{ }
Resource profile / Official FastAPI Contracts & Dependencies
About this skill

Workflow & requirements

BB Skills packaging and scoped native evidence (2026-10-07)

This is the official FastAPI skill from release 0.142.2, pinned to 78c4324f0c56bc5282a459978779a9e532d19709. All seven skill files match the official Python wheel byte for byte. The complete upstream MIT notice, copyright and six references are retained. Original instructions remain unchanged in upstream-original/SKILL.md; this marked preface and the examples are independent BB Skills additions, not upstream certification.

The local fixture executes ten native Python blocks plus independent synthetic contracts. Twenty-nine named observations passed with FastAPI 0.142.2, Pydantic 2.13.5, Starlette 1.7.0 and AnyIO 4.15.1 on Windows/Python 3.12.4. The primary transport is HTTPX2 2.13.1; a separate plain HTTPX 0.28.1 run is comparison evidence. Current Starlette documentation recommends HTTPX2 and deprecates plain HTTPX. The primary requirements do not install the older comparison client.

Observations cover Annotated path/query/body/list errors, normal public response projection, public schema fields, invalid returned data, dependency overrides and their cleanup, class-instance dependencies and yield lifetime relative to ASGI events. The original database-shaped snippet is supplied a synthetic session/query; no database connects. The native function-scope example's print call is captured as an event without rewriting the source. An independent direct-JSONResponse counterexample intentionally retains an extra field: a Response object bypasses declared response_model filtering. Do not deploy these teaching applications.

The original dependency endpoint returns a constant message, not the synthetic identity. The fixture observes provider calls rather than assuming a 200 response proves which provider ran. Response filtering, strict input fields and test overrides do not implement real identity, ownership or authorization.

The fixture makes 27 in-process TestClient HTTP requests per run. It forbids external socket connections and counts event-loop loopback sockets on Windows. No external API, real credential, cloud service, production data or paid model call is required. Dependency installation is separate and contacts the public registry. Python runtimes and wheels are not bundled. Frontend serving, telemetry export, streaming transport, production deployment, concurrent persistence and full security require separate verification.

This fixed download does not automatically follow master or future releases. Use the skill bundled with the FastAPI version your project installs when applying version-specific guidance. No complete AI-client skill execution occurred; runtime_tested remains false. Read examples/README.md and the two named evidence records for exact scope.

FastAPI

Official FastAPI skill to write code with best practices, keeping up to date with new versions and features.

Quick Reference

Use the fastapi CLI

Run the development server on localhost with reload:

fastapi dev

Run the production server:

fastapi run

Prefer declaring the entrypoint in pyproject.toml:

[tool.fastapi]
entrypoint = "my_app.main:app"

When adding the entrypoint is not possible, or the user explicitly asks not to, pass the app file path:

fastapi dev my_app/main.py

Use Annotated

Always prefer the Annotated style for parameter and dependency declarations. It keeps function signatures working in other contexts, respects the types, and allows reusability.

Use Annotated for parameter declarations, including Path, Query, Header, etc.:

from typing import Annotated

from fastapi import FastAPI, Path, Query

app = FastAPI()


@app.get("/items/{item_id}")
async def read_item(
    item_id: Annotated[int, Path(ge=1, description="The item ID")],
    q: Annotated[str | None, Query(max_length=50)] = None,
):
    return {"message": "Hello World"}

Use Annotated for dependencies with Depends(). Unless asked not to, create a new type alias for the dependency to allow reusing it:

from typing import Annotated

from fastapi import Depends, FastAPI

app = FastAPI()


def get_current_user():
    return {"username": "johndoe"}


CurrentUserDep = Annotated[dict, Depends(get_current_user)]


@app.get("/items/")
async def read_item(current_user: CurrentUserDep):
    return {"message": "Hello World"}

Do not use Ellipsis for path operations or Pydantic models

Do not use ... as a default value for required parameters or model fields. It's not needed and not recommended.

from typing import Annotated

from fastapi import FastAPI, Query
from pydantic import BaseModel, Field

app = FastAPI()


class Item(BaseModel):
    name: str
    description: str | None = None
    price: float = Field(gt=0)


@app.post("/items/")
async def create_item(item: Item, project_id: Annotated[int, Query()]):
    return item

See the Pydantic reference for more details.

