Schemathesis
Catch API bugs before your users do.
Schemathesis tests OpenAPI and GraphQL APIs by generating inputs from your schema, adapting to server responses, and chaining operations into realistic workflows.
Finding bugs that manual testing missed
Try it now
# Test a demo API - finds real bugs in 30 seconds
uvx schemathesis run https://example.schemathesis.io/openapi.json
# Test your own API
uvx schemathesis run https://your-api.com/openapi.json
What problems does it solve?
- 💥 500 errors that crash your API on edge case inputs
- 📋 Schema violations where your API returns different data than documented
- 🚪 Validation bypasses where invalid data gets accepted
- 🔗 Integration failures when responses don't match client expectations
- 🔄 Stateful bugs where operations work individually but fail in realistic workflows
What can it do?
- ⚙️ Config file — auth, phases, and per-operation overrides in
schemathesis.toml. No Python. - 🔐 Authentication — static headers, Basic, per-security-scheme credentials, or custom refresh logic.
- 🔗 Stateful testing — operation links inferred from your schema, no manual wiring.
- 🧠 Adaptive testing — learns constraints, ids, and auth from responses, reusing them mid-run.
- ✅ Custom checks — assert your own business rules next to the built-in ones.
- 📖 Fuzz dictionaries — mix real ids, wordlists, or LLM-generated payloads into generated data.
- 🐌 Rate limiting — cap the request rate, or use
autoto followRetry-Afteron 429. - 📊 Reports — JUnit, VCR, HAR, NDJSON, JSON, and Allure.
- 🎯 Schema coverage — keyword-level coverage report showing which constraints your tests exercised.
- 🔁 Replay & baseline — re-run past failures and fail CI only on new ones.
⚠️ Upgrading from older versions? Check our Migration Guide for key changes.
Installation & Usage
Command Line:
uv pip install schemathesis
schemathesis run https://your-api.com/openapi.json
Config file (schemathesis.toml, no Python needed):
headers = { Authorization = "Bearer ${API_TOKEN}" }
generation.max-examples = 500
rate-limit = "auto"
Python Tests:
import schemathesis
schema = schemathesis.openapi.from_url("https://your-api.com/openapi.json")
@schema.parametrize()
def test_api(case):
# Tests with random data, edge cases, and invalid inputs
case.call_and_validate()
# Stateful testing: Tests workflows like: create user -> get user -> delete user
APIWorkflow = schema.as_state_machine()
# Creates a test class for pytest/unittest
TestAPI = APIWorkflow.TestCase
CI/CD:
- uses: schemathesis/action@v3
with:
schema: "https://your-api.com/openapi.json"
Who uses it
Used by teams at Spotify, WordPress, JetBrains, Red Hat, and dozens of other companies.
"Schemathesis is the best tool for fuzz testing of REST APIs on the market. We at Red Hat use it for examining our applications in functional and integration testing levels." - Dmitry Misharov, RedHat
See it in action
🔬 Live Benchmarks showing continuous testing results from real-world APIs:
- Code & API schema coverage achieved
- Issues found with detailed categorization
- Performance across different fuzzing strategies
Documentation
📚 Documentation with guides, examples, and API reference.
Get Help
Contributing
We welcome contributions! See our contributing guidelines and join discussions in issues or Discord.
Acknowledgements
Schemathesis is built on top of Hypothesis, a powerful property-based testing library for Python.
License
This project is licensed under the terms of the MIT license.