NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2283 most downloaded on PyPI
Adaptive API testing for OpenAPI and GraphQL
Last release today
04 Oct 2026
Ships fairly regularly
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
490 releases · first in 2019
Crash in the coverage phase for large arrays of binary strings.
{identifier}.\p{L}.FutureWarning printed to stderr for some schema pattern values.curl commands.anyOf negative coverage cases when a referenced schema contains invalid keywords.$ref with sibling keywords.$anchor in Open API 3.1.$ref points at a whole external file.contains reported as Hypothesis Unsatisfiable.ValueError for non-JSON values such as datetime.date in schemas passed to from_dict.negative_data_rejection failures for empty query values of parameters with allowEmptyValue: true.negative_data_rejection failures for query values that become valid or disappear during serialization.itemSchema definitions in response validation.phases.stateful.max-steps = 50 silently capping scenarios at 6 steps.$ref document.429) responses counted as rejected data in the low_valid_rate warning.409 responses as conflicts, not rejected data, in the low_valid_rate warning. #4932One column per quarter.
Dependency inference unwraps result / data envelopes that carry metadata such as status or time .
result / data envelopes that carry metadata such as status or time.PUT /items/{name} as the creator when nothing POSTs to /items.ImportError on from schemathesis.checks import content_type_conformance (and other built-in checks) before a schema is loaded.schemathesis.check return type: decorated functions and classes keep their own type.base_url passed to Case.call ignored for WSGI applications.anyOf and oneOf.minItems.$ref schemas.minItems.prefixItems, if, or unevaluatedProperties.multipleOf schemas with large bounds.querystring parameters as percent-encoded raw queries.servers definitions as clean loading errors.content as a clean error.$schema URL.negative_data_rejectionminimum or other bounds.unsupported_method failures when a rate limiter answers an undeclared method with 429 Too Many Requests.checks.enabled = false not disabling custom checks.WFC Report output via --report wfc or --report-wfc-path .
--report wfc or --report-wfc-path.code.st replay options -H/--header, --auth, --auth-wfc and --auth-wfc-user for replayed requests.format: binary values include small valid PNG, JPEG, GIF, WebP, PDF and ZIP files.image.png.use_after_free and ensure_resource_availability failures note responses served from a cache.st run and st fuzz fail with exit code 2 when nothing is tested.st run and st fuzz exit 2 on schema, configuration and internal errors.st run, st fuzz and st replay exit 130 when interrupted with Ctrl+C.st replay step chains show each linked value as recorded -> replayed.st replay removes fixed crash files with masked credentials once config or CLI supplies them.generation.maximize or explicit hypothesis.target() calls.ignored_auth stops probing an operation once it rejects missing and invalid credentials.missing_deserializer warning names the response media types that go unvalidated.st run and st fuzzst fuzz --help omitting that fuzzing stops at the first failure without --continue-on-failure.st fuzz omitting schema errors of individual operations.st fuzz workers continuing after the first failure and reporting Stop reason: Completed.Stop reason: Time limit reached for runs stopped by a failure shortly before the deadline.continue-on-failure in the config file ignored.bool: True instead of boolean: true.st replay[auth.openapi] credentials, resending masked values instead.User-Agent and test case ID headers, or dropping -H headers.from_fixture tests missing from pytest Allure and JUnit results.epic label with the API title in CLI Allure results.exit_code of 0 in --report json for runs aborted by a fatal error.stop_reason of interrupted and empty errors in --report json for runs aborted by an error.before_load_schema and after_load_schema.filter_case and map_case in the pytest coverage phase.after_validate.apply_to and skip_for filters on hooks registered by name, e.g. hook("before_call").Unsatisfiable.application/x-www-form-urlencoded, multipart/form-data and formData request bodies.* wildcards never filling request body fields.$ref./projects/{code}.allOf.*/*.$ref applied in Open API 3.0 and Swagger 2.0 schemas.Header(None).$ref siblings dropped when the target defines the same keyword.contains keywords in Open API 3.0 schemas.format: binary strings ignoring minLength and maxLength.minLength: "x".--generation-unique-inputs treating inputs that differ only in sensitive parameter values as duplicates.--mode negative.enum, multipleOf or not in positive test cases.$ref.negative_data_rejection in coverage phase for parameters with unanchored pattern and maxLength.application/json while carrying raw text.True/False/None in label, matrix and object-style parameters.type lists and implicit object or array schemas.encoding styles ignored in application/x-www-form-urlencoded bodies.content parameters.Content-Type header that names another body media type.matrix/label/simple path parameters.Content-Type header that names another media type.boundary when Content-Type: multipart/form-data is set explicitly./ or ~ printed unescaped.1 more branches for a single branch.prefixItems element that admits no value.$ref branches of a oneOf.ignored_auth when unauthenticated requests redirect to a sign-in page.ignored_auth when an API-key cookie is passed via the Cookie header.ignored_auth when credentials are passed in an Authorization header the schema does not declare.negative_data_rejection for numeric array path parameters sent as a single number.negative_data_rejection for multipart bodies with --generation-unique-inputs.negative_data_rejection for string parameters declared as anyOf/oneOf with a false branch.validation_mismatch, missing_test_data and missing_auth warnings from undeclared-method requests.validation_mismatch and missing_test_data warnings from negative test cases.negative_data_rejection for repeated string query parameters whose every value is valid.negative_data_rejection for request bodies referencing a schema of a newer draft, such as one recursing through $dynamicRef.workers values; reject values below 1.bytes value.on:, passed to from_dict.Connection: close.curl reproduction commands for request data with C1 control or Unicode line-separator characters.curl reproduction commands sending wrong bytes in fish, or \$ for $ in bash.Case objects hashing differently when header names differ only in case.curl reproduction commands for non-ASCII request data.enum or const positions, such as recursive request bodies.maxItems, such as OGC CQL2 filters.Fuzz dictionary bindings for GraphQL arguments via <Type>.<field>.<argument> keys.
