NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2283 most downloaded on PyPI
Adaptive API testing for OpenAPI and GraphQL
Last release today
04 Oct 2026
Ships fairly regularly
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
490 releases · first in 2019
1f69add Deprecate schemathesis.runner.prepare
requests related options for the replay commandAPIOperation.iter_parameters helper to iterate over all parameters.readOnly and writeOnly Open API keywordsbefore_init_operation hookdescription attribute for all parsed parameters inside APIOperation.process_call_kwargs CLI hookbefore_call and after_call CLI hooks.ExecutionEvent.is_terminal attribute that indicates whether an event is the last one in the streamevents.stop()Case.data_generation_method attribute that provides the information of the underlying data generation methodBeforeExecution.verbose_name & SerializedCase.verbose_name that reflect specification-specific API operation nameNO_COLOR environment variable or the --no-color CLI optiondata_generation_methods and code_sample_style in all GraphQL loadersapp & base_url arguments for the from_pytest_fixture runnerfrom_wsgi loader for GraphQL appsbefore_generate_case hookevent_type field to the debug output--debug-output-file CLI option to enable storing the underlying runner events in the JSON Lines format in a separate file for debugging purposescount_operations flag to runner.prepare--dry-run CLI option. When applied, Schemathesis won't send any data to the server and won't perform any response checkstext/plain media types with charsetresponse_schema_conformance check on media types that are encoded with JSON (#927)full_path in error messages in recoverable schema-level errorscorrelation_id in BeforeExecution and AfterExecution events if the API schema contains an error that causes an InvalidSchema exception during test execution.content or schema keywordsbase_url in call_asgi, when the base URL has a non-empty base pathfrom_pytest_fixture match no API operationsparameters keyfrom_pytest_fixturedata_generation_methods config option defined on a schema instance when it is loaded via from_pytest_fixtureKeyboardInterrupt that happens outside of the main test loop inside the runnerpytest-legacy jobdata_generation_method to GraphQLCasehypothesis-jsonschema releasecase.validate_responseexit_first enabledTypeError on case.call with bytes data on GraphQL schemasmake_case calls for GraphQL schemas.TypeError during negative testing on Open API schemas with parameters that have non-default style valueKeyError when the response_schema_conformance check is executed against responses without schema definitionEventStream.stop is called, the next event always is the last onestyle & explode for parameters derived from security definitionsstyle & explode keywords to explicit examplestypepattern keywordmultipart/form-data media typeContent-Type override in Case.as_requests_kwargsmultipart/form-data media type$ref keyword in schemas with deeply nested references.date string formatUnicodeEncodeError when sending application/octet-stream payloads that has no format: binary in their schemashypothesis-graphql version to 0.4.1UnicodeDecodeError during schema loading via the from_path loader if it contains certain Unicode symbolspytest fixtures with the from_pytest_fixture loadermake_case for GraphQL schemas@schema.given implementation for schemas created via the from_pytest_fixture loaderimportlib-metadata==3.8 in dependencies$response.body and $request.body runtime expressionsbody parameters during Open API links processing in CLIFAILURES block of the CLI outputUnicodeDecodeError on cURL command generation. and .. strings in path parametersTypeError when additional_checks is a listadd_linkFlaky Hypothesis error during explicit examples generationx-examplesTypeError during nullable array parameter serializationAPIStateMachine.stepUnsatisfiable error in stateful testingUnsatisfiable errors--exitfirst CLI option trims the progress bar output when a failure occurstyping instead of typing_extensionsGET and has payload examples (#930)null payload (#929)null as request payload if the schema expects it (#922)Case instances before passing to check functionsWerkzeug>=2.1.0aevea/action-kanikorequests kwargs to catch cases when the ASGI integration is used, but the proper ASGI client is not suppliedduplicate-code pylint lintTRACE method on Open API 2.0response.elapsed to Schemathesis.ioAfterExecution.data_generation_methodstr for subtest contextschema.parametrize