SlideShare a Scribd company logo
Postman & API Testing
Amber Race
Senior SDET at Big Fish Games
Up Next
EXPLORING YOUR APIS
WITH POSTMAN



Amber Race (@ambertests)

Senior SDET, Big Fish Games
Get Yer Samples!
All code shown in this talk is available on my Github!
https://github.com/
ambertests/explore-with-
postman
Explorator
y Testing
Testing without a pre-set script
or set of test steps.
Amber Race - @ambertests
https://krebsonsecurity.com/2018/05/tracking-firm-locationsmart-leaked-location-data-for-customers-of-
all-major-u-s-mobile-carriers-in-real-time-via-its-web-site/
TESTING A PUBLICLY FACING API
THROUGH YOUR UI IS NOT ENOUGH!!!!!
Getting the Goods
Import From Chrome
Import From Swagger
Amber Race - @ambertests
Service Test
Strategy
P – Parameters
O – Output
I – Interop
S – Security
E – Error Handling
D – Data
Amber Race - @ambertests
PARAMETERS



• The client
is always
wrong
• Boundaries
• Business
rules
Postman & API Testing by Amber Race
Amber Race - @ambertests
OUTPUT
• Status
codes
• Headers
• Logging
Logging and Status Codes
Amber Race - @ambertests
INTEROP
• Clients
• Dependencies
Postman & API Testing by Amber Race
Amber Race - @ambertests
SECURITY
• Authentication and
spoofing
• Exposed data
• SQL Injection
• “Hidden” apis
Postman & API Testing by Amber Race
Amber Race - @ambertests
EXCEPTIONS
• No
unhandled
exceptions
• Error info,
but not too
much
Postman & API Testing by Amber Race
Amber Race - @ambertests
DATA
• Updates and
replication
• Unicode
• Caching
Postman & API Testing by Amber Race
Amber Race - @ambertests
More
Resources
■ Restful-Booker: https://restful-
booker.herokuapp.com/
■ Danny Dainton’s Postman Tips:
https://github.com/DannyDainton/All-
Things-Postman
■ Postman Blog: http://
blog.getpostman.com/
■ Big List of Naughty Strings: https://
github.com/minimaxir/big-list-of-naughty-
strings
■ Workshop Materials: https://
github.com/ambertests/explore-with-
postman
Amber Race - @ambertests
Thank you for
attending!
■ Email:
amber.race
@outlook.co
m
■ LinkedIn:
https://
www.linkedin.c
om/in/amber-
race-tests
■ Twitter:
@ambertest
s

More Related Content

PDF
An Introduction To Automated API Testing
PDF
PPTX
Api testing
PDF
API Testing: The heart of functional testing" with Bj Rollison
PDF
POST/CON 2019 Workshop: Testing, Automated Testing, and Reporting APIs with P...
PDF
Postman: An Introduction for Developers
PPTX
RESTful API Testing using Postman, Newman, and Jenkins
PDF
Postman: An Introduction for Testers
An Introduction To Automated API Testing
Api testing
API Testing: The heart of functional testing" with Bj Rollison
POST/CON 2019 Workshop: Testing, Automated Testing, and Reporting APIs with P...
Postman: An Introduction for Developers
RESTful API Testing using Postman, Newman, and Jenkins
Postman: An Introduction for Testers

What's hot (20)

ODP
Accelerate Quality with Postman - Basics
PDF
API Testing
PPTX
Api Testing
PPTX
Test Design and Automation for REST API
PDF
Postman Webinar: Postman 101
PDF
How to Automate API Testing
PPTX
Api testing
PDF
API Testing. Streamline your testing process.
PPTX
Belajar Postman test runner
PDF
Using Postman to Automate API On-Boarding
PPTX
API Testing for everyone.pptx
PPSX
API Test Automation
PDF
Postman Webinar: “Continuous Testing with Postman”
PDF
API TESTING
PPT
Postman.ppt
PPTX
Postman Introduction
PPTX
B4USolution_API-Testing
PDF
Driving Pipeline Automation With Newman and the Postman API
PDF
Reasons To Automate API Testing Process
PPTX
Api Testing
Accelerate Quality with Postman - Basics
API Testing
Api Testing
Test Design and Automation for REST API
Postman Webinar: Postman 101
How to Automate API Testing
Api testing
API Testing. Streamline your testing process.
Belajar Postman test runner
Using Postman to Automate API On-Boarding
API Testing for everyone.pptx
API Test Automation
Postman Webinar: “Continuous Testing with Postman”
API TESTING
Postman.ppt
Postman Introduction
B4USolution_API-Testing
Driving Pipeline Automation With Newman and the Postman API
Reasons To Automate API Testing Process
Api Testing
Ad

