NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2283 most downloaded on PyPI
Adaptive API testing for OpenAPI and GraphQL
Last release today
04 Oct 2026
Ships fairly regularly
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
490 releases · first in 2019
Add an internal caching layer for data generation strategies. It relies on the fact that the internal BaseSchema structure is not mutated over time. I
BaseSchema structure is not
mutated over time. It is not directly possible through the public
API and is discouraged from doing through hook functions.APIOperation and subclasses of Parameter are now compared by
their identity rather than by value.count_operations boolean flag to runner.prepare. In case of False value, Schemathesis won't count the total number of operations upfront. It improves
count_operations boolean flag to runner.prepare. In case of
False value, Schemathesis won't count the total number of
operations upfront. It improves performance for the direct runner
usage, especially on large schemas. Schemathesis CLI will still use
these calculations to display the progress during execution, but
this behavior may become configurable in the future.One column per quarter.
Percent-encode the generated . and .. strings in path parameters to avoid resolving relative paths and changing the tested path structure. #1036
. and .. strings in path parameters
to avoid resolving relative paths and changing the tested path
structure. #1036Loosen importlib-metadata version constraint and update pyproject.toml. #1039
importlib-metadata version constraint and update pyproject.toml. #1039Support for external examples via the externalValue keyword. #884
Return a default terminal size to prevent crashes on systems with zero-width terminals (some CI/CD servers).
This release updates the documentation to be in-line with the current state.
Docker tags for Buster-based images.
Packaging-only release for Docker images based on Debian Buster. #1028
Allow to use any iterable type for checks and additional_checks arguments to Case.validate_response.
checks and additional_checks
arguments to Case.validate_response.Generating stateful tests, with common parameters behind a reference. #1020
add_link when schema
validation is disabled and response status codes are noted as
integers. #1022operationId then the same
reference resolving logic is applied as in other cases. This change
leads to less reference inlining and lower memory consumption for
deeply nested schemas. #945Flaky Hypothesis error during explicit examples generation. #1018
Flaky Hypothesis error during explicit examples generation. #1018Processing parameters common for multiple API operations if they are behind a reference. #1015
YAML serialization for text/yaml, text/x-yaml, application/x-yaml and text/vnd.yaml media types. #1010.
text/yaml, text/x-yaml,
application/x-yaml and text/vnd.yaml media types. #1010.--skip-deprecated-endpoints is renamed to --skip-deprecated-operations. #869
text/plain payload as test data. Including
variants with non-default charset. #850, #939application/json).response_schema_conformance check
now runs on media types that are encoded with JSON. For example,
application/problem+json. #920--dry-run CLI option. When applied, Schemathesis won't send any
data to the server and won't perform any response checks. #963required: true in path parameters definition is now
automatically enforced if schema validation is disabled. According
to the Open API spec, the required keyword value should be true
for path parameters. This change allows Schemathesis to generate
test cases even for endpoints containing optional path parameters
(which is not compliant with the spec). #941--auth together with --header that sets the
Authorization header causes a validation error. Before, the
--header value was ignored in such cases, and the basic auth
passed in --auth was used. #911hypothesis-jsonschema fails to resolve recursive references,
the test is skipped with an error message that indicates why it
happens.{"type": "integer", "minimum": 5, "maximum": 4}.--operations instead of
--endpoints.Collected API operations instead of collected endpoints
in the CLI. #869--skip-deprecated-endpoints is renamed to
--skip-deprecated-operations. #869endpoint in
their names. #869hypothesis-jsonschema version to 0.19.0. This version
improves the handling of unsupported regular expression syntax and
can generate data for a subset of schemas containing such regular
expressions.null as request payload if the schema expects it. #919GET and has payload examples. #925--exitfirst CLI option trims the progress bar output when a
failure occurs. #951Unsatisfiable errors. #904Unsatisfiable error in stateful testing caused by all API
operations having inbound links. #965, #822APIStateMachine.step. #970TypeError on nullable parameters during Open API specific
serialization. #980x-examples. #982HookContext.endpoint. Use HookContext.operation instead.Case.endpoint. Use Case.operation instead.Case.form_data. Use Case.body instead.Endpoint.form_data. Use Endpoint.body instead.before_generate_form_data hook. Use before_generate_body
instead.pytest plugin.[!NOTE] This release features multiple backward-incompatible changes. The first one is removing
form_dataand hooks related to it -all payload related actions can be done viabodyand its hooks. The second one involves renaming the so-called "endpoint" to "operation". The main reason for this is to generalize terminology and make it applicable to GraphQL schemas, as all Schemathesis internals are more suited to work with semantically different API operations rather than with endpoints that are often connected with URLs and HTTP methods. It brings the possibility to reuse the same concepts for Open API and GraphQL - in the future, unit tests will cover individual API operations in GraphQL, rather than everything available under the same "endpoint".
