Eiffel was designed by Bertrand Meyer in 1985 and released in 1986 by his company, Interactive Software Engineering, based in Santa Barbara, California. The ideas behind Bertrand Meyer's Eiffel and Design by Contract are tightly linked: Eiffel was built to make software correctness something you write down in the code, in the form of explicit contracts between classes and their clients. The language is named after Gustave Eiffel, the engineer behind the Paris tower, as a nod to building reliable structures on time.

Origins of Eiffel

Meyer, a French computer scientist, had worked on formal specification, including the Z notation, and taught software engineering. In the mid-1980s object-oriented programming was emerging, but Simula was little used and C++ was still young. Meyer wanted a language for large, reusable software components, with formal rigour baked in rather than added through external tools.

ISE released the first Eiffel compiler in 1986. In 1988 Meyer published Object-Oriented Software Construction, which used Eiffel throughout and became one of the most influential books on object-oriented design. The language reference Eiffel: The Language followed in 1991. In 2001 Meyer moved to ETH Zurich, where Eiffel was used for introductory programming courses.

Bertrand Meyer's Eiffel and Design by Contract

Design by Contract treats each routine as an agreement. The caller must satisfy the precondition; in return, the routine guarantees the postcondition. A class invariant states properties that hold for every object whenever it is visible to clients. In Eiffel these are written with the keywords require, ensure and invariant.

class
    ACCOUNT

create
    make

feature
    balance: INTEGER

    make
        do
            balance := 0
        end

    deposit (amount: INTEGER)
        require
            positive_amount: amount > 0
        do
            balance := balance + amount
        ensure
            balance_increased: balance = old balance + amount
        end

invariant
    non_negative: balance >= 0
end

The keyword old refers to a value at routine entry. Contracts can be checked at runtime during testing, used to generate documentation, and serve as the basis for automated test generation and proofs. When a precondition fails, the blame lies with the caller; when a postcondition fails, it lies with the routine. That clear assignment of responsibility is the practical heart of the method.

Other key features

  • Multiple inheritance with renaming and redefinition to resolve name clashes cleanly.
  • Genericity, both unconstrained and constrained, from the start.
  • Uniform access principle: clients cannot tell whether balance is a stored attribute or a computed function.
  • Command-query separation: routines either change state or return a value, not both.
  • Agents, Eiffel's closures, for callbacks and iteration.
  • Void safety: the type system can rule out null-pointer dereferences at compile time, added in the late 2000s.
  • SCOOP (Simple Concurrent Object-Oriented Programming), a concurrency model built on the separate keyword.

Standards and tools

YearMilestone
1986First Eiffel compiler released by ISE
1988Object-Oriented Software Construction published
1997Second edition of OOSC
2005ECMA-367 standard
2006ISO/IEC 25436; EiffelStudio released as open source

The main implementation is EiffelStudio from Eiffel Software, available under an open source licence and commercially. It compiles Eiffel to C for portability and performance, and includes AutoTest, a tool that uses contracts to generate and check tests automatically. Other implementations have included SmartEiffel, from the LORIA lab in France, and LibertyEiffel.

Where Eiffel is used

Eiffel never became mainstream, but it found users in finance, telecommunications, defence and other areas where large, long-lived systems need to stay correct. It is also used in teaching and in research on program verification, notably at ETH Zurich and in tools such as AutoProof.

Influence and legacy

Eiffel's influence is larger than its user base. Contracts appear in Ada 2012, D, Racket, the .NET Code Contracts library, and C++26. Java's assert is a modest relative. Sather began as a derivative of Eiffel, and Yukihiro Matsumoto has listed Eiffel among Ruby's influences. Terms such as "command-query separation" and "open-closed principle", both popularised by Meyer, are now standard vocabulary in software design.

Is Eiffel still used today?

Yes, in a niche. Eiffel Software continues to release EiffelStudio, and a community maintains libraries and verification tools. Most programmers meet Eiffel's ideas indirectly, through contracts and object-oriented principles in other languages. The pairing of Bertrand Meyer's Eiffel and Design by Contract remains the clearest example of a language built around the question of how to state what correct code should do.

Frequently asked questions

What is Design by Contract in simple terms?

It is a way of writing down the obligations between a piece of code and its callers. The caller must meet the precondition, the code promises the postcondition, and the class keeps its invariant true. Problems become easier to locate because a broken contract shows exactly who is at fault.

Is "Design by Contract" a trademark?

Eiffel Software registered "Design by Contract" as a trademark, which is why some other languages and libraries use alternative names such as "contract programming" or "contracts". The underlying ideas build on earlier work on program correctness by Tony Hoare and others.

Can I learn Eiffel for free?

Yes. EiffelStudio has a free open source edition, and Bertrand Meyer's textbook Touch of Class, based on his ETH Zurich course, introduces programming with Eiffel. Online documentation and tutorials are available from Eiffel Software.