matches no API operationsverbose_name & data_generation_method parameters to subtest context instead of path & methodCase.headersdefault_language_version for pre-commitDataGenerationMethod instances for the data_generation_methods argumentAfterExecution.verbose_nameBeforeExecution.from_operationdata_generation_method in BeforeExecutionjsonschema errors which are caused by non-string object keyscURL code samples by default instead of PythonDataGenerationMethod.all shortcut to get all possible enum variants.DataGenerationMethod instances for the data_generation_methods argumenttool.poetry.urls sectionheader filtration when not necessaryOpenAPI20CompositeBody.definition type to List[OpenAPI20Parameter]werkzeug to >=0.16.0parameter_cls attributes from BaseOpenAPISchemaresponse from case.call_and_validateFailureContext class attributes to instance attributesSerializedCase.cookiesInitialized eventExecutionEvent.asdict adds the event_type field which is the event class nameEventStream.finish methodAPIOperation.make_case behaviorhypothesis-jsonschema versionTrue, False and None are converted to their JSON equivalents when generated for path parameters or queryUsageError if schema.parametrize or schema.given are applied to the same function more than once/exampleSerializedCase.path_template return path templates as they are in the schema, without base pathSerializedCase.media_type attributenot_a_server_error and status_code_conformance checks.hypothesis-jsonschema versioncolorama to dependencieshypothesis-jsonschema version constraintstarlette to >=0.13,<1shutdown on all handlers before CLI exithypothesis-graphql version to 0.5.0pylint and mypy tox envstox warningschemathesis.runner.preparefrom_path incorrect usageGraphQLSchema.get_stateful_testsschemathesis_SerializedCheck.example and Check.example not optionalcryptography version in Docker imagesget_operation_by_idfrom_aiohttp in the public APIStateful in the public APIinit_default_strategies in the public API/app--base-url for schemas loaded via a file when dry run is enabledbefore_add_examples hooks even if default examples generation failedall option to the test serverseed-isort-config pre-commit hookpre-commit to v3.4.0--auth together with --header that sets the Authorization header.get_case_strategy calltest_read_onlysetuptools explicitlymax_examples in test_hidden_failure to decrease the number of flaky test runspoetry versionsuppress_health_check to test_pet to avoid flakinessDeriving Semantics-Aware Fuzzers from Web API Schemastest_app on WindowsMutationResult.is_success and MutationResult.is_failure helperssplit_schema results for Open API schemas during negative testingget_full_path for Open API schemasrewritten_componentscomponents/schemas before passing schemas to hypothesis-jsonschemacopy.deepcopy calls in some casesresolve_all call in some casesdeepcopy in some casesis_valid_headerresult.verbose_name unconditionally in display_subsectioncls in class methods instead of concrete classesadd_case hookdeadline in flaky teststest_path_parameters_encodingsphinx_rtd_theme versionAPIStateMachine.get_call_kwargsEffective API schemas testing to the list of additional contentschemathesis.loaders to schemathesis.specs.openapi.loaderspytest_subtests integrationfrom_wsgi loader to the public API docsrecipes sectionform_dataHookLocationregister_check to the API referencefilter_too_much health check in test_global_body_hooktest_openapi_links_multiple_threads--hypothesis-max-examples in a slow testCI Hypothesis profileblacken-docsendpoint to operation where necessarytest_optional_form_parametersschema_url fixturetest_global_body_hook testgit checkout HEAD^2 step from the CodeQL jobtoo_slow health check for some teststest_hypothesis_failed_eventpytest plugin. (#933)assume in some pytester-style tests (#924)get_hypothesis_conversions -> get_parameter_serializerOne column per quarter.
Case instances before passing to check functions.639b7ab (docs) Bump Sphinx version
Werkzeug>=2.1.0aevea/action-kanikorequests kwargs to catch cases when the ASGI integration is used, but the proper ASGI client is not suppliedhypothesis-jsonschema versionWerkzeug>=2.1.0. #1410requests kwargs to catch cases when the ASGI integration
is used, but the proper ASGI client is not supplied. #13354c645b5 Extra requests related options for the replay command
requests related options for the replay command--request-tls-verify CLI option for the replay command. It
controls whether Schemathesis verifies the server's TLS certificate.
