NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2000 most downloaded on PyPI
Adaptive API testing for OpenAPI and GraphQL
Last release 2 days ago
19 Sep 2026
Ships fairly regularly
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
486 releases · first in 2019
Connection failures when using multiple workers on free-threaded Python due to shared requests.Session across threads. #3507
requests.Session across threads. #3507False positive negative_data_rejection for integer/number path parameters in the coverage phase.
negative_data_rejection for integer/number path parameters in the coverage phase.One column per quarter.
Negative testing support for GraphQL schemas. #2355
filter_case hook rejects all generated cases. Now reports "Hook Error" with actionable guidance.negative_data_rejection failures for format: password and other formats without validation semantics. #3480jsonschema-rs for data validation instead of jsonschema.PYTHON_GIL=0), providing up to 65% faster multi-worker execution.Examples phase crashing with RecursionError when multiple allOf items reference the same schema target.
RecursionError when multiple allOf items reference the same schema target.Detect foreign key fields (e.g., customer_id, order_ids) in responses and request bodies to generate additional stateful links.
customer_id, order_ids) in responses and request bodies to generate additional stateful links.map_*, filter_*, and flatmap_* hooks receiving GeneratedValue wrappers instead of raw dict values in negative generation mode. #3471Coverage phase hanging on endpoints with many optional parameters due to combinatorial explosion. #3046
TypeError when schema contains non-string pattern values (e.g., "pattern": 0.0).Custom media type strategies registered via schemathesis.openapi.media_type() not being applied in the coverage phase when using @schema.parametrize()
schemathesis.openapi.media_type() not being applied in the coverage phase when using @schema.parametrize(). #3345positive_data_acceptance failures caused by RFC-invalid control characters in generated headers. Positive mode now generates only valid ASCII headers. #3462Duplicate entries in required array causing "non-unique elements" schema validation errors. #3460
required array causing "non-unique elements" schema validation errors. #3460Mix schema examples into fuzzing and stateful data generation.
--report=ndjson) for exporting all engine events as newline-delimited JSON.-Output, -Input, Out, In, DTO).items (e.g., BackupFile from AllBackups.imports[])._name and -name parameter suffixes for resource inference (e.g., file_name -> File).file_name -> BackupFile.name, group_slug -> GroupSummary.slug).-H) not being passed to schema loading requests. #3440\p{L}, \p{N}) in response schemas causing crashes during dependency analysis.anyOf arrays (e.g., different const values) causing crashes during dependency analysis.#/x-bundled/schema1 instead of original refs like #/components/schemas/Item.This release focuses on test budget efficiency - getting more value from every test case.
This release focuses on test budget efficiency - getting more value from every test case.
Benchmarks against a real-world API show success rate improved from 5% to 48%, meaning tests now reach deeper application logic instead of being rejected at input validation.
\p{L}, \p{N}) to Python regex equivalents.null and boolean type mutations for path parameters to improve test budget efficiency.st.sampled_from for captured variants instead of schema augmentation.Pre-populate resource pool with values from response examples.
PermissionError when loading config file.Resources not captured when server returns different 2xx status code than documented.
### :memo: Documentation - Fix code snippets config.
Hook runtime errors are now reported as "Hook Error" instead of misleading "Schema Error".
Crash when parameter has non-string in value.
in value.pattern value.anyOf/oneOf containing only required constraints. #3404unhashable type: 'GeneratedValue' for multipart/form-data with custom encoding.Binary class causing JSON serialization errors in Hypofuzz due to dataclasses.asdict() exposing raw bytes.
Binary class causing JSON serialization errors in Hypofuzz due to dataclasses.asdict() exposing raw bytes.Add 409 to positive_data_acceptance check's default expected statuses to handle conflict responses (e.g., duplicate entries).
