AI-Powered Automated API Testing System

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
AI-Powered Automated API Testing System
Medium
~2-3 days
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1356
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1248
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    953
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1187
  • image_logo-advance_0.webp
    B2B Advance company logo design
    644
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    925

AI-Powered Automated API Testing System

A typical team spends 3 days manually regressing 45 endpoints. Each release risks shipping a bug to production. With daily microservice deployments, manual testing can't keep up. We solve this by generating tests with LLMs. Our solution analyzes OpenAPI specifications and real traffic to automatically create tests for functionality, contracts, security, and performance. Result: regression time cut by 80%, missed bugs by 95%. We use pytest as the test framework. QA budget savings can reach 50%—typically $30,000 per year for mid-size projects.

Problems We Solve

Contract Changes and Regression

In a microservice architecture, a single API change can break dozens of consumers. Without automated contract tests, you learn about the problem only during integration testing—or worse, in production. AI generates tests that verify response schema compliance, field mandatoryness, and data types. This catches breaking changes at the CI stage.

Security Gaps

Typical APIs contain vulnerabilities: missing authentication, SQL injection, insecure deserialization. Manual pentests are quarterly, but new features appear more often. AI security testing checks every endpoint against OWASP Top 10 using synthetic payloads. We guarantee detection of SQL injection, NoSQL injection, and XSS.

Poor Performance Under Load

AI generates Locust scenarios that mimic real usage patterns. For example, for a CRM system—80% reads, 20% writes, with realistic timings. This identifies bottlenecks before they affect users.

How AI API Testing Generates Tests from OpenAPI Specification

import yaml
import json
from langchain_openai import ChatOpenAI
from pathlib import Path

class APITestGenerator:
    CONTRACT_TEST_PROMPT = """Create pytest tests for an API endpoint.

Endpoint: {method} {path}
OpenAPI Spec:
{spec}

The tests must cover:
1. happy path: valid request -> expected response
2. Schema validation: response matches OpenAPI schema (use jsonschema)
3. Auth: request without token -> 401, with invalid token -> 401/403
4. Validation errors: missing required fields -> 422, wrong types -> 422
5. Boundary values: min/max string length, numeric limits
6. Business rules: specific rules from the endpoint description

Use: pytest + httpx + jsonschema
Base URL via pytest fixture: base_url
Auth token via fixture: auth_token

Return the test code."""

    def __init__(self):
        self.llm = ChatOpenAI(model="gpt-4o", temperature=0.1)

    def generate_from_openapi(self, spec_path: str) -> dict[str, str]:
        """Generate tests for all endpoints from an OpenAPI spec"""
        with open(spec_path) as f:
            spec = yaml.safe_load(f)

        test_files = {}
        for path, methods in spec.get("paths", {}).items():
            for method, endpoint_spec in methods.items():
                test_code = self._generate_endpoint_tests(path, method, endpoint_spec, spec)
                filename = f"test_{method}_{path.replace('/', '_').strip('_')}.py"
                test_files[filename] = test_code

        return test_files

    def _generate_endpoint_tests(
        self,
        path: str,
        method: str,
        endpoint_spec: dict,
        full_spec: dict
    ) -> str:
        # Resolve $ref
        resolved_spec = self._resolve_refs(endpoint_spec, full_spec)

        return self.llm.invoke(
            self.CONTRACT_TEST_PROMPT.format(
                method=method.upper(),
                path=path,
                spec=json.dumps(resolved_spec, ensure_ascii=False, indent=2)
            )
        ).content

The code generates tests for 6 layers, covering up to 90% of API scenarios. According to our practice, this approach catches up to 95% of regressions.

Real Traffic Analysis and Regression Test Generation

class TrafficBasedTestGenerator:
    """Generate tests from HAR files or proxy logs"""

    def generate_from_har(self, har_path: str) -> list[str]:
        """Generate regression tests from recorded traffic"""
        with open(har_path) as f:
            har = json.load(f)

        entries = har["log"]["entries"]
        api_calls = [
            e for e in entries
            if "api" in e["request"]["url"] or
               e["response"]["content"].get("mimeType", "").startswith("application/json")
        ]

        tests = []
        for entry in api_calls[:50]:  # top 50 unique requests
            test = self._generate_regression_test(entry)
            tests.append(test)

        return tests

    def _generate_regression_test(self, entry: dict) -> str:
        request = entry["request"]
        response = entry["response"]

        prompt = f"""Create a pytest regression test from the recorded HTTP interaction.

