API CONTRACT REVIEW SHEET — optional local worksheet Full FastAPI course 1.0.0 Describe one route using concrete examples. 1. Method and path: what action does this request express? 2. Caller: who may use it, and which ownership scope applies? 3. Input: path/query/body fields, types, bounds, omission and null behavior. 4. Valid example: request JSON and expected status/body. 5. Response: public fields only; exclude passwords, hashes and internal traces. 6. Invalid input: example and the documented validation format. 7. Missing record, permission denial and conflict: distinct examples/statuses. 8. Transaction: what commits together, and can success be sent before commit? 9. Pagination: total order, cursor boundary, permitted scope and limitations. 10. Repeated request: read-only, idempotent key or unsafe to retry? 11. Regression tests: valid, invalid and nearby denied cases. 12. Compatibility: which previous client behavior must remain unchanged? Worked example: GET /rentals/{id} requires a valid current user. A customer reads their own rental; another owner's rental is denied with 403. Missing UUID records return 404 with a safe not_found envelope. Invalid UUID input is 422 in FastAPI's documented validation format. No mutation occurs. Write your own examples; a downloaded worksheet is not completion evidence.