Support for Werkzeug\>=2.1.0. #1410
auto variant for the --workers CLI option that automatically detects the number of available CPU cores to run tests on. #917
auto variant for the --workers CLI option that automatically
detects the number of available CPU cores to run tests on. #917Use --request-tls-verify during schema loading as well. #897
--request-tls-verify during schema loading as well. #897Display failed response payload in the error output for the pytest plugin. #895
pytest
plugin. #895CheckFailed name. Before, they had
not readable "internal" names.Case
attributes with default values to improve readability. #886Internal error in CLI, when the base_url is an invalid IPv6. #890
--force-schema-version CLI option to force Schemathesis to use the specific Open API spec version when parsing the schema. #876
--force-schema-version CLI option to force Schemathesis to use the
specific Open API spec version when parsing the schema. #876content_type_conformance check now raises a well-formed error
message when encounters a malformed media type value. #877value key. #882In the 3.0 release, you'll need to use relevant body attributes instead. This change includes deprecation of the before_generate_form_data hook, use b…
--request-tls-verify CLI option, that controls whether
Schemathesis verifies the server's TLS certificate. You can also
pass the path to a CA_BUNDLE file for private certs. #830--validate-schema CLI option. #855response_schema_conformance
check. Before, all responses were required to have the
Content-Type header. #844OverflowError when an invalid regex is passed to -E / -M
/ -T / -O CLI options. #870Case.form_data and Endpoint.form_data. In the 3.0
release, you'll need to use relevant body attributes instead. This
change includes deprecation of the before_generate_form_data hook,
use before_generate_body instead. The reason for this is the
upcoming unification of parameter handling and their serialization.--stateful-recursion-limit. It will be removed in 3.0 as a part
of removing the old stateful testing approach. This parameter is
no-op.Missed headers in Endpoint.partial_deepcopy.
headers in Endpoint.partial_deepcopy.An option to set data generation methods. At the moment, it includes only "positive", which means that Schemathesis will generate data that matches th
attrs that caused an error on fresh
installations. #858Invalid keyword in code samples that Schemathesis suggests to run to reproduce errors. #851
New relative_path property for BeforeExecution and AfterExecution events. It represents an operation path as it is in the schema definition.
relative_path property for BeforeExecution and
AfterExecution events. It represents an operation path as it is in
the schema definition.Internal error on malformed JSON when the response_conformance check is used. #832
response_conformance
check is used. #832Shortcut for response validation when Schemathesis's data generation is not used. #485
--app command-line option. #836Adding new Open API links via the add_link method, when the related PathItem contains a reference. #824
add_link method, when the
related PathItem contains a reference. #824New approach to stateful testing, based on the Hypothesis's RuleBasedStateMachine. #737
RuleBasedStateMachine. #737Case.validate_response accepts the new additional_checks
argument. It provides a way to execute additional checks in addition
to existing ones.response_schema_conformance and content_type_conformance
checks fail unconditionally if the input response has no
Content-Type header. #816call_* methods during testing. #814stateful=Stateful.links in schema loaders and parametrize.
Use schema.as_state_machine().TestCase instead. The old approach
to stateful testing will be removed in 3.0. See the
Stateful testing section of our documentation for more
information.New method as_curl_command added to the Case class. #689
as_curl_command added to the Case class. #689Ability to skip deprecated endpoints with --skip-deprecated-endpoints CLI option and skip_deprecated_operations=True argument to schema loaders. #715
schema.parametrize by using schema.given decorator. #768rstcheck, as well as updates to
documentation based on rstcheck. #734--max-response-time. #716response_headers_conformance check that verifies the presence
of all headers defined for a response. #742port parameter added to from_uri() method. #706--skip-deprecated-endpoints CLI option and
skip_deprecated_operations=True argument to schema loaders. #715User-Agent header overriding the passed one. #757User-Agent header in Case.call. #717Case.as_requests_kwargs and Case.as_werkzeug_kwargs now return
the User-Agent header. This change also affects code snippets for
failure reproduction - all snippets will include the User-Agent
header.headers, cookies, and formData
parameters when their schemas do not define the type keyword. #795This release contains only documentation updates which are necessary to upload to PyPI.
This release contains only documentation updates which are necessary to upload to PyPI.
Stateful testing via Open API links for the pytest runner. #616
pytest runner. #616pytest runner. #649stateful argument type in the runner.prepare is
Optional[Stateful] instead of Optional[str]. Use
schemathesis.Stateful enum.Hide Case.endpoint from representation. Its representation decreases the usability of the pytest's output. #719
Case.endpoint from representation. Its representation
decreases the usability of the pytest's output. #719register_target and
register_check decorators. #721IndexError when a user-defined check raises an exception
without a message. #718Ability to register custom targets for targeted testing. #686
AfterExecution event now has path and method fields,
similar to the BeforeExecution one. The goal is to make these
events self-contained, which improves their usability.The default Hypothesis's deadline setting for tests with schema.parametrize is set to 500 ms for consistency with the CLI behavior. #705
KeyError during the content_type_conformance check if the response has no Content-Type header. #692
KeyError during the content_type_conformance check if the
response has no Content-Type header. #692### :rocket: Added - Run checks conditionally.
IndexError when examples list is empty.
