Changelog
What's new in API Test Generator.
6 October 2026
- Fixed: bearer auth in generated pytest. Authenticated requests sent the token without the
Bearer prefix, so a real bearer-protected API answered 401 to every authenticated test. Regenerate to get the fix.
- Fixed: Jest tests read the token. They used a fixed
<valid_token> placeholder; they now read API_TOKEN like the other runners.
- Fewer false failures. "Missing required parameter" tests are now generated only for query parameters (a path parameter can't be left out of a URL, so those tests re-sent the normal request). Tests on URLs with a sample id (
/pets/1) skip with a hint when that record doesn't exist instead of failing.
- With no auth chosen, tests for secured endpoints read
API_TOKEN if it's set.
- Every release now runs a generated suite with real pytest against a live demo API and requires exactly its two deliberate bugs to fail.
5 October 2026
- Try the runner on a demo API. One click runs the checks against a small public API at
apitestgen.dev/demo-api that has two deliberate bugs, so you see real PASS and FAIL rows without an API of your own.
- The “Run against your API” panel is now three clear steps (host, auth, run) with its own auth settings, inline guidance and a downloadable Markdown report.
- Account page: profile, plan and billing portal, searchable history, data export and account deletion.
- AI edge cases have been removed. Test generation never used AI and is unchanged.
4 October 2026
- Multi-step flows. When a spec has a create endpoint and item endpoints (
POST /pets + GET/PUT/DELETE /pets/{petId}), pytest, Jest and Postman output now includes a flow test: create, read the new id from the response, read, update, delete, then check it is gone. The id field comes from OpenAPI links or the response schema, and a failed step still deletes what it created.
- Run against your API (Pro). Verify your staging host with a file at
/.well-known/apitestgen.txt, then run the checks from our server and get pass/fail per check, flows included. Reads only unless you allow writes; writes to existing records are never sent; your token is used once and not stored.
- AI edge cases (Pro, your own Anthropic key). Claude reads the descriptions and constraints in your spec and proposes extra cases (boundaries, documented rules and error codes) as data; our templates write the pytest code. Your key is used for that request only and never stored; you choose Haiku, Sonnet or Opus.
- Spec drift on pull requests (Pro). The project zip includes
.github/workflows/apitestgen-drift.yml: on every PR that changes the spec it comments what changed, flags breaking changes and fails when the committed tests are out of date (the regenerated file is attached to the run). Uses your CI key from the account menu.
- Rate limits now count per visitor; before, all visitors shared one limit behind the hosting proxy.
- Invalid-type checks now only send a string to fields that aren't strings, and query parameters use their
enum/example values, so a correct API no longer fails them.
- Request bodies use the spec's
example, default, enum and formats instead of placeholder strings.
- Fixed: generated pytest code wrote JSON
true/false/null into Python, so tests with boolean or nullable fields failed with NameError. Every generated test is now executed in our test suite, not only compiled.
10 July 2026
- History now has search and a framework filter — find a past generation by title or runner.
- Downloaded projects include a short credit line in the README linking back to apitestgen.
July 2026
- Two new Pro runners: Playwright (TypeScript) and Schemathesis (property-based fuzzing straight from the spec).
- One-click project scaffold — download a ready-to-run
.zip with tests, dependencies, and config for your chosen runner.
- Every scaffold ships a GitHub Actions workflow that runs the tests on push/PR, with a matrix job per environment and secrets instead of hard-coded URLs.
- Generation history — your recent generations are saved to your account and reloadable in one click.
- Import a spec straight from a URL, with an SSRF guard that blocks private/internal addresses.
5 July 2026
- Public launch. Paste an OpenAPI/Swagger spec, get runnable tests for pytest, Jest, or Postman.
- Generated suites cover the happy path, missing auth, missing required params, invalid types, and response-schema validation.
- Bearer, API-key, and basic auth injection via environment variables.
- Paid plans via Lemon Squeezy as Merchant of Record.