Skip to content
aicoolies logo
Schemathesis logo

Schemathesis

Property-based API fuzz testing from OpenAPI and GraphQL schemas

Schemathesis automatically generates test cases from OpenAPI and GraphQL schemas to find crashes, validation errors, and specification violations in APIs. It uses property-based testing and fuzzing techniques to explore edge cases that manual test writing misses. CLI tool and Python library with CI/CD integration. 3.4K+ GitHub stars with support for authentication, custom checks, stateful testing, JUnit XML, and Allure reports.

About Schemathesis

Schemathesis automates API testing by generating schema-aware inputs directly from OpenAPI or GraphQL schema definitions. Rather than manually writing test cases for each endpoint, developers point Schemathesis at their API specification and it systematically generates requests that probe edge cases, boundary conditions, malformed inputs, and unexpected parameter combinations. The property-based testing approach discovers issues that predefined test suites consistently miss because humans cannot anticipate every possible input combination.

The fuzzing engine goes beyond random input generation by understanding API schema constraints and generating inputs that are valid enough to pass initial parsing but unexpected enough to expose implementation bugs. It tests required versus optional parameters, minimum and maximum value boundaries, enum value handling, nested object structures, and content type negotiation. Stateful testing sequences multiple API calls to explore workflows like create-then-update-then-delete that have dependencies between operations.

Schemathesis provides both a CLI tool for quick testing and a Python library for integration into existing test suites. CI/CD integration runs API fuzz testing on every pull request, catching regressions before they reach production. Each discovered issue includes the exact request that triggered it, making reproduction straightforward. Custom checks allow teams to verify business-specific invariants beyond schema compliance, and authentication support handles OAuth, API keys, and custom auth schemes for testing protected endpoints.

Pricing & Platform Specs

Pricing Summary

100% free and open-source under the MIT license ($0). Includes standalone CLI (st), Python library, Pytest integration (@schema.parametrize()), unlimited local property-based fuzzing for OpenAPI (2.0/3.0/3.1) and GraphQL, stateful link testing, automated test shrinking, and CI/CD integrations (GitHub Actions, GitLab CI) with JUnit XML, HAR, and Allure test report exports.

full pricing breakdown →

Supported Platforms

Python, CLI, any OS, CI/CD integration

Explore categories, tags & use cases

Categories

AI-powered test generation agent for automated code coverage improvement

qodo-cover (formerly Cover Agent) is an open-source AI agent that automatically generates meaningful unit tests to improve code coverage. It analyzes existing code and test patterns to produce tests that follow project conventions and target uncovered branches. Uses an iterative approach where generated tests are verified by running them, discarding those that fail. MIT licensed with over 5,300 GitHub stars.

Open Source

CyberArk's open-source LLM fuzzing framework for AI security testing

FuzzyAI is CyberArk's Apache-2.0 framework for fuzzing LLM APIs to identify jailbreaks and related security vulnerabilities. Current README examples cover Ollama/local models, OpenAI, Anthropic, custom REST endpoints, and attacks such as ManyShot, Taxonomy, and ArtPrompt. Use it as a repeatable security-testing starting point, not a complete AI risk-management system.

Open Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Schemathesis?

Schemathesis automatically generates test cases from OpenAPI and GraphQL schemas to find crashes, validation errors, and specification violations in APIs. It uses property-based testing and fuzzing techniques to explore edge cases that manual test writing misses. CLI tool and Python library with CI/CD integration. 3.4K+ GitHub stars with support for authentication, custom checks, stateful testing, JUnit XML, and Allure reports.

Is Schemathesis free?

Yes — Schemathesis is free to use. 100% free and open-source under the MIT license ($0). Includes standalone CLI (st), Python library, Pytest integration (@schema.parametrize()), unlimited local property-based fuzzing for OpenAPI (2.0/3.0/3.1) and GraphQL, stateful link testing, automated test shrinking, and CI/CD integrations (GitHub Actions, GitLab CI) with JUnit XML, HAR, and Allure test report exports.

Is Schemathesis open source?

Yes — Schemathesis is open source.

Is Schemathesis still maintained?

Yes — Schemathesis is active. Its listing was last verified on September 6, 2026.

What are the best Schemathesis alternatives?

The first editor-selected Schemathesis alternatives are qodo-cover, FuzzyAI.

How does Schemathesis score in our review?

The published editorial review lists Schemathesis at 85/100 overall across speed, privacy, and developer experience. Check the review's evidence status and test metadata for its verification level.