Return Type or Response Model

When possible, include a return type. It will be used to validate, filter, document, and serialize the response.

from fastapi import FastAPI
from pydantic import BaseModel

app = FastAPI()


class Item(BaseModel):
    name: str
    description: str | None = None


@app.get("/items/me")
async def get_item() -> Item:
    return Item(name="Plumbus", description="All-purpose home device")

Return types or response models filter data to avoid exposing sensitive information, and they let Pydantic serialize the data on the Rust side for performance.

Use response_model when the type you return is not the same as the public schema you want to validate, filter, document, and serialize. See the response reference.

Performance

Do not use ORJSONResponse or UJSONResponse, they are deprecated.

Instead, declare a return type or response model. Pydantic will handle the data serialization on the Rust side.

Including Routers

When declaring routers, prefer to add router-level parameters like prefix, tags, and shared dependencies to the router itself instead of in include_router().

from fastapi import APIRouter, Depends, FastAPI

app = FastAPI()


def get_current_user():
    return {"username": "johndoe"}


router = APIRouter(
    prefix="/items",
    tags=["items"],
    dependencies=[Depends(get_current_user)],
)


@router.get("/")
async def list_items():
    return []


app.include_router(router)

See the path operation reference for more routing patterns.

Serve Frontend Apps

Use app.frontend() to serve a built static frontend app, for example a directory generated by Vite, Astro, Angular, Svelte, Vue, or a similar tool.

from fastapi import FastAPI

app = FastAPI()

app.frontend("/", directory="dist")

Use router.frontend() when the frontend belongs to an APIRouter; normal router prefix behavior applies when the router is included.

from fastapi import APIRouter, FastAPI

app = FastAPI()
router = APIRouter(prefix="/admin")

router.frontend("/", directory="admin-dist")
app.include_router(router)

app.frontend() and router.frontend() are low-priority routes: regular API routes are matched first, then frontend files and client-side routing fallbacks. Use this for single-page apps and built frontend assets instead of mounting StaticFiles manually.

OpenTelemetry

Prefer FastAPI's native OpenTelemetry support for request traces, metrics, and logs.

Install fastapi[standard] to include the SDK and HTTP/protobuf exporters. Set OTEL_SERVICE_NAME to identify the app and OTEL_EXPORTER_OTLP_ENDPOINT to the collector's HTTP/protobuf base URL. Use OTEL_EXPORTER_OTLP_HEADERS when authentication is required.

Use FastAPI(telemetry={...}) for custom configuration, such as choosing signals or supplying providers.

See the OpenTelemetry tutorial for configuration details.

Dependency Injection

Use dependencies when the logic can't be declared in Pydantic validation, depends on external resources, needs cleanup with yield, or is shared across endpoints.

Apply shared dependencies at the router level via dependencies=[Depends(...)].

See the dependency injection reference for detailed patterns including yield with scope, and class dependencies.

Async vs Sync path operations

Use async path operations only when fully certain that the logic called inside is compatible with async and await, and that it doesn't block.

from fastapi import FastAPI

app = FastAPI()


@app.get("/async-items/")
async def read_async_items():
    data = await some_async_library.fetch_items()
    return data


@app.get("/items/")
def read_items():
    data = some_blocking_library.fetch_items()
    return data

In case of doubt, or by default, use regular def functions. They will be run in a threadpool so they don't block the event loop. The same rules apply to dependencies.

Make sure blocking code is not run inside of async functions. The logic will work, but will damage performance heavily.

When needing to mix blocking and async code, see Asyncer in the other tools reference.

Streaming (JSON Lines, SSE, bytes)

To stream Server-Sent Events, use response_class=EventSourceResponse and yield items from the endpoint.

from collections.abc import AsyncIterable

from fastapi import FastAPI
from fastapi.sse import EventSourceResponse, ServerSentEvent

app = FastAPI()


@app.get("/events", response_class=EventSourceResponse)
async def stream_events() -> AsyncIterable[ServerSentEvent]:
    yield ServerSentEvent(data={"status": "started"}, event="status", id="1")

Plain objects are automatically JSON-serialized as data: fields. Use ServerSentEvent for full control over SSE fields (event, id, retry, comment) and raw_data for pre-formatted strings.

See the streaming reference for JSON Lines, Server-Sent Events (EventSourceResponse, ServerSentEvent), and byte streaming (StreamingResponse) patterns.

Tooling

See the other tools reference for details on uv, Ruff, ty for package management, linting, type checking, formatting, etc.