IndexError when examples list is empty.Possibility to generate values for in: formData parameters that are non-bytes or contain non-bytes (e.g., inside an array). #665
in: formData parameters that
are non-bytes or contain non-bytes (e.g., inside an array). #665required: true in
its definition. #667hypothesis-jsonschema version to
0.17.0. This allows Schemathesis to
use the custom_formats argument in from_schema calls and avoid
using its private API. #684ValueError during sending a request with test payload if the
endpoint defines a parameter with type: array and in: formData. #661KeyError while processing a schema with nullable parameters and
in: body. #660StopIteration during requestBody processing if it has empty
"content" value. #673AttributeError during generation of "multipart/form-data"
parameters that have no "type" defined. #675TypeError. #672graphql-server-core package. #658Possible UnicodeEncodeError during generation of Authorization header values for endpoints with basic security scheme. #656
UnicodeEncodeError during generation of Authorization
header values for endpoints with basic security scheme. #656schemathesis.graphql.from_dict loader allows you to use GraphQL schemas represented as a dictionary for testing.
schemathesis.graphql.from_dict loader allows you to use GraphQL
schemas represented as a dictionary for testing.before_load_schema hook for GraphQL schemas.Deprecated skip_validation argument to HookDispatcher.apply.
skip_validation argument to HookDispatcher.apply._accepts_context internal function.BREAKING. Base URL handling. base_url now is treated as one with a base path included. You should pass a full base URL now instead:
base_url now is treated as one
with a base path included. You should pass a full base URL now
instead:schemathesis run --base-url=http://127.0.0.1:8080/api/v2 ...
This value will override basePath / servers[0].url defined in your
schema if you use Open API 2.0 / 3.0 respectively. Previously if you
pass a base URL like the one above, it was concatenated with the base
path defined in the schema, which leads to a lack of ability to redefine
the base path. #511
Example:
Base URL in the schema : http://0.0.0.0:8081/api/v1
`--base-url` value in CLI : http://0.0.0.0:8081/api/v2
Full URLs before this change : http://0.0.0.0:8081/api/v2/api/v1/users/ # INVALID!
Full URLs after this change : http://0.0.0.0:8081/api/v2/users/ # VALID!
context
argument in the first position.register decorators
instead. For more details, see the "Customization" section in our
documentation.BaseSchema.with_hook and BaseSchema.register_hook. Use
BaseSchema.hooks.apply and BaseSchema.hooks.register instead.loaders.from_asgi supports making calls to ASGI-compliant application (For example: FastAPI). #521
Schema validation error on schemas containing numeric values in scientific notation without a dot. #629
Pass the original case's response to the add_case hook.
add_case hook.examples. #589--verbosity CLI option to minimize the error output. #598apply. #618LazySchema / from_pytest_fixture. #617Tests with invalid schemas are marked as failed instead of passed when hypothesis-jsonschema>=0.16 is installed. #614
hypothesis-jsonschema>=0.16 is installed. #614KeyError during creating an endpoint strategy if it contains a
reference. #612hypothesis-jsonschema>=0.16. #614InvalidSchema text to pytest.fail call.Support for YAML files in references via HTTPS & HTTP schemas. #600
Open API links syntax. #548add_case hook. #458pipeDelimited or deepObject. #599application/json content-type. #594Hypothesis and
hypothesis-jsonschema are 5.15.0 and 0.11.1 respectively. The
main reason is this
fix
that is required for stability of Open API links feature when it is
executed in multiple threads.Support for a colon symbol (:) inside of a header value passed via CLI. #596
:) inside of a header value passed
via CLI. #596Partially generated explicit examples are always valid and can be used in requests. #582
Look at the current working directory when loading hooks for CLI. #586
New before_add_examples hook. #571
Display proper headers in reproduction code when headers are overridden. #566
Display a suggestion to disable schema validation on schema loading errors in CLI. #531
operationId via operation_id
parameter to schema.parametrize or -O command-line option. #546securityDefinitions / securitySchemes and injected to the
generated data. It supports generating API keys in headers or query
parameters and generating data for HTTP authentication schemes. #540context argument for hook functions to provide an additional context for hooks. A deprecation warning is emitted for hook functions that do not accept…
context argument for hook functions to provide an additional
context for hooks. A deprecation warning is emitted for hook
functions that do not accept this argument.before_process_path hook.Deprecated
context as their first argument.
They will become not be supported in Schemathesis 2.0.register decorators
instead. For more details, see the "Customization" section in our
documentation.BaseSchema.with_hook and BaseSchema.register_hook. Use
BaseSchema.hooks.apply and BaseSchema.hooks.register instead.validate_schema argument to
loaders.from_pytest_fixture.Validation of nullable properties in response_schema_conformance check introduced in 1.3.0. #542
response_schema_conformance
check introduced in 1.3.0. #542Update pytest-subtests pin to >=0.2.1,<1.0. #537
pytest-subtests pin to >=0.2.1,<1.0. #537Show exceptions if they happened during loading a WSGI application. Option --show-errors-tracebacks will display a full traceback.
--show-errors-tracebacks will display a full traceback.Your coding agent can read these notes before it upgrades. Set up the MCP server →