QA API Testing and Contracts
When to Use This Skill
Use this skill when you need to:
- Design API test plans for REST, GraphQL, or gRPC services.
- Implement contract testing with Pact or consumer-driven workflows.
- Set up schema validation in CI/CD pipelines.
- Review API changes for backward compatibility.
- Define quality gates for API releases.
Scope
- Validate API schemas and enforce contracts.
- Design functional, negative, and edge case tests.
- Plan mocking and consumer driven contracts.
- Define CI gates and release safety checks.
- Align API tests with SLOs and error budgets.
Ask For Inputs
- API type (REST, GraphQL, gRPC) and schemas (OpenAPI, SDL, proto).
- Environments and authentication methods.
- Critical endpoints and business flows.
- Data constraints, idempotency, and rate limits.
- Change cadence and backward compatibility policy.
- Current test tooling and CI pipeline.
Workflow
- Confirm API surface and schema sources.
- Establish contract rules (breaking vs non breaking).
- Generate schema validation tests.
- Create functional tests for happy paths.
- Add negative, boundary, and auth tests.
- Add consumer contract tests or mocks as needed.
- Define CI gates, reporting, and rollback triggers.
Outputs
- API test plan and coverage map by endpoint.
- Contract validation suite and schema checks.
- Negative and security test list.
- Mock and test data strategy.
- CI quality gates and release checklist.
Quality Checks
- Fail fast on schema violations and breaking changes.
- Ensure tests are deterministic and data stable.
- Separate functional tests from load or resilience tests.
- Keep contract tests aligned with versioning policy.
Templates
templates/api-test-plan.mdfor coverage planning.templates/contract-change-checklist.mdfor breaking change review.templates/schema-validation-matrix.mdfor schema tooling and CI stages.
Resources
resources/contract-testing-patterns.mdfor change safety guidance.
Related Skills
- Use dev-api-design for API design decisions.
- Use qa-testing-strategy for overall testing strategy.
- Use qa-resilience for chaos and reliability testing.
- Use software-security-appsec for API security review.