This roadmap takes you from zero to a job-ready API automation engineer in about ten weeks. It's split into five stages, each with the skills to learn, the exact tutorials to follow, a checklist to confirm you're ready, and a milestone you can put in your portfolio.
Who This Roadmap Is For
- Manual testers expanding into API testing.
- UI automation engineers adding backend validation to their skills.
- Anyone preparing for SDET or API automation interviews.
Time commitment
- Duration: about 8–10 weeks.
- Study time: 1–2 hours a day, with at least half of it hands-on.
- With a strong Java background you'll move faster through the REST Assured stages.
Why API testing matters
- API tests run in milliseconds and don't break when the UI changes.
- They catch backend defects earlier — often before the UI exists.
- They reach error cases and edge conditions the UI hides.
- Modern SDET roles expect both UI and API automation.
Before You Start: Prerequisites
- Basic testing concepts — test cases, positive and negative testing. See The Complete Manual Testing Tutorial.
- Core Java before Stage 3 — classes, collections, exceptions. See Java for Testers.
- Git basics for your portfolio. See The Complete Git Tutorial.
Stage 1 — API Concepts (Weeks 1–2)
Why start here: sending a request in Postman is easy; understanding what happened is the skill. HTTP, REST, authentication and status codes are also the most common interview topics.
| Topic | Tutorial |
|---|---|
| What an API is, client–server, REST vs SOAP | API Testing Fundamentals · REST vs SOAP |
| HTTP methods, status codes, idempotency | HTTP Methods & Status Codes |
| Requests, responses, headers, parameters | HTTP Requests & Responses |
| JSON, XML and schema basics | API Data Formats |
✅ Ready for Stage 2 when you can explain: 401 vs 403 · 500 vs 503 · PUT vs PATCH · which methods are idempotent · path vs query parameters · what makes an API RESTful.
Companion: HTTP Status Codes Cheat Sheet · The Complete API Testing Tutorial
Stage 2 — Postman (Weeks 3–4)
Why Postman: the fastest way to get hands-on — explore real APIs, write assertions and chain requests without writing a framework.
| Topic | Tutorial |
|---|---|
| Workspaces, collections, environments, variables | Postman Essentials |
| Tests tab, assertions, request chaining | Postman Scripting · Assertions & Validations |
| Basic, Bearer, OAuth 2.0 and JWT | API Authentication |
| Hands-on exercises | Postman Practical Roadmap |
🎯 Milestone — an end-to-end Postman collection on RESTful Booker or ReqRes:
Log in → save token → create a resource → GET it → update it → delete it → GET again and expect 404
Every request has assertions, and IDs and tokens pass between requests through variables. Companion: Postman Cheat Sheet.
Stage 3 — REST Assured (Weeks 5–7)
Why REST Assured: it turns the manual checks from Stage 2 into automated Java tests that run in CI.
| Topic | Tutorial |
|---|---|
| Maven setup, given/when/then | Setup & Syntax |
| Requests, parameters, headers | Sending Requests |
| Response validation and Hamcrest | Response Validation |
| JsonPath extraction and chaining | Logging & Extraction |
| POJO serialisation | Serialization & POJO |
| Authentication and tokens | REST Assured Authentication |
| Hands-on exercises | REST Assured Practical Roadmap |
🎯 Milestone: rebuild your Stage 2 Postman flow in Java + REST Assured + TestNG + Maven, with extracted IDs and tokens passed between tests.
Companion: The Complete REST Assured Tutorial · REST Assured Cheat Sheet
Working in JavaScript/TypeScript instead? Playwright has built-in API testing — see Playwright API Testing.
