Goal
Plan external integrations so they are secure, observable, and replaceable enough for the product stage.
When to Use
- The system depends on external APIs or providers.
- Provider choice affects architecture or UX.
- Webhooks, sync jobs, or secrets management need planning.
Instructions
- Define what business capability the integration supports.
- Choose the trusted execution layer for the integration.
- Plan auth/secrets, retries, idempotency, and error visibility.
- Define data ownership between your system and the provider.
- Note provider lock-in and replacement risk only where it matters.
Constraints
- Never expose provider secrets in the client.
- Do not make the user wait on slow integrations if async is viable.
- Avoid adding providers without a clear product reason.
Output Format
- Integration summary
- Provider responsibilities
- Security and execution model
- Failure handling
- Open risks
Examples
- "Plan Stripe, email, and OpenAI integrations for this app."
- "How should webhooks fit into this architecture?"