API marathon: 7 days under the hood
Inna Osinna
7 everyday actions — and each day you see what the backend does with them.
API, JWT, 500, Swagger, Postman — you know the words but have not looked under the hood yet. Over 7 days we take 7 everyday actions (logging in, submitting a form, buying a product) and each day see what the backend does with them.
7-day programme
- Day 1Login. What is inside the token?JWT under the hood
- Day 2Status “200”. But what is in the body?lying status codes
- Day 3The form is sent. What did the backend actually accept?validation bugs
- Day 4An ID in the URL. What if you change the number?authorisation bugs (IDOR)
- Day 5Buying a product. What happens at the edge?business logic bugs
- Day 6Swagger promised one thing. Reality is anothercontract bugs
- Day 7Bug found. What next?a bug report people praise
Bonus: Test scenarios for the refresh token.
Result
At least 10 bugs found and new test scenarios. A level above most junior API QA candidates.