Section 6: Designing the API Contract
- What a good contract contains: endpoint, method, request, response, errors and business rules
- Field specification: data type, length, date format, allowed values and mandatory fields
- Naming fields and endpoints consistently across the organisation
- API versioning and the impact when a partner changes version
- Contract first, so that teams on both sides can develop in parallel
- Lab: write request and response schemas with mandatory fields, data types and date formats
Section 7: Explaining the Flow with Diagrams
- Sequence diagrams for processes that involve several systems
- Data flow diagrams to show data paths and transformations
- Drawing diagrams with Mermaid so they can be embedded in documents and version-controlled
- Using diagrams in partner meetings to reduce misunderstandings
- Lab: draw a sequence diagram of the flow between three systems
Section 8: Designing Error Handling, Timeouts and Retries
- Error matrix: error codes, business meaning, user-facing messages and system actions
- Timeout and retry policy: number of attempts, intervals and exponential backoff
- Lab: design an error matrix for the simulated payment integration with the action for each case
Section 9: Idempotency, Reconciliation and Monitoring
- Idempotency: why resending creates duplicate transactions and how to design an idempotency key
- Handling pending transactions and uncertain states
- Daily reconciliation between source and target systems
- Alerts and monitoring so the team learns about problems before customers do
- Lab: define retry, timeout and idempotency key rules to prevent duplicates, and design the reconciliation process
Section 10: API Security at the Level a BA/SA Needs
- Authentication: API key, Basic Auth, OAuth 2.0 and JWT, their differences and use cases
- Authorisation and role-based permissions
- Rate limiting and throttling and their effect on batch job design
- Encryption in transit and data signing for financial transactions
- PDPA considerations: which data must not be sent through an API or written to logs
Section 11: Non-functional Requirements
- Peak transaction volume, acceptable response time and service hours
- SLAs with external providers and what the contract must state
- Logging and audit trail requirements for later review
Section 12: Test Planning and Handover
- Mock the target system with Mockoon to test before the real system is ready
- Design integration test cases covering the happy path, error paths and edge cases
- Define measurable acceptance criteria
- Go-live checklist: environments, credentials, firewall and fallback plan
- Lab: build a mock API in Mockoon that simulates both success and failure cases
Section 13: Master Workshop: NovaRetail Integration Requirements
- Write API contracts for all three systems: payment, accounting and customer notification
- Assemble the sequence diagram, error matrix, and retry and idempotency policy
- Design the reconciliation process and integration test cases with acceptance criteria
- Present the integration requirement document to the group for feedback
- Review API documents from learners' own projects together (if available)