Stage 4 — Framework & Quality (Weeks 8–9)
Why: interviewers expect a reusable framework, not a folder of isolated scripts.
| Topic | Tutorial |
|---|---|
| Request and response specifications, structure | REST Assured Framework Design |
| TestNG integration and data-driven tests | TestNG Integration |
| Contract checks | JSON Schema Validation |
| Negative testing and error handling | Negative Testing |
| API security basics | API Security Testing |
🎯 Milestone — an API framework on GitHub with:
- Request/response specifications
- POJO models
- Configuration and environment switching
- JSON schema validation
- Negative tests
- TestNG groups (smoke/regression)
- A clear README explaining how to run it
Stage 5 — CI/CD & Ownership (Week 10)
Why: senior automation means tests that run themselves and report to the team.
| Topic | Tutorial |
|---|---|
| Newman, Jenkins and reporting | API Testing in CI/CD |
| Contract testing and senior tasks | Senior-Level API Tasks |
| Performance and load testing | API Performance & Load Testing |
| Jenkins pipelines | Jenkins Pipelines & Jenkinsfile |
🎯 Milestone: your framework runs in Jenkins on every Git push, publishes a report, and credentials come from Jenkins credentials — not the code. See the CI/CD Test Pipeline Visualizer.
Demo APIs for Practice
| Demo API | Best for |
|---|---|
| RESTful Booker | Authentication, CRUD and chaining |
| ReqRes | User APIs, pagination, data-driven tests |
| FakeStore | End-to-end e-commerce flows |
| Swagger Petstore | Reading API docs and contract checks |
| GoRest | Token authentication and role-based access |
| DummyJSON | Query parameters and nested JSON |
| JSONPlaceholder | Quick first requests (writes are simulated) |
Suggested order: JSONPlaceholder → RESTful Booker → ReqRes → FakeStore → Swagger Petstore → GoRest. The API Testing Scenario Lab is great for practising test design.
Common Mistakes on This Path
- Skipping Stage 1 — then struggling to explain status codes and auth in interviews.
- Only checking status codes — validate the body, schema, headers and side effects too.
- Hard-coding tokens and URLs — use variables, specs and configuration from day one.
- No negative tests — most real API bugs are in error handling.
- Staying in Postman too long — move to code once the concepts are solid.
What Interviewers Check
- Can you explain HTTP, REST, status codes and authentication clearly?
- Can you design test cases for an endpoint on the spot — positive, negative, security and boundary?
- Can you write a REST Assured test with chaining and validation from memory?
- Can you explain your framework's layers and how it runs in CI?
Prepare with Top 30 API Testing Interview Questions, Top 25 REST Assured Interview Questions and the API Interview Simulator.
Roadmap Snapshot
| Stage | Weeks | Portfolio outcome |
|---|---|---|
| 1 — Concepts | 1–2 | Clear explanations of HTTP and REST |
| 2 — Postman | 3–4 | An end-to-end Postman collection |
| 3 — REST Assured | 5–7 | The same flow automated in Java |
| 4 — Framework | 8–9 | An API framework on GitHub |
| 5 — CI/CD | 10 | The framework running in Jenkins |
From Real Projects
I've worked with APIs at the level this page covers: CRUD operations, HTTP methods, JSON and XML formats, and extracting and validating values with JSON path. A good habit from that work: test the full create–read–update–delete cycle for a resource and check each response in detail. Testsigma supports web, mobile and API test automation, so understanding APIs was part of understanding the product I was testing. Follow the roadmap in order — HTTP basics and JSON first, then a tool, then automation.
📚 Official documentation: MDN: HTTP · ISTQB Glossary of testing terms
Frequently Asked Questions
How long does it take to learn API testing?
About 8–10 weeks at 1–2 hours a day to go from concepts to an automated framework running in CI. The concepts and Postman can be learned in the first month.
Should I learn Postman or REST Assured first?
Postman first, to understand APIs without code; then REST Assured to automate the same flows in Java.
Do I need Java for API testing?
Not for Postman. For REST Assured, yes — learn Core Java before Stage 3. JavaScript/TypeScript users can automate APIs with Playwright instead.
What should an API automation portfolio include?
A GitHub framework with specifications, POJOs, environment configuration, schema validation, negative tests, TestNG groups, CI integration and a README that explains how to run it.
Which demo APIs are best for practice?
RESTful Booker for auth and CRUD, ReqRes for users and pagination, FakeStore for e-commerce flows, Swagger Petstore for contracts and GoRest for token-based access.
Next Steps
- The Complete API Testing Tutorial
- The Complete REST Assured Tutorial
- REST Assured vs Postman
- 0 to SDET in 6 Months — the full career roadmap