Verifying code that calls other systems.
WHAT MAKES IT HARD
The other system is not under your control It may be slow, rate limited or unavailable Test environments differ from production
WHAT TO TEST AGAINST MOSTLY
A substitute you control.
WHAT THE SUBSTITUTE MUST REPRODUCE
Successful responses Every documented error Timeouts Malformed responses
WHY MALFORMED RESPONSES
Real services return unexpected content, and handling must be verified.
WHAT CONTRACT TESTING PROVIDES
Confirmation that your expectations match the provider's actual behaviour.
WHAT TO RUN AGAINST THE REAL SERVICE
A small set, periodically.
WHY
To confirm the substitute has not diverged.
WHAT TO TEST IN YOUR OWN CODE
Retry behaviour, including that it stops Timeout handling Idempotency Behaviour when the service is entirely down
WHAT TO VERIFY ABOUT RETRIES
That they do not duplicate effects.
WHAT TO TEST ABOUT WEBHOOKS YOU RECEIVE
Signature verification, including rejection of bad signatures Duplicate events Out-of-order events
WHY SIGNATURE REJECTION SPECIFICALLY
An implementation that never rejects is not verifying.
WHAT TO AUTOMATE
All of it, in the pipeline.
WHAT TO MONITOR IN PRODUCTION
Whether the provider's behaviour changed.