When developing a REST API, it is important to test not only successful requests but also requests that should produce errors. Postman Error Testing helps us verify that an API responds correctly when invalid data, incorrect URLs, missing parameters, or unauthorized requests are sent.
Error testing means intentionally sending incorrect or incomplete requests to check how the API handles them.
For example:
GET /students/99999
If the student does not exist, the API should return an appropriate error response.
An API should not only work when valid data is provided. It should also handle invalid requests safely and consistently.
A successful request normally returns a success status code such as 200 OK.
An invalid request may return a status code such as 400 Bad Request.
Success:
200 OK
Error:
400 Bad Request
One simple error test is to request an endpoint that does not exist.
GET http://localhost/api/unknown.php
The server may return a 404 Not Found response if the requested resource does not exist.
Suppose the API returns a single student using an ID.
GET /api/students.php?id=99999
If student 99999 does not exist, the API should return an appropriate response instead of pretending that the student exists.
An API may require certain parameters.
For example:
GET /api/students.php?id=
If the ID is required, the API should validate the request and return an appropriate error response.
An API should validate parameter values.
For example, if a student ID must be a number:
GET /api/students.php?id=abc
The API should detect that the provided value is invalid.
POST, PUT, and PATCH APIs may require JSON data.
Send a request without the required body:
POST /api/students.php
Body:
empty
The API should validate the request and return an appropriate error.
A REST API that expects JSON should validate whether the received data is valid JSON.
Invalid JSON example:
{
"name": "Rahul",
"course": "ADCA"
The closing brace is missing, so the JSON is invalid.
Suppose the API requires both name and course.
Send:
{
"name": "Rahul"
}
If course is required, the API should report the missing field.
Required fields should not accept empty values when the API requires actual data.
{
"name": "",
"course": "ADCA"
}
The API should validate the name field before processing the request.
API fields should contain the expected type of data.
For example, if age should be a number:
{
"name": "Rahul",
"age": "twenty"
}
The API can reject data that does not match the expected format.
An API may prevent duplicate records.
For example, an email address may need to be unique.
{
"name": "Rahul",
"email": "rahul@example.com"
}
If the email already exists, the API should return a suitable error response.
Protected APIs should reject requests that do not contain valid authentication credentials.
For example:
GET /api/profile.php
If authentication is required and no valid credentials are provided, the API should return an appropriate authentication error.
A protected API can also be tested using an invalid token.
Authorization: Bearer invalid_token
The server should verify the token and reject it if it is not valid.
Remove the Authorization header from a protected API request.
GET /api/profile.phpAuthorization: <removed>
This tests whether the API correctly protects the endpoint.
An endpoint may support only specific HTTP methods.
For example, if an endpoint expects POST but you send GET:
GET /api/students.php
The API should handle the unsupported method appropriately.
If an API expects JSON, test what happens when a different content type is sent.
Content-Type: text/plain
The API can reject the request if JSON is required.
A 404 Not Found response is commonly used when the requested resource or endpoint cannot be found.
GET /api/not-found.php
Postman can be used to verify the returned status code and response body.
Server-side problems may result in a 500 Internal Server Error.
When testing an API, check that server errors are handled properly and that the API does not expose unnecessary internal information.
Error testing should include checking the response body, not just the status code.
Example:
{
"success": false,
"message": "Student not found"
}
A useful error message helps the client understand what happened.
After sending an invalid request in Postman, check the HTTP status code.
Examples:
A simple error-testing workflow is:
Postman can be used to test API validation rules.
For example, if name is required:
{
"name": "",
"course": "ADCA"
}
Send the request and verify that the API returns the expected validation error.
Test the following situations:
A complete API test should include both positive and negative test cases.
Positive Test:
POST /api/students.php
{
"name": "Rahul",
"course": "ADCA"
}
The request contains valid data.
Negative Test:
POST /api/students.php
{
"name": "",
"course": ""
}
The request contains invalid or incomplete data and should be validated.
Before connecting a REST API to a React Native application, test its error responses in Postman.
React Native
↓
API Request
↓
REST API
↓
Error Response
↓
React Native Error Handling
This helps the mobile application handle API failures correctly.
Create Request
↓
Send Valid Request
↓
Check Success Response
↓
Change Data to Invalid
↓
Send Request Again
↓
Check Status Code
↓
Check Error JSON
↓
Verify Expected Result
Postman error testing helps developers verify how a REST API behaves when invalid or unexpected requests are received. Test invalid URLs, parameters, request bodies, JSON, authentication, HTTP methods, and validation rules. Always check both the HTTP status code and the response body.
Invalid Request
↓
REST API
↓
Validation
↓
HTTP Status Code
↓
JSON Error Response
↓
Postman Verification
Question: What should you check when testing an API error in Postman?