NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2283 most downloaded on PyPI
Adaptive API testing for OpenAPI and GraphQL
Last release today
04 Oct 2026
Ships fairly regularly
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
490 releases · first in 2019
Add HTTP 428 status to the allowed status list of the negative_data_rejection check. #2669
negative_data_rejection check. #2669Experimental unsupported_method check.
unsupported_method check.Authorization header in the experimental missing_required_header check.One column per quarter.
TypeError on extracting explicit examples.
TypeError on extracting explicit examples.Code sample containing incorrect HTTP method for the Unspecified HTTP method case in the coverage phase.
Unspecified HTTP method case in the coverage phase.TypeError on some x-www-form-urlencoded payloads during the coverage phase.Update the upper bound on pytest-subtests to <0.15.0.
pytest-subtests to <0.15.0.use_after_free as they don't indicate the presence of the previously deleted resource.pytest-subtests to <0.15.0.use_after_free as they don't
indicate the presence of the previously deleted resource.False positive in the ensure_resource_availability check.
ensure_resource_availability check.--experimental-no-failfast CLI option to make Schemathesis continue testing an API operation after a failure is found.
--experimental-no-failfast CLI option to make Schemathesis continue testing an API operation after a failure is found.Ignored request-related configuration inside the ignored_auth check. #2613
ignored_auth check. #2613UnicodeEncodeError when sending a request during the coverage phase.
UnicodeEncodeError when sending a request during the coverage phase.UnicodeEncodeError when sending a request during the coverage phase.
UnicodeEncodeError when sending a request during the coverage phase.Generating duplicate query parameters during the coverage phase.
data_generation_method reported during the coverage phase in some cases.Support arrays for headers & path parameters during the coverage phase.
ignored_auth stricter by always checking for the 401 status exactly instead of any non-200.meta.parameter in more cases during the coverage phase.Compatibility with Hypothesis > 6.115.6. #2565
Generate more negative combinations during the coverage phase.
Generate more negative combinations during the coverage phase.
Internal error on generating missed required path parameters during the coverage phase.
Generating test cases with missing required parameters during the coverage phase.
negative_data_rejection config to include fewer 4XX status codes (400, 401, 403, 404, 422).Support negative cases for items and patternProperties during the coverage phase.
items and patternProperties during the coverage phase.minLength & maxLength are taken into account when generating negative cases with pattern during the coverage phase.additional_checks & excluded_checks to Case.call_and_validate.ignored_auth if auth is provided via --set-query or --set-cookie.ignored_auth is not working under pytest.Performance regression caused by adjusted pretty-printing logic in Hypothesis. #2507
Hypothesis. #2507Support for pytest-subtests up to 0.14.
pytest-subtests up to 0.14.--experimental=positive_data_acceptancenegative_data_rejection check.False positive for ignored_auth when used in the stateful test runner. #2482
ignored_auth when used in the stateful test runner. #2482$ref in a path is incorrectly validated as invalid. #2484seed in cassettes if --hypothesis-derandomize is present.Meta information about generated data in the coverage phase.
Merge minLength & maxLength into pattern to avoid extremely slow generation in most popular cases.
minLength & maxLength into pattern to avoid extremely slow generation in most popular cases.{ and } for path parameters.Use requestBody examples as a source of valid input during the coverage phase.
requestBody examples as a source of valid input during the coverage phase.ignored_auth false positives on custom auth and explicit --auth CLI option. #2462pattern during the coverage phase.requestBody examples as the source of valid inputs during the
coverage phase.ignored_auth false positives on custom auth and explicit --auth
CLI option. #2462pattern during the
coverage phase.Reimplementation of test case deduplication in CLI. It effectively un-deprecates the --contrib-unique-data CLI option.
--contrib-unique-data CLI option.ignored_auth to check for incorrect auth.properties combinations for the coverage phase.default field as a source of valid inputs during the coverage phase.ctx as the first argument for all checks.
