Getting started
Choose how to install Shift-Left API (Cloud or Self-hosted), then complete initial setup so you can create projects and run API tests.
Help Center
Find installation steps, configuration guidance, and release notes—fast. Search across all Help Center content in one place.
Start with the basics, then refine runs for CI/CD reliability and coverage.
Choose Cloud or Windows self-hosting, install the Platform Installer, Engine, and Studio, and get MongoDB-ready for the Engine.
First-time setup—admin account, license, users, first project—and where to set base URL, auth, and test configuration in Total Shift Left.
Explore platform features, workflow concepts, and how the pieces fit together.
See what's new and what changed--feature highlights, fixes, and improvements.
Get the latest Total Shift Left installer for Windows and macOS.
Browse the latest updates and foundational docs.
Choose how to install Shift-Left API (Cloud or Self-hosted), then complete initial setup so you can create projects and run API tests.
Step-by-step guide to install Shift-Left API on Windows—Installer, Engine, Studio, MongoDB setup, and verification.
Where to configure base URL, authentication, and environment variables in Shift-Left API so test runs are stable and CI-ready.
Complete first-time setup—core preferences, licensing, users, and your first project—then validate the installation with a test run.
A map of the platform: the project/feature/endpoint tree, the Execution, Reporting, Analytics, Mocks and Workflows areas, and the path from spec to results.
Create a project — the workspace holding your endpoints, tests, environments, and results. Covers naming, scoping decisions, and what to do immediately after.
Import an OpenAPI, WSDL, or GraphQL definition into your project by file upload or URL, with Auto-Detect, then confirm the endpoints that were discovered.
Navigate the project → feature → endpoint tree in the sidebar: search and filter projects, open features, select endpoints, and reach the test workflow.
Set base URLs per environment, authentication profiles, default headers, change detection, and AI generation options — the settings that make a project run.
Most APIs refuse a request that does not prove who is calling. In Shift-Left Studio you describe how to prove it once, in an authentication profile, and every test, pack, workflow and performance run in the project uses it.
Many APIs sit behind an identity provider such as Microsoft Entra ID, Okta, Auth0, Keycloak or Google, and only accept a token issued to a signed-in user. You cannot get that token with a client ID and secret alone.
Some APIs sign you in with a sequence of calls they designed themselves. A typical example: post a username and password, receive a one-time code by SMS or email, post the code back, and receive a bearer token plus a refresh token.
Import a Postman collection (v2.0 or v2.1) into a project: requests become endpoints and tests, pm.test assertions are converted, and anything that needs review is flagged.
Features group endpoints and come from your spec's tags. Covers creating and editing by hand, why tagging matters, and what deleting a feature takes with it.
Import endpoints from OpenAPI/Swagger, WSDL, or GraphQL, bring in requirements from your backlog, and detect endpoint changes as your API evolves.
Find endpoints by method and path, add or edit them by hand, try a request for debugging, and know when to re-import instead of editing the tree manually.
After selecting an endpoint, confirm method, path, connectivity, authentication, and contract alignment before relying on the definition in broader workflows.
Detect when an imported API spec changes, review new, modified, removed, and breaking endpoints in a diff, then approve and import the changes as new endpoint versions.
Rule Intelligence turns requirement documents and API specs into structured, testable requirements—review them, then feed them into test generation with coverage and traceability.
Upload requirement documents, extract text, AI-parse them into typed requirements, then review, edit, and approve the requirements that drive test generation.
Upload sample Excel/CSV data so generated tests use realistic inputs, then check generation readiness per endpoint and tune request/response mapping overrides.
The Coverage tab shows a per-endpoint × strategy test-coverage matrix, flags endpoints with no tests, and reports how faithfully requirements were extracted from your documents.
Trace each requirement to the tests and endpoints that verify it, run impact analysis when requirements change, and export a requirements traceability matrix for audits.
