API testing

Test a token refresh race

Expert200 pts~75 min
  • Authentication
  • Concurrency
  • Race conditions
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/token-refresh-race

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Reproduce concurrent calls hitting an expired token and prove single-use refresh tokens force a single-flight refresh.

Your task

  1. 1POST BASE_URL + "/auth/token?ttl=0" with qa@target.dev / Test@123 — the access token is expired immediately.
  2. 2GET BASE_URL + "/auth/me" with it → assert 401 TOKEN_EXPIRED.
  3. 3Fire two concurrent POST BASE_URL + "/auth/refresh?ttl=3600" with the same refresh_token → assert exactly one 200 and one 401 INVALID_REFRESH_TOKEN.
  4. 4Implement a single-flight refresh (one shared in-flight refresh for all callers), run several concurrent /auth/me calls through it and assert all return 200.

Acceptance criteria

  • An expired token gets 401 from /auth/me
  • A reused refresh token is rejected with 401
  • Refresh succeeds once and /auth/me returns 200 afterwards
  • Requests run concurrently
  • At least 4 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Featured challenges