Other Libraries

See the other tools reference for details on other libraries:

  • Asyncer for handling async and await, concurrency, mixing async and blocking code, prefer it over AnyIO or asyncio.
  • SQLModel for working with SQL databases, prefer it over SQLAlchemy.
  • HTTPX for interacting with HTTP (other APIs), prefer it over Requests.

Do not use Pydantic RootModels

Do not use Pydantic RootModel; instead use regular type annotations with Annotated and Pydantic validation utilities.

from typing import Annotated

from fastapi import Body, FastAPI
from pydantic import Field

app = FastAPI()


@app.post("/items/")
async def create_items(items: Annotated[list[int], Field(min_length=1), Body()]):
    return items

FastAPI supports these type annotations and will create a Pydantic TypeAdapter for them, so types work normally without custom wrapper models. See the Pydantic reference.

Use one HTTP operation per function

Don't mix HTTP operations in a single function. Having one function per HTTP operation helps separate concerns and organize the code.

from fastapi import FastAPI
from pydantic import BaseModel

app = FastAPI()


class Item(BaseModel):
    name: str


@app.get("/items/")
async def list_items():
    return []


@app.post("/items/")
async def create_item(item: Item):
    return item

See the path operation reference for more examples.

PACKAGE TRANSPARENCY

Inspect before installing

Source: Sebastián Ramírez · MIT · SHA-256 shown alongside the download.

20 files30585 ZIP bytes2 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes
Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-07. These notes are not safety certification or measured task performance.

Requirements

Python and a separately installed FastAPI environment; example requirements pin FastAPI 0.142.2/Pydantic 2.13.5/Starlette 1.7.0/AnyIO 4.15.1/HTTPX2 2.13.1. Windows evidence used Python 3.12.4. Original skill describes additional features outside the fixture scope.

Costs, access & practical limits

Free MIT instructions and references. The experiment uses synthetic in-process API requests, no external service, credential, cloud account or paid model. Dependency installation contacts the public registry separately. Do not deploy intentional response counterexamples; this is not authentication or a security certification.

View the recorded checks
  • Eight originals verified by Git blob and SHA-256; seven skill files also match official release wheel
  • Complete upstream MIT notice, attribution and all relative references retained
  • Twenty-nine named native/synthetic observations passed under HTTPX2; equal HTTPX comparison retained
  • Input errors and invalid server returns tested separately
  • Raw JSONResponse bypass and override restoration documented
  • Yield lifecycle recorded against ASGI events with a synthetic session; no real database

Upstream commit: 78c4324f0c56bc5282a459978779a9e532d19709

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

LICENSE & ATTRIBUTION

License & attribution

The notices identify their files, attribution and changes. Retain the applicable original notices when adapting or redistributing the package.

MIT ↗

Original official FastAPI instruction and all six reference files

Attribution: Copyright (c) 2018 Sebastián Ramírez; FastAPI project

Changes: Marked preface added to primary skill; original bytes retained unchanged

Included notice: fastapi/LICENSE.upstream.txt

Declared source ↗

MIT ↗

Independent BB Skills preface, synthetic contract examples, evidence and packaging

Attribution: Copyright (c) 2026 BB Skills

Changes: Independently authored local experiment and explicit counterexamples; not a production app

Included notice: fastapi/LICENSE.bb-skills.txt

Declared source ↗
SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

Official FastAPI snippets and local public response contracts

Reported passed · v0.142.2.bb1

View input and acceptance criteria

Input

Twenty-nine named observations across ten unchanged upstream Python blocks and 27 in-process HTTP requests per run. FastAPI 0.142.2/Pydantic 2.13.5 with HTTPX2 2.13.1 and a separate HTTPX 0.28.1 comparison. Synthetic symbols support the database-shaped example; separately marked BB Skills examples test strict input, invalid server returns and deliberate raw-response bypasses. Local event-loop loopback sockets only; no external connection, real authentication, database, production route, paid API or complete AI-client skill execution. ASGI cleanup observations do not verify streaming or TCP delivery.

Acceptance criteria

Twenty-nine named observations pass on each recorded TestClient transport. Request rejections, server response errors, public filtering, override cleanup and ASGI lifetime ordering are checked separately. No full-skill or production security claim.