Similar to Postman & API Testing by Amber Race (20)

PPTX
Exploring your APIs with Postman
PDF
Eradicate Flaky Tests
PPTX
Super powered API testing
PDF
Eradicate Flaky Tests - AppiumConf 2021
PDF
AI assisted testing using postman and openAI.pdf
PDF
Behavior Driven Development, Ruby Style
PPTX
Expanding Your .NET Testing Toolbox - GLUG NET
PDF
Smoke Tests @ DevOps-Hamburg 06.02.2017
PDF
Selenium 2 - PyCon 2011
PPTX
Reducing Bugs With Static Code Analysis php tek 2025
PPTX
Android application analyzer
PPTX
Agile roundabout 2017 01 - keeping your ci-cd system as fast as it needs to be
PPTX
2024-11-28 - Mastering Logic Apps Workflows.pptx
PPTX
QA or the Highway 2022.pptx
PDF
Write Antifragile & Domain-Driven tests with ”Outside-in diamond” ◆ TDD
PDF
RESTFul API Design and Documentation - an Introduction
PPT
Sauce Labs Beta Program Overview
KEY
Socket applications
PDF
Serverless in production, an experience report (linuxing in london)
PPTX
Олексій Павленко. CONTRACT PROTECTION ON THE FRONTEND SIDE: HOW TO ORGANIZE R...
Exploring your APIs with Postman
Eradicate Flaky Tests
Super powered API testing
Eradicate Flaky Tests - AppiumConf 2021
AI assisted testing using postman and openAI.pdf
Behavior Driven Development, Ruby Style
Expanding Your .NET Testing Toolbox - GLUG NET
Smoke Tests @ DevOps-Hamburg 06.02.2017
Selenium 2 - PyCon 2011
Reducing Bugs With Static Code Analysis php tek 2025
Android application analyzer
Agile roundabout 2017 01 - keeping your ci-cd system as fast as it needs to be
2024-11-28 - Mastering Logic Apps Workflows.pptx
QA or the Highway 2022.pptx
Write Antifragile & Domain-Driven tests with ”Outside-in diamond” ◆ TDD
RESTFul API Design and Documentation - an Introduction
Sauce Labs Beta Program Overview
Socket applications
Serverless in production, an experience report (linuxing in london)
Олексій Павленко. CONTRACT PROTECTION ON THE FRONTEND SIDE: HOW TO ORGANIZE R...
Ad

More from Postman (20)

PDF
Advanced AI and Documentation Techniques
PDF
WeTestAthens: Postman's AI & Automation Techniques
PDF
Elevating Developer Experiences with AI-Powered API Testing & Documentation
PDF
Discovering Public APIs and Public API Network with Postman
PDF
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
PDF
API testing Beyond the Basics AI & Automation Techniques
PDF
Not Your Grandma’s Rate Limiting (slides)
PDF
Five Ways to Automate API Testing with Postman
PDF
How to Scale APIs-as-Product for Future Success
PPTX
Revolutionizing API Development: Collaborative Workflows with Postman
PDF
Everything You Always Wanted to Know About AsyncAPI
PDF
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
PDF
Five Things You SHOULD Know About Postman
PDF
Integration-, Snapshot- and Performance-Testing APIs
PDF
How ChatGPT led OpenAPI's Recent Spike in Popularity
PDF
Exploring Postman’s VS Code Extension
PDF
2023 State of the API Report: Key Findings and Trends
PDF
Nordic- APIOps is here What will you build in an API First World
PDF
Testing and Developing gRPC APIs
PDF
Testing and Developing GraphQL APIs
Advanced AI and Documentation Techniques
WeTestAthens: Postman's AI & Automation Techniques
Elevating Developer Experiences with AI-Powered API Testing & Documentation
Discovering Public APIs and Public API Network with Postman
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
API testing Beyond the Basics AI & Automation Techniques
Not Your Grandma’s Rate Limiting (slides)
Five Ways to Automate API Testing with Postman
How to Scale APIs-as-Product for Future Success
Revolutionizing API Development: Collaborative Workflows with Postman
Everything You Always Wanted to Know About AsyncAPI
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
Five Things You SHOULD Know About Postman
Integration-, Snapshot- and Performance-Testing APIs
How ChatGPT led OpenAPI's Recent Spike in Popularity
Exploring Postman’s VS Code Extension
2023 State of the API Report: Key Findings and Trends
Nordic- APIOps is here What will you build in an API First World
Testing and Developing gRPC APIs
Testing and Developing GraphQL APIs

