The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

API failures in the wild: timeouts, 429s and bad JSON

Updated

An engineer writing code in a bright office

Three API failure shapes every operator meets: slow answers, rate limits and malformed bodies, each with its own response.

APIs fail in three shapes, and each punishes a different laziness. Timeouts punish missing budgets. 429s punish blind retries. Malformed bodies punish trusting the status code. Learn the three responses once and every integration gets calmer.

Budget, backoff, validate

Timeouts get budgets. Every outbound call carries a deadline derived from what the caller can afford. A timeout converts a freeze into an error you can handle, retry or report.

429s get backoff with jitter. The server asks for slowness; answer with exponential waits plus randomness so a fleet does not retry in lockstep. Cap total retries: a budget, not a loop.

Bodies get validated. Check shape before use: required fields, types, error envelopes. Log the offending body (minus secrets) so the next failure is diagnosed in minutes.

Worked example: a fictional status page integration

The context below is fictional. Fictional monitor ParcelWatch (fictional) polls a carrier API with no timeout, instant retries and blind JSON parsing. One slow carrier evening freezes all checks; then a 429 storm extends itself; then a changed field name crashes the parser at 2 AM.

The rewrite sets a ten second budget, backoff with jitter capped at three tries, and shape validation with the raw body in the error log. Next carrier incident: bounded errors, calm retries, one log line naming the changed field.

Decision table: API failure responses

SignalResponseNever
Slow answerTimeout budget, then handleWait forever
429Backoff with jitter, cappedRetry hot in a loop
200 with wrong shapeValidate, log body, alertTrust status 200 blindly

Straight answers

Frequently asked questions

Retry on 429?

Yes, with backoff and jitter, and only within a retry budget. Retrying a rate limit at full speed is how you extend your own ban.

What timeout should I set?

A budget from the caller side: how long the user waits, minus your own margin. No timeout means one slow dependency freezes everything.

Validate JSON responses?

Yes, at the boundary. A 200 with an unexpected shape breaks more code than a clean 500.

Bu sayfanın Türkçesi

Turn reading into a credential

This post is a free field note. Exams run at dated sittings in 15-seat classes; one price covers one attempt. All lessons are free.