API Tester is a built-in HTTP client for REST, GraphQL and WebSocket calls that runs in the context of the page you are already on — so your cookies, session and origin apply automatically, with no tokens to copy into a separate app.
Testing an API usually means leaving the browser. You open Postman or Insomnia, then spend five minutes recreating something the browser already has: the session cookie, the bearer token, the right origin, the CSRF header. By the time the request is ready, you are testing a different context from the one your bug lives in.
API Tester removes that step. It sends the request from inside the page you are viewing, as the page itself, so whatever you are signed in as is what the request is signed in as. A GET against your own admin endpoint works immediately because the cookie travels with it. There is nothing to configure and nothing to keep in sync.
The REST tab gives you a method, a URL that can be absolute or relative, headers written one per line, and a body. The response comes back with its status, how long it took, how big it was, pretty-printed JSON, and the full response headers. The GraphQL tab takes an endpoint, a query and variables, builds the request for you, and tells you when the response contains GraphQL errors even though the HTTP status was 200. The WebSocket tab opens a real connection, sends frames you type, and logs everything in both directions with timestamps.
When a page's own Content Security Policy or a CORS rule blocks the call, one switch re-sends the identical request from the extension instead, which is subject to neither. That gives you a quick way to tell a server problem apart from a browser policy problem — the same request, two contexts, two answers. Your last 25 requests are kept, so returning to something you tried yesterday is one click.
Pick any method, enter an absolute or relative URL, and write headers one per line as Name: value. Relative URLs resolve against the page you are on, so /api/users just works.
Requests leave from the page's own context, carrying its cookies, origin and session. Authenticated endpoints respond exactly as they do for the app, with no token copying.
Enter an endpoint, a query and JSON variables; the correct POST body is built for you. GraphQL errors returned inside a 200 response are counted and flagged rather than hidden.
Open a ws:// or wss:// connection, send frames, and watch every frame in both directions with timestamps, sizes and connection state — not just a read-only capture.
Status, timing and transfer size up front, with Pretty, Raw and Headers views. JSON is formatted automatically and anything can be copied in one click.
If the page's CSP or a CORS rule blocks a call, switch Run from to Extension and send the identical request from outside the page — an instant way to separate server errors from browser policy.
Hit an endpoint that needs an authenticated session without exporting a cookie or generating a token — you are already logged in in that tab, and the request goes out as you.
Send the exact failing request, inspect the response headers, then re-send with an Authorization header changed by one character to see precisely what the server objects to.
Run a query with real variables against the live endpoint and read the formatted result before you write the frontend code that consumes it.
Connect to a socket, send a subscribe frame, and watch what the server pushes back in real time while you verify the message format.
Capture the failing request and response, copy them, and paste a complete picture into the issue so whoever picks it up does not have to guess.
Click the API Tester icon in the DevSuite Pro dock. A panel opens with tabs for REST, GraphQL, WebSocket and History, pre-filled with the current site's origin.
Choose a method and enter the URL — full, or relative like /api/orders. Add headers one per line (Content-Type: application/json) and paste a body if the method takes one.
Press Send, or Ctrl+Enter (Cmd+Enter on Mac). The request goes out from the page, so you stay signed in as whoever you are in that tab.
The status pill, timing and size appear immediately. Switch between Pretty, Raw and Headers, and copy any of it. If the page's CSP blocked the call, switch Run from to Extension and send again.
Every request is saved to History with its status. Click any entry to load the method, URL, headers and body straight back into the form.
Install DevSuite Pro for free and unlock 71+ developer tools for your browser.