What makes api rate limit design dependable?
Dependability comes from explicit record authority, safe delivery semantics, bounded recovery, and reconciliation—not from the number of endpoints. For traffic shaping, queues, budgets, backoff, and capacity planning, the design must explain what happens after duplicates, delay, partial failure, and an ambiguous timeout. Capacity is a budget that changes over time.
Should this use a request, webhook, queue, or batch?
Use a request when the caller needs an immediate decision, a webhook when a source announces change, a queue when work needs isolation and retry, and a batch or reconciliation job when completeness matters more than immediacy. Many durable integrations use more than one pattern.
What should be tested beyond the happy path?
Test invalid and missing data, stale versions, duplicate events, reordering, throttling, permission changes, timeout after remote commit, and replay. The route risk—letting a burst create cascading retries and stale data—needs a concrete test rather than a sentence in a brief. Bursts and retry storms can consume recovery capacity faster than normal traffic.
What evidence belongs at handoff?
Provide payload examples, mapping rules, state diagrams, failure categories, dashboards, alert ownership, replay instructions, and a reconciliation report. Alert on sustained depletion, queue age, and business lag rather than request count alone.