This is a step towards checks that cover multiple responses at once.ctx as the first argument.timeout in certain situations when loading the schema from the network.with_security_parameters in runner in some cases.Extend explicit examples discovery mechanism by checking response examples.
--dry-run is provided. #1423The example field was missed in the coverage phase.
example field was missed in the coverage phase.example field in the coverage phase.Use more explicit examples in the coverage phase.
generation_config in explicit example tests when it is explicitly passed to the test runner.Restructure the st run --help output.
st run --help output.-D CLI option is respected in the coverage phase.Unsatisfiable if it they previously had successfully generated test cases.New phase field to VCR cassettes to indicate the testing phase of each recorded test case.
phase field to VCR cassettes to indicate the testing phase of each recorded test case.Case.data_generation_method in test cases generated during the coverage phase.EXPERIMENTAL: New "coverage" phase in the test runner. It aims to explicitly cover common test scenarios like missing required properties, incorrect t
--experimental=coverage-phaseAdjust the distribution of negative test cases in stateful tests so they are less likely to occur for starting transitions.
Not using the proper session in the ignored_auth check. #2409
ignored_auth check. #2409ignored_auth.Error in response_header_conformance if the header definition is behind $ref. #2407
response_header_conformance if the header definition is behind $ref. #2407The ensure_resource_availability check. It verifies that a freshly created resource is available in related API operations.
ensure_resource_availability check. It verifies that a freshly created resource is available in related API operations.ignored_auth check. It verifies that the API operation requires the specified authentication.--generation-graphql-allow-null CLI option that controls whether null should be used for optional arguments in GraphQL queries. Enabled by default. #1994TestCase used by pytest & unittest integration.base_url is missing for a schema loaded from a file.Incorrect default deadline for stateful tests in CLI.
allOf subschemas in testing explicit examples. #2375Internal error in stateful testing.
Ignoring nested examples. #2358
--method, --endpoint, --tag, --operation-id, --skip-deprecated-operations CLI options in favor of the new --include-* and --exclude-* options. See mor…
Finally, flexible filters for API operations are released!
name.operation_id & tag filters in some cases.Hypothesis<6.108. #2357--method, --endpoint, --tag, --operation-id, --skip-deprecated-operations CLI options in favor of the new --include-* and --exclude-* options.
See more details in the CLI documentation.method, endpoint, tag, operation_id and skip_deprecated_operations arguments in schemathesis.from_* loaders and the parametrize function in favor of the new include and exclude methods on schema instances.Circular import in schemathesis.runner.events.
schemathesis.runner.events.Filtering by operation_id in conditional auth implementation.
operation_id in conditional auth implementation.--experimental=stateful-test-runner or --experimental=schema-analysis enabled. #2353Hello there! This release extends the recently released stateful testing and fixes a few bugs in there.
Hello there! This release extends the recently released stateful testing and fixes a few bugs in there.
--hypothesis-seed in new-style stateful tests.--set-* CLI options in new-style stateful tests.--max-response-time in new-style stateful tests.--request-* CLI options in new-style stateful tests.--generation-* CLI options in new-style stateful tests.--max-failures in new-style stateful tests.--dry-run in new-style stateful tests.all variant for the --hypothesis-suppress-health-check CLI option.6.108.0.data_generation_method value for HTTP interactions in VCR cassettes.--experimental=stateful-only. #2326--request-proxy for API probing.seed field in cassettes for new-style stateful tests.--exitfirst.Generating negative test cases for path and query parameters. #2312
negative_data_rejectionHTTP Archive (HAR) support comes to Schemathesis! :tada:
HTTP Archive (HAR) support comes to Schemathesis! :tada:
--cassette-format=har CLI option. #2299--generation-with-security-parameters=false CLI option to disable generation of security parameters (like tokens) in test cases.Missing overrides from --set-* CLI options in tests for explicit examples
--set-* CLI options in tests for explicit examplesInternal error when piping stdout to a file in CLI on Windows.
