Developer Tools

Mock API

Build a mock REST API with your own JSON, then call it from Android, iOS, web or any HTTP client.

  • Runs in your browser
  • No upload required
  • Free, no signup

Create your Mock API

Sign in to save and manage your APIs. Projects belong to your account, so they stay reachable from any device and keep working after you close the browser.

  • Free, no payment details
  • 100 requests per day
  • 5 endpoints per project

What you can do with it

Any method, any path

GET, POST, PUT, PATCH, DELETE, HEAD and OPTIONS, at literal paths or with parameters like /users/:id. A project groups them behind one base URL.

Your exact response

Any status code from 200 to 599, your own headers, and a JSON, XML, HTML or plain-text body. JSON is validated before it is saved, so a broken document cannot go live.

Simulate failure

Switch an endpoint to 500, 503 or 429 without editing it, using scenarios selected by the X-Mock-Scenario header. Add a delay to test timeouts and retries.

See what arrived

Every request is logged with method, path, status and timing, plus the headers that were sent. Sensitive headers are masked before they are stored.

Dynamic data

Return a fresh {{uuid}} or {{random.email}} on every call, or echo back what the caller sent with {{body.name}}.

Copy-ready samples

Every endpoint comes with a working cURL, JavaScript, Kotlin, Swift, Dart, Python, PHP and Java call using only standard libraries.

A five-second example

Every project starts with a base URL shaped like https://api.toolduck.in/mock/a8f92dkm. An endpoint added at /users/:id is then reachable at that URL plus the path.

Reaching it from a device
curl https://api.toolduck.in/mock/a8f92dkm/users/1

Nothing is installed, nothing is bundled, and no SDK is required — it is an ordinary HTTPS request, which is the point.

What is stored

  • Every request is logged with its method, path, status and duration.
  • Request headers are stored with the value of sensitive ones — Authorization, Cookie, X-API-Key and friends — replaced by ******** before the row is written.
  • Request bodies are stored only when the operator enables it, and are truncated.
  • Logs for an anonymous project are deleted after 24 hours, and only the most recent 50 are kept.
  • A project and all of its data are deleted immediately when you delete it, and automatically when it expires.

A mock endpoint is a public URL. Treat the project id as the only secret and never put real credentials or personal data in a response.

Your data is processed locally in your browser and is not uploaded to our server.

A mock API lets you build against a URL that already works, before the real service exists. Describe an endpoint, choose what it returns, and you have a public URL you can paste into an Android, iOS, Flutter, React Native or web project straight away.

Unlike a form that echoes JSON back, this is a small API platform. A project holds as many endpoints as you need, each with its own method, path, status code, headers and delay. You can return a 500 on demand, add a two-second delay to see how your loading state behaves, and watch every request that arrives — including the ones from a device you cannot attach a debugger to.

How to use this tool

  1. Sign in — an email address and a password, or Google — then name the project and press Create. A project groups related endpoints behind one base URL, so /users, /users/:id and /products can all live together.
  2. Add your first endpoint: pick a method, give it a path such as /users, paste the JSON you want back, and set the status code. Reference a URL value with {{path.id}} or a query value with {{query.page}}.
  3. Copy the endpoint URL and call it with cURL, Postman, or from your app. The endpoint list, the generated code samples and the request log are all on the project page.
  4. Use scenarios to switch one endpoint between success and failure without editing it, or add a delay to test slow networks and timeouts.

Frequently asked questions

What is a mock API?

A mock API is a stand-in for a real service. It responds at a real URL with the response you configure, so a frontend or mobile team can build and test against it before the backend exists or while it is unavailable. Because the response is yours, you also control failure: a mock is the easiest way to produce a 503 or a slow reply on purpose.

Do I need an account?

You need one to create a project, because a project has to belong to somebody. Signing up is free and takes an email address and a password, or you can continue with Google. Projects made before accounts existed are moved into the account you sign in with from the same browser, once.

Can I call the endpoint from an Android or iOS application?

Yes. The endpoint is an ordinary HTTPS URL with permissive CORS, so it works from an Android app, an iOS app, Flutter, React Native, a browser, Postman or a backend service. There is nothing to install and no SDK to add.

How do I make the endpoint return an error?

Set the status code to whatever you need — 400, 401, 404, 422, 500 — and write an error body. Or add a scenario: one endpoint can carry a success response and a failure response, and you switch between them with the X-Mock-Scenario header, which means your app can be tested against both without changing any code.

How do I simulate a slow network?

Set a delay on the endpoint. Delays from 100 milliseconds up to 5 seconds are available, and the delay is applied before the response is sent, so your loading spinner, timeout handling and retry logic all get exercised for real rather than in a simulator.

Can the response change on every request?

Yes. Use the dynamic values — {{uuid}}, {{timestamp}}, {{random.integer}} and the rest — and each request gets freshly generated data. You can also echo back what the caller sent with {{body.name}} or {{query.page}}, which is useful for confirming that a real device is sending the payload you expect.

Is my mock API public?

Calling it is public — that is what makes it useful from a phone or another machine. Managing it is not: only the account that owns a project can see or change it. Request bodies are never stored, sensitive headers such as Authorization and Cookie are masked before anything is written, only the most recent 50 requests are kept, and those are deleted after 7 days. Treat the URL as the only secret and do not have an endpoint return anything confidential.

What are the free limits?

A free account gives you 10 projects, each with up to 50 endpoints and 10 scenarios per endpoint, 2,000 requests per day and 120 per minute, responses up to 256 KB, and delays up to 5 seconds. Projects do not expire. The figures are also shown on the project page next to your remaining quota, so you never have to guess.