API Load Testing with k6.
Overview
Your API works perfectly in development. One user, one request, instant response. But what happens when 500 users hit the same endpoint at the same time? What about 2,000? Does your server slow down? Does it crash? Does it return errors? These are questions that only load testing can answer — and K6 is one of the best tools to do it.
What to Verify
The suite tests the speed and stability of core REST endpoints (users, posts, todos) under load:
- Every HTTP operation (GET all/by ID, POST, PUT, PATCH, DELETE, filter, nested) per resource.
- Behavior under a ramp-up traffic pattern (warmup, stress up to 500 VUs, DELETE up to 2,000 VUs, then cool-down).
- Error scenarios under load. Missing ID and ID-not-found must still be rejected correctly (404/500), not just under normal conditions.
- Performance contracts via thresholds: p(95) response time, request failure rate, and check pass rate.
How to Verify
- Built with k6 (JavaScript), one operation per file so each can be run and compared in isolation.
- All shared values (base URL, endpoints, and test IDs including a deliberately non-existent USER_ID_NOT_FOUND) are centralized in utils/config.js.
- Each test has options (stages + thresholds) and a default function (the action per iteration); check() asserts the status code and response time on every response.
- Thresholds become the automatic pass/fail. If breached, k6 exits with a non-zero code and fails the CI/CD pipeline.
- Write scenarios use group() with different per-group thresholds (happy path rate<0.01, error scenarios rate>0.95) to verify the API rejects invalid requests even under load.
Testing Stack