Excessive urllib3 warnings during testing localhost via https.
urllib3 warnings during testing localhost via https.Content-Type when documented content types contain wildcards.--output-truncate=false CLI option to disable schema and response payload truncation in error messages.
--output-truncate=false CLI option to disable schema and response payload truncation in error messages.EXPERIMENTAL: New stateful test runner in CLI. #864
--experimental=stateful-only CLI flag to run only stateful tests if the new test runner is enabled. Note that this feature is experimental and may change in future releases without notice.negative_data_rejection check. It ensures that the API rejects negative data as specified in the schema.use_after_free check. It ensures that the API returns a 404 response after a successful DELETE operation on an object. At the moment, it is only available in state-machine-based stateful testing.APIStateMachine.format_rules method to format transition rules in a human-readable format. POST /user
└── 201
├── GET /users/{ids}
└── DELETE /user/{id}
GET /users/{ids}
└── 200
└── PATCH /user
DELETE /user/{id}
└── 204
└── DELETE /user/{id}
minLength keyword on string path parameters to avoid the rejection of empty values later on.
This improves the performance of data generation.MaxRetryError. #2234pytest hooks. #2181response_schema_conformance failure messages. #2270RuntimeError caused by a race condition when initializing Hypothesis' PRNG in multiple workers.Case if it is mutated after the make_case call. #2208example key in Open API 2.0 schemas. #2277pytest<6.0.### :bug: Fixed - Remove temporary print calls.
print calls.Inlining too much in stateful testing.
INTERNAL: Remove the ability to mutate components used in schema["/path"]["METHOD"] access patterns.
schema["/path"]["METHOD"] access patterns.OperationNotFound raised in schema.get_operation_by_id if the relevant path item is behind a reference.KeyError instead of OperationNotFound when the operation ID is not found in Open API 3.1 without path entries.allow_x00=False in headers and cookies. #2220schema["/path"]["METHOD"] access patterns and reduce memory usage.get_operation_by_id method performance and reduce memory usage.get_operation_by_reference method performance.Internal error on unresolvable Open API links during stateful testing.
example or examples keys.add_link by avoiding unnecessary reference resolving.I am happy to announce Schemathesis 3.28 :tada:
I am happy to announce Schemathesis 3.28 :tada:
It does not include a lot of new features but instead clarifies error messages and makes Schemathesis work with more recursive references than before.
Request.deserialize_body and Response.deserialize_body helper methods to deserialize payloads to bytes from Base 64.multipart/mixed media type.Unsatisfiable error.GenerationConfig.headers.strategy attribute for customizing header generation. #2137
GenerationConfig.headers.strategy attribute for customizing header generation. #2137python -m schemathesis.cli. #2142anyio>=4.0. #2081The new release of Schemathesis introduces important changes for ASGI & WSGI applications. Now, you can use Case.call and Case.call_and_validate to ru
The new release of Schemathesis introduces important changes for ASGI & WSGI applications. Now, you can use Case.call and Case.call_and_validate to run tests directly, replacing the previous separate methods for these application types (call_asgi / call_wsgi)
Case.as_transport_kwargs method to simplify the creation of transport-specific keyword arguments for sending requests.Case.call work with ASGI & WSGI applications.Case.call_wsgi & Case.call_asgi in favor of Case.call.Case.as_requests_kwargs & Case.as_werkzeug_kwargs in favor of Case.as_transport_kwargs.Support for pyrate-limiter>=3.0.
pyrate-limiter>=3.0.\x00 bytes as a result of probes.Store time needed to generate each test case.
InvalidArgument when using from_pytest_fixture with parametrized pytest fixtures and Hypothesis settings. #2115Support for per-media type data generators. #962
application/yaml & text/yml media types in YAMLSerializer.Not respecting allow_x00 and codec configs options while filling gaps in explicit examples.
allow_x00 and codec configs options while filling gaps in explicit examples.multipart/form-data requests when the schema defines the */* content type.binary format.swagger key and the schema version is forced.Your coding agent can read these notes before it upgrades. Set up the MCP server →