How do I test an API endpoint?

Choose a method (such as GET or POST), type the endpoint URL and click 'Send'. The response appears below the form with its status code, response time, size, body, headers and cookies. Use the tabs above the Send button to add query parameters, headers, a request body or authentication first.

What is an API tester?

An API tester (also called an API client) sends an HTTP request to an endpoint and shows you exactly what comes back. Developers use one to try out a new API, reproduce a bug, check that authentication works or confirm a deploy didn't break an endpoint – without writing any code. This tool is a lightweight, browser-based alternative to apps like Postman.

Which HTTP methods can I use?

GET, POST, PUT, PATCH, DELETE, HEAD and OPTIONS. A HEAD request returns headers only, and OPTIONS is useful for seeing which methods an endpoint allows.

How do I send a JSON body?

Open the 'Body' tab, choose 'JSON' and type or paste your payload. The tool checks it is valid JSON as you type, and the 'Beautify' button tidies it up. The Content-Type: application/json header is added automatically. For GraphQL, send a POST request with a JSON body like {"query": "{ viewer { id } }"}.

How do I authenticate a request?

Open the 'Auth' tab and pick a type. 'Bearer token' adds an Authorization: Bearer header, 'Basic auth' encodes a username and password into an Authorization: Basic header, and 'API key' adds your key as a custom header or query parameter. You can also set any header by hand in the 'Headers' tab.

What are variables?

Variables let you reuse a value across requests. Define one in the 'Variables' tab (for example base_url = https://api.example.com), then write {{base_url}}/users in the URL. Domify swaps the value in when you send the request. This is handy for tokens, IDs and switching between staging and production. If a variable isn't defined, the tool tells you instead of sending a broken request.

Can I test an API running on localhost?

Yes, but not through the Domify server, which can only reach public addresses. Open 'Settings' and set 'Send request from' to 'My browser'. The request then leaves your own machine, so it can reach localhost and private network addresses. In this mode the API must allow cross-origin requests from this site (CORS), and some details – such as the full timing breakdown and the exact headers sent – aren't available. The CORS checker can help you work out why a request is blocked.

Why does a request fail in 'My browser' mode but work on the server?

Browsers enforce CORS. If the API doesn't return the right Access-Control-Allow-Origin header, the browser blocks the response and this tool can only report a generic network error. The same request sent from the Domify server isn't subject to CORS, so it works. Use the CORS checker to see exactly what the API allows.

Can I import a cURL command or export code?

Yes. Click 'Import cURL' (or just paste a curl command into the URL field) to fill in the method, URL, headers, body and auth automatically. The 'Code' tab turns your current request into a ready-to-run snippet in cURL, JavaScript (fetch), Python (requests) or PHP.

What do the timing figures mean?

The 'Timing' tab splits the request into stages: DNS lookup (finding the server), connect (opening the connection), TLS (the HTTPS handshake), waiting (time until the first byte arrives, often the API's own processing time) and download (receiving the rest of the response). Time spent following redirects is shown separately.

Are my requests stored?

Domify doesn't store your requests or responses on its server. Your history, saved requests, variables and current draft are kept only in your own browser, which means they're private to you but also won't follow you to another device. Your draft and history never keep auth tokens, passwords or the values of credential-like headers (such as Authorization or Cookie), but requests you save and variables you define are stored exactly as typed. Clear them before using a shared computer.

Why do I need to sign in?

The API tester sends requests from Domify's servers to whatever address you give it, so it could be misused to hammer someone else's API. Signing in with Google lets Domify limit and trace abuse. It's free, and Domify doesn't store the requests you send.

Are there any limits?

Requests sent from the Domify server time out after at most 60 seconds, request bodies can be up to 1 MB, and only the first 2 MB of a response is shown. There's also a rate limit to stop abuse. File uploads, WebSockets and streaming responses aren't supported. For a closer look at just a response's headers, try the HTTP header checker.