Research guide

50 Real-World E2E Test Cases for Web Applications

A categorized list of 50 real-world E2E test cases across auth, checkout, search, forms, uploads, RBAC, and billing — each with the user story, steps, and expected result to adapt to your app.

How to use this list

Treat each row as a scenario to adapt, not an assertion to copy. Keep the user story, replace the specifics with your app’s flow, and mark the priority before you automate.

The list is grouped by journey so a release can run the critical set first. Start with the flows that protect revenue, trust, and access.

Authentication (8 cases)

Valid credentials reach the dashboard. Wrong password shows an error and stays on the page. Unknown email does not reveal whether the account exists. Locked or disabled account shows the customer-visible state. Session persists across reload and new tabs. Logout clears the session and a refresh does not restore it. A protected route redirects to sign in and returns to the destination after login. An expired token refreshes without dropping the page.

Checkout and payments (8 cases)

Adding to the cart and opening checkout. Empty cart shows an empty state. Removing an item updates totals. A coupon applies before and after shipping. Checkout with a saved payment method succeeds. A declined card shows a retry path. A 3D Secure challenge completes. The confirmation page shows an order number and the cart clears.

Search, filtering, and pagination (8 cases)

A keyword search returns expected results. No results shows an empty state with a clear message. Filters combine and update results. Clearing filters restores the full list. Pagination moves forward and back without losing filters. Sorting reorders results. A deep link with query parameters renders the filtered state. Filters persist or reset predictably after navigation.

Forms and file uploads (8 cases)

Required fields block submit with inline errors. Email and format validation reject bad input. A multi-step form moves forward and back without losing values. File upload accepts a valid file and shows progress. An unsupported file type is rejected with a message. An oversized file fails with a clear error. Drag-and-drop upload works. A failed upload can be retried without losing the form.

Role-based access and team management (8 cases)

A viewer sees read-only controls and cannot edit. An editor can edit but cannot delete. An admin can invite members. A member of one team is denied access to another team’s data. An anonymous user is blocked from protected routes. A role change takes effect on the next request. A removed member loses access immediately. A denied action returns a clear access-denied state.

Billing and subscription (6 cases)

An upgrade unlocks new limits immediately. A downgrade removes features at the right boundary. A prorated invoice reflects the mid-cycle change. A failed payment enters retry and the customer sees a notice. A cancellation confirms and stops renewals. A reactivation restores the previous plan state.

Release smoke and regression (4 cases)

The app loads without console errors after deploy. Login works on the live environment. The primary core action completes. Key third-party integrations respond. These four checks become the deploy-time smoke set.

Key takeaways

  • Treat the list as scenarios to adapt, not assertions to copy.
  • Group by journey so a release can run the critical set first.
  • Every case needs a user story and an expected outcome to stay reviewable.

Sources

Related CueTest resources