Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
alirezarezvani avatar

Api Test Suite Builder

  • 608 installs
  • 23.5k repo stars
  • Updated July 17, 2026
  • alirezarezvani/claude-skills

api-test-suite-builder is a test-generation skill that helps developers create comprehensive REST API test suites with authentication, error handling, and edge-case coverage using frameworks like Vitest and Supertest.

About

api-test-suite-builder automatically drafts full API test files for REST endpoints before release. Reference patterns show Vitest plus Supertest for Next.js API routes, including `describe` blocks for routes like `GET /api/users/:id`, shared test servers from `@/test/helpers/server`, and JWT helpers such as `generateJWT` and `generateExpiredJWT`. Setup hooks create test users with `createTestUser` and clean up via `cleanupTestUsers`, covering valid tokens, admin tokens, and role-based access paths. Developers reach for api-test-suite-builder when new endpoints ship without tests or existing suites miss auth failures, expired tokens, and boundary responses. The skill targets concrete test files under paths like `tests/api/users.test.ts` rather than manual QA checklists.

  • Generates complete Vitest + Supertest test files from OpenAPI specs or route descriptions
  • Includes auth testing (valid, expired, malformed, missing tokens)
  • Covers standard HTTP status codes, error payloads, and database setup/teardown patterns
  • Produces ready-to-run test files with beforeAll/afterAll helpers
  • Works for Next.js API routes, Express, and similar backend stacks

Api Test Suite Builder by the numbers

  • 608 all-time installs (skills.sh)
  • Ranked #592 of 2,159 Testing & QA skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 31, 2026 (Skillselion catalog sync)
npx skills add https://github.com/alirezarezvani/claude-skills --skill api-test-suite-builder

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs608
repo stars23.5k
Security audit3 / 3 scanners passed
Last updatedJuly 17, 2026
Repositoryalirezarezvani/claude-skills

How do you generate REST API test suites automatically?

Automatically generate comprehensive test suites for REST and API endpoints with proper auth, error, and edge-case coverage.

Who is it for?

Backend developers adding or hardening REST APIs in Node.js or Next.js who need structured auth and error-path test coverage fast.

Skip if: Teams needing browser E2E UI tests or non-HTTP integration testing without REST route coverage.

When should I use this skill?

New or untested REST endpoints need Vitest/Supertest files covering auth tokens, roles, errors, and edge cases.

What you get

`tests/api/*.test.ts` files with auth fixtures, Supertest requests, and edge-case assertions for each endpoint.

  • `tests/api/*.test.ts` suites
  • Auth and database test fixtures

Files

SKILL.mdMarkdownGitHub ↗

API Test Suite Builder

Tier: POWERFUL Category: Engineering Domain: Testing / API Quality

---

Overview

Scans API route definitions across frameworks (Next.js App Router, Express, FastAPI, Django REST) and auto-generates comprehensive test suites covering auth, input validation, error codes, pagination, file uploads, and rate limiting. Outputs ready-to-run test files for Vitest+Supertest (Node) or Pytest+httpx (Python).

---

Core Capabilities

  • Route detection — scan source files to extract all API endpoints
  • Auth coverage — valid/invalid/expired tokens, missing auth header
  • Input validation — missing fields, wrong types, boundary values, injection attempts
  • Error code matrix — 400/401/403/404/422/500 for each route
  • Pagination — first/last/empty/oversized pages
  • File uploads — valid, oversized, wrong MIME type, empty
  • Rate limiting — burst detection, per-user vs global limits

---

When to Use

  • New API added — generate test scaffold before writing implementation (TDD)
  • Legacy API with no tests — scan and generate baseline coverage
  • API contract review — verify existing tests match current route definitions
  • Pre-release regression check — ensure all routes have at least smoke tests
  • Security audit prep — generate adversarial input tests

---

Route Detection

Next.js App Router

# Find all route handlers
find ./app/api -name "route.ts" -o -name "route.js" | sort

# Extract HTTP methods from each route file
grep -rn "export async function\|export function" app/api/**/route.ts | \
  grep -oE "(GET|POST|PUT|PATCH|DELETE|HEAD|OPTIONS)" | sort -u

# Full route map
find ./app/api -name "route.ts" | while read f; do
  route=$(echo $f | sed 's|./app||' | sed 's|/route.ts||')
  methods=$(grep -oE "export (async )?function (GET|POST|PUT|PATCH|DELETE)" "$f" | \
    grep -oE "(GET|POST|PUT|PATCH|DELETE)")
  echo "$methods $route"
done