The Learning tab shows what your workspace has learned from reviewer edits and test runs—acceptance rate, edit distance, time to green, flake rate, and a generation-quality score.
Most projects are described by more than one document: a BRD, a rules workbook, a set of user stories, meeting notes, an email thread.
When several documents describe the same system, they overlap. The BRD says "Email is required", the meeting notes say "Customer email must be present", and the rules workbook lists it again as BR-007.
A requirements workbook is rarely one table. A typical file has a cover sheet, a list of numbered requirements under a two-row title, a data dictionary of fields, a sheet of test data, and a glossary.
Requirement documents change. When the BRD moves from v1 to v2, you need to know which rules changed, which are new, and which disappeared — without reviewing all of them again and without losing the tests you already built.
Every other requirements screen reports what Shift-Left Studio found. The Gaps & conflicts tab reports what it could not turn into a test, and why.
The Project Assistant is a chat panel that reads your own project data (requirements, specs, endpoints, tests and runs) before answering, and shows you exactly what it looked at.
Ask the Project Assistant to run tests, fix a failing test, generate tests, link a requirement or schedule a report. It prepares a proposal card, and nothing changes until you accept it.
Build a project from a conversation: ask the Project Assistant to create features, endpoints, tests, requirements, data sets, workflows or authentication, then review each proposal before it is created.
The Project Assistant in Shift-Left Studio learns from you, one project at a time. When an answer misses something about your project, such as "our 401s come from the API gateway, not the API", you can tell it once.
Use Generate tests on the endpoint test-case screen to create critical tests first, then fill coverage gaps—across many test strategies with business-impact severity.
Edit a test's request, assertions, and expected response; run and delete in bulk; and use the coverage verdict to find the gaps your suite still has.
Define environments, variables, headers, and datasets so tests run consistently across dev/stage/prod without hardcoding secrets or setup.
Choose where tests run: Shift-Left Engine on server for CI/CD and schedules, or Shift-Left Agent locally for development and private APIs.
Run endpoint test cases from the actions column, monitor progress, and review detailed test-result summaries with assertions and logs.
Control per project which requirement types the AI extracts, which test strategies fire, and which severity tiers are kept—so generation focuses on what matters for that project.
When a test fails, use Fix with AI to get a proposed patch you can review and apply—plus a fix-suggestion lifecycle that classifies whether the failure is a bad test or a product bug.
Many APIs don't take JSON. A login or OAuth token endpoint may expect an HTML-style form. An avatar or document upload expects a multipart form with a file in it.
Read assertion results row by row (expected, actual, passed), and write custom checks whose script log appears right under the result when they fail.
How Fix with AI grounds each proposed repair in your API contract, your requirements and the last run, and what the workbench Diagnostics show about what was actually sent.
Shift-Left Studio tests JSON-RPC 2.0 services and Model Context Protocol (MCP) servers alongside your REST, SOAP and GraphQL APIs. An MCP server is a JSON-RPC 2.0 server with a fixed set of methods, so the same capability covers both.
Some services are not called with independent HTTP requests. You open a WebSocket connection, sign in once during the handshake, and then send a series of calls over that same connection.
Test endpoints that answer with text/event-stream: see each event in the response viewer, assert on events, and stream with limits on events, duration and idle time.
Run a test once per row of data—from an internal table, a saved dataset, a data source, or a generator—binding columns to request fields with {{row.COLUMN}} tokens.
Create reusable connections to CSV, Excel, databases, JSON, or APIs, then bind their columns into tests with [[variable]] tokens for single-row or iterate-all execution.
Open Test Execution to create, run, schedule, and monitor Test Run Packs. Covers the packs table, Run Now, enable/disable scheduling, and viewing run results.
Build a Test Run Pack in five steps — pack details, test selection, execution preferences, notifications, and scheduling — with the validation rules for each.
After creating a pack, run it now, edit configuration, monitor status, and manage lifecycle actions from the Execution list.