<Type>.<field>.<argument> keys.low_valid_rate warning for operations that accept few of the requests sent to them.Server Unavailable error.missing_test_data warns for GraphQL operations whose responses never carry data.st replay retries passing crashes up to three times and reports intermittent ones as FLAKY.extract_from = "cookie" takes a named cookie from a Set-Cookie login response.schemathesis.errors.FailureGroup for catching failures raised by validate_response.pytest 8.4.validate() and is_valid() on request parameters for checking values against the schema.negative_data_rejection for regex, uri-reference and similar string formats in fuzzing.response_schema_conformance for HEAD responses that declare a body.examples maps inside a parameter or body schema.extensions.examples keyword.$ref (//host/schema.json) failing to resolve for schemas loaded from a file.format: binary JSON bodies.null as a GraphQL schema violation, severity high.missing_test_data names the operation that appears to supply the data an unlinked operation needs, or reports that none does.Crash on schemas where properties is not an object.
properties is not an object.examples values that violate that schema in the examples phase.[[operations]].allOf members with wrongly typed examples or required.itemSchema and a sibling schema.allOf/anyOf branches.Examples phase fills missing values with schema default values; required parameter defaults count as examples.
default values; required parameter defaults count as examples.--report ndjson output containing only the Initialize event. #4807example/examples declared on array items in the examples phase.allOf, oneOf, and anyOf at any depth in the examples phase.ignored_auth crash on generated cookie values the stdlib parser rejects. #4804anyOf branches for examples when a schema declares both oneOf and anyOf.example and x-example values in a stable order across runs.x-example and x-examples in OpenAPI 3 parameters in the examples phase.enum rejects, which made those branches ungeneratable.Refine generation from Luracast Restler 4xx errors.
st starts about 2.5x faster.${VAR} in config values; $${ escapes it, any other $ stays literal. #4785QUERY in phases.coverage.unexpected-methods. #4787type.missing_required_header for 404 responses on generated path parameters.Schema Error aborting operations whose 4xx responses carry a malformed Content-Type.Recognize +yaml media types (e.g. application/apply-patch+yaml ) and YAML content types with parameters.
+yaml media types (e.g. application/apply-patch+yaml) and YAML content types with parameters.maximum/minimum that lies outside the range of format: int32/int64.enum and const values containing / by sending them percent-encoded.negative_data_rejection failure message.text/* media types without a dedicated serializer as plain text.email, hostname and uri values with a dotted domain, which strict checkers require. #4782allOf sharing a node with additionalProperties.ensure_resource_availability when a verb other than DELETE removed the resource.negative_data_rejection when another location's negation only adds undeclared parameters.ensure_resource_availability for a POST to a resource URI that does not create it.example values that omit required fields, and skip those the schema still rejects.!!binary.format: duration under Swagger 2.0 and Open API 3.0.format and a wider pattern both apply, instead of skipping the body.$ref base reused across nesting levels.Decline unbuildable negated bodies instead of raising UnsupportedSchema during negative generation. #4753
UnsupportedSchema during negative generation. #4753examples mismatch its schema.example, examples, and default values are invalid.items with a valid value when a conflicting sibling type would otherwise silence it.oneOf branch's own properties even when it can never win exclusivity over a sibling branch.null as an incorrect type for nullable OpenAPI 3.0 properties.Dependency inference links body fields to the collection listing their accepted values.
2.0) under Open API 3.1 and 3.2.filter_failure hook to drop check failures by a custom condition. #1792missing_test_data warning tips reflect whether links reach the operation and whether stateful testing ran.format, pattern, and a length bound together. #4593format and a length bound.format value can reach are ruled out without drawing.format: date-time values are built to fit a length bound instead of drawn until one fits.format: email and format: uri values are built to fit a length bound too.format and a length bound could not both be met. #4592missing_auth warning for operations that returned 2xx responses later in the run.KeyError from an evicted cache entry on free-threaded Python.dictionary changed size during iteration when several workers reuse values from responses.@Range bounds ignored in Spring error responses.format: int32/int64 range.--exclude-method and other exclusions ignored for unexpected HTTP methods in the coverage phase. #3142positive_data_acceptance and negative_data_rejection for 429 responses.--origin option that takes scheme, host and port, and appends the schema's own base path.
