Catch API bugs before your users do
Schemathesis: open source API testing tool that generates tests from OpenAPI and GraphQL schemas
uvx schemathesis run https://example.schemathesis.io/openapi.json
docker run --rm schemathesis/schemathesis run https://example.schemathesis.io/openapi.json
name: API Tests on: [push, pull_request] jobs: test: runs-on: ubuntu-latest steps: - uses: schemathesis/action@v3 with: schema: https://example.schemathesis.io/openapi.json
api-tests: image: schemathesis/schemathesis:stable script: - schemathesis run https://example.schemathesis.io/openapi.json
Runs against a deliberately buggy demo API and finishes in about 20 seconds. For your own API, point it at a running instance and its schema.
What a run finds
Apache Airflow 3.3.2, one hour of Schemathesis: an empty bulk-action list crashes the endpoint
____ PATCH /api/v2/connections ____
1. Test Case ID: TMgIWk
- Server error
- Undocumented HTTP status code
Received: 500
Documented: 200, 401, 403, 422
[500] Internal Server Error:
`Internal Server Error`
Reproduce with:
curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"actions": [{"action_on_non_existence": "fail", "entities": []}]}' http://0.0.0.0:45085/api/v2/connections
- Open WebUI88 of 535
- InvenTree98 of 583
- Prefect38 of 187
- Apache Airflow16 of 128
Runs from October 2026. See all 12 APIs on Workbench
- vLLM: 500 when
stop_sequenceshas more than 4 items - Qdrant: validation panic drops the connection
- API Platform: large
pageoverflows the offset
Core features
Property-based testing: Schemathesis checks rules every response must follow and searches for inputs that break them
Property-based testing
Generates test cases from your schema's types and constraints, probing boundary values, type mismatches, and constraint violations you would not think to write by hand
Schema validation
Checks each response against your OpenAPI spec and flags status codes, headers, and bodies that differ from what you documented
Stateful testing
Chains operations into multi-step workflows, inferring the links between them from your schema. Finds bugs that only appear after create, read, update, and delete run in sequence
Adaptive testing
Learns from responses mid-run: validation rules from rejected inputs, resource IDs from successful ones, auth requirements from 401s. Later requests reuse what earlier ones uncovered
One config file
A schemathesis.toml file covers auth, rate limits, test volume, and per-operation overrides. You need Python only for extensions
Custom checks
Assert your own business rules against every generated response, in Python, alongside the built-in checks. Their failures land in the same report, with the same reproduction commands
Fuzz dictionaries
Feed in real IDs, wordlists, or LLM-generated payloads and mix them with generated data at whatever probability you choose. Plain value lists in config, no code required
Reports & replay
Export JUnit, VCR, HAR, NDJSON, JSON, or Allure. Schemathesis saves each failure with a curl command, and schemathesis replay reruns it to confirm your fix
Deriving Semantics-Aware Fuzzers from Web API Schemas
Counting only HTTP 500 errors, which every fuzzer checks, grouped by stack trace in Sentry, Schemathesis found 136 across 16 open-source APIs. The next best fuzzer found 33.
Read the PaperWhat engineers and researchers say
"Schemathesis is the best tool for fuzz testing of REST API on the market. We at Red Hat use it for examining our applications in functional and integrations testing levels."
Dmitry MisharovPrincipal Quality Engineer at Red Hat
"The tool is incredible; it handles negative scenario testing much faster than I could in Postman, and without the maintenance burden."
Luděk NovýQuality Engineer at JetBrains
"Among the other six tools, Schemathesis is clearly the one that puts the most emphasis on usage by practitioners, with its user-friendliness (e.g., GitHub Actions support) and extensive documentation."
Frequently asked questions
How does Schemathesis differ from traditional API testing tools?
Schemathesis generates test cases from your API schema with property-based testing, built on Hypothesis. You write no per-endpoint tests, so you have no per-endpoint test code to maintain, and the generated inputs reach edge cases that hand-written scripts skip.
Do I need to write Python to use it?
No. The CLI takes a schema URL or file and runs. Everything else (authentication, rate limits, test volume, report formats, fuzz dictionaries, per-operation overrides) lives in a schemathesis.toml file. You need Python only for extensions such as custom checks, hooks, or the pytest integration.
What types of API bugs can Schemathesis detect?
Server crashes, responses that violate the schema, undocumented status codes, invalid input the API accepts, valid input it rejects, and bugs that need several calls in sequence. In one-hour runs, 16 of 128 Apache Airflow operations and 38 of 187 Prefect operations returned a 500 (Workbench).
What's the maintenance burden?
Low. Schemathesis derives tests from your schema, so when you add or change an endpoint there, the next run covers it. You have no per-endpoint test code to update.
Is it safe to run against production?
Run it against staging or a local instance. Schemathesis sends hundreds to thousands of requests, many of them invalid, and probes methods your schema does not document: a path documented only with GET also receives DELETE, PUT, and POST. Turn that off with unexpected-methods = [] under [phases.coverage], skip documented operations with --exclude-method DELETE, and cap traffic with --rate-limit. See the triage guide.
Which API specifications does it support?
OpenAPI (Swagger) 2.0, 3.0, 3.1, and 3.2, plus GraphQL schemas. Load schemas from local files, URLs, or programmatically via the Python API.
How can I integrate Schemathesis into my CI/CD pipeline?
Use the GitHub Action (schemathesis/action@v3), the Docker image, or pip/uvx in any CI. Exit codes gate the build. On an existing API, record the current failures once with --baseline schemathesis-baseline.json and commit the file: CI then fails only on new failures.
Can Schemathesis test authenticated APIs?
Yes. Declare credentials in schemathesis.toml, per security scheme, with environment variable substitution for secrets, or pass them as CLI flags (--auth, --header). Supports Bearer tokens, Basic auth, and API keys, plus Python hooks for token refresh and other dynamic flows.
Can I use Schemathesis with my existing test framework?
Yes. Run the CLI next to any test framework or build script, or use the native pytest integration in Python projects.