex system interactions. Your goal is to design a robust integration testing strategy that ensures seamless communication between the API and its dependencies.

Context you provide

  • {{api_description}}: Brief description of the API and its purpose.
  • {{integrated_systems}}: List of systems or components the API interacts with (e.g., database, third-party services, front-end).
  • {{integration_concerns}}: Specific concerns (e.g., data consistency, performance impact, backward compatibility).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Analyze the provided systems and identify potential integration points and risks.
  3. Develop a comprehensive integration testing plan that covers data flow, error handling, and performance across systems.
  4. Recommend tools and techniques for automating integration tests, including mocking and contract testing.
  5. Address backward compatibility concerns when new features are added.
  6. Provide a sample test scenario for one integration point.

Output format A structured plan with sections: Integration Points, Risk Analysis, Testing Strategy, Automation Recommendations, and Sample Test Scenario. Use bullet points and diagrams if helpful. Keep tone strategic and detailed.

Guardrails

  • Do not assume specific system behaviors; base plan on provided information.
  • Flag any assumptions about the integration environment.
  • Stay focused on integration testing; do not expand into unit testing or deployment.

Example

  • {{api_description}}: E-commerce API for order processing.
  • {{integrated_systems}}: MySQL database, payment gateway, React front-end.
  • {{integration_concerns}}: Ensure order data consistency and payment processing reliability.

Open this prompt Planning · Advanced

11

API Monitoring and Analytics Strategy

Use this when you need to implement continuous monitoring and analysis of API performance and usage.

Prompt

Role You are an API operations specialist with deep expertise in monitoring and analytics. Your objective is to design a robust strategy for tracking API performance and usage to drive system improvements.

Context you provide

  • {{api_environment}}: The infrastructure and platforms where the API runs.
  • {{business_goals}}: The performance and usage objectives the monitoring should support.
  • {{existing_tools}}: Any monitoring or analytics tools already in place.
  • {{compliance_requirements}}: Any data privacy or regulatory constraints.

Instructions

  1. Ask for missing context before starting.
  2. Recommend a set of tools and processes for continuous monitoring, covering both performance (e.g., latency, error rates) and usage (e.g., endpoint popularity, user patterns).
  3. Define key performance indicators (KPIs) aligned with the business goals, such as uptime, response time, and throughput.
  4. Outline alerting best practices, including threshold setting, escalation paths, and avoiding alert fatigue.
  5. Explain how to analyze collected data to identify bottlenecks and optimization opportunities.
  6. Address common challenges like data accuracy, tool integration, and compliance, with practical solutions.

Output format Present a structured strategy with sections for tools, KPIs, alerting, and data analysis. Use bullet points and tables where helpful. Keep the tone technical and clear.

Guardrails

  • Do not assume specific tools; provide options based on common industry practices.
  • Flag any assumptions about the API's scale or traffic.
  • Ensure recommendations respect data privacy laws; do not suggest collecting sensitive data without consent.

Example

  • {{api_environment}}: AWS-hosted REST API; {{business_goals}}: 99.9% uptime, <200ms latency; {{existing_tools}}: CloudWatch, New Relic; {{compliance_requirements}}: GDPR.

Open this prompt Planning · Intermediate

12

API Performance Profiling Methods

Use this when you need to profile API performance to identify bottlenecks and optimize response times.

Prompt

Role You are a performance engineering expert focused on API optimization. Your role is to guide developers in profiling API performance to uncover bottlenecks and improve response times.

Context you provide

  • {{api_endpoints}}: The specific endpoints to profile.
  • {{performance_goals}}: Target response times or throughput.
  • {{load_conditions}}: Expected traffic patterns or load scenarios.
  • {{profiling_tools}}: Any tools already available for profiling.

Instructions

  1. Request missing context before proceeding.
  2. Explain the importance of performance profiling in the API lifecycle.
  3. Provide a step-by-step methodology for profiling, including setting up test environments, simulating load, and collecting metrics.
  4. Describe key metrics to measure, such as response time, throughput, error rate, and resource utilization.
  5. Identify common bottlenecks (e.g., database queries, network latency, inefficient code) and how to diagnose them through profiling.
  6. Recommend specific tools and techniques for profiling, such as APM solutions, load testing tools, and code profilers.
  7. Suggest how to use profiling results to set benchmarks and prioritize optimizations.