--origin option that takes scheme, host and port, and appends the schema's own base path.UnicodeDecodeError on non-ASCII response headers.Host than the schema fetch.abort(404) and 405 raised as internal errors.true / false / null.text/plain body booleans and nulls sent as Python literals instead of true / false / null.enum collapsing the URL segment.allOf of two disjoint contains.allOf branch forbids a required property with false.Content-Type header value its own schema rejects.responses node crashing operation counting.requestBody, content, media type, or security nodes aborting the run.components, path item parameters, or non-object reference targets aborting the run.servers URL templates aborting the run at startup instead of reporting a schema error.x-codegen-contextRoot beside the path templates crashing.$ref and a sibling keyword point at the same target.negative_data_rejection for an empty array or string the schema admits.negative_data_rejection for read-only properties a server ignores instead of rejecting.negative_data_rejection for operations whose security lists alternative requirements.negative_data_rejection and missing_required_header for 415 responses to requests without Content-Type.positive_data_acceptance when type lists null but enum omits it.positive_data_acceptance for nullable / x-nullable fields whose enum omits null.positive_data_acceptance for allOf mixing items with a sibling branch's prefixItems.--report json missing from the list of written reports in the run summary.UnicodeEncodeError when the output encoding cannot represent status glyphs, such as CP1252 on Windows.allow-extra-parameters = false ignored for request bodies in the fuzzing phase.-aUSER:PASS, -HAuthorization: ...) leaking into report command lines..schemathesis directory.--checks, including --checks all.st replay reporting sanitized crash files as fixed and deleting them.base_url_mismatch, unsupported_regex, unresolvable_reference in [warnings], and report invalid warning names clearly.pattern dropped from a request parameter or body.Negative coverage case that omits a request body the operation declares required.
_entities and _service stay out unless filters select them.base_url_mismatch warning when every response is 404 and --url omits the schema's base path.unresolvable_reference warning listing the parameters and responses skipped over a missing schema component.--max-time stops st run after the given number of seconds.--auth-wfc and --auth-wfc-user for Web Fuzzing Commons auth files.--report json writes the run's verdict as one JSON document.state in the ASGI lifespan scope.starlette-testclient and starlette dependencies.anyio 4.15.HEAD operations failing with an internal AttributeError.TypeError.ValueError.session passed to case.call() ignored.ALLOWED_HOSTS rejection reported without an explanation.Content-Type.multipart/mixed request bodies sent as an empty payload.authTemplate not merged into each entry when loading auth files.user is configured, as documented.token nor expectCookies rejected, ignoring the returned cookies.not over patternProperties.patterns must match at once.pattern that names a capture group.allowEmptyValue: false. #4574true / false / null.null sent instead of omitted.contentMediaType: application/octet-stream form fields not sent as file uploads.application/*+json sent without a concrete Content-Type.allOf requiring a property no branch combination admits.allOf branches naming integer and number as unsatisfiable.anyOf/oneOf violations for branches with $ref siblings.items violations for arrays declaring prefixItems.prefixItems when building array cases for OpenAPI 3.1 operations.properties does not declare from generated array items.propertyNames rejects.multipleOf value outside the float bound minimum and maximum pin.maxContains.responses that is not an object reported as a generic parsing failure.servers URL templates crashing instead of reporting a schema error.$ref values that name no readable file crashing instead of reporting an unresolvable reference.$ref in an optional parameter or required body rejecting the operation.$ref in a response schema rejecting the operation.openapi versions with a suffix, such as 3.1.0-custom, rejected.responses, such as x-note: null, rejected.ignored_auth for APIs that reject unauthenticated requests with 403.negative_data_rejection for example header and cookie values.negative_data_rejection for GraphQL when captured identifiers replaced the violating argument.negative_data_rejection for GraphQL arguments that declare a default value.negative_data_rejection for non-numeric query and path parameters whose serialized value is valid. #4600unsupported_method when a secured operation answers 401 or 403 before routing.unsupported_method for 404 responses on paths whose parameters are pinned.ignored_auth bypasses in APIs that accept any well-formed bearer or basic credentials.security accepts unauthenticated access via {}.{} is not allowed.negative_data_rejection message omitting parameter names when several parameters are mutated. #4600positive_data_acceptance extra-properties hint shown when the server rejects a declared field.st fuzz startup outlasts --max-time.NDJSON report spells phase names and skip reasons as machine tokens ( stateful , not_applicable ).
stateful, not_applicable).--header, --auth, --proxy and the schema URL stored unsanitized in the recorded command.Reports section of the CLI summary.pattern-matching string as a multipleOf violation for union types.oneOf branches admit when one keeps keywords beside $ref.$ref when generating values.patternProperties entries matching a declared property name.Support for validating httpx2 responses in Case.validate_response .