Express

# Find all router files
find ./src -name "*.ts" -o -name "*.js" | xargs grep -l "router\.\(get\|post\|put\|delete\|patch\)" 2>/dev/null

# Extract routes with line numbers
grep -rn "router\.\(get\|post\|put\|delete\|patch\)\|app\.\(get\|post\|put\|delete\|patch\)" \
  src/ --include="*.ts" | grep -oE "(get|post|put|delete|patch)\(['\"][^'\"]*['\"]"

# Generate route map
grep -rn "router\.\|app\." src/ --include="*.ts" | \
  grep -oE "\.(get|post|put|delete|patch)\(['\"][^'\"]+['\"]" | \
  sed "s/\.\(.*\)('\(.*\)'/\U\1 \2/"

FastAPI

# Find all route decorators
grep -rn "@app\.\|@router\." . --include="*.py" | \
  grep -E "@(app|router)\.(get|post|put|delete|patch)"

# Extract with path and function name
grep -rn "@\(app\|router\)\.\(get\|post\|put\|delete\|patch\)" . --include="*.py" | \
  grep -oE "@(app|router)\.(get|post|put|delete|patch)\(['\"][^'\"]*['\"]"

Django REST Framework

# urlpatterns extraction
grep -rn "path\|re_path\|url(" . --include="*.py" | grep "urlpatterns" -A 50 | \
  grep -E "path\(['\"]" | grep -oE "['\"][^'\"]+['\"]" | head -40

# ViewSet router registration
grep -rn "router\.register\|DefaultRouter\|SimpleRouter" . --include="*.py"

---

Test Generation Patterns

Auth Test Matrix

For every authenticated endpoint, generate:

Test CaseExpected Status
No Authorization header401
Invalid token format401
Valid token, wrong user role403
Expired JWT token401
Valid token, correct role2xx
Token from deleted user401

Input Validation Matrix

For every POST/PUT/PATCH endpoint with a request body:

Test CaseExpected Status
Empty body {}400 or 422
Missing required fields (one at a time)400 or 422
Wrong type (string where int expected)400 or 422
Boundary: value at min-1400 or 422
Boundary: value at min2xx
Boundary: value at max2xx
Boundary: value at max+1400 or 422
SQL injection in string field400 or 200 (sanitized)
XSS payload in string field400 or 200 (sanitized)
Null values for required fields400 or 422

---

Example Test Files

→ See references/example-test-files.md for details

Generating Tests from Route Scan

When given a codebase, follow this process:

1. Scan routes using the detection commands above 2. Read each route handler to understand:

  • Expected request body schema
  • Auth requirements (middleware, decorators)
  • Return types and status codes
  • Business rules (ownership, role checks)

3. Generate test file per route group using the patterns above 4. Name tests descriptively: "returns 401 when token is expired" not "auth test 3" 5. Use factories/fixtures for test data — never hardcode IDs 6. Assert response shape, not just status code

---

Common Pitfalls

  • Testing only happy paths — 80% of bugs live in error paths; test those first
  • Hardcoded test data IDs — use factories/fixtures; IDs change between environments
  • Shared state between tests — always clean up in afterEach/afterAll
  • Testing implementation, not behavior — test what the API returns, not how it does it
  • Missing boundary tests — off-by-one errors are extremely common in pagination and limits
  • Not testing token expiry — expired tokens behave differently from invalid ones
  • Ignoring Content-Type — test that API rejects wrong content types (xml when json expected)

---

Best Practices

1. One describe block per endpoint — keeps failures isolated and readable 2. Seed minimal data — don't load the entire DB; create only what the test needs 3. Use beforeAll for shared setup, afterAll for cleanup — not beforeEach for expensive ops 4. Assert specific error messages/fields, not just status codes 5. Test that sensitive fields (password, secret) are never in responses 6. For auth tests, always test the "missing header" case separately from "invalid token" 7. Add rate limit tests last — they can interfere with other test suites if run in parallel

Related skills

How it compares

Pick api-test-suite-builder for REST route files; use browser automation skills when validation requires Playwright UI flows instead of HTTP assertions.

FAQ

Which test stack does api-test-suite-builder use?

api-test-suite-builder references Vitest with Supertest for Next.js API routes. Example output lives in `tests/api/users.test.ts` with shared helpers for servers, JWT tokens, and database fixtures.

What API scenarios does api-test-suite-builder cover?

api-test-suite-builder targets authentication with valid and expired JWTs, role-based access such as admin tokens, database setup and cleanup helpers, and edge-case responses for REST endpoints.

Is Api Test Suite Builder safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Testing & QAintegrationstesting

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.