When a run of 200 tests ends with 47 failures, the hard part is not fixing them. It is working out how many different problems those 47 failures actually are.
A green run is good news, but it does not always mean what it seems to. A test that only checks "the status was 200" stays green even if the endpoint starts returning an empty body.
A functional test tells you whether your API gives the right answer. A performance test tells you whether it still gives that answer, fast enough, when many people use it at once.
Design a performance test step by step (kind, workloads, load profile, targets), check it with a dry run, run it and watch it live, then find out why a run failed.
When a performance run finishes, Shift-Left Studio builds one report for it. The same report is what you see on screen, what you export as HTML, JSON or JUnit, what a share link shows, and what the project assistant reads.
Open Reporting to browse execution history, use Run Type to distinguish Functional and Workflow runs, and open reports from the Execution Summaries list.
The first stop after any run: execution metadata, pass rate, test distribution, and per-test rows that drill through into the detailed report.
Second reporting step for Workflow runs only: per-workflow node summary, node table, and View Report to open the detailed report for a node.
Full evidence for one test: the request and response as sent and received, validation results, execution logs, and error information.
The Workflow run layout: sequential node executions, extracted variables, per-node request/response and logs, and why an early failure cascades.
How Analytics differs from Reporting: trends over time rather than one run. Covers project metrics, time ranges, and what each view answers.
Work the Analytics dashboard: project overview, execution and performance summaries, endpoint analytics, environment comparison, and trends.
Use the Project Analytics tab to select a project, set the time window, and review overview metrics, status breakdowns, execution summary, and expandable trend and failure sections.
See how test outcomes trend over time, catch regressions and newly flaky tests, and compare runs so you know whether quality is improving before a release.
Create named dashboard layouts of widgets and assign them to users, so each role sees the metrics that matter to them—an admin-managed personalization feature.
Share a dashboard via a link (public, authenticated, or password-protected), embed a widget in another site with an iframe/JS snippet, or run a full-screen TV wall display.
Email a dashboard report on a recurring schedule and set threshold alerts on quality metrics so the team is notified in-app, by email, or via webhook when something slips.
Reorder, resize, hide and configure dashboard widgets, pick a Focus Project and time range, and show a dashboard full-screen in TV Mode.
Set the Public Address that shared dashboard links and emailed reports use, and share dashboards from the desktop app when colleagues cannot reach your machine.
API mocks replace real backend calls during test runs or run as a standalone mock server—organized per project with static or dynamic responses across REST, SOAP, and GraphQL.
A step-by-step walkthrough: open API Mocks, pick a project, create or bulk-generate mocks, configure static and dynamic responses with conditions and delays, and start the mock server.
Workflows are integration tests: visual flows of API and logic nodes that chain calls, pass data between steps, and validate with per-step and workflow-level SLA assertions.
Open Workflows, manage the Integration tests list, then build flows in the editor with Test details, Test library, and Node types—extract variables, add assertions, and launch.
A workflow is the one test in Shift-Left Studio that you assemble by hand: blocks on a canvas, green connectors for the order of execution, and data connectors that carry values from one step to the next.
An end-to-end workflow tests a journey — create an order, pay for it, fetch the receipt — rather than one call.
Discuss work in context with threaded comments on tests, endpoints, projects, test runs, requirements, and workflows, with @mentions that surface in the activity feed.
Open Shift-Left API Platform Help to see version and build information for the application, Engine, Studio, and Agent, plus auto-update status and Check for Updates.
How the in-app Settings screen is organized: main tabs and sections map to System Administration documentation so you can jump to the right guide.
Settings > Configuration > Server Connection: point Studio at the Shift-Left Engine URL, view status, and reconfigure when you change environments.
Settings > Configuration > Proxy Settings: enable proxies separately for Shift-Left Engine and Shift-Left Agent based on execution mode.
