Agent skill

Validating API Contracts

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract).

MITAuto-check passedBackend & APIs

Install Validating API Contracts

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-api-contracts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace validating-api-contracts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/validating-api-contracts .claude/skills/validating-api-contracts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validating-api-contracts
GitHub stars
2.8k
Token cost
~1.8k tokens
SKILL.md length
550 words
Files
9 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract).

  • Works in 7 steps: Identify consumer-provider relationships… → Write consumer-side contract tests (Pact… → Publish consumer contracts to the Pact… → …
  • Performing specialized testing
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; calls git; needs PACT_BROKER_TOKEN

What it does

Validating API Contracts is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract). Use when performing specialized testing. Trigger with phrases like "validate API contract", "run contract tests", or "check consumer contracts".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/config_template.yaml` and `assets/openapi_example.yaml`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering API design and Integration testing. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Performing specialized testing
  • With phrases like validate API contract
  • Run contract tests
  • Check consumer contracts

Example prompts

  • “validate API contract”
  • “run contract tests”
  • “check consumer contracts”
  • “/validating-api-contracts”

Requirements

  • Python 3
  • A credential in PACT_BROKER_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(test:contract-*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify consumer-provider relationships in the system
  2. Write consumer-side contract tests (Pact consumer tests)
  3. Publish consumer contracts to the Pact Broker
  4. Write provider-side verification tests
  5. Handle contract evolution
  6. For schema-based validation (non-Pact)
  7. Integrate contract tests into the CI/CD pipeline for both consumers and providers.

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(test:contract-*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.pact.io
    • pactflow.io
    • spring.io
    • github.com
    • martinfowler.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PACT_BROKER_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Validating API Contracts loads about 1.8k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 550 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 550 words, ~1,772 tokens.

Download SKILL.mdSave it as .claude/skills/validating-api-contracts/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
validating-api-contracts
description
Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract). Use when performing specialized testing. Trigger with phrases like "validate API contract", "run contract tests", or "check consumer contracts".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(test:contract-*)
compatibility
Designed for Claude Code
version
1.24.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
testing, api, validating-api

Contract Test Validator

Overview

Validate API contracts between services using consumer-driven contract testing to prevent breaking changes in microservice architectures. Supports Pact (the industry standard for CDC testing), Spring Cloud Contract (JVM), and OpenAPI-diff for specification comparison.

Prerequisites

  • Contract testing framework installed (Pact JS/Python/JVM, or Spring Cloud Contract)
  • Pact Broker running (or PactFlow SaaS) for contract storage and verification
  • Consumer and provider services with clearly defined API boundaries
  • Existing integration points documented (which consumers call which provider endpoints)
  • CI pipeline configured for both consumer and provider repositories

Instructions

  1. Identify consumer-provider relationships in the system:
    • Map which services call which APIs (e.g., Frontend calls User API, Order API calls Payment API).
    • Document each interaction: HTTP method, path, headers, request body, expected response.
    • Prioritize contracts for the most critical and frequently changing integrations.
  2. Write consumer-side contract tests (Pact consumer tests):
    • Define the expected interaction: method, path, query parameters, headers, request body.
    • Specify the expected response: status code, headers, and response body structure.
    • Use matchers for flexible assertions (like(), eachLike(), term()) instead of exact values.
    • Generate a Pact file (JSON contract) from the consumer test.
  3. Publish consumer contracts to the Pact Broker:
    • Run pact-broker publish with the consumer version and branch/tag.
    • Enable webhooks to trigger provider verification when new contracts are published.
    • Configure can-i-deploy checks in CI to gate deployments.
  4. Write provider-side verification tests:
    • Configure the Pact verifier to fetch contracts from the Pact Broker.
    • Set up provider states (test data scenarios matching consumer expectations).
    • Run verification against the actual provider implementation.
    • Publish verification results back to the Pact Broker.
  5. Handle contract evolution:
    • Adding new fields: Safe -- consumers using matchers will not break.
    • Removing fields: Breaking -- coordinate with all consumers before removal.
    • Changing field types: Breaking -- requires consumer updates first.
    • Use can-i-deploy to check compatibility before releasing either side.
  6. For schema-based validation (non-Pact):
    • Compare OpenAPI spec versions using openapi-diff to detect breaking changes.
    • Flag removed endpoints, changed parameter types, and narrowed response schemas.
    • Run schema validation tests against the actual API responses.
  7. Integrate contract tests into the CI/CD pipeline for both consumers and providers.
Show full SKILL.md (202 more words)Show less