You can also pass the path to a CA_BUNDLE file for private certs. #1395--request-cert
and --request-cert-key arguments for the replay command.375f4f6 Use full_path in error messages in recoverable schema-level errors
full_path in error messages in recoverable schema-level errorscorrelation_id in BeforeExecution and AfterExecution events if the API schema contains an error that causes an InvalidSchema exception during test execution.correlation_id in BeforeExecution and
AfterExecution events if the API schema contains an error that
causes an InvalidSchema exception during test execution.full_path in error messages in recoverable schema-level
errors. It makes events generated in such cases consistent with
usual events.cf03191 APIOperation.iter_parameters helper to iterate over all parameters.
APIOperation.iter_parameters helper to iterate over all parameters.content or schema keywordsAPIOperation.iter_parameters helper to iterate over all
parameters.content
or schema keywords.5370c80 (example) asyncpg==0.23.0 installs from wheels
test_read_only89cda52 Generating illegal Unicode surrogates in queries
duplicate-code pylint lintfe51d57 Not-escaped single quotes in generated Python code samples
ccb39b7 Improper handling of base_url in call_asgi, when the base URL has a non-empty base path
base_url in call_asgi, when the base URL has a non-empty base pathbase_url in call_asgi, when the base URL
has a non-empty base path. #136645a0eb1 Generating values not compliant with the ECMAScript regex syntax
setuptools explicitlytyping-extensions to >=3.7,<5.jsonschema to ^4.3.2.hypothesis-jsonschema to >=0.22.0.48ee34c Update dev dependencies
max_examples in test_hidden_failure to decrease the number of flaky test runspoetry versionsuppress_health_check to test_pet to avoid flakinessDeriving Semantics-Aware Fuzzers from Web API Schemasebf9061 Support for readOnly and writeOnly Open API keywords
readOnly and writeOnly Open API keywordstest_app on Windowsdded3b1 Generate tests for API operations with the HTTP TRACE method on Open API 2.0
TRACE method on Open API 2.0response.elapsed to Schemathesis.ioTRACE method on
Open API 2.0.7621f40 Minor changes to the Schemathesis.io integration
AfterExecution.data_generation_methodAfterExecution.data_generation_method.Silently failing to detect numeric status codes when the schema contains a shared parameters key. #1343
Use name & data_generation_method parameters to subtest context instead of path & method. It allows the end-user to disambiguate among subtest reports
name & data_generation_method parameters to subtest context
instead of path & method. It allows the end-user to disambiguate
among subtest reports.schema.parametrize
matches no API operations. #1336KeyboardInterrupt that happens outside of the main test
loop inside the runner. It makes interrupt handling consistent,
independent at what point it happens. #1325data_generation_methods config option defined on a
schema instance when it is loaded via from_pytest_fixture. #1331from_pytest_fixture. #1340Update click and PyYaml dependency versions. #1328
click and PyYaml dependency versions. #1328Show cURL code samples by default instead of Python. #1269
cURL code samples by default instead of Python. #1269jsonschema errors which are caused by
non-string object keys.data_generation_method in BeforeExecution.Case.headers. #1280data_generation_method to Case for GraphQL schemas.components/schemas before passing schemas
to hypothesis-jsonschema.DataGenerationMethod.all shortcut to get all possible enum variants.
DataGenerationMethod.all shortcut to get all possible enum
variants.hypothesis-jsonschema release. #1290Optional integration with Schemathesis.io.
before_init_operation hook.description attribute for all parsed parameters
inside APIOperation.werkzeug to >=0.16.0.OpenAPI20CompositeBody.definition type to
List[OpenAPI20Parameter].DataGenerationMethod instances for the data_generation_methods
argument. #1260make_case calls for GraphQL schemas.TypeError on case.call with bytes data on GraphQL schemas.exit_first enabled. #1204case.validate_response.New process_call_kwargs CLI hook. #1233
New before_call and after_call CLI hooks. #1224, #700
Preserve non-body parameter types in requests during Open API runtime expression evaluation.
