Skip to content
>devspeak
← glossary
level 6Testing & Reliability

Validation

also: input validation, validate, validating, validated

Checking that data coming into your app, like a form entry, is acceptable before using it. For example, rejecting an email address with no @.

a bit more technical

Checks that run in the live app on incoming data (form fields, API request bodies, uploads) to confirm its type, format and range before it's processed or stored. Unlike tests, validation runs on every input. Libraries like Zod define the rules.

picture it

A bouncer checking IDs at the door every night is validation. A fire inspection before the venue opens is more like testing. Different jobs, both needed.

why it matters

"Validate" and "test" get mixed up. Validation protects your live app from bad data; tests check your code works before you ship. When an agent says it "validated" something, ask which one it means.

what your agent might say
agent
I added validation to the signup endpoint: email must be valid and password at least 12 characters. Invalid requests now get a 400 with a clear message.
how you might use it
you → your agent
Add server-side validation to the booking form: the date can't be in the past and party size must be 1 to 20. Don't rely only on the check in the browser.
common mistake

Thinking validation and testing are the same thing. Tests check your code during development; validation checks users' data every time the live app runs.