Recorded outcome

Twenty-nine named observations across ten unchanged upstream Python blocks and 27 in-process HTTP requests per run. FastAPI 0.142.2/Pydantic 2.13.5 with HTTPX2 2.13.1 and a separate HTTPX 0.28.1 comparison. Synthetic symbols support the database-shaped example; separately marked BB Skills examples test strict input, invalid server returns and deliberate raw-response bypasses. Local event-loop loopback sockets only; no external connection, real authentication, database, production route, paid API or complete AI-client skill execution. ASGI cleanup observations do not verify streaming or TCP delivery.

Recommended-transport evidence:
{
  "executed_at": "2026-10-07T09:40:48.566623+00:00",
  "python": "3.12.4",
  "platform": "Windows",
  "versions": {
    "fastapi": "0.142.2",
    "pydantic": "2.13.5",
    "starlette": "1.7.0",
    "anyio": "4.15.1",
    "httpx": "0.28.1",
    "httpx2": "2.13.1"
  },
  "test_transport_module": "httpx2",
  "observations": 29,
  "cases": [
    {
      "name": "native_annotated_valid_path",
      "status": "passed",
      "observation": "Pinned Annotated Path/Query example returns its declared response."
    },
    {
      "name": "native_path_lower_bound",
      "status": "passed",
      "observation": "Path zero rejected with 422 and matching lower-bound error."
    },
    {
      "name": "native_path_type",
      "status": "passed",
      "observation": "Invalid integer path rejected at the path field."
    },
    {
      "name": "native_query_max_length",
      "status": "passed",
      "observation": "Query longer than the native limit is rejected."
    },
    {
      "name": "native_dependency_original",
      "status": "passed",
      "observation": "The upstream endpoint returns a constant message; its synthetic identity is not authentication."
    },
    {
      "name": "dependency_override_applied",
      "status": "passed",
      "observation": "The function-keyed test override runs; the native endpoint still returns its constant message."
    },
    {
      "name": "dependency_override_restored",
      "status": "passed",
      "observation": "After cleanup, the overriding provider is not called on the later request."
    },
    {
      "name": "native_required_query_and_body_valid",
      "status": "passed",
      "observation": "Native typed body and required query work together."
    },
    {
      "name": "native_required_query_missing",
      "status": "passed",
      "observation": "Required query omitted: matching 422 query error."
    },
    {
      "name": "native_required_body_missing",
      "status": "passed",
      "observation": "Required body value omitted: matching 422 body error."
    },
    {
      "name": "native_positive_price_constraint",
      "status": "passed",
      "observation": "Zero price fails the upstream positive-price constraint."
    },
    {
      "name": "native_annotated_list",
      "status": "passed",
      "observation": "Native Annotated list validation works without RootModel."
    },
    {
      "name": "native_empty_list_rejected",
      "status": "passed",
      "observation": "The native minimum list length is enforced."
    },
    {
      "name": "native_list_item_type_rejected",
      "status": "passed",
      "observation": "Invalid list item reports its exact index."
    },
    {
      "name": "native_return_annotation",
      "status": "passed",
      "observation": "Upstream return annotation serializes its public Item."
    },
    {
      "name": "native_response_model_dictionary",
      "status": "passed",
      "observation": "Upstream response_model validates a dictionary return."
    },
    {
      "name": "native_internal_field_filtered",
      "status": "passed",
      "observation": "The original InternalItem field is absent from the public response."
    },
    {
      "name": "native_public_response_schema",
      "status": "passed",
      "observation": "Public OpenAPI Item schema excludes the internal field."
    },
    {
      "name": "native_yield_request_result",
      "status": "passed",
      "observation": "Original yield dependency uses a synthetic session/query, not a database."
    },
    {
      "name": "native_request_scope_cleanup",
      "status": "passed",
      "observation": "Default request-scope release follows the ASGI response body."
    },
    {
      "name": "native_yield_function_result",