KeyError when the response_schema_conformance check is executed against responses without schema definition. #1220
ExecutionEvent.is_terminal attribute that indicates whether an event is the last one in the stream.
ExecutionEvent.is_terminal attribute that indicates whether an
event is the last one in the stream.EventStream.stop is called, the next event always is the last
one.Return response from Case.call_and_validate.
response from Case.call_and_validate.ExecutionEvent.asdict adds the event_type field which is the event class name.
ExecutionEvent.asdict adds the event_type field which is the
event class name.Initialized event.SerializedCase.cookiesFailureContext class attributes to instance
attributes. For simpler serialization via attrs.A way to stop the Schemathesis runner's event stream manually via events.stop() / events.finish() methods. #1202
Case.data_generation_method attribute that provides the information of the underlying data generation method (e.g. positive or negative)
Case.data_generation_method attribute that provides the
information of the underlying data generation method (e.g. positive
or negative)UsageError if schema.parametrize or schema.given are
applied to the same function more than once. #1194True, False and None are converted to their
JSON equivalents when generated for path parameters or query. #1166hypothesis-jsonschema version. It allows the end-user to
override known string formats.hypothesis version.APIOperation.make_case behavior. If no media_type is passed
along with body, then it tries to infer the proper media type and
raises an error if it is not possible. #1094hypothesis>=6.13.3.Open API style & explode for parameters derived from security definitions.
style & explode for parameters derived from security
definitions.Apply the Open API's style & explode keywords to explicit examples. #1190
style & explode keywords to explicit
examples. #1190Disable filtering optimization for headers when there are keywords other than type. #1189
type. #1189Too much filtering in headers that have schemas with the pattern keyword. #1189
pattern
keyword. #1189Internal: SerializedCase.path_template returns path templates as they are in the schema, without base path.
SerializedCase.path_template returns path templates
as they are in the schema, without base path.Invalid multipart payload generated for unusual schemas for the multipart/form-data media type.
multipart/form-data media type.SerializedCase.media_type that stores the information about what media type was used for a particular case.
SerializedCase.media_type that stores the information about what
media type was used for a particular case.multipart/form-data
media type. #1152Content-Type override in
Case.as_requests_kwargs.Internal: FailureContext.title attribute that gives a short failure description.
FailureContext.title attribute that gives a short
failure description.FailureContext.message attribute that gives a longer
failure description.JSONDecodeErrorContext.message to
JSONDecodeErrorContext.validation_message for consistency.schema & instance in
ValidationErrorContext.ResponseTimeout to RequestTimeout.Additional context for each failure coming from the runner. It allows the end-user to customize failure formatting.
not_a_server_error and
status_code_conformance checks. It improves the variance of found
errors.Internal: BeforeExecution.verbose_name & SerializedCase.verbose_name that reflect specification-specific API operation name.
BeforeExecution.verbose_name &
SerializedCase.verbose_name that reflect specification-specific
API operation name.Explicitly add colorama to project's dependencies.
colorama to project's dependencies.hypothesis-jsonschema version.Ignored $ref keyword in schemas with deeply nested references. #1167
Relax dependency on starlette to >=0.13,<1. #1160
starlette to >=0.13,<1. #1160Missing support for the date string format (only full-date was supported).
date string format (only full-date was
supported).Improve error message for failing Hypothesis deadline healthcheck in CLI. #880
Support for disabling ANSI color escape codes via the NO_COLOR \ environment variable or the --no-color CLI option. #1153
NO_COLOR \<https://no-color.org/\>
environment variable or the --no-color CLI option. #1153Bump minimum hypothesis-graphql version to 0.5.0. It brings support for interfaces and unions and fixes a couple of bugs in query generation.
hypothesis-graphql version to 0.5.0. It brings
support for interfaces and unions and fixes a couple of bugs in
query generation.Bump minimum hypothesis-graphql version to 0.4.1. It fixes a problem with generating queries with surrogate characters.
