Testing mode Features and test data can change before launch.
BeginnerManual testing

API Testing for Manual QA

Practice HTTP requests, API test design, and reproducible reporting with Harbor Shop. Use live REST, SOAP, and WebSocket exercises. Analyze supplied GraphQL and gRPC examples offline.

HTTP and RESTcurl and PostmanSwagger and OpenAPIAPI test designJSON and XMLSOAP, GraphQL and gRPCWebSocket testing

What you’ll be able to do.

01

Explain frontend, backend, client, server, API, and HTTP in plain words

02

Send authenticated REST and SOAP requests and interpret their responses

03

Design risk-based positive, negative, boundary, authorization, workflow, and retry tests

04

Use curl, Postman, Swagger UI, and the WebSocket console to preserve reproducible evidence

05

Recognize GraphQL, gRPC, and WebSocket contracts and choose appropriate manual checks

12 focused modules.

50 lessons total
01API foundations through one order journeyFollow one Harbor Shop order from the screen to the API, identify system roles, and select API checks from business risk.
  1. ↳Welcome to API Testing for Manual QALesson
  2. ↳Frontend, backend, and the journey of a clickLesson
  3. ↳What an API is and why teams use oneLesson
  4. ↳Clients, servers, and environmentsLesson
  5. ↳Your first API risk mapLesson
02Read data and make your first controlled requestRead URLs and JSON, establish an authenticated baseline, and interpret HTTP responses and methods.
  1. ↳URLs, paths, query parameters, and headersLesson
  2. ↳JSON objects, arrays, values, and nullLesson
  3. ↳Start a private practice sessionLesson
  4. ↳Requests, responses, and status codesLesson
  5. ↳GET, HEAD, and safe readingLesson
  6. ↳POST, PUT, PATCH, DELETE, and stateLesson
03Reading API data and contractsRead JSON, check media types, assess compatibility, and use an API description as test evidence.
  1. ↳Headers, media types, and content negotiationLesson
  2. ↳Contracts, schemas, and compatible changesLesson
  3. ↳OpenAPI and Swagger as a test mapLesson
04REST operations in practiceTest resource representations, collection queries, creation, updates, deletion, and repeated requests.
  1. ↳Resources, representations, and RESTLesson
  2. ↳Filtering, sorting, search, and paginationLesson
  3. ↳Creating orders and Location headersLesson
  4. ↳Updates, deletes, and idempotencyLesson
05API tools and reproducible evidenceUse curl, Postman, and OpenAPI safely, then turn Harbor Shop observations into a reproducible API defect report.
  1. ↳curl: the small portable requestLesson
  2. ↳Postman: workspaces, collections, and variablesLesson
  3. ↳Importing OpenAPI and copying curlLesson
  4. ↳Evidence, logs, and a reproducible API bugLesson
06Authentication and controlled access testingTest the practice bearer identity and review role and ownership models through safe offline scenarios.
  1. ↳Authentication, authorization, and identityLesson
  2. ↳Bearer tokens, API keys, cookies, and Basic authLesson
  3. ↳Roles, ownership, and object-level accessLesson
  4. ↳Safe security tests for manual QALesson
07Designing strong API testsDerive risk-focused tests from rules, error contracts, workflows, and data consistency needs.
  1. ↳Positive paths, rules, and boundariesLesson
  2. ↳Negative testing and error contractsLesson
  3. ↳State transitions and workflow testingLesson
  4. ↳Data integrity, concurrency, and retriesLesson
08Independent REST practiceRun a bounded exploratory session against the private Harbor Shop API and produce reviewable evidence.
  1. ↳Explore products and find contract gapsLesson
  2. ↳Build an order lifecycleLesson
  3. ↳Hunt the deliberate REST defectsLesson
09SOAP and XML contractsRead XML and SOAP messages, compare them with schema and WSDL contracts, and test the Harbor Shop service safely.
  1. ↳XML: elements, attributes, namespaces, and validationLesson
  2. ↳SOAP envelopes, operations, and faultsLesson
  3. ↳WSDL and contract-first servicesLesson
  4. ↳Test the practice order SOAP serviceLesson
10GraphQL testingRead a GraphQL contract, test operations and errors, and run a bounded manual charter.
  1. ↳GraphQL schema, queries, and fieldsLesson
  2. ↳Variables, mutations, and nested dataLesson
  3. ↳GraphQL errors, nullability, and partial dataLesson
  4. ↳A GraphQL manual test charterLesson
11gRPC contracts and controlled testingRead Protocol Buffer contracts, reason about RPC streams, and plan safe tool-based checks in an authorized gRPC lab.
  1. ↳Protocol Buffers: messages, services, and methodsLesson
  2. ↳Unary and streaming RPCsLesson
  3. ↳gRPC status, metadata, and deadlinesLesson
  4. ↳Testing gRPC with grpcurl and GUI toolsLesson
12WebSockets and the final investigationInspect long-lived event communication, then complete a source-backed API investigation across the course outcomes.
  1. ↳HTTP upgrade, connections, frames, and eventsLesson
  2. ↳WebSocket auth, reconnect, ordering, and heartbeatsLesson
  3. ↳Observe live order eventsLesson
  4. ↳Capstone: plan, execute, report, and reflectLesson
  5. ↳Review your API testing evidence and choose your next practiceLesson