httpx2 responses in Case.validate_response.base_url error fires.warnings.fail-on in the --warnings help text.false for const: 0 (and vice versa) when intersecting allowed values.anyOf/oneOf/allOf or the keywords beside them.allOf branch requires and another forbids.anyOf/oneOf with keywords beside them.const that the rest of its schema rejects.oneOf value a second branch admits under the operation's draft.enum/const members the operation's draft rejects.example/default values the operation's draft rejects.anyOf/oneOf branch values against the parent in the wrong draft.multipleOf beside a numeric bound past 28 significant digits.multipleOf steps no float can carry, landing back on the excluded bound.exclusiveMinimum/exclusiveMaximum overriding a tighter minimum/maximum instead of combining.7.0.minimum/maximum repeats a large float exclusiveMinimum/exclusiveMaximum.integer when number is allowed too.multipleOf past 2^53.inf as a violation of a bound at the largest float.multipleOf.additionalProperties for required names absent from properties.maxProperties when covering a property the template omits.minProperties violation for untyped schemas.if, then, else, or not from nested templates.pattern whose minLength exceeds the generation buffer.minLength exceeds maxLength.maxLength.pattern whose minLength exceeds maxLength.minItems/minProperties past the generation buffer beside a combinator.minItems/minProperties floor past a smaller ceiling.maxProperties past the generation buffer.minItems without items, and building arrays past the generation buffer.minProperties past the generation buffer.minProperties in the hundreds and then emitting nothing.example/default values with non-alphanumeric characters.readOnly field.$ref targets differ.positive_data_acceptance for values with a sibling anyOf/oneOf in the coverage phase.negative_data_rejection for format: float bounds a single-precision server cannot distinguish.negative_data_rejection for numeric bounds past 2^53 in the coverage phase.negative_data_rejection for bodies whose schema declares a format anywhere.minItems/minProperties past the generation buffer as a schema error instead of a health check.anyOf/oneOf/$ref schemas losing their null branch to the default string type.anyOf/oneOf serialized as their property names.Report filter expressions that match no API operations, with the closest match as a suggestion.
allow_header_conformance check comparing the Allow header against the methods declared in the schema.pattern under a length bound.pattern whose repeated group cannot fit an exact length bound.pattern like ^[a-z]$ allows when maxLength is set.pattern with possessive quantifiers like 0++0 when a length bound is set.pattern naming characters outside generation.codec.\p{L}.(?<name>...).anyOf branches when one names an ungeneratable pattern.pattern the API enforces when Python cannot read it.format when generating string values for Open API 3.1.hostname and idn-hostname values that validators accept.pattern and format in a conjunction.contentEncoding and contentMediaType under Draft 7.type.oneOf / anyOf branches whose discriminator property is nullable.true/false/null for booleans and nulls nested in array query parameters.maxProperties when a captured resource value is injected.$id in place, without fetching it.$id is a bare fragment like #/definitions/text.pattern the validator cannot compile as an invalid regular expression.patternProperties regexes and patterns containing a quote.true.$response. in Open API links.on, off, yes and no in YAML documents as strings, per YAML 1.2.pattern with optional parts and maxLength.allOf, oneOf, or anyOf.\d and \w as ASCII.null for nullable schemas an allOf sibling restricts to objects.allOf schemas with no equivalent flat form.required from allOf branches that sit beside an unresolved $ref.allOf, like additionalProperties: false.allOf sibling forbids.positive_data_acceptance for values a sibling not excludes.anyOf / oneOf in bodies, like items or additionalProperties.maxLength violation for a pattern whose repeated group spans two lengths.$ref. #4499unsupported_method when a templated path returns 404 instead of 405. #4503operation-id.phases.fuzzing.generation.modes.positive_data_acceptance for not clauses in schemas using references.positive_data_acceptance for credential-granting operations answering 400 or 422.negative_data_rejection for empty array path parameters.--checks selects only specific checks.--suppress-health-check with a subset of checks re-enabling the rest in stateful tests.RuntimeError: generator ignored GeneratorExit when an interrupt arrives while the event stream closes.pattern across operations.pattern strings with maxLength above 8192.pattern.maxItems above 15.pattern strings whose quantifier sits inside a group.pattern no value can violate.pattern strings with a high minLength.hypothesis-jsonschema dependency.Faster strategy construction for string , integer , and anyOf schemas.
string, integer, and anyOf schemas.string, integer, and anyOf schemas built from the jsonschema-rs canonical form.string, integer, and anyOf schemas.string, integer, and anyOf schemas built from the jsonschema-rs canonical form.positive_data_acceptance hint counting properties declared under allOf/anyOf/oneOf as undocumented.
positive_data_acceptance hint counting properties declared under allOf/anyOf/oneOf as undocumented.$ref. #4350config.*.update() ignoring invalid values and resetting flags it was not given.Fuzz dictionaries not applied to body fields nested under oneOf/anyOf/allOf or if/then/else. #4347
oneOf/anyOf/allOf or if/then/else. #4347enum, const, and bare type schemas moved to jsonschema-rs.Dynamic token authentication support for OAuth2 and OpenID Connect security schemes.
auth.dynamic.openapi.<scheme>.retry-on, @schemathesis.auth(retry_on=[401])).401/403 responses from a dynamic authentication token endpoint as rejected credentials.dictionary changed size during iteration with multiple workers under free-threaded Python.$schema dialect.positive_data_acceptance for required array query parameters generated as empty.negative_data_rejection for body schemas with additionalProperties: false. #4332prefixItems in OpenAPI 3.1 schemas.Cannot sample from a length-zero sequence for array items with an empty enum.positive_data_acceptance for array items with enum entries violating the item schema.$refs silently skipped when dependency ordering applies.missing_deserializer warning for media types whose own schema is unstructured.Configuration Error heading.missing_deserializer warning by media type, one line per operation.Reuse literal values from the application's Python source during generation. Disable via analysis.constants.enabled.
