> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# API pull request testing

> A change review can run an API application when you pass its preview base URL.

A change review can run tests for an API application. The review agent executes tests against a preview deployment URL or a mobile build. An API application's environment is a base URL, so it uses the preview URL path, not a build upload.

Point the review at that application:

* GitHub Change Review Action: set `environment.url` to the preview API base URL inside `applications_config`.
* Change review API: set `environment.url` on that application's `applicationOverrides` entry.

There is no application-kind filter on those overrides. A mapped environment is a ready deployment, and the agent runs the tests that belong to it. The API agent then calls that base URL from the sandbox. See [API testing](/core-concepts/api-testing).

If the change is only visible through a website, the review tests it in the web application instead. Backend changes that power a user-facing flow are covered through that UI.

When the preview is behind Vercel deployment protection, API tests should send `x-vercel-protection-bypass` only. Do not send `x-vercel-set-bypass-cookie`: the sandbox has no cookie jar, so that header loops and the request fails.

<Note>
  This page is the API application. Starting the review from a pipeline that is
  not GitHub Actions, GitLab CI, or Bitrise is [API pull request
  testing](/pr-testing/api).
</Note>