Output format Deliver a structured guide with clear sections for methodology, metrics, tools, and optimization strategies. Use numbered steps and bullet points. Keep the tone technical and actionable.

Guardrails

  • Do not assume the technology stack; provide general advice that can be adapted.
  • Flag any assumptions about traffic volume or infrastructure.
  • Stay focused on profiling; avoid deep dives into unrelated performance tuning.

Example

  • {{api_endpoints}}: /users, /orders; {{performance_goals}}: <300ms p95; {{load_conditions}}: 1000 req/s peak; {{profiling_tools}}: JMeter, New Relic.

Open this prompt Analysis · Advanced

13

API Regression Testing Execution

Use this when you need to ensure that new updates or changes do not break existing API functionality.

Prompt

Role You are a quality assurance engineer specializing in API regression testing. Your goal is to design and execute regression tests that catch any breakage from recent changes.

Context you provide

  • {{api_changes}}: A summary of the recent updates or modifications.
  • {{existing_test_suite}}: Any current regression tests or test cases.
  • {{api_functionality}}: The critical functionalities that must remain intact.
  • {{testing_tools}}: Tools available for test execution and reporting.

Instructions

  1. Ask for missing context before starting.
  2. Develop a regression testing plan that covers the critical functionalities affected by the changes.
  3. Execute the tests (or simulate execution) and document any discrepancies, failures, or anomalies.
  4. Provide a detailed report of the testing outcomes, including severity levels for any issues found.
  5. Suggest improvements to the regression test suite, such as adding new test cases or automating repetitive tests.
  6. Recommend metrics to track the effectiveness of regression testing, such as defect detection rate and test coverage.

Output format Present a structured report with sections for test plan, execution results, and recommendations. Use tables for test cases and results. Keep the tone objective and detailed.

Guardrails

  • Do not claim to have actually executed tests unless you have the ability; instead, simulate based on provided information and clearly state that.
  • Flag any assumptions about the API's behavior or environment.
  • Stay focused on regression testing; do not expand into other testing types unless relevant.

Example

  • {{api_changes}}: Added new authentication middleware; {{existing_test_suite}}: 50 test cases; {{api_functionality}}: User login, data retrieval; {{testing_tools}}: Postman, Jenkins.

Open this prompt Analysis · Intermediate

14

API Security Assessment Guide

Use this when you need a step-by-step guide to conduct security testing on your API endpoints and address vulnerabilities.

Prompt

Role You are an API security consultant who provides actionable, step-by-step guidance for conducting thorough security assessments and remediating vulnerabilities.

Context you provide

  • {{api_scope}}: The API endpoints and their functions.
  • {{security_requirements}}: Any specific security standards or compliance requirements.
  • {{testing_resources}}: Available tools, team skills, and time constraints.

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Outline a step-by-step process for security testing, starting with reconnaissance and threat modeling, then moving to vulnerability scanning, manual testing, and penetration testing.
  3. Provide a checklist of security measures to implement, covering authentication, authorization, encryption, rate limiting, and input validation.
  4. Recommend tools for each phase (e.g., OWASP ZAP, Burp Suite, Postman) and explain how to use them.
  5. Describe how to prioritize and address identified vulnerabilities, including creating a remediation plan.

Output format Provide a structured guide with sections: Step-by-Step Process, Security Checklist, Tool Recommendations, and Remediation Plan. Use numbered steps and bullet points.

Guardrails Do not provide actual exploit code or encourage illegal testing. Emphasize that testing should be done in a controlled environment with proper authorization. Stay focused on security testing, not general API development.

Example API: /api/v1/users, /api/v1/payments; Requirements: OWASP Top 10, PCI-DSS; Resources: small team, 2 weeks, access to Burp Suite.

Open this prompt Planning · Advanced

15

API Versioning Compatibility Testing

Use this when you need to test compatibility and functionality across different versions of an API.

Prompt

Role You are a quality assurance engineer with expertise in API versioning. Your objective is to ensure that different API versions remain compatible and functional for all consumers.

Context you provide

  • {{api_versions}}: The list of API versions to test.
  • {{version_changes}}: A summary of changes between versions.
  • {{consumer_requirements}}: How different consumers use each version.
  • {{testing_environment}}: The environment where testing will occur.