Request:
- Method: {request['method']}
- URL: {request['url']}
- Headers: {json.dumps({h['name']: h['value'] for h in request.get('headers', [])[:5]}, ensure_ascii=False)}
- Body: {request.get('postData', {}).get('text', '')[:500]}

Response:
- Status: {response['status']}
- Body: {response['content'].get('text', '')[:500]}

Create a test that:
1. Reproduces the request (with parameterized test data instead of real data)
2. Checks the status code
3. Checks the response schema (keys, types)
4. Does not hardcode real data (use fixtures instead)

Return pytest code."""

        return self.llm.invoke(prompt).content

This method catches regressions not covered by contract testing—e.g., undocumented fields or date format changes.

Limitations of Automation

If the API changes frequently without a spec, or if you have no access to real traffic, AI generation may produce false positives. In such cases, we recommend first establishing contract testing and log collection. For fully dynamic APIs (e.g., generated on the fly), we offer custom solutions.

How We Test API Security

class APISecurityTester:
    SECURITY_PROMPTS = {
        "sql_injection": [
            "' OR '1'='1", "'; DROP TABLE users;--",
            "1 UNION SELECT NULL,NULL,NULL--",
            "' AND SLEEP(5)--"
        ],
        "nosql_injection": [
            '{"$gt": ""}', '{"$where": "this.password.length > 0"}',
            '{"$regex": ".*"}'
        ],
        "xss": [
            "<script>alert('xss')</script>",
            "javascript:alert(1)",
            '"><img src=x onerror=alert(1)>'
        ]
    }

    async def test_injection_resilience(
        self,
        endpoint: str,
        param_name: str,
        client
    ) -> list[dict]:
        results = []
        for attack_type, payloads in self.SECURITY_PROMPTS.items():
            for payload in payloads:
                response = await client.post(
                    endpoint,
                    json={param_name: payload}
                )
                # Application must return 400/422, not 500 or data
                results.append({
                    "attack_type": attack_type,
                    "payload": payload,
                    "status": response.status_code,
                    "vulnerable": response.status_code == 500 or
                                   self._contains_db_error(response.text)
                })
        return results

We guarantee detection of SQL injection, NoSQL injection, and XSS. In one project, we found 3 production vulnerabilities missed by manual audits.

Load Testing with Locust

    LOCUST_PROMPT = """Create a Locust load test for an API.

Endpoints under load:
{endpoints}

Create:
- HttpUser class with tasks for each endpoint
- Realistic distribution: frequent operations -> higher weight
- @task(3) for reads, @task(1) for writes
- between(1, 5) for wait_time
- Error handling via on_failure

Target: 100 RPS, latency P95 < 500 ms.
Return Python code for locustfile.py."""

AI-written scenarios are 10x faster than manual ones, and results are more reproducible.

CI/CD Configuration

# API test pyramid in CI
api-tests:
  contract:
    run: pytest tests/api/contract/ -v
    on: [push, pull_request]
  security:
    run: pytest tests/api/security/ -v
    on: [pull_request]
  performance:
    run: locust -f tests/api/locustfile.py --headless -u 50 -r 5 --run-time 2m
    on: [manual, schedule]  # do not block PR

What's Included

Category Description Volume
Contract test generation From OpenAPI spec, coverage of all endpoints with schema validation Up to 1000 tests in 1 day
Regression tests from traffic Reproduce real requests with schema checks 50+ scenarios
Security tests OWASP Top 10, SQL injection, XSS, NoSQL injection 100+ tests
Performance tests Locust scenarios with realistic load 10+ scenarios
CI/CD integration Configuration for your system 1–2 days
Documentation and reports Detailed analysis of found issues Per project
Team training 2-hour workshop on test maintenance 1 day
Post-deployment support Maintenance, test modifications 2 weeks

Case Study

Fintech startup REST API with 45 endpoints. We generated 180 contract tests from OpenAPI spec and 60 security tests. Tests discovered: 2 endpoints without authentication, 1 SQL injection in report filter, incorrect Unicode handling. Time saved on regression: 3 days → 2 hours. QA budget savings up to 50%—equivalent to $40,000 per year for a typical team.

