{"id":2449,"date":"2022-06-30T10:00:51","date_gmt":"2022-06-30T10:00:51","guid":{"rendered":"https:\/\/loadfocus.com\/blog\/?p=2449"},"modified":"2023-09-03T14:09:48","modified_gmt":"2023-09-03T14:09:48","slug":"performance-testing-of-oauth-2-0-secured-apps-and-services","status":"publish","type":"post","link":"https:\/\/loadfocus.com\/blog\/2022\/06\/performance-testing-of-oauth-2-0-secured-apps-and-services","title":{"rendered":"Performance Testing of OAuth 2.0 Secured Apps and Services"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes read<\/span><\/span><!-- pn-tldr --><h2>Key takeaways<\/h2><ul><li>Token acquisition should sit outside the measured path so you test the service, not the identity provider.<\/li><li>Model expiry and refresh, because a run that never refreshes is not production-like.<\/li><li>Watch for rate limits on the token endpoint, which cap concurrency before your API does.<\/li><\/ul><!-- \/pn-tldr -->\n<p class=\"lead\"><a href=\"https:\/\/loadfocus.com\/\">LoadFocus<\/a> now provides easy testing for services that are using OAuth authorization (we support OAuth2.0 as OAuth1.0 was retired in 2012).<\/p>\n\n\n\n<p>We support all the OAuth 2.0 grant types:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Authorization Code <\/li><li>Implicit<\/li><li>Password Credentials<\/li><li>Client Credentials<\/li><li>Refresh Token<\/li><\/ul>\n\n\n\n<p>For testing a service that is behind a login (that has OAuth authorization) the only thing the user needs to do is:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"782\" height=\"366\" src=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.28.png\" alt=\"\" class=\"wp-image-2456\" srcset=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.28.png 782w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.28-600x281.png 600w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.28-768x359.png 768w\" sizes=\"auto, (max-width: 782px) 100vw, 782px\" \/><figcaption>Select OAuth 2.0 Authorization Type from the New Load Test page<\/figcaption><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Go to <em><strong>Services -> <a href=\"https:\/\/loadfocus.com\/load-testing\" title=\"load testing in the cloud\">Load Testing<\/a> -> New Test<\/strong><\/em><\/li><li>On the &#8220;New Test&#8221; page select the &#8220;Authorization type&#8221; as OAuth 2.0 and the &#8220;Grant type&#8221; that is used for OAuth authorization as in the image below<\/li><li>Once the &#8220;Grant type&#8221; has been selected you will need to populate the details for that specific grant type (the details can be found either by accessing the interface of the OAuth provider or from the team that is in charge of the OAuth provider integration)<\/li><li>Once the details are entered the only thing left to do is to enter the APIs that are going to be tested<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-1280x525.png\" alt=\"\" class=\"wp-image-2457\" width=\"580\" height=\"237\" srcset=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-1280x525.png 1280w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-800x328.png 800w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-600x246.png 600w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-768x315.png 768w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-1536x630.png 1536w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/Screenshot-2022-06-30-at-12.51.58-2048x840.png 2048w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><figcaption>Configure OAuth 2.0 for Performance Test<\/figcaption><\/figure>\n\n\n\n<p>The call to the authorization server will be done only once before the performance testing of the API endpoints starts. A token will be retrieved from the authorization server and the token is going to be used to make the calls for testing the APIs in the created test configuration.<\/p>\n\n\n\n<p>We are not going to make more than 1 call to the authorization server as that will more likely result in a &#8220;429 Too Many Requests&#8221; error.