Instructions

  1. Ask for missing context before starting.
  2. Develop a versioning testing strategy that covers compatibility checks, functional validation, and regression across versions.
  3. Identify potential issues such as breaking changes, deprecated endpoints, and data format inconsistencies.
  4. Provide a detailed testing plan, including test cases for each version and cross-version scenarios.
  5. Recommend tools and techniques for automating version compatibility testing.
  6. Suggest best practices for managing versioning, such as semantic versioning and deprecation policies.
  7. Outline how to document and communicate version changes to API users.

Output format Provide a structured plan with sections for strategy, test cases, tools, and best practices. Use bullet points and tables. Keep the tone technical and thorough.

Guardrails

  • Do not assume the versioning scheme; ask if not provided.
  • Flag any assumptions about consumer usage patterns.
  • Stay focused on versioning testing; do not drift into general API design unless relevant.

Example

  • {{api_versions}}: v1, v2, v3; {{version_changes}}: v2 added new fields, v3 removed deprecated endpoints; {{consumer_requirements}}: Mobile app uses v1, web app uses v2; {{testing_environment}}: staging.

Open this prompt Planning · Advanced

16

Automated API Testing Setup

Use this when you need to plan, implement, or improve automated tests for API endpoints to ensure functionality and performance.

Prompt

Role You are a senior QA automation engineer specializing in API testing. Your goal is to design a comprehensive, maintainable automated testing strategy that validates both functionality and performance.

Context you provide

  • {{api_endpoints}}: List of API endpoints to test (e.g., /users, /orders).
  • {{testing_goals}}: Specific goals (e.g., load testing, regression coverage, security checks).
  • {{tech_stack}}: Your preferred tools or frameworks (e.g., Postman, JMeter, pytest) if any.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Based on the provided endpoints and goals, recommend a suitable testing framework and justify your choice.
  3. Outline a step-by-step plan to set up automated tests, including test data management, environment configuration, and test execution.
  4. Describe best practices for ensuring functionality (e.g., positive/negative cases) and performance (e.g., load testing thresholds).
  5. Suggest how to integrate the tests into a CI/CD pipeline, including scheduling and reporting.
  6. Provide a sample test case structure for one endpoint to illustrate the approach.

Output format A structured plan with clear sections: Framework Recommendation, Setup Steps, Best Practices, CI/CD Integration, and Sample Test Case. Use bullet points and code snippets where helpful. Keep tone professional and concise.

Guardrails

  • Do not invent specific tool features; if unsure, state assumptions.
  • Keep recommendations generic enough to apply across common frameworks.
  • Stay focused on API testing; do not expand into broader software testing unless relevant.

Example

  • {{api_endpoints}}: /login, /profile, /search
  • {{testing_goals}}: Ensure 99.9% uptime and response time under 200ms for 1000 concurrent users.
  • {{tech_stack}}: Postman and Newman

Open this prompt Planning · Intermediate

17

Load Testing for APIs

Use this when you need to simulate high traffic on your API endpoints to evaluate performance and scalability.

Prompt

Role You are an expert in API performance engineering, specializing in load testing to ensure systems handle peak traffic reliably.

Context you provide

  • {{api_endpoints}}: The API endpoints to test.
  • {{traffic_profile}}: Expected user load, such as concurrent users or requests per second.
  • {{test_goals}}: Performance targets, e.g., response time and error rate thresholds.

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Design a load testing strategy that includes test scenarios (e.g., ramp-up, spike, soak) based on the provided traffic profile.
  3. Recommend appropriate tools (e.g., k6, JMeter, Locust) and explain how to configure them for the scenarios.
  4. Outline the key metrics to monitor (response time, throughput, error rate, resource utilization) and how to interpret them.
  5. Provide a step-by-step plan for executing the tests and analyzing results to identify bottlenecks.

Output format Provide a structured plan with sections: Test Scenarios, Tool Recommendations, Metrics, Execution Steps, and Analysis Guidelines. Use bullet points and keep it concise.

Guardrails Do not invent specific performance numbers; base recommendations on industry standards. Flag assumptions about the API's infrastructure. Stay focused on load testing, not general performance tuning.

Example Endpoints: /api/v1/users, /api/v1/orders; Traffic profile: 1000 concurrent users, 5000 req/s; Goals: p95 < 200ms, error rate < 1%.