Recently uploaded (20)

PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PPTX
L1 - Introduction to python Backend.pptx
PDF
Download FL Studio Crack Latest version 2025 ?
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PDF
Digital Systems & Binary Numbers (comprehensive )
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
PPTX
Oracle Fusion HCM Cloud Demo for Beginners
PDF
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
PPTX
Computer Software and OS of computer science of grade 11.pptx
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPTX
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
PPTX
Transform Your Business with a Software ERP System
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
L1 - Introduction to python Backend.pptx
Download FL Studio Crack Latest version 2025 ?
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
Digital Systems & Binary Numbers (comprehensive )
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
Oracle Fusion HCM Cloud Demo for Beginners
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
Computer Software and OS of computer science of grade 11.pptx
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
Advanced SystemCare Ultimate Crack + Portable (2025)
Transform Your Business with a Software ERP System
Wondershare Filmora 15 Crack With Activation Key [2025
Odoo Companies in India – Driving Business Transformation.pdf
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...

Postman & API Testing by Amber Race

  • 1. Postman & API Testing Amber Race Senior SDET at Big Fish Games Up Next
  • 2. EXPLORING YOUR APIS WITH POSTMAN
 
 Amber Race (@ambertests)
 Senior SDET, Big Fish Games
  • 3. Get Yer Samples! All code shown in this talk is available on my Github! https://github.com/ ambertests/explore-with- postman
  • 4. Explorator y Testing Testing without a pre-set script or set of test steps.
  • 5. Amber Race - @ambertests https://krebsonsecurity.com/2018/05/tracking-firm-locationsmart-leaked-location-data-for-customers-of- all-major-u-s-mobile-carriers-in-real-time-via-its-web-site/ TESTING A PUBLICLY FACING API THROUGH YOUR UI IS NOT ENOUGH!!!!!
  • 9. Amber Race - @ambertests Service Test Strategy P – Parameters O – Output I – Interop S – Security E – Error Handling D – Data
  • 10. Amber Race - @ambertests PARAMETERS
 
 • The client is always wrong • Boundaries • Business rules
  • 12. Amber Race - @ambertests OUTPUT • Status codes • Headers • Logging
  • 14. Amber Race - @ambertests INTEROP • Clients • Dependencies
  • 16. Amber Race - @ambertests SECURITY • Authentication and spoofing • Exposed data • SQL Injection • “Hidden” apis
  • 18. Amber Race - @ambertests EXCEPTIONS • No unhandled exceptions • Error info, but not too much
  • 20. Amber Race - @ambertests DATA • Updates and replication • Unicode • Caching
  • 22. Amber Race - @ambertests More Resources ■ Restful-Booker: https://restful- booker.herokuapp.com/ ■ Danny Dainton’s Postman Tips: https://github.com/DannyDainton/All- Things-Postman ■ Postman Blog: http:// blog.getpostman.com/ ■ Big List of Naughty Strings: https:// github.com/minimaxir/big-list-of-naughty- strings ■ Workshop Materials: https:// github.com/ambertests/explore-with- postman
  • 23. Amber Race - @ambertests Thank you for attending! ■ Email: amber.race @outlook.co m ■ LinkedIn: https:// www.linkedin.c om/in/amber- race-tests ■ Twitter: @ambertest s