Cookbooks
Choose a cookbook for the task you want to complete. Each page contains copyable examples, the inputs they need, and the result to expect.
| Cookbook | What you can do |
|---|---|
| Preparing requests | Generate test data, validate inputs, and sign requests with pre scripts |
| Processing responses | Transform values, find records, save tokens, and compose post scripts |
| Testing APIs | Check contracts, sensitive fields, timestamps, individual records, and datasets |
| Chaining requests | Reuse tokens, compare endpoints, verify idempotency and caching, and clean up resources |
Before you start
Section titled “Before you start”Copy request examples into .yml files in an initialized collection. Replace
api.example.com and its fields with your API, and configure any named
environment values. Examples that belong in settings.yml or folder.yml
identify the file explicitly. Review scripts before running them: they can read
selected-environment secrets and send HTTP requests. Keep secrets out of logs.
Use saved request fields and variables for static values, captures for direct extraction, and assertions for simple response checks. Scripting explains authoring and lifecycle; the Script API documents methods and limits.
The request lifecycle is substitution → pre → HTTP → captures → post → assertions → tests. All three script phases use the same inherited order: collection → outermost folder → nearest folder → request. Each block has isolated JavaScript locals; successful RunScope writes are visible to later blocks. See inheritance and upgrade notes.
Preparing requests
Section titled “Preparing requests”- Timestamps
- Expiration windows and timezones
- Identifiers and nonces
- Idempotency keys
- Dynamic JSON bodies
- Dynamic query parameters
- Validate before sending
- Hashing and signing
- Repeatable test users
Processing responses
Section titled “Processing responses”- Process a response conditionally
- Save a token for later manual sends
- Transform a captured value
- Find a record by a field
- Clear an expired session cookie
- Apply a shared default before request processing
Testing APIs
Section titled “Testing APIs”- Check a basic response contract
- Validate a JSON schema
- Keep sensitive fields out of responses
- Check an empty 204 response
- Check every item in an array
- Compare related fields
- Verify sorting and pagination
- Check that the response reflects the request
- Detect duplicate IDs
- Report one test per record
- Validate timestamp order and freshness
- Use expected values from a dataset
- Share checks across a folder
Chaining requests
Section titled “Chaining requests”- Share data across requests
- Saved requests and captured values
- Log in once and reuse the token
- Direct HTTP with fallback
- Create a resource and fetch it
- Compare list and detail responses
- Verify idempotency with a repeated request
- Test conditional GET with an ETag
- Create and clean up a test resource
Inspect results
Section titled “Inspect results”The TUI Results tab shows script status, errors, and redacted logs. Human CLI
output reports status and log count; --json includes the redacted scripts
result group. See Inspect script results
for details. Manual timeline entries retain bounded, redacted script
diagnostics and logs.
Script source, capture results, and RunScope values stay excluded, while
successful request snapshots reflect prepared mutations. Automation does not
create history.