analysis.constants.enabled.[auth.wfc].429 retries honoring the Retry-After header with --rate-limit=auto. #1722checks.response_schema_conformance.validate-formats to disable format validation in response checks. #2481positive_data_acceptance for arrays with contains/minContains/maxContains in the coverage phase.positive_data_acceptance for objects with dependentRequired/dependentSchemas in the coverage phase.negative_data_rejection for objects combining additionalProperties with matching patternProperties.positive_data_acceptance for path integers at the schema minimum. #4312format: int32/int64. #593multipleOf with minimum and maximum in the coverage phase.negative_data_rejection for const and propertyNames under Open API 3.0 in the coverage phase.int64 minimum accepted during schema validation.False positive use_after_free when PUT re-creates a resource after DELETE. #4286
use_after_free when PUT re-creates a resource after DELETE. #4286jsonschema-rs upgraded to 0.47.0 with better validator build performance.Intermittent internal traceback for arrays requiring items that can never be generated. #4282
Response schema conformance failures name the matched response status code. #4272
False positive negative_data_rejection when a before_call hook overwrites an invalid parameter with a valid value. #4277
negative_data_rejection when a before_call hook overwrites an invalid parameter with a valid value. #4277Class-based checks that run per response and once after the whole run. #1147, #1689
st replay. #3006junit-xml dependency; generate JUnit reports with the standard library.tenacity dependency in favor of the standard library.httpx dependency.False positive negative_data_rejection for boolean query/path parameters in the coverage phase. #4254
Encode spaces in path parameters as %20 instead of +. #4252
%20 instead of +. #4252False positive response schema validation for nullable enums (type: [..., "null"] with enum). #4249
type: [..., "null"] with enum). #4249False positive positive_data_acceptance for array parameters with a percent-encoded ,/| separator. #4246
positive_data_acceptance for array parameters with a percent-encoded ,/| separator. #4246Infer stateful links for path parameters named after their collection (e.g. /sessions/{session}).
/sessions/{session}).False positive negative_data_rejection for array path parameters serializing to a valid comma-joined value. #4240
negative_data_rejection for array path parameters serializing to a valid comma-joined value. #4240False positive negative_data_rejection with a globally-registered @schemathesis.auth handler setting a cookie. #4236
negative_data_rejection with a globally-registered @schemathesis.auth handler setting a cookie. #4236False positive negative_data_rejection when using @schemathesis.auth with a cookie security scheme. #4236
Response cookies leaking between generated test cases, causing false authentication failures.
Missing boundary negative in the coverage phase for boolean exclusiveMinimum / exclusiveMaximum.
exclusiveMinimum / exclusiveMaximum.UnicodeEncodeError when failure or error output contains lone Unicode surrogate characters. #4229Chain GraphQL operations on non-id identifiers (fullPath, slug, ...) in stateful and fuzzing phases.
id identifiers (fullPath, slug, ...) in stateful and fuzzing phases.maxLength / maxItems.maxLength / maxItems values.hypothesis-graphql to 0.13.0 that brings up to 180x performance improvements for deeply nested GraphQL schemas.harfile to 0.5.0 for slightly better performance.const / enum fields with invalid data.additionalProperties: false from Pydantic extra_forbidden errors and the exception_detail validation envelope.Skip coverage generation for header and cookie parameters whose pattern requires a non-alphanumeric character.
pattern requires a non-alphanumeric character.Fuzzing phase marked as failed without any reported failure. #4209patterns with maxLength.max_response_time failures.Re-raise original server exceptions in WSGI apps for distinct error deduplication. #1289
pattern requires /, {, or }.Skip coverage boundary-length variants that are structurally impossible for the declared pattern.
pattern.tls-verify and tls-cert to dynamic auth token requests. #4199Override server variable defaults via [servers.variables] in config. #4166
[servers.variables] in config. #4166payload_content_type. #4167properties declared next to a non-object type.$ref instead of generating null/{}.servers[] declared at path-item and operation scopes. #4166minLength negatives for string schemas whose pattern requires more characters than minLength - 1.minLength/maxLength negatives for string schemas whose format (e.g. email, uuid) makes the bounded length unsatisfiable.enum / const keywords when entries violate the declared type by emitting each entry as a negative case.Content-Type: application/json on JSON-serialized nested multipart/form-data parts.AAA) as the string-type negative for non-string parameters so ?q= no longer collapses to absent on the wire.AttributeError.maxLength negatives for string schemas whose format makes the exact length unsatisfiable when maxLength exceeds 100.negative_data_rejection for integer enum entries under type: integer / type: number.Stateful tests damp reuse of extracted values from unreliable API links.
