Lesson 44 of 158 – Postman Error Testing
44%

Postman Error Testing

When developing a REST API, it is important to test not only successful requests but also requests that should produce errors. Postman Error Testing helps us verify that an API responds correctly when invalid data, incorrect URLs, missing parameters, or unauthorized requests are sent.

Note: Error testing helps ensure that your API handles unexpected situations properly and returns useful HTTP status codes and JSON error responses.

1. What is Error Testing?

Error testing means intentionally sending incorrect or incomplete requests to check how the API handles them.

For example:

GET /students/99999

If the student does not exist, the API should return an appropriate error response.

2. Why Test API Errors?

An API should not only work when valid data is provided. It should also handle invalid requests safely and consistently.

  • Find API bugs
  • Check validation
  • Verify status codes
  • Verify error messages
  • Test authentication
  • Improve application reliability

3. Successful Response vs Error Response

A successful request normally returns a success status code such as 200 OK.

An invalid request may return a status code such as 400 Bad Request.

Success:
200 OK

Error:
400 Bad Request

4. Test an Invalid URL

One simple error test is to request an endpoint that does not exist.

GET http://localhost/api/unknown.php

The server may return a 404 Not Found response if the requested resource does not exist.

5. Test a Missing Resource

Suppose the API returns a single student using an ID.

GET /api/students.php?id=99999

If student 99999 does not exist, the API should return an appropriate response instead of pretending that the student exists.

6. Test Missing Parameters

An API may require certain parameters.

For example:

GET /api/students.php?id=

If the ID is required, the API should validate the request and return an appropriate error response.

7. Test Invalid Parameters

An API should validate parameter values.

For example, if a student ID must be a number:

GET /api/students.php?id=abc

The API should detect that the provided value is invalid.

8. Test Missing Request Body

POST, PUT, and PATCH APIs may require JSON data.

Send a request without the required body:

POST /api/students.php

Body:
empty

The API should validate the request and return an appropriate error.

9. Test Invalid JSON

A REST API that expects JSON should validate whether the received data is valid JSON.

Invalid JSON example:

{
    "name": "Rahul",
    "course": "ADCA"

The closing brace is missing, so the JSON is invalid.

10. Test Missing JSON Fields

Suppose the API requires both name and course.

Send:

{
    "name": "Rahul"
}

If course is required, the API should report the missing field.

11. Test Empty Values

Required fields should not accept empty values when the API requires actual data.

{
    "name": "",
    "course": "ADCA"
}

The API should validate the name field before processing the request.

12. Test Wrong Data Types

API fields should contain the expected type of data.

For example, if age should be a number:

{
    "name": "Rahul",
    "age": "twenty"
}

The API can reject data that does not match the expected format.

13. Test Duplicate Data

An API may prevent duplicate records.

For example, an email address may need to be unique.

{
    "name": "Rahul",
    "email": "rahul@example.com"
}

If the email already exists, the API should return a suitable error response.

14. Test Unauthorized Requests

Protected APIs should reject requests that do not contain valid authentication credentials.

For example:

GET /api/profile.php

If authentication is required and no valid credentials are provided, the API should return an appropriate authentication error.

15. Test Invalid Token

A protected API can also be tested using an invalid token.

Authorization: Bearer invalid_token

The server should verify the token and reject it if it is not valid.

16. Test Missing Authorization Header

Remove the Authorization header from a protected API request.

GET /api/profile.php

Authorization: <removed>

This tests whether the API correctly protects the endpoint.

17. Test Wrong HTTP Method

An endpoint may support only specific HTTP methods.

For example, if an endpoint expects POST but you send GET:

GET /api/students.php

The API should handle the unsupported method appropriately.

18. Test Invalid Content-Type

If an API expects JSON, test what happens when a different content type is sent.

Content-Type: text/plain

The API can reject the request if JSON is required.

19. Test Not Found Response

A 404 Not Found response is commonly used when the requested resource or endpoint cannot be found.

GET /api/not-found.php

Postman can be used to verify the returned status code and response body.

20. Test Server Errors

Server-side problems may result in a 500 Internal Server Error.

When testing an API, check that server errors are handled properly and that the API does not expose unnecessary internal information.

21. Check the Response Body

Error testing should include checking the response body, not just the status code.

Example:

{
    "success": false,
    "message": "Student not found"
}

A useful error message helps the client understand what happened.

22. Check the Status Code

After sending an invalid request in Postman, check the HTTP status code.

Examples:

  • 400 – Bad Request
  • 401 – Unauthorized
  • 403 – Forbidden
  • 404 – Not Found
  • 405 – Method Not Allowed
  • 500 – Internal Server Error

23. Error Testing with Postman

A simple error-testing workflow is:

  1. Open a request in Postman.
  2. Change a valid value to an invalid value.
  3. Send the request.
  4. Check the status code.
  5. Check the response body.
  6. Compare the result with the expected behavior.

24. Test Validation with Postman

Postman can be used to test API validation rules.

For example, if name is required:

{
    "name": "",
    "course": "ADCA"
}

Send the request and verify that the API returns the expected validation error.

25. Error Testing Checklist

Test the following situations:

  • Invalid URL
  • Missing ID
  • Invalid ID
  • Missing request body
  • Invalid JSON
  • Missing fields
  • Empty fields
  • Wrong data type
  • Duplicate data
  • Missing token
  • Invalid token
  • Wrong HTTP method
  • Invalid Content-Type

26. Common Error Testing Mistakes

  • Testing only successful requests
  • Ignoring HTTP status codes
  • Ignoring response messages
  • Not testing missing fields
  • Not testing invalid authentication
  • Not testing invalid JSON
  • Not checking validation rules

A complete API test should include both positive and negative test cases.

27. Positive and Negative Testing

Positive Test:

POST /api/students.php

{
    "name": "Rahul",
    "course": "ADCA"
}

The request contains valid data.

Negative Test:

POST /api/students.php

{
    "name": "",
    "course": ""
}

The request contains invalid or incomplete data and should be validated.

28. Error Testing for a React Native App

Before connecting a REST API to a React Native application, test its error responses in Postman.

React Native
     ↓
API Request
     ↓
REST API
     ↓
Error Response
     ↓
React Native Error Handling

This helps the mobile application handle API failures correctly.

29. Complete Error Testing Workflow

Create Request
      ↓
Send Valid Request
      ↓
Check Success Response
      ↓
Change Data to Invalid
      ↓
Send Request Again
      ↓
Check Status Code
      ↓
Check Error JSON
      ↓
Verify Expected Result

30. Postman Error Testing Summary

Postman error testing helps developers verify how a REST API behaves when invalid or unexpected requests are received. Test invalid URLs, parameters, request bodies, JSON, authentication, HTTP methods, and validation rules. Always check both the HTTP status code and the response body.

Invalid Request
      ↓
REST API
      ↓
Validation
      ↓
HTTP Status Code
      ↓
JSON Error Response
      ↓
Postman Verification

📌 Key Points

  • Error testing checks how an API handles invalid requests.
  • Test both successful and unsuccessful API requests.
  • Test invalid URLs and missing resources.
  • Test missing and invalid parameters.
  • Test missing and invalid request bodies.
  • Test invalid JSON data.
  • Test missing required fields and empty values.
  • Test authentication and invalid tokens.
  • Test incorrect HTTP methods.
  • Check both HTTP status codes and JSON error responses.
  • Postman can be used to perform positive and negative API testing.
  • Error testing is important before integrating an API with React Native.

🧠 Quick Quiz

Question: What should you check when testing an API error in Postman?