Supported by Curity Logotype

Session

Fuzz Testing Web APIs: Overview of Existing Tools

Andrea Arcuri 2025
Andrea Arcuri Kristiania University of Applied Sciences

Verifying the correctness of Web APIs is an expensive, tedious task.
For example, writing test cases to send HTTP requests and verify the responses returned from the APIs requires expertise and time.
Automatically generating test cases to find functional faults, security vulnerabilities and cover requirements would hence be highly beneficial.
You can throw an OpenAPI schema to your LLM of choice, and get some test cases out of it.
Results will be shallow, though.
In the last few years, advances in AI techniques have led to few specialized open-source tools that can be used for this task, like EvoMaster, CATS, Restler and Schemathesis.
But most testers and developers in industry are still not aware of these existing solutions.
This talk will summarize the current state-of-the-art on this exciting testing automation problem, discussing their strengths and limitations.
We will briefly as well discuss our direct experience in introducing these techniques in large enterprises such as Meituan and Volkswagen.

Smarter Tech Decisions Using APIs

Smarter Tech Decisions Using APIs

API blog

High impact blog posts and eBooks on API business models, and tech advice

API conferences

Connect with market leading platform creators at our events

API community

Join a helpful community of API practitioners

API Insights Straight to Your Inbox!

Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.

By clicking below, you agree that we process your information per the terms in our Privacy Policy.

Ranked #1 API blog on the web

Ranked #1 API blog on the web

Join Our Thriving Community

Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.