forumNew topic

Is it normal to accept delivery without API integration testing, or should we have made it a contract requirement?

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#1

We run a boutique hotel and guided city tour business in Paris. To revamp our website and direct booking engine, we signed a contract with a local dev agency for 14,000 EUR with a 3-month delivery timeline. Development is finished, and they submitted the project for our sign-off, stating the payment gateway and booking engine are fully integrated.

But when we asked whether end-to-end testing was done for the payment API, calendar sync, and automated confirmation emails, the agency gave us a shocking reply: "We hooked up the necessary endpoints, the system returns a 200 code. You can test the rest of the scenarios in production or with your own test cards." So basically no simulation, no failed transaction tests, and no load testing whatsoever.

We've never managed a technical project like this before, so we're at a loss. Is it normal for a software agency to hand over a project without running API integration tests? How should we formally and technically demand these tests before releasing the final milestone payment of 4,000 EUR?

KKemal G***Member
Job title
Store associate
Sector
IT services
Organization type
medium-sized business
Joined
Apr 2023
Message
7

Doki · Incident response support · 2024

Most Helpful#2

Short answer: Absolutely not normal, and you should never accept delivery of payment or booking software without integration testing. An API endpoint returning a 200 just means the servers can talk to each other; it does not prove funds are properly captured bookings are written correctly to the database or how the system reacts if a transaction drops midway.

Integration testing verifies the scenarios that arise when two different systems exchange data. For payments and bookings, you don't just test successful checkouts. You simulate edge cases like insufficient funds, invalid cards, timeouts, duplicate charge prevention, and proper webhook processing. The agency saying "test it in production" basically dumps the risk of charging a customer without generating a booking straight onto your shoulders.

Definitely hold back the remaining 4,000 EUR payment and make things official with these steps: 1) Send the agency a formal notice stating User Acceptance Testing (UAT) cannot be considered complete without test reports. 2) Demand a test scenario matrix run in a sandbox environment covering at least successful payments failed payments, refunds, timeouts, and webhook triggers as acceptance criteria. 3) Require execution logs and error logs from automated or manual test runs as mandatory attachments to the handover protocol.

Even if your contract lacks detailed technical specs under contract law and standard commercial practice, delivering software that is fit for purpose and free of defects is the contractor's core obligation. A system with untested integrations constitutes defective performance.

MMehmet I***MemberCommunity member
Joined
May 2024
Message
3
#3

I've been managing these kinds of projects for years; the agency is trying to pawn off scenario testing—the most tedious part—onto you. An endpoint returning 200 means nothing. What happens if the bank approves the charge but your system times out right then? You never launch an untested payment setup.

SSelinMember
Job title
Frontend developer
Organization type
20-person company
Joined
Feb 2024
Message
164
#4

The critical piece in payment setups is webhook handling. If the user closes their browser or loses connection, can they handle the async notification in the background? How does the API behave on refunds or partial cancellations? They are obligated to run these in a sandbox with mock requests and provide you with the logs.

VVeli Y***MemberCommunity member
Joined
Feb 2024
Message
8
#5

Block that final payment immediately. Email the agency: "Per our acceptance criteria, no sign-off will be given until 5 core scenarios (successful charge, insufficient funds, 3D secure drop, timeout and automated refund) are documented in the payment provider's sandbox." Watch how fast their tune changes.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#6

We made a similar mistake two years ago on an 18,000 EUR tour booking project. We took the agency's word and launched; first week, 22 charges went through without booking slots on the calendar. We had to refund 3,100 EUR and shut down the platform for 10 days. Skipping three days of testing cost us two whole weeks.

EEbru O***Member
Job title
Quality control inspector
Sector
IT services
Organization type
8-person team
Joined
Jan 2022
Message
139
#7

Does the contract you signed mention acceptance testing or go-live procedures? If they slipped in a boilerplate clause like "deemed accepted if no objection is raised within 14 days of delivery," you need to file your written objection right away before that window closes.

YYiğit Ç***MemberCommunity member
Joined
Mar 2025
Message
107
#8

tbh I doubt the agency even has developers qualified to write integration tests. Usually they just install an off-the-shelf plugin, paste two API keys, and call it a day. That's why they're dodging. Even if you push them, they probably won't be able to deliver a proper test matrix.

PPerihan K***MemberCommunity member
Joined
Jan 2023
Message
152
#9

Demand these three deliverables before signing off: 1) A results matrix of scenarios executed in the sandbox, 2) Screenshots of customer-facing error messages on failed attempts, 3) A reconciliation report matching test-card transactions between the payment gateway dashboard and your website database. Without these, it's not a completed delivery.

ÖÖzgür Y***Member
Job title
IT Manager
Sector
Chemistry
Organization type
boutique agency
Joined
Nov 2023
Message
5

Doki · Mobile app · 2025

#10

don't stress but don't back down either. devs hate writing tests because fixing the bugs that pop up delays their payout and stand your ground on the money—not a cent of that 4,000 EUR leaves your account until you see a test report.

LLale K***MemberCommunity member
Joined
Oct 2025
Message
323
#11

I felt relieved reading this answer, so it's not just me. If acceptance criteria aren't written, when the work is done is open to debate.

If you don't write this down from the start, it leads to arguments later.

TTülay K***ExpertCommunity member
Joined
Jul 2022
Message
276
#12

Let me summarize what's been said so far. The system lives on after delivery; maintenance is a separate line item.

Payment schedules should be tied to project phases, not calendar dates. Proven by experience.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#13

You're right, I've been down that road too. The system lives on after delivery; maintenance is a separate line item.

Implementing a change request process doesn't slow things down, it speeds them up. That's all, sorry if I went on too long.

IIrmak B***MemberCommunity member
Joined
Jan 2025
Message
304
#14

Exactly, and not many people know this. The system lives on after delivery; maintenance is a separate line item.

I'm also curious if anyone does it differently.

MMeryem S***Member
Job title
System administrator
Sector
Electrical-electronics
Organization type
two-branch business
Joined
Mar 2026
Message
398
#15

I didn't know that. When making a decision, first look at what data you have on hand.

Of course it varies if your situation is different.

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
#16

Good call starting this thread.

FFatma G***MemberCommunity member
Joined
Mar 2023
Message
24
#17

Could you elaborate on that? The system lives on after delivery; maintenance is a separate line item.

Just leaving this note, it might be useful.

MMurat T***Member
Job title
Network Administrator
Sector
Insurance
Organization type
boutique agency
Joined
Jan 2025
Message
80
#18

There's a part I don't understand. The biggest time-waster for us was not knowing who had the final say.

CCeren K***MemberCommunity member
Joined
Jan 2023
Message
377
#19

I've been down this road let me tell you. I mean mistakes made on the api integration testing side are usually reversible but expensive.

Just leaving this note it might be useful.

SSinan B***VeteranCommunity member
Joined
Apr 2022
Message
48
#20

Following.

Reply