409 to positive_data_acceptance check's default expected statuses to handle conflict responses (e.g., duplicate entries).#/x-bundled/schema1 instead of original refs like #/components/schemas/Item.Hypothesis database setting from @settings decorator or loaded profiles being ignored with @schema.parametrize().
database setting from @settings decorator or loaded profiles being ignored with @schema.parametrize().AttributeError when using Schemathesis with HypoFuzz due to uninitialized _override attribute in ProjectsConfig.pytest-subtest from <0.15.0 to <0.16.0.Stateful testing crash on links with nested $refs. #3394
$refs. #3394Coverage phase now generates test cases for additionalProperties with schema constraints.
additionalProperties with schema constraints.maxProperties and minProperties constraints.prefixItems.anyOf/oneOf contains array schemas with tuple validation (items as list).format: binary in JSON request bodies.const and type keywords.PointerToNowhere error when prefixItems contains $ref in Open API 3.1 schemas.auth argument passed to call_and_validate not being recognized by the ignored_auth check. #3386False positive in negative_data_rejection check when numeric strings are generated for integer/number path parameters.
negative_data_rejection check when numeric strings are generated for integer/number path parameters.Use Python 3.14 in Docker images.
False positive in negative_data_rejection check when multiple mutations conflict. #3367
negative_data_rejection check when multiple mutations conflict. #3367/ in their string representation routing requests to the wrong endpoints during negative testing.False positive in negative_data_rejection check when single-element arrays serialize to scalar values for query/header/cookie parameters. #3375
Crash when handling connection errors with empty header values.
application/x-tar.Incomplete fix for false positive API rejected schema-compliant request for application/x-www-form-urlencoded with required body. #3360
API rejected schema-compliant request for application/x-www-form-urlencoded with required body. #3360format constraints like uuid.Nested external $ref links in multi-file schemas not resolving relative to their containing file. #3361
False positive in negative_data_rejection check for text/plain and application/octet-stream endpoints where non-string values become valid after seria
negative_data_rejection check for text/plain and application/octet-stream endpoints where non-string values become valid after serialization.negative_data_rejection check for text/plain and application/octet-stream endpoints where non-string values become valid after serialization.:tada: This release extends dependency analysis to non-stateful phases, so they can reuse successful API responses too.
:tada: This release extends dependency analysis to non-stateful phases, so they can reuse successful API responses too.
base_url.max_examples) is now properly applied to tests.schemathesis.openapi.from_url() now uses wait_for_schema from config when not explicitly provided.items: false with prefixItems in OpenAPI 3.1.0 schemas.encoding.contentType is an array. #3339format: binary and format: byte in negative testing.application/x-www-form-urlencoded bodies in negative testing. #3338application/x-www-form-urlencoded with WSGI apps.allOf contained $ref that required bundling.Invalid examples extracted from schemas with allOf and required fields. #3333
allOf and required fields. #3333Positive test cases generated without required body. #3327
schema.given now works with fixture-backed schemas regardless of decorator order. #3320
schema.given now works with fixture-backed schemas regardless of decorator order. #3320paths.Fix propagation of base_url / session data from Case.call_and_validate, so auth checks no longer crash when schemas are loaded from files. #3318
base_url / session data from Case.call_and_validate, so auth checks no longer crash when schemas are loaded from files. #3318OpenAPI-aware authentication via [auth.openapi. ] config. Automatically aligns with schema security definitions and warns about unused/misnamed scheme
pytest>=9.0. #3312[auth.openapi.<scheme>] config. Automatically aligns with schema security definitions and warns about unused/misnamed schemes. #1710contentType: "image/png, image/jpeg").contentType is specified in the OpenAPI schema.10-50% faster schema iteration through parameter bundling cache.
backoff with tenacity. #3286missing_required_header check message to show which header was missing instead of repeating the check title.Empty $ref references in schemas are now gracefully skipped during bundling.
$ref references in schemas are now gracefully skipped during bundling.schema.find_operation_by_path(method, path) to match actual request paths to API operations.
