API and Contract Testing Questions

Testing services and their interfaces directly. Covers REST and other API testing, request/response and schema validation, status and error handling, and contract testing between producers and consumers. Includes service-level and integration testing without a UI.

HardTechnical
65 practiced

A service you depend on keeps shipping changes that break your integration with it, and the breakage is only caught after it reaches production. Propose both a technical and a process fix: what would you put in place so a breaking change is caught before it ships, who should own the tests that catch it, and how would you pilot the change and show it actually reduced regressions?

MediumTechnical
63 practiced

Implement a reusable function that performs an HTTP GET with retry and exponential backoff for transient failures (server errors and network errors), with configurable attempt count and base delay. What do you need to be careful about if this function is used concurrently by many tests at once?

MediumTechnical
67 practiced

Design automated tests that validate JWT-based authentication for a set of realistic failure cases: a missing token, a malformed token, an expired token, a token with the wrong issuer or audience, and a token that was signed with a key that has since been revoked. For each case, what status code do you expect, and how would you generate the test tokens deterministically?

MediumTechnical
70 practiced

Write a script that compares two API contract manifests (each describing endpoints, HTTP methods, required parameters, and response fields) and reports the differences between them. What normalization would you need to do first, and how does the approach scale as the manifests grow large?

MediumTechnical
74 practiced

You consume webhooks from an external vendor that signs each payload with HMAC SHA-256 and includes a timestamp to guard against replay. Write a Postman pre-request script (or describe the equivalent code) that generates the correct signature header for a test webhook request, and describe the automated tests you'd write on the receiver side to verify signature validation, timestamp freshness, and replay protection.

Unlock Full Question Bank

Get access to all 18 API and Contract Testing interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.