Welcome to REST League 2026, the 1st edition of the ultimate competition for automated black-box testing tools designed for RESTful APIs.
The goal of REST League is to evaluate the performance of open-source and proprietary tools in finding bugs, security vulnerabilities, and logic flaws in real-world REST APIs without access to their source code.
Participants submit their automated black-box testing tools to compete against a benchmark set of REST APIs. These APIs contain a variety of intentionally injected issues, ranging from functional defects to common security flaws.
What is black-box testing?
In this context, black-box testing means the tools interact with an API solely via its public endpoints, documented by an OpenAPI specification. Tools generate test cases by leveraging the specification and the feedback from the API, without looking at the API’s internal implementation.
Tools must meet the following general requirements to participate
In particular, the tools must be compatible with RESTgym, a benchmarking infrastructure specifically designed for REST API testing tools. Check here the details of our experimental setting.
Tools will be scored based on a comprehensive set of criteria, focusing on both quality of testing and resource efficiency
5XX responses obtained by the tool2XX response)The final score will be a weighted aggregate of these metrics. Testing metrics will be collected by using the Restats tool.
Sandboxed Execution: All submitted tools will be run in a secure, isolated, and controlled environment by REST League organizers. Details of the machine used to run the experiments will be provided after registration.
REST League 2026 will be hosted by SBFT@ICSE2026 in Rio de Janeiro, Brazil, with the following schedule.
| Date (AoE) | Event |
|---|---|
| [17/10/2025] | Call for Participation Opens (Tool Registration) |
| [05/12/2025] | Final Deadline for Tool Submission |
| [01/01/2026] | Notification of results |
| [26/01/2026] | Tool report camera ready deadline |
| [12/04/2026] | REST League Awards Ceremony |
5XX foundWinning tools and their authors will be prominently featured on this GitHub page, recognized at the Awards Ceremony, and invited to present their tool during SBFT@ICSE2026 in Rio.
ACM Publication: The tool report for all participants will be included in the SBFT@ICSE2026 proceedings and published by ACM.
This first edition of REST League received five submissions, comprising industry-ready tools and research prototypes:
🥇
The ultimate champion of the competition is
AutoRestTestwhich achieved the Gold API Tester badge!
Detailed results can be found in the competition report.
To quickly develop your REST API testing tool, you can consider using the RestTestGen Framework. The framework provides many ready-to-use components to:
All components and the testing engine are easily customizable, to develop brand new testing tools in minutes. For more details, see the RestTestGen Framework Wiki.
Before submitting your tool to REST League, please check its compliance with RESTgym for easy deployment and running on our platform.
All tools will be run with a time budget of one hour for each API; experiments will be repeated ten times, averaging the results.
You can test your tool on the REST APIs provided in the apis directory of this repository (see the specific apis/README for details) and on the APIs available in RESTgym.
REST League is organized by
michele.pasqua@univr.itmariano.ceccato@univr.itsofia.mari@univr.itdavide.corradini@uni.luIf you have questions, feel free to reach out to us!