      "status": "passed",
      "observation": "Native function-scoped yield dependency supplies its value."
    },
    {
      "name": "native_function_scope_cleanup",
      "status": "passed",
      "observation": "Function-scope release precedes the ASGI response start."
    },
    {
      "name": "native_function_returns_class_instance",
      "status": "passed",
      "observation": "Native function dependency constructs the local paginator."
    },
    {
      "name": "independent_public_projection",
      "status": "passed",
      "observation": "Separate strict example returns only public fields."
    },
    {
      "name": "independent_unknown_field_rejected",
      "status": "passed",
      "observation": "Independent extra=forbid input contract rejects an unknown field."
    },
    {
      "name": "independent_empty_name_rejected",
      "status": "passed",
      "observation": "Independent minimum name length is enforced."
    },
    {
      "name": "invalid_server_response_raises",
      "status": "passed",
      "observation": "Default TestClient reports a response contract exception, not a client 422."
    },
    {
      "name": "direct_response_bypasses_projection",
      "status": "passed",
      "observation": "Explicit synthetic counterexample: JSONResponse bypasses declared response_model filtering."
    },
    {
      "name": "invalid_server_response_is_500",
      "status": "passed",
      "observation": "With server exceptions disabled, invalid returned data is a server error."
    }
  ],
  "native_snippets_executed": 10,
  "executed_snippets": [
    {
      "source": "upstream-original/SKILL.md",
      "block_index": 0,
      "block_sha256": "df4ab94990bae926c4f4d85ecd870b0898fd1e8bc870d894e4796ac57963fd48",
      "provided_synthetic_symbols": []
    },
    {
      "source": "upstream-original/SKILL.md",
      "block_index": 1,
      "block_sha256": "b4b5f7aff65318c92dec580a4820014a3fd796cef8d343197ffed5ceb7a707d7",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/pydantic.md",
      "block_index": 0,
      "block_sha256": "b1ea75b348630f8d30d1d943ffcc0b1e5e7d0f0ef4625e2b5a2a4dbdb8ae4abb",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/pydantic.md",
      "block_index": 2,
      "block_sha256": "538d3ad39f89d6cfbe77513961c2e8be836d795c55dab744993d43d606818453",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 0,
      "block_sha256": "a52d3f947f912762fb8cc0c7ce7781b70b4ddb596eed4a5f48df8a014182ee9f",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 1,
      "block_sha256": "77a14027c8aa91c28e39d93c1b0a5a5bc551ac135353e6854b41a7c40bd93942",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 2,
      "block_sha256": "b97a60340a1ffc4caedc781fd7b2cb646d85418bdb07340678040423a07caf33",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/dependencies.md",
      "block_index": 0,
      "block_sha256": "8cdbdc573e18ef8b93ae2a43a4f143f045ded12b7f2b1680a6db26bfaeb53f0a",
      "provided_synthetic_symbols": [
        "DBSession",
        "Item"
      ]
    },
    {
      "source": "references/dependencies.md",
      "block_index": 1,
      "block_sha256": "647c4d20d092b03e161ae75edcd2e43ce3cc1c1090f6339a0d1e30fcfd9ca414",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/dependencies.md",
      "block_index": 2,
      "block_sha256": "6158a5ebf18f72a98f4f844cfd2efe1e1cd512558d7dba945b65fb004b681841",
      "provided_synthetic_symbols": []
    }
  ],
  "source_hashes": {
    "upstream-original/SKILL.md": "0fc817d25584b48981bfb3e9a4ad96dde0e4ce7396f15e91a0ba30cbece243f7",
    "references/pydantic.md": "840ab962739861aed2ea77805dc46979c9a96abd8fc0043f197b3bd5d638e84b",
    "references/responses.md": "7c921508bbd093697301ca9612038976cfb5b65bdc2dc42a0c02e2809d3652a7",
    "references/dependencies.md": "8b6b71a03fa14680905a81f53f1883b90c2ab7ac65eefa77c2664c2d038de469",
    "examples/public_contract.py": "9512a49de958b020a62b479e9e6b592d095a0a0c03a0817b310d4943314f2050",
    "examples/run_contract_fixture.py": "3ea88de2f56718f4b2ac49246a7dfbbd54539645a0096063c209295e0fdafdbb"
  },
  "in_process_http_requests": 27,
  "loopback_socket_connections": 12,
  "external_network_requests": false,
  "external_connections_prohibited": true,
  "runtime_tested": false,
  "ai_client_executed": false,
  "production_tested": false,
  "database_connected": false,
  "credentials_required": false,
  "paid_api_used": false
}

