VA

validating-api-responses

Ensures API reliability by validating responses against documented schemas and contracts.

Install

mkdir -p .claude/skills/validating-api-responses && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7104" && unzip -o skill.zip -d .claude/skills/validating-api-responses && rm skill.zip

Installs to .claude/skills/validating-api-responses

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Validate API responses against schemas to ensure contract compliance
68 charsno explicit “when” trigger
Advanced

Key capabilities

  • Validate API responses against OpenAPI schemas
  • Detect schema drift and undocumented fields
  • Enforce contract compliance in CI pipelines
  • Validate required response headers
  • Generate validation coverage reports

How it works

Uses JSON Schema validators to intercept and compare API responses against documented OpenAPI specifications to ensure contract adherence.

Inputs & outputs

You give it
API response body and OpenAPI schema
You get back
Validation report or schema violation log

When to use validating-api-responses

  • Validating API response correctness
  • Enforcing contract compliance
  • Detecting schema drift during tests

About this skill

Validating API Responses

Overview

Validate API responses against OpenAPI schemas, JSON Schema definitions, and contract specifications to detect data integrity violations, schema drift, and backward compatibility regressions. Run validation in middleware (development/staging) or as post-deployment contract tests to ensure every response conforms to the documented API contract.

Prerequisites

  • OpenAPI 3.0+ specification with complete response schema definitions for all endpoints
  • JSON Schema validator: Ajv (Node.js), jsonschema (Python), or everit-org/json-schema (Java)
  • Response validation middleware or test harness integrated into CI pipeline
  • API test client for exercising endpoints and capturing response bodies
  • Schema diff tool for detecting contract changes between versions

Instructions

  1. Read the OpenAPI specification using Read and extract all response schemas per endpoint, including success responses (200, 201), error responses (400, 404, 500), and header definitions.
  2. Compile JSON Schema validators for each endpoint-status combination, enabling strict mode (additionalProperties: false) to detect undocumented fields leaking into responses.
  3. Implement response validation middleware that intercepts outgoing responses and validates the body against the corresponding schema, logging violations without blocking responses in production.
  4. Configure validation strictness per environment: strict (fail on violation) in development/staging, warn (log only) in production, with violation metrics emitted for monitoring.
  5. Add header validation to verify required response headers (Content-Type, Cache-Control, rate limit headers) match the OpenAPI specification.
  6. Build a contract test suite that sends representative requests to each endpoint and validates every response field, including nested objects, arrays, enums, nullable fields, and format constraints (date-time, email, URI).
  7. Implement schema drift detection that compares the current response shape against the documented schema after each deployment, alerting when undocumented fields appear or documented fields disappear.
  8. Generate a validation coverage report showing which endpoints and response codes have schema validation, identifying gaps in the specification.

See ${CLAUDE_SKILL_DIR}/references/implementation.md for the full implementation guide.

Output

  • ${CLAUDE_SKILL_DIR}/src/middleware/response-validator.js - Response schema validation middleware
  • ${CLAUDE_SKILL_DIR}/src/validators/ - Compiled JSON Schema validators per endpoint
  • ${CLAUDE_SKILL_DIR}/tests/contract/ - Contract test suite validating all endpoint responses
  • ${CLAUDE_SKILL_DIR}/reports/validation-coverage.md - Schema coverage report per endpoint and status code
  • ${CLAUDE_SKILL_DIR}/reports/schema-drift.json - Detected undocumented response field changes
  • ${CLAUDE_SKILL_DIR}/src/config/validation.js - Per-environment validation strictness configuration

Error Handling

ErrorCauseSolution
Additional property detectedResponse contains field not defined in schemaAdd field to schema if intentional; remove from serializer if data leak; configure additionalProperties
Type mismatchField returns string instead of documented integer (or vice versa)Fix serializer to match schema type; add type coercion test; check ORM field mapping
Required field missingResponse omits a field marked required in schemaVerify database query includes the field; check conditional serialization logic
Null value on non-nullableField returns null but schema does not include nullable: trueUpdate schema to allow null, or fix data source to guarantee non-null values
Format validation failureDate field does not match RFC 3339 format or email field format invalidApply format serialization at the ORM/model level before response construction

Refer to ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error patterns.

Examples

CI contract gate: On every pull request, run contract tests that validate all endpoint responses against the OpenAPI spec, failing the build if any response violates the documented schema.

Production response sampling: In production, validate 5% of responses against schemas (sampled randomly), emitting response_validation_failure metrics to detect schema drift caused by data changes.

Backward compatibility check: Compare v1 and v2 response schemas to verify that v2 is a superset of v1 (no removed fields, no type changes), ensuring existing consumers are not broken.

See ${CLAUDE_SKILL_DIR}/references/examples.md for additional examples.

Resources

When not to use it

  • When the API lacks an OpenAPI specification

Prerequisites

OpenAPI 3.0+ specificationJSON Schema validatorResponse validation middleware

Limitations

  • Requires complete response schema definitions for all endpoints
  • Strict mode may block responses if not configured correctly

How it compares

Automates contract testing and schema drift detection instead of relying on manual endpoint verification.

Compared to similar skills

validating-api-responses side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
validating-api-responses (this skill)126dReviewAdvanced
swapper-integration65moCautionIntermediate
run-api-e2e-tests76moReviewBeginner
langfuse-ci-integration226dReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

swapper-integration

shapeshift

Integrate new DEX aggregators, swappers, or bridge protocols (like Bebop, Portals, Jupiter, 0x, 1inch, etc.) into ShapeShift Web. Activates when user wants to add, integrate, or implement support for a new swapper. Guides through research, implementation, and testing following established patterns.

696

run-api-e2e-tests

novuhq

Run e2e tests for the API service. Use when the user wants to run API E2E tests.

711

langfuse-ci-integration

jeremylongshore

Configure Langfuse CI/CD integration with GitHub Actions and automated testing. Use when setting up automated testing, configuring CI pipelines, or integrating Langfuse tests into your build process. Trigger with phrases like "langfuse CI", "langfuse GitHub Actions", "langfuse automated tests", "CI langfuse", "langfuse pipeline".

212

api-test-generator

mikopbx

Генерация полных Python pytest тестов для REST API эндпоинтов с валидацией схемы. Использовать при создании тестов для новых эндпоинтов, добавлении покрытия для CRUD операций или валидации соответствия API с OpenAPI схемами.

16

http-generate

spring-ai-alibaba

Generates HTTP request examples for Spring Boot Web interfaces according to task specification and saves them as .http files in module-generate.md directories

16

openapi-analyzer

mikopbx

Извлечение и анализ OpenAPI 3.1.0 спецификации из MikoPBX для валидации эндпоинтов. Использовать при проверке соответствия API, генерации тестов, проверке схем эндпоинтов или интеграции с навыками endpoint-validator и api-test-generator.

25

Search skills

Search the agent skills registry