validating-api-responses
Ensures API reliability by validating responses against documented schemas and contracts.
Install
mkdir -p .claude/skills/validating-api-responses && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7104" && unzip -o skill.zip -d .claude/skills/validating-api-responses && rm skill.zipInstalls to .claude/skills/validating-api-responses
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Validate API responses against schemas to ensure contract complianceKey capabilities
- →Validate API responses against OpenAPI schemas
- →Detect schema drift and undocumented fields
- →Enforce contract compliance in CI pipelines
- →Validate required response headers
- →Generate validation coverage reports
How it works
Uses JSON Schema validators to intercept and compare API responses against documented OpenAPI specifications to ensure contract adherence.
Inputs & outputs
When to use validating-api-responses
- →Validating API response correctness
- →Enforcing contract compliance
- →Detecting schema drift during tests
About this skill
Validating API Responses
Overview
Validate API responses against OpenAPI schemas, JSON Schema definitions, and contract specifications to detect data integrity violations, schema drift, and backward compatibility regressions. Run validation in middleware (development/staging) or as post-deployment contract tests to ensure every response conforms to the documented API contract.
Prerequisites
- OpenAPI 3.0+ specification with complete response schema definitions for all endpoints
- JSON Schema validator: Ajv (Node.js), jsonschema (Python), or everit-org/json-schema (Java)
- Response validation middleware or test harness integrated into CI pipeline
- API test client for exercising endpoints and capturing response bodies
- Schema diff tool for detecting contract changes between versions
Instructions
- Read the OpenAPI specification using Read and extract all response schemas per endpoint, including success responses (200, 201), error responses (400, 404, 500), and header definitions.
- Compile JSON Schema validators for each endpoint-status combination, enabling strict mode (
additionalProperties: false) to detect undocumented fields leaking into responses. - Implement response validation middleware that intercepts outgoing responses and validates the body against the corresponding schema, logging violations without blocking responses in production.
- Configure validation strictness per environment:
strict(fail on violation) in development/staging,warn(log only) in production, with violation metrics emitted for monitoring. - Add header validation to verify required response headers (Content-Type, Cache-Control, rate limit headers) match the OpenAPI specification.
- Build a contract test suite that sends representative requests to each endpoint and validates every response field, including nested objects, arrays, enums, nullable fields, and format constraints (date-time, email, URI).
- Implement schema drift detection that compares the current response shape against the documented schema after each deployment, alerting when undocumented fields appear or documented fields disappear.
- Generate a validation coverage report showing which endpoints and response codes have schema validation, identifying gaps in the specification.
See ${CLAUDE_SKILL_DIR}/references/implementation.md for the full implementation guide.
Output
${CLAUDE_SKILL_DIR}/src/middleware/response-validator.js- Response schema validation middleware${CLAUDE_SKILL_DIR}/src/validators/- Compiled JSON Schema validators per endpoint${CLAUDE_SKILL_DIR}/tests/contract/- Contract test suite validating all endpoint responses${CLAUDE_SKILL_DIR}/reports/validation-coverage.md- Schema coverage report per endpoint and status code${CLAUDE_SKILL_DIR}/reports/schema-drift.json- Detected undocumented response field changes${CLAUDE_SKILL_DIR}/src/config/validation.js- Per-environment validation strictness configuration
Error Handling
| Error | Cause | Solution |
|---|---|---|
| Additional property detected | Response contains field not defined in schema | Add field to schema if intentional; remove from serializer if data leak; configure additionalProperties |
| Type mismatch | Field returns string instead of documented integer (or vice versa) | Fix serializer to match schema type; add type coercion test; check ORM field mapping |
| Required field missing | Response omits a field marked required in schema | Verify database query includes the field; check conditional serialization logic |
| Null value on non-nullable | Field returns null but schema does not include nullable: true | Update schema to allow null, or fix data source to guarantee non-null values |
| Format validation failure | Date field does not match RFC 3339 format or email field format invalid | Apply format serialization at the ORM/model level before response construction |
Refer to ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error patterns.
Examples
CI contract gate: On every pull request, run contract tests that validate all endpoint responses against the OpenAPI spec, failing the build if any response violates the documented schema.
Production response sampling: In production, validate 5% of responses against schemas (sampled randomly), emitting response_validation_failure metrics to detect schema drift caused by data changes.
Backward compatibility check: Compare v1 and v2 response schemas to verify that v2 is a superset of v1 (no removed fields, no type changes), ensuring existing consumers are not broken.
See ${CLAUDE_SKILL_DIR}/references/examples.md for additional examples.
Resources
- JSON Schema Specification: https://json-schema.org/specification
- Ajv JSON Schema validator: https://ajv.js.org/
- OpenAPI response validation best practices
- Consumer-Driven Contract Testing with Pact: https://pact.io/
When not to use it
- →When the API lacks an OpenAPI specification
Prerequisites
Limitations
- →Requires complete response schema definitions for all endpoints
- →Strict mode may block responses if not configured correctly
How it compares
Automates contract testing and schema drift detection instead of relying on manual endpoint verification.
Compared to similar skills
validating-api-responses side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| validating-api-responses (this skill) | 1 | 26d | Review | Advanced |
| swapper-integration | 6 | 5mo | Caution | Intermediate |
| run-api-e2e-tests | 7 | 6mo | Review | Beginner |
| langfuse-ci-integration | 2 | 26d | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
swapper-integration
shapeshift
Integrate new DEX aggregators, swappers, or bridge protocols (like Bebop, Portals, Jupiter, 0x, 1inch, etc.) into ShapeShift Web. Activates when user wants to add, integrate, or implement support for a new swapper. Guides through research, implementation, and testing following established patterns.
run-api-e2e-tests
novuhq
Run e2e tests for the API service. Use when the user wants to run API E2E tests.
langfuse-ci-integration
jeremylongshore
Configure Langfuse CI/CD integration with GitHub Actions and automated testing. Use when setting up automated testing, configuring CI pipelines, or integrating Langfuse tests into your build process. Trigger with phrases like "langfuse CI", "langfuse GitHub Actions", "langfuse automated tests", "CI langfuse", "langfuse pipeline".
api-test-generator
mikopbx
Генерация полных Python pytest тестов для REST API эндпоинтов с валидацией схемы. Использовать при создании тестов для новых эндпоинтов, добавлении покрытия для CRUD операций или валидации соответствия API с OpenAPI схемами.
http-generate
spring-ai-alibaba
Generates HTTP request examples for Spring Boot Web interfaces according to task specification and saves them as .http files in module-generate.md directories
openapi-analyzer
mikopbx
Извлечение и анализ OpenAPI 3.1.0 спецификации из MikoPBX для валидации эндпоинтов. Использовать при проверке соответствия API, генерации тестов, проверке схем эндпоинтов или интеграции с навыками endpoint-validator и api-test-generator.