Output

  • Consumer Pact test files defining expected API interactions
  • Generated Pact contract files (JSON) in pacts/ directory
  • Provider verification test configuration
  • Pact Broker deployment with published contracts and verification status
  • CI pipeline integration with can-i-deploy deployment gates
  • Contract evolution report flagging breaking vs. non-breaking changes

Error Handling

ErrorCauseSolution
Provider verification failsProvider response does not match consumer expectationsCheck if the contract is outdated; update consumer tests if the change is intentional; fix provider if regression
can-i-deploy blocks releaseConsumer has unverified or failed contractsRun provider verification; check if the right version tags are published; verify Pact Broker webhook fired
Pact Broker connection errorBroker URL or credentials misconfiguredVerify PACT_BROKER_BASE_URL and PACT_BROKER_TOKEN environment variables; check network connectivity
Provider state not foundConsumer test references a state the provider does not implementAdd the missing provider state setup function; align state names between consumer and provider
Too many contracts to maintainEvery consumer-provider pair has extensive contractsFocus on critical interactions; use matchers instead of exact values; consolidate similar interactions

Examples

Pact consumer test (JavaScript):

typescript
import { PactV4 } from '@pact-foundation/pact';

const provider = new PactV4({ consumer: 'Frontend', provider: 'UserAPI' });

describe('User API Contract', () => {
  it('fetches a user by ID', async () => {
    await provider
      .addInteraction()
      .given('user with ID 1 exists')
      .uponReceiving('a request for user 1')
      .withRequest('GET', '/api/users/1', (builder) => {
        builder.headers({ Accept: 'application/json' });
      })
      .willRespondWith(200, (builder) => {  # HTTP 200 OK
        builder
          .headers({ 'Content-Type': 'application/json' })
          .jsonBody({
            id: like('1'),
            name: like('Alice'),
            email: like('alice@example.com'),
          });
      })
      .executeTest(async (mockServer) => {
        const response = await fetch(`${mockServer.url}/api/users/1`);
        const user = await response.json();
        expect(user.name).toBeDefined();
      });
  });
});

Provider verification test:

typescript
import { Verifier } from '@pact-foundation/pact';

describe('User API Provider Verification', () => {
  it('validates consumer contracts', async () => {
    await new Verifier({
      providerBaseUrl: 'http://localhost:3000',  # 3000: 3 seconds in ms
      pactBrokerUrl: process.env.PACT_BROKER_BASE_URL,
      pactBrokerToken: process.env.PACT_BROKER_TOKEN,
      provider: 'UserAPI',
      publishVerificationResult: true,
      providerVersion: process.env.GIT_SHA,
      stateHandlers: {
        'user with ID 1 exists': async () => {
          await db.users.create({ id: '1', name: 'Alice', email: 'alice@example.com' });
        },
      },
    }).verifyProvider();
  });
});

can-i-deploy CI check:

bash
pact-broker can-i-deploy \
  --pacticipant Frontend \
  --version $(git rev-parse HEAD) \
  --to-environment production \
  --broker-base-url $PACT_BROKER_URL \
  --broker-token $PACT_BROKER_TOKEN

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references, assets) in skills/.curated/validating-api-contracts of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/config_template.yaml
  • assets/openapi_example.yaml
  • assets/pact_contract_template.json
  • assets/report_template.html
  • references/README.md
  • scripts/README.md
  • scripts/generate_pact_tests.py

