Generating REST API Specifications through Static Analysis
Ruikai Huang, Manish Motwani, Idel Martinez, Alessandro Orso
Abstract
Web Application Programming Interfaces (APIs) allow services to be accessed over the network. RESTful (or REST) APIs, which use the REpresentation State Transfer (REST) protocol, are a popular type of web API. To use or test REST APIs, developers use specifications written in standards such as OpenAPI. However, creating and maintaining these specifications is time-consuming and error-prone, especially as software evolves, leading to incomplete or inconsistent specifications that negatively affect the use and testing of the APIs. To address this problem, we present Respector (REST API specification generator), the first technique to employ static and symbolic program analysis to generate specifications for REST APIs from their source code. We evaluated Respector on 15 real-world APIs with promising results in terms of precision and recall in inferring endpoint methods, endpoint parameters, method responses, and parameter attributes, including constraints leading to successful HTTP responses or errors. Furthermore, these results could be further improved with additional engineering. Comparing the Respector-generated specifications with the developer-provided ones shows that Respector was able to identify many missing end-point methods, parameters, constraints, and responses, along with some inconsistencies between developer-provided specifications and API implementations. Finally, Respector outperformed several techniques that infer specifications from annotations within API implementations or by invoking the APIs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- A Multi-Agent Approach for REST API Testing with Semantic Graphs and LLM-Driven InputsMyeongsoo Kim, Tyler Stennett, Saurabh Sinha, Alessandro OrsoICSE 2025 · 4 citations
- SATORI: Static Test Oracle Generation for REST APIsJuan C. Alonso, Alberto Martin-Lopez, Sergio Segura, Gabriele Bavota et al.ASE 2025 · 2 citations
- Fidelity of Cloud Emulators: The Imitation Game of Testing Cloud-Based SoftwareAnna Mazhar, Saad Sher Alam, William X. Zheng, Yinfang Chen et al.ICSE 2025 · 2 citations
- RestPi: Path-Sensitive Type Inference for REST APIsMark W. Aldrich, Kyla Levin, Michael Coblenz, Jeffrey S. FosterOOPSLA 2025 · 1 citation
- SAINT: Service-level Integration Test Generation with Program Analysis and LLM-based AgentsRangeet Pan, Raju Pavuluri, Ruikai Huang, Tyler Stennett et al.ICSE 2026 · 1 citation
Builds on4
- Automated test generation for REST APIs: no time to rest yetMyeongsoo Kim, Qi Xin, Saurabh Sinha, Alessandro OrsoISSTA 2022 · 67 citations
- Online testing of RESTful APIs: promises and challengesAlberto Martin-Lopez, Sergio Segura, Antonio Ruiz-CortésFSE 2022 · 34 citations
- Adaptive REST API Testing with Reinforcement LearningMyeongsoo Kim, Saurabh Sinha, Alessandro OrsoASE 2023 · 29 citations
- Carving UI Tests to Generate API Tests and API SpecificationRahulkrishna Yandrapally, Saurabh Sinha, Rachel Tzoref-Brill, Ali MesbahICSE 2023 · 21 citations
Related papers
- Speculate: Generating REST API Specifications using LLMsKrishanu Singh, Kushagra Karar, Abhilash Jindal, Guowei YangFSE 2026
- Combinatorial Testing of RESTful APIsHuayao Wu, Lixin Xu, Xintao Niu, Changhai NieICSE 2022 · 47 citations
- Enhancing REST API Testing with NLP TechniquesMyeongsoo Kim, Davide Corradini, Saurabh Sinha, Alessandro Orso et al.ISSTA 2023 · 34 citations
- RBCTest: Leveraging LLMs to Mine and Verify Oracles of API Response Bodies for RESTful API TestingHieu Huynh, Quoc-Tri Le, Tu Nguyen, Viet Nguyen et al.ICSE 2026
- Morest: Model-based RESTful API Testing with Execution FeedbackYi Liu, Yuekang Li, Gelei Deng, Yang Liu et al.ICSE 2022 · 52 citations