Additional Details The implementation included full CI/CD integration and team training. The startup reported zero regressions in the following quarter.

Implementation Timeline

Stage Time
Contract test generation 2–3 weeks
Adding security and performance 3–4 weeks
Full turnkey cycle 4–6 weeks

Cost is calculated individually. Get a free consultation on automating your API testing—we'll assess your project and suggest the best solution for your stack. Order a free analysis of your API today.

We are OWASP certified and experienced with high-load APIs. We ensure full coverage of critical vulnerabilities.

LLM Development: Fine-Tuning, RAG, Agents, and Production Deployment

Using GPT‑4 or Claude 3.5 Sonnet through a public API is not a solution — it's just a tool. When the requirement is to "make it like ChatGPT, but on our data," there is a real engineering challenge behind it: from prompt engineering to training a 70B model on your own infrastructure. End-to-end LLM solution development is a complex stack, and we have been doing it for over 5 years. During this time, we have completed over 20 projects in generative AI: from RAG systems for legal departments to custom support agents. Where exactly your task falls depends on data, latency requirements, budget, and how critical confidentiality is.

A typical situation: the client has already tried ChatGPT, but results are unstable — sometimes accurate, sometimes hallucinating. Or they need integration into a corporate portal while complying with security policies. Let's break down each layer of the stack in detail — from RAG to production deployment.

Why Do RAG Systems Break and How to Fix It?

RAG (Retrieval-Augmented Generation) looks simple: find relevant documents, put them in context, get an answer. In practice, it fails in several places.

Chunking without overlap. Classic mistake: chunk_size=512, overlap=0. If the answer lies across two chunks, retrieval won't find either with sufficient confidence. Solution: overlap 15–25% of chunk_size, or better yet, sentence-aware splitting with spaCy or NLTK instead of naive character splitting.

Poor embedder. text-embedding-ada-002 is good for general use, but on legal or medical texts, specialized models like E5-large-v2, BGE-M3, or fine-tuned sentence-transformers on domain data outperform it. Recall@5 differences can be 15–25%.

No re-ranking. Vector search optimizes for speed, not relevance. A cross-encoder re-ranker (ms-marco-MiniLM-L-6-v2, bge-reranker-large) after initial retrieval improves top-3 accuracy with acceptable latency (+50–150ms). This is often more impactful than improving the embedding model.

Hybrid search. Dense vectors alone work poorly on exact queries: names, SKUs, codes. BM25 (sparse) finds exact matches but misses semantics. Hybrid via RRF (Reciprocal Rank Fusion) is the optimal compromise. Qdrant, Weaviate, and pgvector 0.7+ support hybrid search natively.

Typical production architecture for a corporate knowledge base
  1. Documents → preprocessing (PyMuPDF, Unstructured)
  2. Chunking → embedding (BGE-M3)
  3. Qdrant (hybrid dense+sparse)
  4. Cross-encoder re-ranking
  5. Context → LLM (vLLM or OpenAI API)
  6. Answer with sources (RAGAS for quality evaluation)

When to Fine-Tune Instead of Prompt Engineering?

Prompt engineering solves ~70% of LLM adaptation tasks for a domain. The remaining 30% require fine-tuning. Three indicators: the model ignores a specific output format even with detailed prompting; the task requires deep knowledge of specialized vocabulary (medicine, law); you need to significantly reduce token costs by replacing a large model with a smaller specialized one.

LoRA and QLoRA are the standard for SFT. LoRA adds trainable low-rank matrices to attention layers. A typical configuration for Llama-3 8B: r=64, lora_alpha=128, target_modules=["q_proj","v_proj","k_proj","o_proj"] yields ~0.8% trainable parameters, training on one A100 40GB. QLoRA adds 4-bit quantization (NF4) and allows fine-tuning 70B models on two A100 40GB, though speed drops by half compared to bf16.

