# 1. API Access & Keys — Test Cases

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: api_access_keys.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 | API key management | TC-TI-7-01-001 |
| 1.1 | Create a key with a name and scope | TC-TI-7-01-002 |
| 1.1 | Active keys list | TC-TI-7-01-003 |
| 1.1 | Revoke a key | TC-TI-7-01-004 |
| 1.1 | Key shown only once at creation | TC-TI-7-01-005 |
| 1.1 | Key scope limits access | TC-TI-7-01-006 |
| 1.1 | Management available on web and mobile | TC-TI-7-01-007 |
| 1.1 | Management event logging (created, revoked) | TC-TI-7-01-008 |
| 1.1 | Audit logging of the API key management | TC-TI-7-01-009 |
| 1.1 | Rule: The key is shown only once at creation. | TC-TI-7-01-001 |
| 1.1 | Rule: A revoked key stops working immediately. | TC-TI-7-01-002 |
| 1.1 | Rule: Management events (created, revoked) are logged with the account and the timestamp. | TC-TI-7-01-003 |
| 1.1 | Rule: The API key management is audit-logged with the account and the timestamp. | TC-TI-7-01-004 |
| 1.2 | API usage view | TC-TI-7-01-010 |
| 1.2 | Calls per day shown | TC-TI-7-01-011 |
| 1.2 | Usage by endpoint category | TC-TI-7-01-012 |
| 1.2 | Rate limit headroom shown | TC-TI-7-01-013 |
| 1.2 | Recent errors shown | TC-TI-7-01-014 |
| 1.2 | Set a usage alert threshold | TC-TI-7-01-015 |
| 1.2 | Usage available on web and mobile | TC-TI-7-01-016 |
| 1.2 | Usage event logging (viewed) | TC-TI-7-01-017 |
| 1.2 | Audit logging of the API usage monitoring | TC-TI-7-01-018 |
| 1.2 | Rule: The rate limit headroom is shown against the plan limit. | TC-TI-7-01-010 |
| 1.2 | Rule: A usage alert is sent at the threshold. | TC-TI-7-01-011 |
| 1.2 | Rule: Usage events (viewed) are logged with the account and the timestamp. | TC-TI-7-01-012 |
| 1.2 | Rule: The API usage monitoring is audit-logged with the account and the timestamp. | TC-TI-7-01-013 |
| 1.3 | API documentation | TC-TI-7-01-019 |
| 1.3 | Endpoint reference | TC-TI-7-01-020 |
| 1.3 | Authentication guide | TC-TI-7-01-021 |
| 1.3 | Sandbox environment | TC-TI-7-01-022 |
| 1.3 | Test without affecting live data | TC-TI-7-01-023 |
| 1.3 | Copy example requests | TC-TI-7-01-024 |
| 1.3 | Documentation available on web and mobile | TC-TI-7-01-025 |
| 1.3 | Documentation event logging (viewed) | TC-TI-7-01-026 |
| 1.3 | Audit logging of the API documentation and sandbox | TC-TI-7-01-027 |
| 1.3 | Rule: The sandbox does not affect live data. | TC-TI-7-01-019 |
| 1.3 | Rule: The documentation is versioned with the API. | TC-TI-7-01-020 |
| 1.3 | Rule: Documentation events (viewed) are logged with the account and the timestamp. | TC-TI-7-01-021 |
| 1.3 | Rule: The API documentation and sandbox is audit-logged with the account and the timestamp. | TC-TI-7-01-022 |

## 1.1 API Key Management

### TC-TI-7-01-001 — API key management
**Type:** Positive
**Covers:** 1.1 → API key management; Rule: The key is shown only once at creation.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: API key management.
2. Observe the result and verify the full behavior: API key management.
**Expected Result:** API key management — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-01-002 — Create a key with a name and scope
**Type:** Positive
**Covers:** 1.1 → Create a key with a name and scope; Rule: A revoked key stops working immediately.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Create a key with a name and scope.
2. Observe the result and verify the full behavior: Create a key with a name and scope.
**Expected Result:** Create a key with a name and scope — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-003 — Active keys list
**Type:** Positive
**Covers:** 1.1 → Active keys list; Rule: Management events (created, revoked) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Active keys list.
2. Observe the result and verify the full behavior: Active keys list.
**Expected Result:** Active keys list — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-004 — Revoke a key
**Type:** Positive
**Covers:** 1.1 → Revoke a key; Rule: The API key management is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Revoke a key.
2. Observe the result and verify the full behavior: Revoke a key.
**Expected Result:** Revoke a key — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-005 — Key shown only once at creation
**Type:** Positive
**Covers:** 1.1 → Key shown only once at creation
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Key shown only once at creation.
2. Observe the result and verify the full behavior: Key shown only once at creation.
**Expected Result:** Key shown only once at creation — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-006 — Key scope limits access
**Type:** Edge
**Covers:** 1.1 → Key scope limits access
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Key scope limits access.
2. Observe the result and verify the full behavior: Key scope limits access.
**Expected Result:** Key scope limits access — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-007 — Management available on web and mobile
**Type:** Positive
**Covers:** 1.1 → Management available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Management available on web and mobile.
2. Observe the result and verify the full behavior: Management available on web and mobile.
**Expected Result:** Management available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-008 — Management event logging (created, revoked)
**Type:** Positive
**Covers:** 1.1 → Management event logging (created, revoked)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Management event logging (created, revoked).
2. Observe the result and verify the full behavior: Management event logging (created, revoked).
**Expected Result:** Management event logging (created, revoked) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-009 — Audit logging of the API key management
**Type:** Positive
**Covers:** 1.1 → Audit logging of the API key management
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the API key management action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The API key management action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.2 API Usage Monitoring