.schemathesis/; probing replays them to skip rediscovery.[dictionaries.<name>] and [generation.dictionaries]. #2121[parameters] with body.<jsonpath> keys.$ref paths containing URI-reserved characters (e.g. paths/{id}/op.yaml). #4152$ref strings without a / separator.--report-allure-path (or reports.allure.path) cannot be used as a filesystem path.RecursionError in coverage phase on multi-branch allOf schemas that canonicalish cannot simplify.collectionFormat.minItems: 1 arrays when items is unsatisfiable.maxLength thresholds between 32 KB and 1 MB.allOf when a sibling property uses a bundled $ref.maxItems negatives for uniqueItems: true arrays whose items.enum domain is exhausted.enum to that domain via items.enum.items is declared without type: array.maxLength negatives even when the schema's pattern is intrinsically unsatisfiable.pattern negatives for header and cookie parameters.Optional[Enum] query parameters (anyOf with $ref and sibling enum).repr.positive_data_acceptance for body schemas with additionalProperties: false inherited via allOf.positive_data_acceptance for maxItems: 0 arrays whose items schema is satisfiable.positive_data_acceptance for not clauses whose violations breach other outer constraints.positive_data_acceptance when a discriminator branch references a polymorphic schema.positive_data_acceptance when sibling oneOf/anyOf constraints reference bundled $ref schemas.Render negative_data_rejection mutation descriptions cleanly: no trailing at, readable original values.
negative_data_rejection mutation descriptions cleanly: no trailing at, readable original values.prefixItems. #4099negative_data_rejection when a before_call hook reassigns request parameters. #4101minItems so per-item violations fire instead of length violations.formData Swagger 2.0 parameters as form payloads when consumes only declares non-form media types.additionalProperties: false through deep allOf chains.sqlite-libs in docker images.discriminator branch when the type tag literal differs from the schema name.Serialize nested-object query parameters using recursive bracket notation.
oneOf: [array, string] parameters by forcing non-empty strings.Content-Type to the body media type when it is declared as an explicit header parameter.pattern/minLength/maxLength (e.g. Kubernetes CRDs).$ref schemas carrying sibling validation keywords.additionalProperties: {schema} on objects without explicit type: object.type: array parameters so item-level keywords reach coverage.*/* from Swagger 2.0 consumes so coverage requests carry a concrete Content-Type.negative_data_rejection.--wait-for-schema. #4058negative_data_rejection on query-level additionalProperties mutations. #3730$ref in positive_data_acceptance hint to avoid false "additional properties" suggestions.allOf with readOnly required properties.uniqueItems.Crash in coverage phase on multipart bodies whose schemas reference each other.
application/x-www-form-urlencoded bodies declared as top-level arrays or scalars.$ref body before required-path propagation.id field.Probe for strict URL decoders (Tomcat, common WAFs) and sanitize backslash/control chars from generated path strings when the server rejects them.
pattern against maxLength.example/examples/default values that cannot be validated against the schema in positive coverage.phases.stateful.enabled = false in the state machine.must not be blank feedback as a body-required signal so generation stops emitting empty bodies.content as a single-property response wrapper during dependency inference.use_after_free false positives when the DELETE itself returned a non-2xx status (server crash or 404).Seed strategy draws in add_single_example unconditionally so example generation is deterministic.
add_single_example unconditionally so example generation is deterministic.application/jwt, text/json, application/x-json as JSON media types.oneOf branch when the branch is a $ref with sibling pin keywords.example/examples/default on array items so curated values reach populated arrays instead of synthetic empty fills.example/examples/default values that carry readOnly-stripped properties by dropping those keys before validating.oneOf/anyOf branches when spec examples only match a sibling branch.multipart/form-data string properties — stringification makes them wire-indistinguishable from enum violations.if/then/else constraints in positive and negative coverage.type and enum when canonicalization drops the explicit type.$ref in OpenAPI 3.0 / Swagger 2.0 schemas.maxProperties in positive coverage cases for additionalProperties schemas.required for allOf schemas combined with nullable $ref.anyOf/oneOf constraints.minItems negatives for array schemas that also declare examples/example/default.maxLength/minLength boundary strings for nullable string schemas (type: ["string", "null"]).items branch in positive coverage when the array has size constraints.multipart/form-data property mutations whose stringified value still satisfies the schema.default and example spec hints (0, "", false, [], {}) in positive coverage.example/default into recursively-generated object templates instead of synthesising values that ignore them.type: ["string", "number", ...] schemas in positive coverage.propertyNames: emit objects with keys violating the sub-schema constraints.Capture identifiers from { : , ...} map-by-id GET responses (e.g. team / pod / cluster status maps).