DPO instead of RLHF. Direct Preference Optimization requires only (chosen, rejected) pairs, not scalar reward signals. DPOTrainer from the trl library (Hugging Face) implements it in a few dozen lines.

Common mistake. A dataset of 500 examples, 5 epochs, validation loss 0.8 — seems fine. But on test, the model degrades on general instructions. Cause: catastrophic forgetting. Solution: add 10–20% general instruction-following examples (Alpaca, FLAN) to the training set to preserve original capabilities.

How to Choose a Base Model: 8B or 70B?

Model Parameters Strengths Context
Llama-3.1 8B 8B Quality/speed balance 128k
Llama-3.1 70B 70B Complex reasoning 128k
Mistral 7B / Mixtral 8x7B 7B / 47B Efficiency for size 32k
Qwen2.5 72B 72B Code, multilingual 128k
Gemma 2 27B 27B Open license 8k

For most tasks, fine-tuning an 8B model is sufficient. 70B is needed when deep reasoning is required or the 8B baseline does not reach the required quality even after fine-tuning. Inference cost for Llama-3 8B via vLLM on A100 is efficient; the exact cost depends on volume.

What Does PagedAttention Bring to Production?

vLLM is the first choice for serving open-source models. PagedAttention is the key technical innovation: KV-cache is managed like virtual memory in an OS, without fragmentation. This yields 2–4x higher throughput compared to naive HuggingFace Transformers inference. The vLLM documentation confirms that continuous batching and PagedAttention are the standard for high-load LLM services.

Typical numbers on A100 80GB for Llama-3 8B (bf16): 400–600 req/s, P50 latency 200–400ms, P99 latency 600–900ms at concurrency 64. For 70B on two A100 with tensor parallelism: 80–120 req/s, P99 latency 1.5–2.5s. AWQ or GPTQ quantization reduces memory consumption by 2x with quality loss within 1–3%.

Multi-Agent Systems

Agents are LLMs with access to tools: search, code execution, API calls, database interaction. Common patterns:

  • ReAct (Reason + Act): the model reasons → chooses a tool → observes the result → reasons again. LangChain and LlamaIndex implement it out of the box.
  • Multi-agent orchestration: multiple specialized agents with a coordinator on top. Example: coordinator → researcher (search + summarization) → coder (code generation and execution) → critic (verification). Tools: AutoGen (Microsoft), CrewAI, custom implementation on LangGraph.

In production, agent systems are non-deterministic. Essential: guardrails, step limits, logging of each step, human-in-the-loop for critical actions.

How We Work: Stages, Timeline, Deliverables

Stage Duration What You Get
Audit and data collection 1–2 weeks Eval dataset of 100+ examples, task formalization
Baseline (prompt + RAG) 1–2 weeks Working prototype, quality metrics
Fine-tuning (if needed) 2–4 weeks Trained model, LoRA weights, model card
Deployment and monitoring 1–2 weeks vLLM server, Grafana + Prometheus
Documentation and training 1 week API documentation, team training

What Is Included

We deliver:

  • Technical documentation (model card, configs, deployment instructions)
  • Access to infrastructure (code repository, trained weights)
  • 1 month of post-deployment support (consultations, bug fixes)
  • Customer team training (2–3 sessions on system operation)

Timeline: basic RAG prototype — 1–2 weeks. Fine-tuning with customer data — 3–6 weeks (including data preparation). Production system with monitoring and retraining — 2–4 months. Cost is calculated individually based on data volume, model complexity, and infrastructure requirements.

We guarantee the quality of the final model with performance benchmarks and ongoing monitoring. Our engineers have hands‑on experience with dozens of production LLM systems.

Want to evaluate your project? Leave a request — we will prepare a preliminary summary within 1–2 business days. Or get a consultation on choosing the approach: RAG, fine-tuning, or hybrid — we will tell you what works best for you. Contact us to discuss your LLM development needs. Schedule a free consultation today.