schema.find_operation_by_path(method, path) to match actual request paths to API operations.paths (e.g., webhook-only specs) by making path lookups resilient when paths is absent.$ref chains in response definitions.allOf structures.schema.find_operation_by_path(method, path) to match actual request paths to API operations.Content-Type header instead of always validating against the first declared media type.paths (e.g., webhook-only specs) by making path lookups resilient when paths is absent.$ref chains in response definitions.allOf structures.Extracting incomplete schema-level and property-level examples when parent schema with allOf has its own complete example. #3268
allOf has its own complete example. #3268not schemas in --mode=all vs --mode=negative.schemathesis and schemathesis run to improve readability in terminals.Support for custom content types in multipart/form-data encoding via OpenAPI's encoding property. #697
multipart/form-data encoding via OpenAPI's encoding property. #697fail-on in warnings configuration. #2956generation.allow-extra-parameters config option to control whether Schemathesis generates unexpected query, header, or cookie parameters in negative testing (set to false to skip them entirely).schemathesis.deserializer). #2934schema.as_state_machine().schemathesis.serializer.alias() to reuse built-in serializers (YAML, JSON, XML) for custom media types without reimplementing them. #2952schemathesis.openapi.media_type.operationRef and operationId.image/*) for all request body types, not just multipart encoding.result, data, response, payload).False positives in negative_data_rejection check when test cases are modified after generation by hooks, stateful testing, or auth providers. #3073
negative_data_rejection check when test cases are modified after generation by hooks, stateful testing, or auth providers. #3073schemathesis.pytest.from_fixture.negative_data_rejection check for all testing phases.Config-based auth, headers, test phases and generation settings not applied when using schemathesis.pytest.from_fixture.
schemathesis.pytest.from_fixture.schemathesis.pytest.from_fixture.schemathesis.pytest.from_fixture, causing AttributeError when accessing schemathesis.checks.*.Improve error message when remote reference is not JSON / YAML.
readOnly / writeOnly.Override order for explicit transport arguments to Case.call and Case.call_and_validate.
Case.call and Case.call_and_validate.required properties when they are absent from properties and additionalProperties is set to false.schemathesis.checks by using a module-level __getattr__.unsupported_method check.Unsatisfiable schema errors now show the specific parameter and its schema.
graphql package lazily.Unsatisfiable schema errors now show the specific parameter and its schema.Allow POST API operations without request bodies to be used in stateful tests when provided via explicit Open API links. #3087
POST API operations without request bodies to be used in stateful tests when provided via explicit Open API links. #3087Infer links based on common REST patterns.
query, header & cookie in dependency inference.Do not conservatively consider all recursive references as infinite ones in the examples phase.
allOf in the examples phase.tomli optional for Python 3.11+. #3199Internal error when generating an invalid type in the coverage phase.
Missing required request body for some schemas during the coverage phase.
hypothesis-jsonschema can generate data for them.Display mutation metadata in negative_data_rejection failures if available. Currently, only available for the coverage phase.
negative_data_rejection failures if available. Currently, only available for the coverage phase.items inside requestBody during dependency inference.Properly fix an empty list to phases.coverage.unexpected-methods disabling testing of unexpected HTTP methods.
phases.coverage.unexpected-methods disabling testing of unexpected HTTP methods.Case.validate_response. It is relevant for manually constructing Case instances outside of Schemathesis tests. #3184Support inference of dependencies from listings to subresources (GET /orders -> GET /orders/{id}/notes).
GET /orders -> GET /orders/{id}/notes).Setting an empty list to phases.coverage.unexpected-methods will disable testing of unexpected HTTP methods.
phases.coverage.unexpected-methods will disable testing of unexpected HTTP methods.RecursionError.requestBody in explicit links.requestBody is optional, choose empty body only in 5% of cases (instead of 50%).Deduplicate explicit and inferred links.
Use requestBody to infer producer -> producer dependencies.
requestBody to infer producer -> producer dependencies.negative_data_rejection failures in stateful tests.Incorrect reference resolution scope change when resolving responses. #1184
Path parameters with unsupported regex patterns now use sample values instead of failing generation during the coverage phase.
Automatic API Operation Dependency Detection: Schemathesis now automatically discovers dependencies between operations (e.g., POST /users -> GET /user
POST /users -> GET /users/{userId}), enabling stateful testing without manual configuration. Currently detects path parameter dependencies; query / body parameter support coming in next release.False positive error about recursive references when there are non-recursive and non-removable ones present in the same schema.
False positive schema error message due to incorrect schema type detection. #3149
Your coding agent can read these notes before it upgrades. Set up the MCP server →