This guide is the exclusive intellectual property of Hofler Enterprises LLC, protected under US and international copyright law.
This guide is for the recruiter who places QA engineers and is tired of screening for a role nobody ever explained in plain terms. You do not need to code. You need to understand the work well enough to source, screen, and place with confidence.
Every page here comes from the other side of the interview. It is what a working senior QA engineer would tell a recruiter he trusted.
Read it once, start to finish. Then keep it open beside you on your next QA screen and use the sections as a reference. The questions at the end of each section are meant to be used, not admired.
What API testing actually is, what real experience looks like, and how to tell it from a copied bullet point.
Why one resume line hides five different jobs
The phrase “performed API testing” is honestly true on five completely different resumes — a manual tester who twice clicked a button, and an engineer who owns contract testing across a dozen microservices, would both write it. You’ll learn to see why the API layer is where the expensive, invisible bugs live. The section closes with the shift this whole guide is built around: stop treating “API testing experience” as a checkbox and start treating it as a depth question.
The plain-language version, no hand-waving
Before you can judge anyone’s API testing, you need the non-technical picture: an API is the waiter carrying an order between two systems that never see each other directly. You’ll learn to recognize the vocabulary that separates a candidate who has actually debugged an API from one who hasn’t. The section closes with the one thing a green 200 never proves.
Status codes, schemas, auth, data — the real checks
Real API testing breaks down into five distinct checks — status, shape, data correctness, security, and load — and counting how many a candidate names unprompted is one of the cleanest depth signals you have. You’ll learn to use authentication and test data as invisible, hard-to-fake depth probes. The section closes with a ready-to-ask question for each that’s nearly impossible to fake.
The two shapes you’ll hear about, and why it matters
REST and GraphQL are the two shapes an API can take, and you don’t need to build either — just recognize which one a candidate is describing. You’ll learn to hear the vocabulary that separates real GraphQL experience from someone who merely name-drops it. The section closes with the one asymmetry that actually matters for placement: a GraphQL tester adapts to a REST shop in days, but a REST-only tester walks into a GraphQL shop needing weeks.
Postman, REST Assured, Playwright/Cypress, k6, Pact
Tool names are where a vague resume line finally gets specific, and they all sort along one line: some API testing is done by clicking, some by writing code that runs itself. You’ll learn to read Postman as a double-edged signal, and to read code tools as concrete clues to language, ecosystem, and seniority. The section closes with contract testing, the senior signal most recruiters miss entirely.
Why the same line means five different skill levels
This is the section the whole guide has been building toward: two candidates can submit the word-for-word identical line while one clicked through a collection someone else built and the other designed the entire strategy from scratch. You’ll learn to place any claim on the four-level ladder (Ran it, Wrote it, Automated it, Owns it) and match each rung to the role it actually fits. The section closes with the one leap that matters most for seniority: Level 2 to Level 3, manual clicking to automated coding.
What to ask instead of “do you know API testing?”
This section converts everything you’ve read into five open questions engineered so depth answers richly and shallowness answers thinly — no technical knowledge required on your end to hear the difference. You’ll learn to ask things like “were those tests automated, or did you run them by hand?” The section closes with a calibration reminder: a shallow answer doesn’t disqualify a candidate, it just tells you which rung they belong on.
From a buzzword to a measurement
The closing section pulls every thread together: an API is the messenger between two systems, testing it means checking five things, and the clicking-versus-coding line is what separates manual from automated work. You’ll learn to state, in one sentence to a hiring manager, exactly what level a candidate operates at and why. It closes with the guide’s core promise: while other recruiters forward candidates on a hope and a keyword match, you can ask five questions and know.
Rehearse the screen — 2 reps + sample script
Knowing the theory and using it live under call pressure are different skills, so this section turns the guide’s questions into rehearsed reps. You’ll learn to run two live drills — “automated, or by hand?” and “what do you check beyond a 200?” The section closes with a full mock screening script you can read aloud, showing the reaction that actually earns a deep candidate’s trust.
The API Testing Depth Cheat Sheet
This is the one-page reference to keep open during any live screen where “API testing” comes up: the plain definition, the five-check depth ladder, the clicking-vs-coding line, the tools placed by what they signal, REST vs. GraphQL at a glance, and the four levels with a sample quote for each. It closes with the fast rule that summarizes the entire volume: the level isn’t in the tool, it’s in whether the tests run without the candidate in the room.
A plain model of what API testing is, what genuine hands-on experience sounds like, and the questions that tell it apart from a line someone copied.
API testing appears on almost every QA resume, and almost nobody screening for it can say what it means. Two minutes fixes that.
An API is how two pieces of software talk to each other. Think of it as a waiter. You do not walk into the kitchen; you give the waiter your order, and the waiter brings back exactly what you asked for. The API is that waiter.
API testing checks that the waiter always does the right thing. Right order in, right food out, and a sensible response when you ask for something that is not on the menu.
API testing is the phrase most often copied onto a resume without the experience behind it. The good news: it is also one of the easiest to check, because real experience has a very specific texture.
Here is what genuine hands-on API testing sounds like:
The question that works: "Tell me about a bug you found through the API that the UI never showed." Real experience has that story. A copied bullet does not.
API testing is one of the most copied phrases on a QA resume and one of the easiest to verify once you know what to ask. The full guide hands you the model and the questions.
Get this guide →The complete QA hiring playbook, start to finish.
All 7 recruiter guides in one bundle. Source, screen, and place QA talent end to end.