{<id>: <object>, ...} map-by-id GET responses (e.g. team / pod / cluster status maps).405 Method Not Allowed and surface a method_not_allowed warning.extra-data-sources config for the examples and coverage phases. #3972schemathesis.toml for editor autocompletion. #3971pattern rewrites that collapse optional variable-length sub-groups to {0}.{} as positive coverage body for schemas with minProperties but no required fields.oneOf/anyOf branches violating a root-level constraint (e.g. type: object branch under type: array root) were yielded as valid.readOnly fields nested in allOf and listed in parent required.minimum: 0 / maximum: 0 and Draft 4 boolean exclusiveMinimum / exclusiveMaximum in coverage-phase number generation.multipleOf due to IEEE-754 subtraction (e.g. 99999.99 - 0.01).exclusiveMinimum: 0 + exclusiveMaximum: 1).minLength / maxLength when the pattern rewrite cannot encode them.format: uuid negative cases in coverage on OpenAPI 3.0 / Swagger 2.0 schemas.minProperties / maxProperties violations for object schemas alongside additionalProperties.paths ordering.allOf / oneOf / anyOf composition.$ref targets when generating from cached schemas.positive_data_acceptance when a runtime pool body variant was missing required fields. #3949use_after_free checkuse_after_free on a second DELETE - DELETE is idempotent (RFC 7231 §4.3.5).use_after_free after a DELETE on a collection path with no path parameters.use_after_free reproduce when it is a sibling step.negative_data_rejection for integer/number query parameters when an array element is a numeric string. #3931negative_data_rejection on 405 responses from routing-level rejection.negative_data_rejection for body schemas combining $ref with sibling keywords.response_headers_conformance for Swagger 2.0 array headers serialised via collectionFormat.{0,N} regex quantifiers (e.g. {0,404600}).Runtime Error from invalid Schema Object when every required parameter of a set is excluded from generation.filename on binary multipart/form-data parts; use encoding.headers.Content-Disposition if present, field name otherwise. #3951. and .. path-parameter values; URL normalisation routes the request to a different operation.locationId, userUuid, orderId).site_ids, userUuids, session_guids)._name-suffixed body fields as attributes when no path or schema backs the inferred resource (first_name, last_name).Group / Group1, Member / Member1).jsonschema.application/jose+jwe as JSON media type.Capture path-parameter values from successful 2xx requests for reuse during fuzzing.
st fuzz scenarios via inferred and schema Links, biased 80% toward link-driven steps.<resource>Name-style body fields on collection paths (e.g. POST /products {productName: ...}).username, containerGroupName).POST /resource/{name} as a producer when the response has no body.POST /collection {idField: ...} as a producer when the response has no body.GET /collection returning an array of identifier strings.{ids} path parameters (e.g. GET /persons/{ids}).negative_data_rejection for body-level type mutations on multipart/form-data endpoints. #3801negative_data_rejection for body fields with format: binary or format: byte.properties (e.g. an integer where a sub-schema is expected).hypothesis-jsonschema constants in the same process.$ref with sibling keywords when exploring the Python API outside the pytest runner.HypothesisRefResolutionError when a $ref and its target both have distinct anyOf lists.description: null) as a clean schema error.Unsatisfiable for arrays with allOf of multiple contains requiring distinct const values.InvalidSchema instead of a generic InvalidArgument from the strategy generator.InfiniteRecursiveReference on cycles breakable through patternProperties.InfiniteRecursiveReference on cycles breakable through oneOf/anyOf, top-level allOf, or unused definitions.\p{X} Unicode property escapes inside character classes (e.g. [\p{Alnum}_]+).[[:alnum:]_]) to Python equivalents instead of misparsing them.\p{X} patterns combine with PCRE class-set operators (||, &&) or nested classes.prefixItems. #3842discriminator pin in oneOf/anyOf validation under Draft 4 (OpenAPI 2.0/3.0).FlakyStrategyDefinition from st fuzz when the time limit trips mid-scenario.format: binary data alongside captured pool values.type: object.1 when the path also contains an integer parameter.requests import race in the writer.meta in NDJSON reports.auth API on LazySchema to match BaseSchema. #3797
auth API on LazySchema to match BaseSchema. #3797schemathesis.openapi.require_security_scheme() for scoping auth providers to specific OpenAPI security schemes. #3745
schemathesis.openapi.require_security_scheme() for scoping auth providers to specific OpenAPI security schemes. #3745style/explode are omitted from the spec, ignoring OpenAPI 3.0 defaults.encoding.contentType. #3785before_call hook setting a missing required header in the coverage phase had no effect. #3784positive_data_acceptance false positivesexample values violating constraints (examples phase):
example has a property violating a nested format constraint (e.g. date-time without timezone).example value violates its declared schema type.example violates the parameter's own constraints (e.g. pattern).format constraint.example violates its field's own type (also applies to the coverage phase).anyOf/oneOf constraints via bundled $refs.minItems > 1 and object items.allOf with additionalProperties: false).Composition (allOf / oneOf / anyOf / $ref) in the coverage phase:
oneOf branches with nested multi-$ref allOf.oneOf body schemas where generated values satisfy multiple branches simultaneously.oneOf body schemas where a branch requires fields only defined in the parent schema.anyOf branch has const: null but a sibling type constraint excludes null.allOf chain causes required properties from a base schema to be generated as null.$ref + additionalProperties: false and pattern/minLength/maxLength constraints.enum vs sibling constraints (coverage phase):
enum constraint.enum values violate a sibling constraint (e.g. maxLength).type (e.g. YAML-parsed false for type: string).enum contains values violating the declared type in template body generation.Structural required / properties mismatches:
