REST API Tester
Testing tool for REST API.
Request
Response
| Status | {{ status }} |
|---|---|
| Headers | {{ hkey }}: {{ hval }} |
* Cannot retrieve data unless the API add 'Access-Control-Allow-Origin' : * header. Please consider to use the below extension if you use Google Chrome.
https://chromewebstore.google.com/detail/cors-unblock/lfhmikememgdcahcdlaciloancbhjino
What Is a REST API Tester?
A REST API tester lets you pick an HTTP method (GET, POST, PUT, DELETE and so on), send a request to an endpoint from your browser, and inspect the status code, response headers and response body on the spot. You can verify how an API behaves without installing a desktop application like Postman or reaching for cURL on the command line.
It suits checking behaviour while you develop an API, or poking at a public API to learn the shape of its responses before reading the documentation. Bear in mind, though, that because requests go straight from the browser, you cannot receive a response if the target API does not permit CORS (the Access-Control-Allow-Origin header).
How to Use the REST API Tester
- Select the HTTP method Choose the method matching the operation you want — GET, POST, PUT, PATCH, DELETE and so on.
- Enter the endpoint URL Enter the URL of the API you are requesting. Give a complete URL beginning with https.
- Set headers and a body if needed Enter headers such as an authentication token or Content-Type, and the JSON body you are sending with POST or PUT.
- Send and inspect the response The status code, response headers and body are displayed right there.
Tips for getting more out of it
- Due to CORS restrictions, APIs without an
Access-Control-Allow-Originheader cannot be requested directly. Use public APIs or CORS-enabled APIs. - Set
Content-Type: application/jsonin the request headers to send a JSON body. - HTTP status codes at a glance: 2xx = success, 4xx = client error (401 = unauthorized, 404 = not found), 5xx = server error.
- For APIs requiring Bearer Token authentication, add
Authorization: Bearer {token}to the headers.
When a REST API Tester Comes in Handy
Checking an API under development
See immediately whether the backend API you are building returns the response you expect, while you are still writing it.
Investigating the response shape of a public API
Before reading an external service's API documentation, send a real request and look at the JSON structure that comes back.
Verifying authentication headers
Test whether a request carrying a bearer token or an API key authenticates correctly.
Seeing what an error response contains
Send a deliberately invalid parameter and check what error message and status code the API returns.
Glossary
- REST
- Short for Representational State Transfer. A design style for web APIs in which resources are manipulated through HTTP methods and URLs.
- CORS
- Short for Cross-Origin Resource Sharing. The mechanism by which browsers restrict requests to a different origin (domain): unless the API server returns the permitting header, the response cannot be read.
- Endpoint
- The URL at which an API accepts requests. Something like «/api/users», indicating the resource being operated on.
- HTTP Method
- The identifier that states the kind of request. GET (retrieve), POST (create), PUT (update) and DELETE (remove) are among them.
- Bearer Token
- A token format widely used for API authentication. It is attached to the request header in the form «Authorization: Bearer {token}».
FAQ
Access-Control-Allow-Origin header, the browser will block it. Use a CORS-enabled or public API, or install a browser extension such as CORS Unblock.Content-Type: application/json to the request headers and enter a valid JSON string in the body field before submitting.Authorization: Bearer {your_token} to the request headers, replacing {your_token} with your actual token value.
Side Note — The Birth of REST: How Roy Fielding's Dissertation Changed Web Development
REST was proposed in 2000 by Roy Fielding in his doctoral dissertation "Architectural Styles and the Design of Network-based Software Architectures." Fielding was one of the principal co-authors of the HTTP/1.1 specification, and the REST concept emerged as he organized the design principles behind HTTP.
Twitter migrated from SOAP to REST API around 2010 and opened it to developers, triggering explosive adoption. Today, services like Stripe, GitHub, Slack, and OpenAI (ChatGPT) all offer REST APIs, forming what is often called the "API economy."
The original REST architecture includes a constraint called "Hypermedia as the Engine of Application State (HATEOAS)," yet very few real-world services implement it strictly. Debates about "what truly counts as REST" regularly heat up in web development communities, and the definition of "RESTful" remains contested.