Calculator API - Instructions

We created an API version of the Server Side Calculator API. This offers more features.

About App

We’ve documented the API in three different ways.

When working with APIs you may be lucky enough to get an openapi specification which is well constructed with correct types and examples.

But you might also receive hand crafted documentation that might be ambiguous, incomplete or possibly out of date.

Like the Server Side Calculator the API can handle numbers or sentences as input e.g. “one thousand and three”

API Tools

Swagger and Redoc UIs depend on external library distributions so they may not always render properly. They can also have CORS issues where JavaScript is not allowed to communicate with the server.

API testing is usually best done with a dedicated tool.

You may want to use an API tool to help with this e.g.

We have a list of API tools on our apichallenges site with links to more practice APIs and tutorial content.

HTTP API Exercises

Use the Calculator API to practice the basics of HTTP API testing.

Start with the documented endpoints:

  • GET /apps/api/calculator/calculate?operation=plus&left=1&right=2
  • POST /apps/api/calculator/calculate
  • POST /apps/api/calculator/sequence

Then vary the request deliberately:

  • send Accept: application/json and confirm that the response is JSON
  • change Content-Type between application/json, application/x-www-form-urlencoded, and an unsupported value
  • send malformed JSON and compare the status code and error response
  • try unsupported verbs such as PUT, PATCH, or DELETE
  • send OPTIONS requests and compare the Allow header with the documented behaviour
  • send numeric values, number words, and malformed operand lists
  • compare the API response with the form-backed calculator UI

Example curl GET:

curl -i "https://testpages.eviltester.com/apps/api/calculator/calculate?operation=plus&left=1&right=2"

Example JSON POST:

curl -i \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d "{\"operation\":\"divide\",\"left\":\"10\",\"right\":\"2\"}" \
  https://testpages.eviltester.com/apps/api/calculator/calculate

Example form encoded POST:

curl -i \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "number1=one%20hundred&function=minus&number2=twenty" \
  https://testpages.eviltester.com/apps/api/calculator/calculate

When reporting API issues, include the method, URL, request headers, request body, status code, response headers, and response body. This makes the behaviour easier to reproduce from any HTTP client.

Browser And Proxy Observation

The form calculator uses JavaScript to call the API. Open DevTools, use the Network tab, and submit calculations through the form UI.

Compare:

  • the browser-generated API request
  • the same request recreated in an API client
  • the same request copied as curl
  • requests amended through a proxy or replay tool

This is a useful way to move from observing a GUI workflow to testing the underlying API directly.