list collection
Read-onlyThe most common call. If it is slow with no filters, look at default page size and missing indexes.
Every common REST scenario: lists, pagination, filters, items, caching, writes, bulk, uploads, content negotiation, error handling and auth.
Category APIStack Any JSON REST APIJobs 48
Covers every common REST scenario for any JSON API: lists, pagination (first page and deep offset), filtering, sorting, sparse fields and expanded relations, single and missing items, conditional requests, create, replace, patch and delete, bulk and large bodies, uploads, content negotiation, error handling and authentication.
It holds 48 ready-made jobs: 29 single scenarios and an enterprise test plan of 19 stages to run in order, 15 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.
Scenarios include list collection, pagination: first page, pagination: deep offset, filtered list and sorted list.
url and id to point at your own REST API patterns system, ideally a staging copy.urlresourceiduploadPathtokenThe most common call. If it is slow with no filters, look at default page size and missing indexes.
Cursor or offset page 1.
OFFSET 10000 forces the database to skip 10,000 rows per request, so latency grows with the page number. Compare with the first page; if it is slower, move to cursor (keyset) pagination.
Filtering on a column without an index is a table scan: the first thing to check when a list endpoint gets slower as data grows.
Sorting on an unindexed field sorts every matching row in memory.
Asking for fewer fields should be cheaper. If it costs the same, the API loads everything anyway.
?include= or ?expand= triggers extra queries per row (the N+1 problem). Latency that grows with limit gives it away.
Primary key lookup: should be the fastest call the API has.
404 path: must be as cheap as a hit, and must not leak stack traces.
Existence check without the body.
Browsers send this before cross-origin writes; it should never reach the application code.
Sends a deliberately stale ETag. A correct API answers 200 with the new body; a 304 on a wrong ETag would be a caching bug, so only 200 counts.
Write path with validation and an insert. Creates a row per request, so clean up afterwards. Staging only.
Clients retry on timeout. With the same Idempotency-Key the API must create ONE item and replay the response. 409 is also acceptable.
Full update of the item named by id. Staging only.
Single-field update; row lock contention shows when many requests hit the same id. Staging only.
DELETE on an id that does not exist must be a fast 404 (or 204 if idempotent). Never points at a real item.
One request carrying 100 rows: tests transaction size, validation loops and the request body limit. Creates 100 rows per request. Staging only.
Body size limits and parsing cost. 413 (payload too large) is a correct answer.
File upload path: multipart parsing, temp files and storage. Run with a larger file in your own job to test disk and proxy limits.
A JSON body sent as text/plain must be refused with 415 or 400, not parsed or crash.
Invalid JSON must give a clean 400, quickly, with no stack trace.
DELETE on the collection must not wipe it: expect 404 or 405.
Asking for a format the API does not offer should be 406 or the default JSON, not an error.
Rejected requests should be cheaper than accepted ones.
Swagger/OpenAPI JSON, fetched by docs and generators; it can be megabytes and is often generated per request.
Load balancer probe.
Ramps list requests to find the rate where latency climbs.
Steady load that finds leaks, pool exhaustion and cache decay.
Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.
Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: list collection.
Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: list collection.
Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: list collection.
Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: list collection.
Step 5 of 10. Ramps to four times average over 10 minutes, then holds for 2. Finds where it degrades and HOW: gracefully (latency rises, errors stay low) or badly (errors, timeouts, crashes, restarts). Observation only, no gate. Reference request: list collection.
Step 6 of 10. Reaches ten times average within 10 seconds and holds for 2 minutes: a campaign email, a news link, a failover. Checks autoscaling, queue limits and load shedding. Gate: at most 5% errors, because shedding load is acceptable and crashing is not. Reference request: list collection.
Step 7 of 10. Run IMMEDIATELY after the spike, at average load for 5 minutes. Latency and errors must return to the baseline from step 2. If they do not, something is stuck: queues, connection pools, GC, an autoscaler cool-down. Gate: same as average load. Reference request: list collection.