### TC-TI-7-01-010 — API usage view
**Type:** Positive
**Covers:** 1.2 → API usage view; Rule: The rate limit headroom is shown against the plan limit.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: API usage view.
2. Observe the result and verify the full behavior: API usage view.
**Expected Result:** API usage view — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-01-011 — Calls per day shown
**Type:** Positive
**Covers:** 1.2 → Calls per day shown; Rule: A usage alert is sent at the threshold.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Calls per day shown.
2. Observe the result and verify the full behavior: Calls per day shown.
**Expected Result:** Calls per day shown — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-012 — Usage by endpoint category
**Type:** Positive
**Covers:** 1.2 → Usage by endpoint category; Rule: Usage events (viewed) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Usage by endpoint category.
2. Observe the result and verify the full behavior: Usage by endpoint category.
**Expected Result:** Usage by endpoint category — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-013 — Rate limit headroom shown
**Type:** Edge
**Covers:** 1.2 → Rate limit headroom shown; Rule: The API usage monitoring is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Rate limit headroom shown.
2. Observe the result and verify the full behavior: Rate limit headroom shown.
**Expected Result:** Rate limit headroom shown — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-014 — Recent errors shown
**Type:** Positive
**Covers:** 1.2 → Recent errors shown
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Recent errors shown.
2. Observe the result and verify the full behavior: Recent errors shown.
**Expected Result:** Recent errors shown — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-015 — Set a usage alert threshold
**Type:** Edge
**Covers:** 1.2 → Set a usage alert threshold
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Set a usage alert threshold.
2. Observe the result and verify the full behavior: Set a usage alert threshold.
**Expected Result:** Set a usage alert threshold — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-016 — Usage available on web and mobile
**Type:** Positive
**Covers:** 1.2 → Usage available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Usage available on web and mobile.
2. Observe the result and verify the full behavior: Usage available on web and mobile.
**Expected Result:** Usage available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-017 — Usage event logging (viewed)
**Type:** Positive
**Covers:** 1.2 → Usage event logging (viewed)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Usage event logging (viewed).
2. Observe the result and verify the full behavior: Usage event logging (viewed).
**Expected Result:** Usage event logging (viewed) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-018 — Audit logging of the API usage monitoring
**Type:** Positive
**Covers:** 1.2 → Audit logging of the API usage monitoring
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the API usage monitoring action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The API usage monitoring action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.3 API Documentation & Sandbox

### TC-TI-7-01-019 — API documentation
**Type:** Positive
**Covers:** 1.3 → API documentation; Rule: The sandbox does not affect live data.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: API documentation.
2. Observe the result and verify the full behavior: API documentation.
**Expected Result:** API documentation — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-01-020 — Endpoint reference
**Type:** Positive
**Covers:** 1.3 → Endpoint reference; Rule: The documentation is versioned with the API.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Endpoint reference.
2. Observe the result and verify the full behavior: Endpoint reference.
**Expected Result:** Endpoint reference — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-021 — Authentication guide
**Type:** Positive
**Covers:** 1.3 → Authentication guide; Rule: Documentation events (viewed) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Authentication guide.
2. Observe the result and verify the full behavior: Authentication guide.
**Expected Result:** Authentication guide — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-022 — Sandbox environment
**Type:** Positive
**Covers:** 1.3 → Sandbox environment; Rule: The API documentation and sandbox is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sandbox environment.
2. Observe the result and verify the full behavior: Sandbox environment.
**Expected Result:** Sandbox environment — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-023 — Test without affecting live data
**Type:** Positive
**Covers:** 1.3 → Test without affecting live data
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Test without affecting live data.
2. Observe the result and verify the full behavior: Test without affecting live data.
**Expected Result:** Test without affecting live data — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-024 — Copy example requests
**Type:** Positive
**Covers:** 1.3 → Copy example requests
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Copy example requests.
2. Observe the result and verify the full behavior: Copy example requests.
**Expected Result:** Copy example requests — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-025 — Documentation available on web and mobile
**Type:** Positive
**Covers:** 1.3 → Documentation available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Documentation available on web and mobile.
2. Observe the result and verify the full behavior: Documentation available on web and mobile.
**Expected Result:** Documentation available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-026 — Documentation event logging (viewed)
**Type:** Positive
**Covers:** 1.3 → Documentation event logging (viewed)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Documentation event logging (viewed).
2. Observe the result and verify the full behavior: Documentation event logging (viewed).
**Expected Result:** Documentation event logging (viewed) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-01-027 — Audit logging of the API documentation and sandbox
**Type:** Positive
**Covers:** 1.3 → Audit logging of the API documentation and sandbox
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the API documentation and sandbox action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The API documentation and sandbox action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
