Test a token refresh race
Expert200 pts~75 min
- Authentication
- Concurrency
- Race conditions
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Reproduce concurrent calls hitting an expired token and prove single-use refresh tokens force a single-flight refresh.
Your task
- 1POST BASE_URL + "/auth/token?ttl=0" with qa@target.dev / Test@123 — the access token is expired immediately.
- 2GET BASE_URL + "/auth/me" with it → assert 401 TOKEN_EXPIRED.
- 3Fire two concurrent POST BASE_URL + "/auth/refresh?ttl=3600" with the same refresh_token → assert exactly one 200 and one 401 INVALID_REFRESH_TOKEN.
- 4Implement a single-flight refresh (one shared in-flight refresh for all callers), run several concurrent /auth/me calls through it and assert all return 200.
Acceptance criteria
- An expired token gets 401 from /auth/me
- A reused refresh token is rejected with 401
- Refresh succeeds once and /auth/me returns 200 afterwards
- Requests run concurrently
- At least 4 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Featured challenges