Step 8 of 10. One hour of steady load. Finds leaks and slow decay in memory, connections, file descriptors, disk, log volume and cache churn. Watch the resource graphs: any line that climbs and never flattens is a finding. Gate: at most 0.5% errors. Reference request: list collection.
Step 9 of 10. Ramps to twenty times average over 20 minutes. Stop it when errors pass about 5%: the rate at that moment is your ceiling, and ceiling divided by peak is your capacity margin. Use a production-like environment, never production. Reference request: list collection.
Step 10 of 10. Average load for 15 minutes. About 5 minutes in, cause the event you are testing: kill a pod or node, fail over the database, roll out a new version, drain a zone. Errors in the window are your real availability loss. Gate: at most 1% errors overall; read the time series for how long the dip lasted. Reference request: list collection.
Sends Connection: close, so every request pays for a new TCP and TLS handshake: the cost for clients that do not reuse connections (scripts, some mobile SDKs, health checkers). Shows load balancer and TLS termination limits. Reference request: list collection.
Same request identified as a search crawler. Tests WAF and bot-management rules and whether crawlers get cached or origin responses. Crawlers can easily be a third of all traffic. Reference request: list collection.
Adds a 4 KB Cookie header, like a logged-in user with many tracking cookies. Proxies and servers reject headers around 8 KB, so this shows how close you are to that limit. Reference request: list collection.
A fleet of synthetic monitors checking the URL with HEAD requests every 30 seconds from 20 locations, plus load balancer probes. Cheap each, constant in total. Reference request: list collection.
Three times normal for 10 minutes on the most-used endpoint. Reference request: list collection.
Ramps requests for page 200 to four times normal. Offset pagination gets slower the deeper you go: a scraper walking the whole collection can take the API down. Reference request: pagination: deep offset.
Twice normal creates for 10 minutes: an import job or a busy ordering hour. Staging only. Reference request: create an item (POST). This job WRITES or creates data on every request: staging only, and expect a lot of rows.
Ten times normal concurrency on ONE id: a viral item, a homepage banner, a config record. Exposes row-lock contention, cache stampedes and missing HTTP caching. Reference request: get one item.
Twice normal filtered lists for 10 minutes; unindexed filters are what fall over first. Reference request: filtered list.
The REST API patterns template has 48 jobs: 29 single scenarios and an enterprise test plan of 19 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include list collection, pagination: first page, pagination: deep offset and filtered list. 15 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.
Open the template in BLASTA and set url and id, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new rest-patterns with your address.
Of the 48 jobs, 39 are read-only, 9 write data and 0 change state. Run the writing and state-changing jobs against a staging system, never against production data. Only test systems you own or have permission to test.
Welcome back. Sign in to run and review load tests.
Send the confirmation email again
Just looking? Try a quick test without an account
Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.
Queries are read-only unless Allow writes is on.
Multi-statement input and writable CTEs (WITH d AS (DELETE…)) are always refused.
For MQTT, LDAP, AMQP and other binary protocols. The templates fill this in for you.
The address accepts host:port or tcp://host:port.
Leave this empty to only test the connection handshake.
No results yet
Set up a target above and press Start test. Charts and numbers appear here as the test runs.
Ready-made jobs for common systems. Search by system, protocol or what you want to test (wordpress, saml, redis, spike, login storm…), pick a job, and it opens on the Test page ready to run.
You are browsing as a visitor: you can read every template and job. Sign in or create an account to use them.
No templates match
Try a shorter search, or a system name such as keycloak, postgres or soap.
You are browsing as a visitor: you can read every job here. Sign in or create an account to use them.
Fill in your system's address. The jobs below update as you type.
Your tests. Open one to see it the way it looked live, with its charts, load settings and server usage.
| When | Job | Target | Requests | Avg req/s | p95 | Errors | CPU avg | RAM avg | Result |
|---|
Charts were not recorded for this run (it was saved by an older version).