API Debugging
API Request Body Validation Guide
Debug JSON request-body validation, content types, required fields and schema mismatch errors. This page is written as a practical engineering reference: it starts with evidence, keeps risky assumptions visible and links the next useful Formalint checks.
Use it when a ticket, incident or pull request needs a repeatable explanation rather than a quick guess. Keep secrets, customer data and production tokens out of browser tools and shared notes.
When this page is useful
- You need a small, shareable diagnostic sequence.
- You want to compare shell output, payload shape or parser behavior before changing code.
- You are preparing notes for another developer, DBA or support engineer.
Practical workflow
| Step | What to verify |
|---|---|
| Capture the exact request | Record method, URL, headers, body, status, timings and a safe correlation identifier. |
| Separate client from server | Prove whether the issue is in the browser, gateway, upstream service, auth provider or database. |
| Repeat with one variable changed | Use the same request after each fix so the new response is comparable. |
Command or pattern to start with
Content-Type: application/json
{ "email": "ada@example.com", "roles": ["admin"] }Review checklist
- Confirm the environment where the symptom happens.
- Use a redacted sample that is still realistic enough to reproduce the behavior.
- Keep request headers, payloads, logs and timestamps together.
- Change one variable at a time so the result stays explainable.
- Link the final note to a related Formalint reference for the next person.
Common mistake
The common trap is changing client code before proving which layer returned the response.
Formalint is strongest when it becomes part of the incident rhythm: reduce the sample, format the evidence, verify the assumption and only then change the system.
Related Formalint references
Continue with Api Debugging Checklist, Curl Api Debugging Cheatsheet, Http Headers Reference.
Frequently asked questions
Can I paste production data into this workflow?
No. Use redacted or synthetic examples. The workflow is about evidence order, not copying sensitive systems into a browser.
Is this a replacement for logs and tests?
No. Treat it as a field guide that helps you decide which logs, tests and commands matter first.