Comparison evidence:
{
  "executed_at": "2026-10-07T09:39:38.650960+00:00",
  "python": "3.12.4",
  "platform": "Windows",
  "versions": {
    "fastapi": "0.142.2",
    "pydantic": "2.13.5",
    "starlette": "1.7.0",
    "anyio": "4.15.1",
    "httpx": "0.28.1"
  },
  "test_transport_module": "httpx",
  "observations": 29,
  "cases": [
    {
      "name": "native_annotated_valid_path",
      "status": "passed",
      "observation": "Pinned Annotated Path/Query example returns its declared response."
    },
    {
      "name": "native_path_lower_bound",
      "status": "passed",
      "observation": "Path zero rejected with 422 and matching lower-bound error."
    },
    {
      "name": "native_path_type",
      "status": "passed",
      "observation": "Invalid integer path rejected at the path field."
    },
    {
      "name": "native_query_max_length",
      "status": "passed",
      "observation": "Query longer than the native limit is rejected."
    },
    {
      "name": "native_dependency_original",
      "status": "passed",
      "observation": "The upstream endpoint returns a constant message; its synthetic identity is not authentication."
    },
    {
      "name": "dependency_override_applied",
      "status": "passed",
      "observation": "The function-keyed test override runs; the native endpoint still returns its constant message."
    },
    {
      "name": "dependency_override_restored",
      "status": "passed",
      "observation": "After cleanup, the overriding provider is not called on the later request."
    },
    {
      "name": "native_required_query_and_body_valid",
      "status": "passed",
      "observation": "Native typed body and required query work together."
    },
    {
      "name": "native_required_query_missing",
      "status": "passed",
      "observation": "Required query omitted: matching 422 query error."
    },
    {
      "name": "native_required_body_missing",
      "status": "passed",
      "observation": "Required body value omitted: matching 422 body error."
    },
    {
      "name": "native_positive_price_constraint",
      "status": "passed",
      "observation": "Zero price fails the upstream positive-price constraint."
    },
    {
      "name": "native_annotated_list",
      "status": "passed",
      "observation": "Native Annotated list validation works without RootModel."
    },
    {
      "name": "native_empty_list_rejected",
      "status": "passed",
      "observation": "The native minimum list length is enforced."
    },
    {
      "name": "native_list_item_type_rejected",
      "status": "passed",
      "observation": "Invalid list item reports its exact index."
    },
    {
      "name": "native_return_annotation",
      "status": "passed",
      "observation": "Upstream return annotation serializes its public Item."
    },
    {
      "name": "native_response_model_dictionary",
      "status": "passed",
      "observation": "Upstream response_model validates a dictionary return."
    },
    {
      "name": "native_internal_field_filtered",
      "status": "passed",
      "observation": "The original InternalItem field is absent from the public response."
    },
    {
      "name": "native_public_response_schema",
      "status": "passed",
      "observation": "Public OpenAPI Item schema excludes the internal field."
    },
    {
      "name": "native_yield_request_result",
      "status": "passed",
      "observation": "Original yield dependency uses a synthetic session/query, not a database."
    },
    {
      "name": "native_request_scope_cleanup",
      "status": "passed",
      "observation": "Default request-scope release follows the ASGI response body."
    },
    {
      "name": "native_yield_function_result",
      "status": "passed",
      "observation": "Native function-scoped yield dependency supplies its value."
    },
    {
      "name": "native_function_scope_cleanup",
      "status": "passed",
      "observation": "Function-scope release precedes the ASGI response start."
    },
    {
      "name": "native_function_returns_class_instance",
      "status": "passed",
      "observation": "Native function dependency constructs the local paginator."
    },
    {
      "name": "independent_public_projection",
      "status": "passed",
      "observation": "Separate strict example returns only public fields."
    },
    {
      "name": "independent_unknown_field_rejected",
      "status": "passed",
      "observation": "Independent extra=forbid input contract rejects an unknown field."
    },
    {
      "name": "independent_empty_name_rejected",
      "status": "passed",
      "observation": "Independent minimum name length is enforced."
    },
    {
      "name": "invalid_server_response_raises",
