Api Test Automation
Automated API endpoint testing with request generation, validation, and comprehensive test coverage
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.27.0
- Author
- Claude Code Plugins
What Api Test Automation is
Api Test Automation is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Api Test Automation adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Api Test Automation
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install api-test-automation@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Api Test Automation in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/testing/api-test-automation/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Automated API endpoint testing with intelligent test generation, validation, and comprehensive coverage for REST and GraphQL APIs.
Features
- REST API testing - Complete CRUD operation coverage
- GraphQL testing - Queries, mutations, subscriptions
- Authentication - Multiple auth methods (Bearer, OAuth, API keys)
- Contract testing - Validate against OpenAPI/Swagger specs
- Automatic test generation - Analyze endpoints and generate tests
- Comprehensive validation - Status codes, headers, body structure
- Performance testing - Response time assertions
- Security testing - Auth bypass, injection attempts
Installation
/plugin install api-test-automation@claude-code-plugins-plusUsage
The API testing agent activates automatically when you mention API testing needs. You can also invoke directly:
Generate tests for REST API
Generate API tests for the user management endpoints in src/routes/users.jsTest GraphQL API
Create GraphQL API tests for the product queries and mutationsValidate against OpenAPI spec
Generate contract tests validating against openapi.yamlTest authentication flows
Create tests for JWT authentication including login, refresh, and protected endpointsWhat Gets Generated
1. Complete Test Suites
// RESTful API test example
describe('User API', () => {
// Authentication tests
describe('POST /api/auth/login', () => {
it('should return JWT token with valid credentials', async () => {
const response = await api.post('/api/auth/login', {
email: '[email protected]',
password: 'password123'
});
expect(response.status).toBe(200);
expect(response.data).toHaveProperty('token');
expect(response.data).toHaveProperty('user');
expect(response.data.user.email).toBe('[email protected]');
});
it('should return 401 with invalid credentials', async () => {
const response = await api.post('/api/auth/login', {
…2. Authentication Helpers
// Authentication utility functions
async function loginUser(email, password) {
const response = await api.post('/api/auth/login', { email, password });
return response.data.token;
}
async function createTestUser(role = 'user') {
const user = {
email: `test-${Date.now()}@example.com`,
password: 'test123',
role
};
await api.post('/api/users', user, { headers: { Authorization: adminToken } });
return loginUser(user.email, user.password);
}3. Test Data Factories
// Factory functions for test data
const userFactory = {
valid: () => ({
email: `user-${Date.now()}@example.com`,
name: 'Test User',
password: 'securePassword123'
}),
invalid: () => ({
email: 'invalid-email',
name: '',
password: '123' // Too short
})
};4. GraphQL Tests
describe('GraphQL API', () => {
describe('Query: user', () => {
it('should fetch user by ID', async () => {
const query = `
query GetUser($id: ID!) {
user(id: $id) {
id
email
name
}
}
`;
const response = await graphql.query(query, { id: userId });
expect(response.errors).toBeUndefined();
expect(response.data.user.id).toBe(userId);
});
…Test Coverage
The agent generates tests for:
Success Scenarios
- Valid requests with proper authentication
- Correct data formats and required fields
- Expected response structures
Error Scenarios
- Missing or invalid authentication
- Validation errors (bad data formats)
- Missing required fields
- Unauthorized access (wrong permissions)
- Resource not found (404)
- Conflict errors (409, duplicates)
Edge Cases
- Empty request bodies
- Null/undefined values
- Boundary values (min/max lengths)
- Special characters in inputs
- Large payloads
Performance
- Response time thresholds
- Payload size validation
- Concurrent request handling
Best Practices Applied
- Descriptive test names - Clear what is tested and expected
- Test isolation - No dependencies between tests
- Proper cleanup - Delete test data after tests
- Authentication management - Reusable auth helpers
- Data factories - Generate test data dynamically
- Comprehensive assertions - Validate all critical fields
- Error testing - Both success and failure paths
- Documentation - Comments for complex scenarios
Requirements
- Claude Code CLI
- HTTP client library (axios, requests, etc.)
- Testing framework (Jest, pytest, RSpec, etc.)
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Api Test Automation?
Api Test Automation is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Automated API endpoint testing with request generation, validation, and comprehensive test coverage
How do I install Api Test Automation in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install api-test-automation@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Api Test Automation in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Api Test Automation in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Api Test Automation safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Content Seo Analyzes page-level traffic performance, classifies rising and declining content, identifies gaps, and recommends data-backed content strategy from Umami analytics. Use when evaluating which content drives results or deciding what to publish next. Trigger with \"analyze content performance\", \"what should I publish next\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Contract Test Validate API contracts with consumer-driven testing and OpenAPI validation Slash Command · jeremylongshore/tons-of-skills-marketplace
- Continue Execute the next step in the current session Slash Command · jeremylongshore/tons-of-skills-marketplace
- Contract Test Validator API contract testing with Pact, OpenAPI validation, and consumer-driven contract verification Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Throttling Manager Manage API throttling with dynamic rate limits and quota management Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Security Scanner Scan APIs for security vulnerabilities and OWASP API Top 10 Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Versioning Manager Manage API versions with migration strategies and backward compatibility Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Sdk Generator Generate client SDKs from OpenAPI specs for multiple languages Plugin · jeremylongshore/tons-of-skills-marketplace