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><a href=\"https:\/\/loadfocus.com\"><img loading=\"lazy\" decoding=\"async\" width=\"870\" height=\"360\" src=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/sign-up.jpeg\" alt=\"\" class=\"wp-image-2301\" srcset=\"https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/sign-up.jpeg 870w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/sign-up-800x331.jpeg 800w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/sign-up-600x248.jpeg 600w, https:\/\/loadfocus.com\/blog\/wp-content\/uploads\/sign-up-768x318.jpeg 768w\" sizes=\"auto, (max-width: 870px) 100vw, 870px\" \/><\/a><figcaption>Cloud Testing Platform for Websites and APIs.<\/figcaption><\/figure>\n\n\n\n<p><em>Written by&nbsp;Chris R.<\/em><\/p>\n\n\n\n<p><em><a href=\"https:\/\/loadfocus.com\/\">LoadFocus<\/a>&nbsp;is a cloud testing platform,&nbsp;a&nbsp;<a href=\"https:\/\/loadfocus.com\/load-testing\" target=\"_blank\" rel=\"noreferrer noopener\">load and stress testing tool<\/a>&nbsp;which provides the infrastructure to run tests with thousands of concurrent users, from&nbsp;<a href=\"https:\/\/loadfocus.com\/locations\">multiple cloud locations<\/a>, in less than a few minutes, keep history of the results, compare different runs to inspect performance improvements or performance degradation.<\/em>&nbsp;<em>It also supports running&nbsp;<a href=\"https:\/\/loadfocus.com\/jmeter-load-testing\" target=\"_blank\" rel=\"noreferrer noopener\">JMeter load tests from the cloud<\/a><\/em>&nbsp;and&nbsp;<a href=\"https:\/\/loadfocus.com\/page-speed-monitoring\">monitoring and audit web and mobile performance<\/a>.<\/p>\n<!-- pn-faq --><h2>Frequently Asked Questions<\/h2><h3>Where should token acquisition sit?<\/h3><p>Outside the measured path. Otherwise the identity provider&#8217;s timings are folded into your API&#8217;s numbers, and you cannot tell which one is slow.<\/p><h3>Do I need to model refresh?<\/h3><p>Yes on any run long enough for tokens to expire. A test that never refreshes is not production-like, and it misses the failure mode where refresh itself becomes the bottleneck.<\/p><h3>What limit catches people out?<\/h3><p>Rate limits on the token endpoint. They cap concurrency before your API does, and the resulting failures look like an application problem rather than an auth one.<\/p><!-- \/pn-faq --><!-- pn-related-reading --><h2>Related reading<\/h2><ul><li><a href=\"https:\/\/loadfocus.com\/blog\/2022\/01\/how-to-test-oauth-secured-apis-apps-using-jmeter\">How to Test OAuth Secured APIs and Apps using JMeter<\/a><\/li><li><a href=\"https:\/\/loadfocus.com\/blog\/2024\/07\/top-10-tools-for-monitoring-oauth-client-credentials-endpoints\">10 Tools for Monitoring OAuth Credentials Endpoints<\/a><\/li><li><a href=\"https:\/\/loadfocus.com\/blog\/2026\/08\/api-performance-testing-oauth2-guide\">Performance Testing APIs With OAuth2<\/a><\/li><\/ul>","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes read<\/span><\/span>Key takeaways Token acquisition should sit outside the measured path so you test the service, not the identity provider. Model expiry and refresh, because a run that never refreshes is not production-like. Watch for rate limits on the token endpoint, which cap concurrency before your API does. LoadFocus now provides easy testing for services that&#8230;  <a href=\"https:\/\/loadfocus.com\/blog\/2022\/06\/performance-testing-of-oauth-2-0-secured-apps-and-services\" class=\"more-link\" title=\"Read Performance Testing of OAuth 2.0 Secured Apps and Services\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":2455,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[479,9],"tags":[393,394],"class_list":["post-2449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-api-monitoring","category-load-testing","tag-oauth-load-testing","tag-secured-apis-oauth"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/posts\/2449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/comments?post=2449"}],"version-history":[{"count":1,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/posts\/2449\/revisions"}],"predecessor-version":[{"id":2765,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/posts\/2449\/revisions\/2765"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/media\/2455"}],"wp:attachment":[{"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/media?parent=2449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/categories?post=2449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/loadfocus.com\/blog\/wp-json\/wp\/v2\/tags?post=2449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}