Windows: UnicodeDecodeError during schema loading via the from_path loader if it contains certain Unicode symbols. from_path loader defaults to UTF-8
UnicodeDecodeError during schema loading via the
from_path loader if it contains certain Unicode symbols.
from_path loader defaults to UTF-8
from now on.Using parametrized pytest fixtures with the from_pytest_fixture loader. #1121
pytest fixtures with the from_pytest_fixture
loader. #1121Custom keyword arguments to schemathesis.graphql.from_url that are proxied to requests.post.
schemathesis.graphql.from_url that are
proxied to requests.post.from_wsgi, from_asgi, from_path and from_file loaders for
GraphQL apps. #1097, #1100data_generation_methods and code_sample_style in all
GraphQL loaders.app & base_url arguments for the
from_pytest_fixture runner.import schemathesis
# Load schema
schema = schemathesis.graphql.from_url("http://127.0.0.1:8000/graphql")
# Initialize runner
runner = schemathesis.runner.from_schema(schema)
# Emit events
for event in runner.execute():
...
Breaking
# BEFORE
schema = schemathesis.from_uri("http://example.com/openapi.json", "http://127.0.0.1:8000/", "GET")
# NOW
schema = schemathesis.from_uri("http://example.com/openapi.json", base_url="http://127.0.0.1:8000/", method="GET")
Query type. It makes the testing process unified for both
Open API and GraphQL schemas.Query field instead of
HTTP method & path.schemathesis.graphql.from_url loader now uses the usual
Schemathesis User-Agent.schemathesis.loaders is moved to
schemathesis.specs.openapi.loaders.from_path
loader in the Schemathesis runner.schemathesis.runner.prepare will be removed in Schemathesis 4.0.
Use schemathesis.runner.from_schema instead. With this change, the
schema loading part goes to your code, similar to using the regular
Schemathesis Python API. It leads to a unified user experience where
the starting point is API schema loading, which is much clearer than
passing a callback & keyword arguments to the prepare function.@schema.given implementation for schemas created
via the from_pytest_fixture loader. #1093@schema.given.make_case for GraphQL schemas.operation_id argument in from_asgi loader.fixups argument for
schemathesis.runner.prepare is removed.Do not use importlib-metadata==3.8 in dependencies as it causes RuntimeError. Ref:
importlib-metadata==3.8 in
dependencies as it causes RuntimeError. Ref:
https://github.com/python/importlib_metadata/issues/293Prefix worker thread names with schemathesis_.
schemathesis_.Encoding for response payloads displayed in the CLI output. #1073
flask.Response.mimetype_params) when
storing WSGI responses rather than defaulting to
flask.Response.charset.before_generate_case hook, that allows the user to modify or filter generated Case instances. #1067
event_type field to the debug output.
event_type field to the debug output.--debug-output-file CLI option to enable storing the underlying runner events in the JSON Lines format in a separate file for debugging purposes. #105
--debug-output-file CLI option to enable storing the underlying
runner events in the JSON Lines format in a separate file for
debugging purposes. #1059Request.body, Response.body and Response.encoding
internal attributes optional. For Request, it means that absent
body will lead to Request.body to be None. For Response,
body will be None if the app response did not have any payload.
Previously these values were empty strings, which was not
distinguishable from the cases described above. For the end-user, it
means that in VCR cassettes, fields request.body and
response.body may be absent.models.Status enum now has string values for more readable
representation.Displaying wrong headers in the FAILURES block of the CLI output. #792
FAILURES block of the CLI output. #792Display failing response payload in the CLI output, similarly to the pytest plugin output. #1050
UnicodeDecodeError when generating cURL commands for failed test
case reproduction if the request's body contains non-UTF8
characters.Internal
Support for Hypothesis 6. #1013
Wrong test results in some cases when the tested schema contains a media type that Schemathesis doesn't know how to work with. #1046
Your coding agent can read these notes before it upgrades. Set up the MCP server →