Open source, MIT license / OpenAPI & GraphQL

Catch API bugs before your users do

Schemathesis: open source API testing tool that generates tests from OpenAPI and GraphQL schemas

Start testing in seconds
uvx schemathesis run https://example.schemathesis.io/openapi.json

Runs against a deliberately buggy demo API and finishes in about 20 seconds. For your own API, point it at a running instance and its schema.

Trusted by engineers from
Netflix SAP Red Hat IBM Checkmk JetBrains Qdrant Pixie WordPress

What a run finds

Apache Airflow 3.3.2, one hour of Schemathesis: an empty bulk-action list crashes the endpoint

schemathesis runFull log
____ PATCH /api/v2/connections ____
1. Test Case ID: TMgIWk

- Server error

- Undocumented HTTP status code

    Received: 500
    Documented: 200, 401, 403, 422

[500] Internal Server Error:

    `Internal Server Error`

Reproduce with:

    curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"actions": [{"action_on_non_existence": "fail", "entities": []}]}' http://0.0.0.0:45085/api/v2/connections
Operations that returned a 500 in one hour
  • Open WebUI88 of 535
  • InvenTree98 of 583
  • Prefect38 of 187
  • Apache Airflow16 of 128

Runs from October 2026. See all 12 APIs on Workbench

Reported upstream
  • vLLM: 500 when stop_sequences has more than 4 items
  • Qdrant: validation panic drops the connection
  • API Platform: large page overflows the offset

More in the trophy case

Core features

Property-based testing: Schemathesis checks rules every response must follow and searches for inputs that break them

Property-based testing

Generates test cases from your schema's types and constraints, probing boundary values, type mismatches, and constraint violations you would not think to write by hand

Schema validation

Checks each response against your OpenAPI spec and flags status codes, headers, and bodies that differ from what you documented

Stateful testing

Chains operations into multi-step workflows, inferring the links between them from your schema. Finds bugs that only appear after create, read, update, and delete run in sequence

Adaptive testing

Learns from responses mid-run: validation rules from rejected inputs, resource IDs from successful ones, auth requirements from 401s. Later requests reuse what earlier ones uncovered

One config file

A schemathesis.toml file covers auth, rate limits, test volume, and per-operation overrides. You need Python only for extensions

Custom checks

Assert your own business rules against every generated response, in Python, alongside the built-in checks. Their failures land in the same report, with the same reproduction commands

Fuzz dictionaries

Feed in real IDs, wordlists, or LLM-generated payloads and mix them with generated data at whatever probability you choose. Plain value lists in config, no code required

Reports & replay

Export JUnit, VCR, HAR, NDJSON, JSON, or Allure. Schemathesis saves each failure with a curl command, and schemathesis replay reruns it to confirm your fix

Academic research / ICSE 2022 Companion

Deriving Semantics-Aware Fuzzers from Web API Schemas

by Zac Hatfield-Dodds, Dmitry Dygalo

Counting only HTTP 500 errors, which every fuzzer checks, grouped by stack trace in Sentry, Schemathesis found 136 across 16 open-source APIs. The next best fuzzer found 33.

Read the Paper
HTTP 500 errors found16 open-source APIs
4x
Schemathesis: 136
APIFuzzer: 33
CATS: 16
RESTler: 8
Got-Swag: 7

What engineers and researchers say

"Schemathesis is the best tool for fuzz testing of REST API on the market. We at Red Hat use it for examining our applications in functional and integrations testing levels."
Dmitry Misharov portrait Dmitry MisharovPrincipal Quality Engineer at Red Hat
"The tool is incredible; it handles negative scenario testing much faster than I could in Postman, and without the maintenance burden."
Luděk Nový portrait Luděk NovýQuality Engineer at JetBrains
"Among the other six tools, Schemathesis is clearly the one that puts the most emphasis on usage by practitioners, with its user-friendliness (e.g., GitHub Actions support) and extensive documentation."
Man Zhang & Andrea ArcuriOpen Problems in Fuzzing RESTful APIs, ACM TOSEM 2023

Frequently asked questions

Need help?

Talk to the maintainers and other users on Discord

Join our Discord
How does Schemathesis differ from traditional API testing tools?

Schemathesis generates test cases from your API schema with property-based testing, built on Hypothesis. You write no per-endpoint tests, so you have no per-endpoint test code to maintain, and the generated inputs reach edge cases that hand-written scripts skip.

Do I need to write Python to use it?

No. The CLI takes a schema URL or file and runs. Everything else (authentication, rate limits, test volume, report formats, fuzz dictionaries, per-operation overrides) lives in a schemathesis.toml file. You need Python only for extensions such as custom checks, hooks, or the pytest integration.

What types of API bugs can Schemathesis detect?

Server crashes, responses that violate the schema, undocumented status codes, invalid input the API accepts, valid input it rejects, and bugs that need several calls in sequence. In one-hour runs, 16 of 128 Apache Airflow operations and 38 of 187 Prefect operations returned a 500 (Workbench).

What's the maintenance burden?

Low. Schemathesis derives tests from your schema, so when you add or change an endpoint there, the next run covers it. You have no per-endpoint test code to update.

Is it safe to run against production?

Run it against staging or a local instance. Schemathesis sends hundreds to thousands of requests, many of them invalid, and probes methods your schema does not document: a path documented only with GET also receives DELETE, PUT, and POST. Turn that off with unexpected-methods = [] under [phases.coverage], skip documented operations with --exclude-method DELETE, and cap traffic with --rate-limit. See the triage guide.

Which API specifications does it support?

OpenAPI (Swagger) 2.0, 3.0, 3.1, and 3.2, plus GraphQL schemas. Load schemas from local files, URLs, or programmatically via the Python API.

How can I integrate Schemathesis into my CI/CD pipeline?

Use the GitHub Action (schemathesis/action@v3), the Docker image, or pip/uvx in any CI. Exit codes gate the build. On an existing API, record the current failures once with --baseline schemathesis-baseline.json and commit the file: CI then fails only on new failures.

Can Schemathesis test authenticated APIs?

Yes. Declare credentials in schemathesis.toml, per security scheme, with environment variable substitution for secrets, or pass them as CLI flags (--auth, --header). Supports Bearer tokens, Basic auth, and API keys, plus Python hooks for token refresh and other dynamic flows.

Can I use Schemathesis with my existing test framework?

Yes. Run the CLI next to any test framework or build script, or use the native pytest integration in Python projects.

Ready to test your API?

Point the same command at your own schema.