API testing
Qodex helps you create reusable API tests from specs, collections, cataloged endpoints, or plain-English requests. You can import an OpenAPI spec or Postman collection, let Qodex catalog every endpoint, then ask the agent to create scenarios for happy paths, validation errors, auth failures, IDOR checks, and other API behaviors. Saved scenarios replay as normal HTTP requests, without an LLM call on every run.How API testing works
The API testing flow has four parts:- Catalog endpoints from OpenAPI, Swagger, Postman, UI discovery, or manual requests.
- Create scenarios from chat, from a cataloged endpoint with Generate tests, or from a request you built in the API Playground.
- Verify scenarios immediately against your staging environment when they are saved.
- Run scenarios on demand, on a schedule, through webhooks, or in CI.
What you can start with
Import an OpenAPI spec
Upload an OpenAPI 3.x or Swagger 2.0 document and let Qodex catalog every endpoint.
Import a Postman collection
Bring a Postman v2.1 collection in with auth and folder structure preserved.
Scenarios
Reusable API tests with steps, assertions, captures, tags, and lifecycle state.
API Playground
A Postman-style runner on every endpoint in your project, with environment interpolation, a sent-request view, and deep links.
Why replays are cheaper
Most AI testing tools charge per replay because every run is an LLM call. Qodex uses the LLM when a scenario is created or repaired. After that, replay is a plain HTTP request against your environment. That means nightly regression, webhook runs, and CI runs scale with HTTP execution cost, not token cost.What you can do today
- Import OpenAPI 3.x, Swagger 2.0, or Postman v2.1 collections.
- Catalog every endpoint with coverage status (covered, uncovered, failing) and filter by auth, security tests, last run, findings, sensitive data, method, tag, and recent changes.
- Track each endpoint’s lifecycle (active, deprecated, removed) and its change history.
- Manage collections from chat: create one, add an endpoint from a pasted cURL, remove, rename, or merge.
- Author scenarios from chat, then rename, edit, and promote them from the Scenarios page.
- Run scenarios as multiple roles using auth profiles (admin, regular user, viewer).
- Chain steps via captures and reference earlier-step values in later requests.
- Generate request data automatically or supply it manually.
- Write test rules in plain English and let Qodex convert to JavaScript.
- Run scenarios on demand, on a schedule, or via webhook, then inspect and copy each step’s request and response from the run.
Where to go next
Auth profiles
Run the same scenario as admin, user, viewer, or any custom role.
Auto-verification on save
See pass or fail the moment you save.
API governance
Coverage status across every endpoint Qodex has seen.
Chaining and postscripts
Pass tokens and IDs between steps without glue code.