The fastest way to learn API testing is to test real APIs. These ten are free, public and live today, and each is good for practising something different. After the list there are ten practice projects, from a first GET request to auth flows, negative tests and running your suite in CI.
Every API below was checked on 28 September 2026.
The APIs at a glance
| API | Auth to start | Do writes persist? | Best for practising |
|---|---|---|---|
| ReqRes | None | Demo: no. Projects: yes | Status codes, login, delays, then real CRUD |
| JSONPlaceholder | None | No (faked) | First GET and POST requests |
| DummyJSON | None | No (simulated) | JWT login, search, pagination |
| Restful Booker | Token for changes | Yes (resets periodically) | Full CRUD with auth, finding bugs |
| Swagger Petstore | None | Shared demo data | Testing against an OpenAPI spec |
| httpbin | None | Not applicable | Status codes, headers, delays |
| GoRest | Token for writes | Yes | Bearer tokens, validation errors |
| PokeAPI | None | Read-only | Nested data, pagination, caching |
| restful-api.dev | None | Yes | Simple create, read, update, delete |
| ReqRes projects | API key | Yes | Your own data, per-user auth, request logs |
1. ReqRes
https://reqres.in/api/users
A hosted REST API used in tutorials and courses for over a decade. The demo endpoints need no signup and return realistic success and error responses, so you can test more than the happy path.
curl "https://reqres.in/api/users?page=2" # paginated list
curl https://reqres.in/api/users/23 # 404 Not Found
curl "https://reqres.in/api/users?delay=3" # slow response
curl -X POST https://reqres.in/api/login \
-H 'Content-Type: application/json' \
-d '{"email": "eve.holt@reqres.in", "password": "cityslicka"}' # returns a token
curl -X POST https://reqres.in/api/login \
-H 'Content-Type: application/json' \
-d '{"email": "peter@klaven"}' # 400 Missing password
Demo writes return 201 Created with an id, but they are not stored. When you need data that persists, a free ReqRes project gives you your own collections, app users and a log of every request.
Good for: status codes, login success and failure, pagination, timeouts and loading states.
2. JSONPlaceholder
https://jsonplaceholder.typicode.com
The classic fake REST API: posts, comments, users, todos and photos with relationships between them. It is simple and very fast.
POST, PUT and DELETE return the response you would expect, but nothing is saved. A POST to /posts returns id: 101, and GET /posts/101 then returns 404. That is useful to know before you write a test that creates and then reads back.
Good for: your first requests, and nested routes like /posts/1/comments.
3. DummyJSON
https://dummyjson.com
Products, carts, users, posts, recipes and more, with search, limit and skip pagination, and a real JWT login:
curl -X POST https://dummyjson.com/auth/login \
-H 'Content-Type: application/json' \
-d '{"username": "emilys", "password": "emilyspass"}'
Adds, updates and deletes are simulated and not stored.
Good for: token-based auth, passing a Bearer token to protected routes, search and pagination.
4. Restful Booker
https://restful-booker.herokuapp.com
A hotel booking API built specifically for people learning to test. Getting bookings is open; creating a token (POST /auth with the documented demo credentials) lets you update and delete them. The data resets periodically.
It also contains deliberate bugs, which makes it good practice for exploratory testing: can you find where the API does not match its own documentation?
Good for: full CRUD with auth, and practising bug reports.
5. Swagger Petstore
https://petstore3.swagger.io
The reference example for the OpenAPI specification. You get a published spec, interactive docs and endpoints for pets, orders and users.
The data is shared by everyone using it, so do not rely on records you create still being there.
Good for: importing an OpenAPI spec into Postman or another client, and checking responses against a schema.
6. httpbin
https://httpbin.org
Not a data API but an HTTP tool. It echoes what you send and returns whatever you ask for:
curl -i https://httpbin.org/status/418 # any status code
curl https://httpbin.org/headers # the headers you sent
curl https://httpbin.org/delay/2 # a 2-second delay
Good for: understanding headers, status codes and timeouts in isolation.