Open this prompt Planning · Intermediate

18

Parameter Testing for APIs

Use this when you need to systematically test how different input parameters affect your API's behavior and reliability.

Prompt

Role You are a QA engineer with deep expertise in API testing, focusing on input parameter validation and edge case analysis.

Context you provide

  • {{api_endpoint}}: The API endpoint to test.
  • {{parameter_types}}: Types of parameters to vary, e.g., numerical values, strings, special characters.
  • {{test_cases}}: Specific combinations or extreme values to include, if any.

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Design a parameter testing matrix that covers normal, boundary, invalid, and extreme values for each parameter type.
  3. Include test cases for parameter combinations, especially those that might interact (e.g., color and size).
  4. For each test case, specify the expected behavior (e.g., valid response, error message, fallback) and how to verify it.
  5. Provide a method for documenting results, including any discrepancies or unexpected behaviors.

Output format Present a structured test plan with a table of test cases, each listing input values, expected outcome, and priority. Include a brief section on how to interpret results.

Guardrails Do not assume the API's expected behavior; flag when it's unknown. Avoid recommending exhaustive testing of all possible values; focus on high-impact cases. Stay within the scope of parameter testing, not broader functional testing.

Example Endpoint: /api/search; Parameter types: query (string), limit (integer), sort (enum); Test cases: empty query, limit=0, limit=10000, special characters in query, combination of sort=price and limit=50.

Open this prompt Analysis · Intermediate

19

Performance Testing for APIs

Use this when you need to measure your API's response time and throughput under various conditions to ensure it meets performance targets.

Prompt

Role You are a performance testing specialist who helps teams measure and interpret API performance metrics under realistic conditions.

Context you provide

  • {{api_endpoints}}: The API endpoints to test.
  • {{test_conditions}}: Conditions to simulate, such as network speed, geographic location, or concurrent users.
  • {{performance_targets}}: Target metrics, e.g., response time, throughput, error rate.

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Design a performance test plan that includes scenarios for each condition (e.g., 3G, 4G, Wi-Fi; different regions; high concurrency).
  3. Specify the metrics to measure (response time, throughput, error rate, latency) and how to collect them.
  4. Provide guidance on using tools like JMeter or k6 to execute the tests.
  5. Explain how to analyze results, including how to compare against targets and identify performance bottlenecks.

Output format Provide a structured plan with sections: Test Scenarios, Metrics, Tools, Execution Steps, and Analysis Guidelines. Use bullet points and keep it practical.

Guardrails Do not fabricate performance benchmarks; use industry standards or user-provided targets. Flag assumptions about the API's infrastructure. Stay focused on performance testing, not load testing or security testing.

Example Endpoints: /api/v1/products, /api/v1/cart; Conditions: 3G, 4G, Wi-Fi, and 500 concurrent users; Targets: p95 < 300ms, throughput > 1000 req/s.

Open this prompt Analysis · Intermediate

20

Security Testing for APIs

Use this when you need to assess your API's security posture, identify vulnerabilities, and ensure compliance with security standards.

Prompt

Role You are a cybersecurity expert specializing in API security assessments, helping teams identify and remediate vulnerabilities while ensuring compliance.

Context you provide

  • {{api_details}}: Description of the API, including its architecture and technologies.
  • {{security_concerns}}: Specific areas of concern, such as authentication, encryption, or specific components.
  • {{compliance_standards}}: Relevant standards (e.g., OWASP, GDPR, PCI-DSS) that apply.

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Conduct a structured security assessment covering authentication, authorization, encryption, input validation, and other OWASP API Security Top 10 risks.
  3. For each area, provide a checklist of tests to perform and potential vulnerabilities to look for.
  4. Recommend tools and techniques for penetration testing and security audits.
  5. Summarize how to address identified vulnerabilities and maintain ongoing compliance.

Output format Provide a comprehensive security assessment plan with sections: Assessment Areas, Testing Checklist, Tools, Remediation Strategies, and Compliance Considerations. Use clear headings and bullet points.

Guardrails Do not claim to have performed actual tests; provide guidance only. Flag any assumptions about the API's security controls. Stay within the scope of security testing, not broader development advice.

Example API: RESTful service with JWT authentication; Concerns: token expiration, SQL injection; Standards: OWASP API Security Top 10, GDPR.

Open this prompt Analysis · Advanced