required lists fields absent from properties (examples phase).required properties absent from properties (coverage phase).type: object alongside items (coverage phase).false schema (coverage phase).type: string properties that also declare properties: {} (coverage phase).Pattern / keyword combinations (coverage phase):
pattern containing alternation inside a quantified group (e.g. ([a-z]|-[a-z])*).format: uuid and optional-hyphen pattern.pattern alongside a non-string type (e.g. number).propertyNames restricts object keys and additionalProperties is present. #3771format constraints in negative mode.negative_data_rejection false positivespattern + length-constraint interaction:
pattern + maxLength where maxLength was silently lost into an unanchored regex quantifier.pattern has an inner quantifier (e.g. ^[a-z]([-a-z]*[a-z])?$) and maxLength is present.pattern optional group wraps variable-length content and maxLength is present (coverage phase).pattern with nested quantifiers caused maxLength/minLength to be silently dropped from the schema.pattern fields ending with \x1c–\x1f control characters (coverage phase).Wire-identical type mutations:
application/x-www-form-urlencoded and application/xml body properties where type mutations are wire-identical (e.g. integer stringifies to a valid string).application/x-www-form-urlencoded body properties whose schema contains $ref to bundled definitions.application/x-www-form-urlencoded body properties with nested array/object mutations whose serialized form satisfies the schema.Schema-shape edge cases (coverage phase):
additionalProperties is a schema object and required has exactly 2 fields.properties and exactly 2 required fields.additionalProperties: {}.maxLength, minLength, or format constraints.enum and maxLength/minLength.type: integer and inapplicable minLength/maxLength constraints.multipart/form-data fields with format: binary and nullable: true. #3777maxItems array constraints with complex nested item schemas.negative_data_rejectionpattern produces a large DFA (e.g. \S{1,8192}).pattern that jsonschema_rs rejects (e.g. {,3} as an incomplete quantifier).integer form-urlencoded schema).application/x-www-form-urlencoded requests with format: binary body fields in negative mode.not: {}).on: fields) in the coverage phase.required names a property absent from properties in the coverage phase.enum at the array level with items also defined in the coverage phase.allOf (with required fields) and outer-level properties in the coverage phase.default or example fails format validation (e.g. "7.00:00:00" for format: duration) in the coverage phase.Show compact path for body property violations instead of a verbose chain.
negative_data_rejection for integer query parameters with type mutations. #3712positive_data_acceptance for arrays with uniqueItems and enum items.False positive negative_data_rejection for type: number body fields in fuzzing. #3697
negative_data_rejection for type: number body fields in fuzzing. #3697negative_data_rejection for type: integer query parameters mutated to array. #3697content: application/json query parameters in coverage phase. #3701$ref properties ignored in examples phase for OAS 3.1 schemas. #3698positive_data_acceptance for headers with RFC 9110 control characters. #3696positive_data_acceptance for path parameters containing null bytes. #3696unsupported_method failures from coverage phase. #3699st fuzz command for continuous multi-step API fuzzing across operation sequences.
st fuzz command for continuous multi-step API fuzzing across operation sequences.If-Match, If-None-Match, If-Modified-Since, If-Unmodified-Since, and Range headers.filter_case and map_case hooks in the coverage phase. #3675schemathesis.pytest.parametrize() for testing multiple named schemas in a single test function. #1409discriminator property values against known schema mappings in response_schema_conformance. #1589discriminator property to the correct value when generating data for oneOf/anyOf schemas. #1589--wait-for-schema retry on HTTP 503 responses. #3672pytest plugin.schema.parametrize().response_schema_conformance and response_headers_conformance. #1174deadline=None lost when @settings applied after @lazy_schema.parametrize().
deadline=None lost when @settings applied after @lazy_schema.parametrize().format: uuid now generates RFC 4122 compliant UUIDs. #2909AttributeError on DoctestItem when schemathesis plugin is loaded. #3663
ModuleNotFoundError on xdist session end when the allure extra is not installed.
ModuleNotFoundError on xdist session end when the allure extra is not installed.Allure report integration. #2756
pytest plugin via schema.config.reports. #701after_validate hook fires after all checks run on a response, carrying a list of CheckResult objects.oneOf/anyOf branch. #2371format: email fields generating values rejected by jsonschema_rs response validation.flatmap_* hooks raising RuntimeError in negative testing mode. #3652allow-extra-parameters = false now also suppresses unexpected properties in request bodies.use_after_free) not triggering when run via schema.as_state_machine().InvalidSchema exceptions displayed an empty message in pytest output.HypothesisWarning when overriding built-in string formats via schemathesis.openapi.format(). #3269[auth.dynamic.openapi. ] config block for token fetch authentication that allows for dynamic authentication without writing Python code. #3620
[auth.dynamic.openapi.<scheme>] config block for token fetch authentication that allows for dynamic authentication without writing Python code. #3620--request-retries to retry requests on network failures with exponential back-off.apply_to / skip_for filter sets not updated between hook registrations, causing hooks registered after the first to silently receive the wrong filter set.minLength/maxLength constraints in the coverage phase when update_quantifier cannot encode length into the pattern.False positive positive_data_acceptance in the coverage phase for path parameters with minLength greater than 1.
positive_data_acceptance in the coverage phase for path parameters with minLength greater than 1.Malformed request body media types (e.g. application.json instead of application/json) now report a clean "Schema Error" with the location in the sche
application.json instead of application/json) now report a clean "Schema Error" with the location in the schema instead of a raw Python traceback. #3615Your coding agent can read these notes before it upgrades. Set up the MCP server →