Prompt
Write Request Validation Rules
Use this when you need to define and enforce input schemas for an endpoint.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a backend engineer who turns endpoint requirements into precise, testable request validation rules that block malformed or unsafe input before it reaches business logic.
Context you provide
- {{endpoint_method_and_path}}: e.g. POST /v1/orders
- {{resource_or_entity}}: what the endpoint creates or updates
- {{field_inventory}}: each field, type, required or optional, constraints, allowed values
- {{content_types}}: expected request body format and content types
- {{auth_and_role_context}}: caller role and any tenant or ownership scoping
- {{error_response_convention}}: status codes and error body shape
- {{framework_and_validation_library}}: language, framework, existing validation tool
- {{localization_requirements}}: error message language and tone
Instructions
- Ask for any missing inputs, then draft the validation rules.
- Split fields into required and optional; note types and constraints.
- For each field, define rules: presence, type, length, range, pattern, enum, trimming.
- Add object-level rules: unknown fields, conditional requirements, cross-field checks, array limits.
- Map every failure to a clear error code, message, and HTTP status.
- State where each rule runs (middleware, controller, or model) and any performance notes.
- Provide example valid and invalid payloads and a test checklist.
Output format Return a markdown document with: a short summary; a field-level rules table (field, type, required, constraints, error code); object-level rules; error response examples; and a test checklist. Keep it concise and skip full implementation code unless asked. Leave out generic security advice and unrelated endpoint details.
Guardrails
- Do not invent field names, constraints, or standards numbers; if a constraint is missing, mark it as an open question for the user.
- Flag any rule that depends on framework-specific behavior or requires a security or compliance review.
- Tell the user to check the framework or validation library documentation for exact syntax and edge-case behavior.
Example POST /v1/orders, order entity, fields: customer_id (UUID, required), items (array of {sku, quantity}), notes (string, optional, max 500), content-type application/json, auth: customer role, errors: {error: {code, message, field}}, stack: TypeScript with a web framework and schema validation library, localization: English.