Read your licence state — Active, Trial, Grace Period, Expired, Revoked, Offline — update the licence key, and understand what each state means for your team.
Settings > Licensing & Users > User Management: search users, review limits, add users, and edit or delete accounts (role and status).
Settings > Licensing & Users > Role Permissions: pick a role, then allow or deny grouped capabilities; reset to default or save changes.
System-wide rules for who can sign up and how: public registration, admin approval, email verification, default role, user caps, and password requirements.
Settings > Integrations > AI Settings: enable the AI engine, choose from ~20 model providers (including self-hosted), manage API keys, and test the connection—system-wide.
Settings > Integrations > Public API: Swagger and base URL, enable API, rate limits, token expiry, and which roles may use the API for CI/CD.
Create the mail profiles that let Shift-Left API send notifications: SMTP and IMAP hosts, ports, security, and credentials — with the usual provider gotchas.
Manage the templates behind notifications: summary, detailed, and custom; categories for reports, system alerts, and test notifications; search and edit.
Monitor user activity and system events: summary tiles, filters by action, entity, role and status, and per-change field-level before/after detail.
Configure log level, file output, rotation and retention, and the sensitive-field redaction list — plus why Debug level is a temporary tool, not a default.
Connect your identity provider (Entra ID/Azure AD, Okta, Google Workspace, or any OIDC/SAML IdP) so users sign in with corporate credentials, with group-to-role mapping.
Create scoped, rotatable API keys for programmatic access to the platform, with a grace window on rotation and immediate revoke—an alternative to username/password login.
Connect HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault so test credentials are resolved at runtime with a secretref:// reference instead of being stored in the app.
Register outbound webhooks that POST signed event notifications to external URLs—for example when a test run completes—with a signing secret, test/redeliver, and a delivery log.
Shift-Left Studio's Model Context Protocol (MCP) server lets you connect Claude, Cursor, or another MCP client to the product. Available as of the September 2026 release (build 2.0.96.231).
Run tests from a lightweight desktop agent on your own machine so you can reach private or internal endpoints the central engine can't, then report results back to the platform.
Data-privacy (GDPR) and HIPAA/PHI capabilities—consent, data-subject access and erasure requests, PHI records and access logs, breach recording, and admin compliance reporting.
Turn on the live Activity Feed for administrators, filter and read events, and understand the one-signed-in-machine-per-user policy that signs an account out when it signs in elsewhere.
Studio now explains your test results instead of just listing them — failed runs grouped into causes, passing runs checked for regressions they would miss, a Project Assistant that answers from your own project and acts on changes you approve, multi-document requirements, self-building workflows, more faithful Postman imports, and a broad performance pass.
A Project Assistant that answers from your own project and can act on it, JSON-RPC 2.0 / MCP and WebSocket-RPC testing, streaming responses, failed runs explained as causes, end-to-end workflows built from your requirements, and a platform-wide performance pass.
Our largest release to date — enterprise SSO and access control, data-driven testing across many rows of data, a rebuilt test-generation engine, the new Test Workbench, a CI/CD runner, and execution parity between the desktop Agent and the cloud Engine.
Data-driven testing built in, enterprise collaboration and access control with workspaces, SSO, and fine-grained roles, plus a smarter AI foundation that learns from your API.
Our biggest release yet—a major leap in automatic test generation, 100+ tests per endpoint, a new Coverage dashboard, faster spec imports, scalable execution, and stronger data security.
Cookie-based authentication, refreshed analytics charts, and a smoother multi-step workflow canvas.
Rename and copy endpoints, plus smoother workflow canvas connector controls across zoom levels.
Reliable auth-profile sync across the Shift-Left Engine and Agent, an EV code-signed Windows installer, and faster test runs.
Documentation navigation improvements, faster Help Center discovery, and minor UI fixes released in February 2026.
We can help you scope coverage, stabilize test data, and wire up spec-first testing for your pipeline.