Skip to main content
The Checksum API Agent is a continuous testing agent for your backend APIs. You give it your API surface through specs, HAR files, Postman collections, or existing traffic, and it generates journey-based tests that reflect how your product actually works. From there it runs in the background, expanding coverage, picking up new endpoints and flows, and detecting when a contract changes, without anyone needing to re-prompt it. The goal isn’t to generate tests once. It’s to keep a living test suite that stays current with your API, continuously.
API Testing end-to-end flow

What you get

  • Pytest tests in your repo: Every test is standard Python committed to your repository. It’s readable, editable, and runnable on its own. You own the tests and there’s no black box or vendor lock-in.
  • Journey-based coverage: Tests chain calls together the way a real user does (create a resource, update it, trigger a downstream effect) and verify the whole sequence, not just that one endpoint returns a 200.
  • A self-maintaining suite: When your API changes, the agent updates the affected tests and opens a PR. You review what it surfaces instead of hand-maintaining hundreds of tests.
  • Breadth, fast: The agent works across your whole API surface in parallel. Most teams reach meaningful coverage in days, not the months it takes to write the same tests by hand.

How it works

API testing runs as a continuous loop. As your API evolves, your test suite evolves with it.
  1. Ingest: Upload your API definitions and traffic (OpenAPI/Swagger, HAR, Postman, and more). Checksum parses them into a single endpoint catalog you can browse on the API Coverage map.
  2. Generate: The agent groups related endpoints into realistic journeys and writes pytest tests for each, then delivers them as a pull request.
  3. Review & merge: Read the generated tests and merge the PR to add them to your suite.
  4. Run: Run the whole suite, a single suite, or one case, from the app or in CI.
  5. Triage & heal: Failures and skips flow to the Triage board. The agent heals tests broken by API changes and opens PRs; you confirm the failures that are real product bugs.
  6. Monitor: Track coverage and trends on the API Health Dashboard.

Key concepts


Where you work

The API testing area in the Checksum web app gives you a product surface over everything the agent does:
  • API Specs: Upload sources and kick off generation.
  • API Coverage: A live map of every endpoint and where your gaps are.
  • API Tests: Browse generated suites, cases, and steps; run them.
  • API Test Runs: Run reports with per-call timing, status codes, and request/response detail.
  • API Triage: Review failures, confirm bugs, and trigger healing.
  • API Files: Inspect or edit the generated test files directly.
  • Health Dashboard: Coverage and test-health trends over time.

Security & ownership

Your tests are committed to your own repository, so you own them and can run them anywhere. Secrets and credentials live in the environment variables layer and are injected at runtime, never hardcoded into test files. Checksum is SOC 2 and ISO 27001 certified; full details are at trust.checksum.ai.

Next Steps