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Validating API Contracts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validating API Contracts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validating API Contracts this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT
Contract Testingproffesor-for-testing/agentic-qe495—~1.8kAutomated safety check: PassMIT
Contract Firstqshanx/docs-governance134—~1.2kAutomated safety check: PassMIT
Eval IntegrationIbrahim-3d/orchestrator-supaconductor381—~1.8kAutomated safety check: PassAGPL-3.0
API Contract ReviewTencentCloudBase/CloudBase-AI-Toolkit1.1k—~1.5kAutomated safety check: PassMIT
Hybrid Cloud Test Gengetsentry/sentry46k—~2.6kAutomated safety check: PassCustom licence

Similar skills

  • Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.

    495 GitHub stars~1.8k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Contract First

    qshanx/docs-governance

    分前端/后端(或多个服务)多端开发的项目,用 CONTRACT.md 指向的唯一机器契约,各端只照它各做各的,防止字段漂移导致集成时白屏。支持单会话多 agent 和多终端各自跑两种模式。只要项目有前后端/多服务、接口字段老对不上、各端联调卡住、某端改了字段忘了通知别人、或前端为渲染一个页面要调一堆接口拼数据,就用这个…

    134 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Eval Integration

    Ibrahim-3d/orchestrator-supaconductor

    Specialized integration evaluator for the Evaluate-Loop. An agent skill from Ibrahim-3d/orchestrator-supaconductor.

    381 GitHub stars~1.8k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • API Contract Review

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes…

    1.1k GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Hybrid Cloud Test Gen

    getsentry/sentry

    Official

    Generate hybrid cloud tests for the Sentry codebase. An agent skill from getsentry/sentry.

    46k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Add delivery controllers for specx services, especially FastAPI HTTP routes.

    202 GitHub stars~704 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Validating API Contracts

What does Validating API Contracts do?

Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract). Validating API Contracts is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate API contracts using consumer-driven contract testing (Pact, Spring Cloud Contract).

When should I use Validating API Contracts?

Validating API Contracts fits situations like: performing specialized testing; with phrases like validate API contract; run contract tests; check consumer contracts.

How do I install Validating API Contracts in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-api-contracts -a claude-code`. Or copy the skill folder (skills/.curated/validating-api-contracts in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/validating-api-contracts in your project. Claude Code loads it when a task matches its description.

How do I install Validating API Contracts in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-api-contracts -a codex`. Or copy the skill folder (skills/.curated/validating-api-contracts in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/validating-api-contracts in your project. Codex loads it when a task matches its description.

Can I use Validating API Contracts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validating-api-contracts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-api-contracts, .gemini/skills/validating-api-contracts, .github/skills/validating-api-contracts and .opencode/skills/validating-api-contracts in your project.

What does Validating API Contracts need to run?

Going by SKILL.md and its folder, Validating API Contracts needs Python for the scripts in its folder, the command-line tools its instructions call (git) and credentials named PACT_BROKER_TOKEN. Our summary lists: Python 3; A credential in PACT_BROKER_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(test:contract-*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Validating API Contracts access the network?

SKILL.md names 5 domains. As links in the text: docs.pact.io, pactflow.io, spring.io, github.com and martinfowler.com. This is read from the text; nothing was executed.

Is Validating API Contracts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validating API Contracts use?

Validating API Contracts is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validating API Contracts use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17 tokens, read only when the agent opens those files.

What are the alternatives to Validating API Contracts?

Skills that share tags, products or a category with Validating API Contracts: Contract Testing (proffesor-for-testing/agentic-qe, 495 stars), Contract First (qshanx/docs-governance, 134 stars), Eval Integration (Ibrahim-3d/orchestrator-supaconductor, 381 stars) and API Contract Review (TencentCloudBase/CloudBase-AI-Toolkit, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validating API Contracts?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.