ReqRes Blog

10 Free Public APIs to Practice API Testing (with Projects)

Sep 28, 2026 7 min read
testing qa api postman education
Next step

Set up a classroom with isolated student API keys in under 5 minutes.

The fastest way to learn API testing is to test real APIs. These ten are free, public and live today, and each is good for practising something different. After the list there are ten practice projects, from a first GET request to auth flows, negative tests and running your suite in CI.

Every API below was checked on 28 September 2026.

The APIs at a glance

API Auth to start Do writes persist? Best for practising
ReqRes None Demo: no. Projects: yes Status codes, login, delays, then real CRUD
JSONPlaceholder None No (faked) First GET and POST requests
DummyJSON None No (simulated) JWT login, search, pagination
Restful Booker Token for changes Yes (resets periodically) Full CRUD with auth, finding bugs
Swagger Petstore None Shared demo data Testing against an OpenAPI spec
httpbin None Not applicable Status codes, headers, delays
GoRest Token for writes Yes Bearer tokens, validation errors
PokeAPI None Read-only Nested data, pagination, caching
restful-api.dev None Yes Simple create, read, update, delete
ReqRes projects API key Yes Your own data, per-user auth, request logs

1. ReqRes

https://reqres.in/api/users

A hosted REST API used in tutorials and courses for over a decade. The demo endpoints need no signup and return realistic success and error responses, so you can test more than the happy path.

curl "https://reqres.in/api/users?page=2"            # paginated list
curl https://reqres.in/api/users/23                  # 404 Not Found
curl "https://reqres.in/api/users?delay=3"           # slow response
curl -X POST https://reqres.in/api/login \
  -H 'Content-Type: application/json' \
  -d '{"email": "eve.holt@reqres.in", "password": "cityslicka"}'   # returns a token
curl -X POST https://reqres.in/api/login \
  -H 'Content-Type: application/json' \
  -d '{"email": "peter@klaven"}'                     # 400 Missing password

Demo writes return 201 Created with an id, but they are not stored. When you need data that persists, a free ReqRes project gives you your own collections, app users and a log of every request.

Good for: status codes, login success and failure, pagination, timeouts and loading states.

2. JSONPlaceholder

https://jsonplaceholder.typicode.com

The classic fake REST API: posts, comments, users, todos and photos with relationships between them. It is simple and very fast.

POST, PUT and DELETE return the response you would expect, but nothing is saved. A POST to /posts returns id: 101, and GET /posts/101 then returns 404. That is useful to know before you write a test that creates and then reads back.

Good for: your first requests, and nested routes like /posts/1/comments.

3. DummyJSON

https://dummyjson.com

Products, carts, users, posts, recipes and more, with search, limit and skip pagination, and a real JWT login:

curl -X POST https://dummyjson.com/auth/login \
  -H 'Content-Type: application/json' \
  -d '{"username": "emilys", "password": "emilyspass"}'

Adds, updates and deletes are simulated and not stored.

Good for: token-based auth, passing a Bearer token to protected routes, search and pagination.

4. Restful Booker

https://restful-booker.herokuapp.com

A hotel booking API built specifically for people learning to test. Getting bookings is open; creating a token (POST /auth with the documented demo credentials) lets you update and delete them. The data resets periodically.

It also contains deliberate bugs, which makes it good practice for exploratory testing: can you find where the API does not match its own documentation?

Good for: full CRUD with auth, and practising bug reports.

5. Swagger Petstore

https://petstore3.swagger.io

The reference example for the OpenAPI specification. You get a published spec, interactive docs and endpoints for pets, orders and users.

The data is shared by everyone using it, so do not rely on records you create still being there.

Good for: importing an OpenAPI spec into Postman or another client, and checking responses against a schema.

6. httpbin

https://httpbin.org

Not a data API but an HTTP tool. It echoes what you send and returns whatever you ask for:

curl -i https://httpbin.org/status/418     # any status code
curl https://httpbin.org/headers           # the headers you sent
curl https://httpbin.org/delay/2           # a 2-second delay

Good for: understanding headers, status codes and timeouts in isolation.

