Highlights from 4.26.1 to 4.30.0: Schemathesis signs itself in, mixes valid PNG, PDF and ZIP files into binary uploads, reads streaming responses without hanging, and lets CI fail only on new failures.
Automatic sign-up and login (4.30.0)
Without credentials, Schemathesis gets a 401 from every protected operation and never reaches the code behind it. If your schema declares a sign-up operation (a POST path ending in a word such as register or signup) and a login that returns a bearer token or API key, Schemathesis creates an account, logs in and sends the token to every operation that requires it:
✅ Auth: signed up via POST /auth/register and logged in
If a sign-up field offers an administrator value such as ADMIN, Schemathesis picks it, so it tests admin-only operations as well. Each run creates a new account (see Check your CI below). Any credentials you pass turn sign-up off: --auth, an Authorization or API key header, or the [auth] section of schemathesis.toml. If sign-up or login fails, the output says why and points to dynamic auth. Details in the auth guide.
Accept known failures: a list or a rule (4.27.0)
Add Schemathesis to the CI of an existing API and the first run can report dozens of failures that nobody can fix this week. Until they are fixed, the build stays red and new regressions hide among them. A baseline file accepts today's failures, so CI flags only new ones. Record it once:
uvx schemathesis run http://localhost:8000/openapi.json --baseline schemathesis-baseline.json
This run writes the file and exits 1. Commit the file and put its path in your config, so later runs need no flag. They still report the recorded failures but exit 0; anything new exits 1.
# schemathesis.toml baseline = "schemathesis-baseline.json"
--baseline-update adds failures you accept, --baseline-prune drops the ones this run no longer sees. See the baseline guide.
If the failures you accept follow a rule rather than a fixed list, for example a flaky upstream answering 503, write a filter_failure hook instead (#1792). It returns False for failures to drop, based on the failure, case or response. Put hooks.py in the directory you run Schemathesis from:
# hooks.py import schemathesis @schemathesis.hook def filter_failure(ctx, failure, case, response): # A flaky upstream is not this API's bug return response.status_code != 503
# schemathesis.toml hooks = "hooks"
The run summary counts what the hook dropped. Reference: hooks.
Valid PNG, PDF and ZIP uploads (4.29.0)
Schemathesis has always uploaded files for format: binary fields, but filled them with random bytes. Upload handlers reject those at the first file-type check, so the code that processes the file never runs. Schemathesis mixes small valid PNG, JPEG, GIF, WebP, PDF and ZIP files into the random bytes, and names each multipart file after its field with the matching extension, e.g. avatar.png.
Streaming endpoints stop hanging the run (4.30.0)
Before 4.30.0, an endless text/event-stream response hung the run or ended in a timeout error. Schemathesis stops reading once the server closes the stream, 20 events arrive or the request timeout passes.
Schemathesis checks each event against itemSchema. On OpenAPI 3.0 and 3.1 without itemSchema, schema takes that role. Otherwise schema describes the whole stream, and Schemathesis checks it only when the server closed the stream; a stream cut at the limit gets per-event checks only. Raise the event limit in schemathesis.toml:
max-stream-events = 100
See Testing Server-Sent Events.
Also
- Schemathesis 4.28.0 and later work with pytest 8.4, so you can upgrade Schemathesis without moving to pytest 9.
- The opt-in
low_valid_ratewarning (--warnings low_valid_rate) names operations that accept few of the requests sent to them. The run passes, yet the logic behind them stays untested (4.28.0).
In Python, validate() and is_valid() on a request parameter or body check a parsed value against its schema (4.28.0):
limit = schema["/users"]["GET"].get_parameter("limit", "query")
limit.is_valid(50) # bool
limit.validate(-1) # raises jsonschema_rs.ValidationError when invalid
Check your CI
Since 4.29.0, schemathesis run and schemathesis fuzz exit 2 when they tested nothing or hit a schema, configuration or internal error, and 130 on Ctrl+C. 1 still means a check failed. If your pipeline treats any non-zero exit as a found bug, see exit codes.
Since 4.30.0, a run without credentials against a schema that declares sign-up and login creates an account on the target API. If a sign-up field offers an admin role, the account gets it. If your CI tests a shared environment that way, pass credentials or point it at a disposable one.
Upgrade with pip install -U schemathesis, or uv tool upgrade schemathesis if you installed it with uv. The changelog lists the rest, including many false-positive fixes. If a check flags something your API does right, open an issue with the check name and the response.