Set the x-program-id header — it's the only thing the matcher reads. VERIAUTH, VERIAUTHUS, VERIAUTHNONUS, VERIAUTHMULTI, and the literal string PROGRAMID select the five account fixtures; COMPANYINDIVIDUAL, COMPANYORGANIZATION, SCREENITINDIVIDUAL, and SCREENITORGANIZATION drive the entity side; BADREQUEST, FORBIDDEN, RATELIMITED, and SERVERERROR summon the error envelopes. Matching is exact — a near-miss or a missing header falls through to nothing — and the body you post changes no outcome, so the same client request can walk every fixture just by rotating one header value.