      "status": "passed",
      "observation": "Default TestClient reports a response contract exception, not a client 422."
    },
    {
      "name": "direct_response_bypasses_projection",
      "status": "passed",
      "observation": "Explicit synthetic counterexample: JSONResponse bypasses declared response_model filtering."
    },
    {
      "name": "invalid_server_response_is_500",
      "status": "passed",
      "observation": "With server exceptions disabled, invalid returned data is a server error."
    }
  ],
  "native_snippets_executed": 10,
  "executed_snippets": [
    {
      "source": "upstream-original/SKILL.md",
      "block_index": 0,
      "block_sha256": "df4ab94990bae926c4f4d85ecd870b0898fd1e8bc870d894e4796ac57963fd48",
      "provided_synthetic_symbols": []
    },
    {
      "source": "upstream-original/SKILL.md",
      "block_index": 1,
      "block_sha256": "b4b5f7aff65318c92dec580a4820014a3fd796cef8d343197ffed5ceb7a707d7",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/pydantic.md",
      "block_index": 0,
      "block_sha256": "b1ea75b348630f8d30d1d943ffcc0b1e5e7d0f0ef4625e2b5a2a4dbdb8ae4abb",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/pydantic.md",
      "block_index": 2,
      "block_sha256": "538d3ad39f89d6cfbe77513961c2e8be836d795c55dab744993d43d606818453",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 0,
      "block_sha256": "a52d3f947f912762fb8cc0c7ce7781b70b4ddb596eed4a5f48df8a014182ee9f",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 1,
      "block_sha256": "77a14027c8aa91c28e39d93c1b0a5a5bc551ac135353e6854b41a7c40bd93942",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/responses.md",
      "block_index": 2,
      "block_sha256": "b97a60340a1ffc4caedc781fd7b2cb646d85418bdb07340678040423a07caf33",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/dependencies.md",
      "block_index": 0,
      "block_sha256": "8cdbdc573e18ef8b93ae2a43a4f143f045ded12b7f2b1680a6db26bfaeb53f0a",
      "provided_synthetic_symbols": [
        "DBSession",
        "Item"
      ]
    },
    {
      "source": "references/dependencies.md",
      "block_index": 1,
      "block_sha256": "647c4d20d092b03e161ae75edcd2e43ce3cc1c1090f6339a0d1e30fcfd9ca414",
      "provided_synthetic_symbols": []
    },
    {
      "source": "references/dependencies.md",
      "block_index": 2,
      "block_sha256": "6158a5ebf18f72a98f4f844cfd2efe1e1cd512558d7dba945b65fb004b681841",
      "provided_synthetic_symbols": []
    }
  ],
  "source_hashes": {
    "upstream-original/SKILL.md": "0fc817d25584b48981bfb3e9a4ad96dde0e4ce7396f15e91a0ba30cbece243f7",
    "references/pydantic.md": "840ab962739861aed2ea77805dc46979c9a96abd8fc0043f197b3bd5d638e84b",
    "references/responses.md": "7c921508bbd093697301ca9612038976cfb5b65bdc2dc42a0c02e2809d3652a7",
    "references/dependencies.md": "8b6b71a03fa14680905a81f53f1883b90c2ab7ac65eefa77c2664c2d038de469",
    "examples/public_contract.py": "9512a49de958b020a62b479e9e6b592d095a0a0c03a0817b310d4943314f2050",
    "examples/run_contract_fixture.py": "3ea88de2f56718f4b2ac49246a7dfbbd54539645a0096063c209295e0fdafdbb"
  },
  "in_process_http_requests": 27,
  "loopback_socket_connections": 12,
  "external_network_requests": false,
  "external_connections_prohibited": true,
  "runtime_tested": false,
  "ai_client_executed": false,
  "production_tested": false,
  "database_connected": false,
  "credentials_required": false,
  "paid_api_used": false
}

Environment

Windows; Python 3.12.4; disposable virtual environment with FastAPI 0.142.2, Pydantic 2.13.5, Starlette 1.7.0 and AnyIO 4.15.1. HTTPX2 2.13.1 primary and HTTPX 0.28.1 comparison TestClient runs. Synthetic in-process ASGI requests and permitted event-loop loopback sockets. No credentials or production data.

Package SHA-256: 0c3505ee4a21453f8e53b2b968244b78b8ddbb84346148f9ac0fa627f35ca9d5

Outcome recorded: 2026-10-07 09:40 UTC

Open evidence ↗

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

Guides using this resource

All guides →
Practical guide

PostgreSQL RLS tests: roles, writes and session context

PostgreSQL row-level security needs tests that use the same ordinary database roles as the application. A successful query from a superuser cannot establish that another user's…

By BB Skills · Read guide →
Practical guide

FastAPI API contracts: response filtering and dependency tests

Test FastAPI's public response contracts with local examples: reject invalid input, detect direct-response bypasses, isolate dependency overrides and check when yield cleanup runs.

By BB Skills · Read guide →
View all ↗

Links use published guide associations and catalog labels. Inspect each resource’s requirements and license.