# Schema Reference
Exhaustive specification of the test file format.
## Global `[config]`
| `base_url` | string | yes | Base URL for all requests |
| `default_headers` | map<string,string> | no | Added to every request |
| `insecure` | bool | no | Accept invalid TLS certs |
| `allowed_commands`| array<string> | no | Whitelist for command hooks |
Environment variables can be interpolated in any string via <code v-pre>${{NAME}}</code>.
```toml
[config]
base_url = "https://api.example.com"
default_headers = { "Content-Type" = "application/json" }
insecure = false
allowed_commands = ["bash", "sh", "echo", "jq"]
```
## `[[tests]]` entries
| `name` | string | yes | Display name |
| `method` | string | yes | GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS |
| `endpoint` | string | yes | Appended to `base_url`; supports <code v-pre>{{vars}}</code> |
| `query_params` | map<string,string> | no | Each value supports <code v-pre>{{vars}}</code> and <code v-pre>${{ENV}}</code> |
| `headers` | map<string,string> | no | Per-test headers |
| `body` | JSON value | no | Inline JSON; strings support <code v-pre>{{vars}}</code> and <code v-pre>{{file:path}}</code> |
| `body_file` | string (relative path) | no | Load body from file; `.json` parsed as JSON |
| `expected_status` | number | yes | HTTP status code |
| `expected_body` | JSON value | no | Exact match; use `assertions` for flexible checks |
| `assertions` | `array<Assertion>` | no | See Assertions Reference |
| `store` | map<string,string> | no | JSONPath (like `$.id`) → variable name |
| `get_cookie` | map<string,string> | no | Cookie name → variable name |
| `max_response_time` | number (ms) | no | Fails if exceeded |
| `before` | `array<CommandStep>` | no | Run before HTTP call |
| `after` | `array<CommandStep>` | no | Run after; supports `on` condition |
Mutual exclusivity: `body` and `body_file` cannot be used together.
### CommandStep
| `run` | string | yes | Command binary or script |
| `args` | array<string> | no | Arguments array |
| `shell` | bool | no | Run via shell (`sh -lc`) |
| `dir` | string | no | Working directory |
| `env` | map<string,string> | no | Step environment variables |
| `timeout_ms` | number | no | Default 30000 |
| `ignore_error`| bool | no | Don’t fail on non-zero exit |
| `capture` | `{ var: string }` | no | Save stdout→`{{var}}`, stderr→`{{var}}_stderr` |
| `export` | map<string,string> | no | JSONPath from stdout → variable |
| `when` | string | no | Simple `==`/`!=` condition after substitution |
| `on` | string | no | Only for `after`: `success`/`failure`/`always` |
Security: every step is validated against `[config].allowed_commands`.