7. GoRest
https://gorest.co.in
Users, posts, comments and todos. Reads are open; writes need a free access token sent as a Bearer header, and a write without one returns 401. It also returns validation errors when a field is missing or wrong.
Good for: Bearer auth, 401 and 422 responses, and data that persists.
8. PokeAPI
https://pokeapi.co/api/v2/pokemon/ditto
A large, read-only API with deeply nested data and consistent pagination. No key is needed; please cache responses, as its fair-use policy asks.
Good for: asserting on nested fields, following links between resources, pagination.
9. restful-api.dev
https://api.restful-api.dev/objects
A simple object store. POST an object and you can GET it back by id, then update or delete it. The public API allows 50 requests a day, reset every 24 hours.
Good for: a first create, read, update, delete test that actually round-trips.
10. A ReqRes project (when you need your own backend)
Public APIs share data with everyone, reset, or fake their writes. When you need tests that create data and read it back reliably, create a free project at app.reqres.in:
const res = await fetch('https://reqres.in/api/collections/tickets/records', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'x-api-key': 'YOUR_MANAGE_KEY', // pro_* key for writes, keep it server-side
},
body: JSON.stringify({ data: { subject: 'Checkout fails', priority: 'high' } }),
});
You also get app users with login, and a log of every request, which helps when a test fails and you need to see what was actually sent.
10 practice projects
Work through these in order. Each one names an API from the list that suits it.
- Your first request. GET
https://reqres.in/api/users?page=2in Postman, curl or your browser. Assert the status is 200 anddatahas six items. - Status codes. Make requests that return 200, 201, 400 and 404 (ReqRes), then any code you like (httpbin). Write one assertion per code.
- Create and read back. POST an object to restful-api.dev, GET it by id and assert every field matches. Then try the same against JSONPlaceholder and explain why it fails.
- Login success and failure. Log in to the ReqRes demo with valid credentials (token returned) and without a password (400). Assert on both.
- Protected routes. Get a JWT from DummyJSON, call a protected endpoint with it, then with no token and with a broken one.
- Full CRUD with auth. In Restful Booker, create a booking, update it with a token, delete it, and confirm it is gone.
- Pagination. Walk every page of PokeAPI's
/pokemonlist and assert you never see a duplicate. - Timeouts. Use
?delay=3on ReqRes or/delay/3on httpbin and set your client timeout to 2 seconds. Assert that your test fails cleanly rather than hanging. - Schema checks. Import the Swagger Petstore spec and validate a response against it.
- Run it in CI. Put your suite in a GitHub Actions workflow and run it on every push. Point it at a ReqRes project so the data your tests create is still there when they read it back.
Which should you start with?
- Complete beginner: ReqRes demo endpoints, then JSONPlaceholder.
- Learning auth: ReqRes login, then DummyJSON, then Restful Booker.
- Preparing for a QA interview: Restful Booker, for its deliberate bugs.
- Teaching a class: ReqRes, since it needs no signup, and gives each student their own project when you need persistent data.
- Building a real test suite: a ReqRes project, so your data is yours and does not reset.
Common questions
What is the best free API to practise API testing?
Start with the ReqRes demo endpoints: no signup, realistic success and error responses, login and delays. For auth flows, add DummyJSON and Restful Booker. For your own persistent data, use a free ReqRes project.
Which free APIs keep the data I create?
Restful Booker (until it resets), GoRest (with a token), restful-api.dev, and ReqRes projects. JSONPlaceholder, DummyJSON and the ReqRes demo endpoints return realistic responses but do not store writes.
Do I need an API key to practise API testing?
No. ReqRes demo endpoints, JSONPlaceholder, DummyJSON, httpbin, PokeAPI and restful-api.dev all work without one. GoRest needs a free token to write, and ReqRes projects use an API key.
Can I use these APIs in Postman?
Yes, all ten work in Postman, and in curl, Playwright, Cypress and REST Assured. See API testing with Postman for a step-by-step guide.