7. GoRest

https://gorest.co.in

Users, posts, comments and todos. Reads are open; writes need a free access token sent as a Bearer header, and a write without one returns 401. It also returns validation errors when a field is missing or wrong.

Good for: Bearer auth, 401 and 422 responses, and data that persists.

8. PokeAPI

https://pokeapi.co/api/v2/pokemon/ditto

A large, read-only API with deeply nested data and consistent pagination. No key is needed; please cache responses, as its fair-use policy asks.

Good for: asserting on nested fields, following links between resources, pagination.

9. restful-api.dev

https://api.restful-api.dev/objects

A simple object store. POST an object and you can GET it back by id, then update or delete it. The public API allows 50 requests a day, reset every 24 hours.

Good for: a first create, read, update, delete test that actually round-trips.

10. A ReqRes project (when you need your own backend)

Public APIs share data with everyone, reset, or fake their writes. When you need tests that create data and read it back reliably, create a free project at app.reqres.in:

const res = await fetch('https://reqres.in/api/collections/tickets/records', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': 'YOUR_MANAGE_KEY', // pro_* key for writes, keep it server-side
  },
  body: JSON.stringify({ data: { subject: 'Checkout fails', priority: 'high' } }),
});

You also get app users with login, and a log of every request, which helps when a test fails and you need to see what was actually sent.

10 practice projects

Work through these in order. Each one names an API from the list that suits it.

  1. Your first request. GET https://reqres.in/api/users?page=2 in Postman, curl or your browser. Assert the status is 200 and data has six items.
  2. Status codes. Make requests that return 200, 201, 400 and 404 (ReqRes), then any code you like (httpbin). Write one assertion per code.
  3. Create and read back. POST an object to restful-api.dev, GET it by id and assert every field matches. Then try the same against JSONPlaceholder and explain why it fails.
  4. Login success and failure. Log in to the ReqRes demo with valid credentials (token returned) and without a password (400). Assert on both.
  5. Protected routes. Get a JWT from DummyJSON, call a protected endpoint with it, then with no token and with a broken one.
  6. Full CRUD with auth. In Restful Booker, create a booking, update it with a token, delete it, and confirm it is gone.
  7. Pagination. Walk every page of PokeAPI's /pokemon list and assert you never see a duplicate.
  8. Timeouts. Use ?delay=3 on ReqRes or /delay/3 on httpbin and set your client timeout to 2 seconds. Assert that your test fails cleanly rather than hanging.
  9. Schema checks. Import the Swagger Petstore spec and validate a response against it.
  10. Run it in CI. Put your suite in a GitHub Actions workflow and run it on every push. Point it at a ReqRes project so the data your tests create is still there when they read it back.

Which should you start with?

  • Complete beginner: ReqRes demo endpoints, then JSONPlaceholder.
  • Learning auth: ReqRes login, then DummyJSON, then Restful Booker.
  • Preparing for a QA interview: Restful Booker, for its deliberate bugs.
  • Teaching a class: ReqRes, since it needs no signup, and gives each student their own project when you need persistent data.
  • Building a real test suite: a ReqRes project, so your data is yours and does not reset.

Common questions

What is the best free API to practise API testing?

Start with the ReqRes demo endpoints: no signup, realistic success and error responses, login and delays. For auth flows, add DummyJSON and Restful Booker. For your own persistent data, use a free ReqRes project.

Which free APIs keep the data I create?

Restful Booker (until it resets), GoRest (with a token), restful-api.dev, and ReqRes projects. JSONPlaceholder, DummyJSON and the ReqRes demo endpoints return realistic responses but do not store writes.

Do I need an API key to practise API testing?

No. ReqRes demo endpoints, JSONPlaceholder, DummyJSON, httpbin, PokeAPI and restful-api.dev all work without one. GoRest needs a free token to write, and ReqRes projects use an API key.

Can I use these APIs in Postman?

Yes, all ten work in Postman, and in curl, Playwright, Cypress and REST Assured. See API testing with Postman for a step-by-step guide.

Ready to ship? Continue in the app.