AWS Serverless Eda
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .claude/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .claude/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .agents/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .agents/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .cursor/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .cursor/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .gemini/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .gemini/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .github/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .github/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws deploying-custom-domain-rest-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api .opencode/skills/deploying-custom-domain-rest-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deploying-custom-domain-rest-api" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api into .opencode/skills/deploying-custom-domain-rest-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploying-custom-domain-rest-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deploying-custom-domain-rest-apiDeploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.
Deploying Custom Domain REST API is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI. Covers ACM certificate provisioning, API Gateway REST API creation, Lambda function deployment, request authorizer setup, custom domain configuration, base path mapping, and Route 53 DNS record creation. Trigger keywords: custom domain, REST API, Lambda, Route 53, API Gateway, regional endpoint, request authorizer, base path mapping.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/dns-record.json`, `scripts/lambda-trust-policy.json` and `scripts/validate.sh`).
It sits in Backend & APIs, covering REST APIs, Serverless and Microservices. It works with Amazon Web Services and AWS Lambda. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (JavaScript and Shell), which the agent can run.
Shell commands in SKILL.md call:
awscurlpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deploying Custom Domain REST API loads about 4.8k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,942 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 1,942 words, ~4,812 tokens.
.claude/skills/deploying-custom-domain-rest-api/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.This SOP deploys a REST API with a Regional custom domain name, a Lambda backend function, and a request-based Lambda authorizer. It handles ACM certificate provisioning, IAM role creation, Lambda function deployment, API Gateway REST API creation with a custom authorizer, custom domain configuration, base path mapping, and Route 53 DNS setup.
The architecture includes:
GET /exampleImportant: This SOP uses Regional endpoints. If the user requests a private endpoint, inform them that this skill covers Regional endpoints only. Private endpoints require VPC endpoint configuration.
api.example.com)Constraints for parameter acquisition:
Constraints:
This step MUST be performed before all other steps.
Constraints:
aws sts get-caller-identity --query 'Account' --output textSkip this step if acm_certificate_arn is already provided.
Constraints:
aws acm request-certificate --domain-name {custom_domain_name} --validation-method DNS --region {region}aws acm describe-certificate --certificate-arn {cert_arn} --query 'Certificate.DomainValidationOptions[0].ResourceRecord' --region {region}aws route53 change-resource-record-sets --hosted-zone-id {hosted_zone_id} --change-batch '{"Changes":[{"Action":"UPSERT","ResourceRecordSet":{"Name":"{validation_name}","Type":"CNAME","TTL":300,"ResourceRecords":[{"Value":"{validation_value}"}]}}]}'aws acm wait certificate-validated --certificate-arn {cert_arn} --region {region}aws acm describe-certificate --certificate-arn {cert_arn} --query 'Certificate.Status' --region {region} and retry the wait if status is still PENDING_VALIDATIONConstraints:
scripts/lambda-trust-policy.json. The trust policy includes an aws:SourceAccount condition scoped to the user's account IDACCOUNT_ID placeholder with the actual account ID from Step 1. Use: sed 's/ACCOUNT_ID/{account_id}/' scripts/lambda-trust-policy.json > /tmp/lambda-trust-policy.jsonaws iam create-role --role-name request-authorizer-role --assume-role-policy-document file:///tmp/lambda-trust-policy.jsonaws iam attach-role-policy --role-name request-authorizer-role --policy-arn arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRoleaws iam create-role --role-name example-function-role --assume-role-policy-document file:///tmp/lambda-trust-policy.jsonaws iam attach-role-policy --role-name example-function-role --policy-arn arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRoleConstraints:
python3 -c "import zipfile,io,base64; z=io.BytesIO(); f=zipfile.ZipFile(z,'w'); f.writestr('index.mjs', open('scripts/authorizer.mjs').read()); f.close(); open('/tmp/authorizer.zip','wb').write(z.getvalue())"aws lambda create-function --function-name request-authorizer --runtime nodejs22.x --handler index.handler --role {authorizer_role_arn} --zip-file fileb:///tmp/authorizer.zip --timeout 10 --region {region}python3 -c "import zipfile,io; z=io.BytesIO(); f=zipfile.ZipFile(z,'w'); f.writestr('index.mjs', open('scripts/example_function.mjs').read()); f.close(); open('/tmp/example_function.zip','wb').write(z.getvalue())"aws lambda create-function --function-name example-function --runtime nodejs22.x --handler index.handler --role {example_role_arn} --zip-file fileb:///tmp/example_function.zip --timeout 10 --region {region}aws lambda get-function --function-name {function_name} --region {region}Constraints:
aws apigateway create-rest-api --name custom-domain-api --endpoint-configuration types=REGIONAL --region {region}aws apigateway get-resources --rest-api-id {api_id} --region {region}aws apigateway create-authorizer --rest-api-id {api_id} --name request-authorizer --type REQUEST --authorizer-uri 'arn:aws:apigateway:{region}:lambda:path/2015-03-31/functions/arn:aws:lambda:{region}:{account_id}:function:request-authorizer/invocations' --identity-source 'method.request.header.HeaderAuth1,method.request.querystring.QueryString1,context.stage' --region {region}aws lambda add-permission --function-name request-authorizer --statement-id apigateway-auth-invoke --action lambda:InvokeFunction --principal apigateway.amazonaws.com --source-arn 'arn:aws:execute-api:{region}:{account_id}:{api_id}/authorizers/{authorizer_id}' --region {region}aws apigateway create-resource --rest-api-id {api_id} --parent-id {root_resource_id} --path-part example --region {region}aws apigateway put-method --rest-api-id {api_id} --resource-id {example_resource_id} --http-method GET --authorization-type CUSTOM --authorizer-id {authorizer_id} --region {region}aws apigateway put-integration --rest-api-id {api_id} --resource-id {example_resource_id} --http-method GET --type AWS_PROXY --integration-http-method POST --uri 'arn:aws:apigateway:{region}:lambda:path/2015-03-31/functions/arn:aws:lambda:{region}:{account_id}:function:example-function/invocations' --region {region}aws lambda add-permission --function-name example-function --statement-id apigateway-invoke --action lambda:InvokeFunction --principal apigateway.amazonaws.com --source-arn 'arn:aws:execute-api:{region}:{account_id}:{api_id}/*/GET/example' --region {region}Constraints:
aws apigateway create-deployment --rest-api-id {api_id} --stage-name {stage_name} --region {region}aws apigateway update-stage --rest-api-id {api_id} --stage-name {stage_name} --patch-operations op=replace,path=/variables/StageVar1,value=stageValue1 --region {region}aws apigateway get-stage --rest-api-id {api_id} --stage-name {stage_name} --region {region} and confirming StageVar1 is present in the variablesaws logs create-log-group --log-group-name api-gw-access-logs --region {region}. Then enable logging with format: aws apigateway update-stage --rest-api-id {api_id} --stage-name {stage_name} --patch-operations op=replace,path=/accessLogSettings/destinationArn,value=arn:aws:logs:{region}:{account_id}:log-group:api-gw-access-logs op=replace,path=/accessLogSettings/format,value='{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","httpMethod":"$context.httpMethod","resourcePath":"$context.resourcePath","status":"$context.status"}' --region {region}Constraints:
aws apigateway create-domain-name --domain-name {custom_domain_name} --regional-certificate-arn {acm_certificate_arn} --endpoint-configuration types=REGIONAL --security-policy TLS_1_2 --region {region}aws apigateway create-base-path-mapping --domain-name {custom_domain_name} --rest-api-id {api_id} --stage {stage_name} --base-path '(none)' --region {region}aws apigateway get-domain-name --domain-name {custom_domain_name} --region {region}Constraints:
scripts/dns-record.json with placeholders replaced: sed -e 's/CUSTOM_DOMAIN_NAME/{custom_domain_name}/' -e 's/REGIONAL_DOMAIN_NAME/{regional_domain_name}/' -e 's/REGIONAL_HOSTED_ZONE_ID/{regional_hosted_zone_id}/' scripts/dns-record.json > /tmp/dns-record.jsonaws route53 change-resource-record-sets --hosted-zone-id {hosted_zone_id} --change-batch file:///tmp/dns-record.jsonConstraints:
scripts/validate.sh {custom_domain_name} {api_id} {region} to check all resourcescurl 'https://{custom_domain_name}/example?QueryString1=queryValue1' -H 'HeaderAuth1: headerValue1'{"message": "Hello from the example function!"}custom_domain_name: api.example.com
region: us-east-2
hosted_zone_id: Z2OJLYMUO9EFXC
stage_name: prodACM certificate issued for api.example.com
ARN: arn:aws:acm:us-east-2:123456789012:certificate/abc-123
IAM roles created
Authorizer: arn:aws:iam::123456789012:role/request-authorizer-role
Example: arn:aws:iam::123456789012:role/example-function-role
Lambda functions deployed
Authorizer: arn:aws:lambda:us-east-2:123456789012:function:request-authorizer
Example: arn:aws:lambda:us-east-2:123456789012:function:example-function
REST API deployed
API ID: a1b2c3d4e5
Stage: prod (StageVar1=stageValue1)
Authorizer: request-authorizer (REQUEST type)
Custom domain configured
Domain: api.example.com
Regional endpoint: d-abc123.execute-api.us-east-2.amazonaws.com
TLS: 1.2
Route 53 DNS record created
A-alias: api.example.com -> d-abc123.execute-api.us-east-2.amazonaws.com
Test command (authorized):
curl 'https://api.example.com/example?QueryString1=queryValue1' -H 'HeaderAuth1: headerValue1'
Test command (denied):
curl 'https://api.example.com/example'Verify the DNS validation CNAME record exists in Route 53 by running aws acm describe-certificate --certificate-arn {arn} --query 'Certificate.DomainValidationOptions'. Ensure the CNAME was created in the correct hosted zone.
The request authorizer checks three values: HeaderAuth1 header must be headerValue1, QueryString1 query parameter must be queryValue1, and stage variable StageVar1 must be stageValue1. Verify all three are present and correct. Check CloudWatch Logs for the authorizer function for detailed error messages.
API Gateway returns 401 when the authorizer function cannot be invoked. Verify the Lambda permission was added for API Gateway to invoke the authorizer. Check that the authorizer URI is correct.
The request path doesn't match a configured resource. Verify the /example resource exists with aws apigateway get-resources --rest-api-id {api_id}. Ensure the API was deployed after creating all resources.
DNS propagation can take up to 48 hours. Check with dig {custom_domain_name}. Verify the A-alias record points to the correct regionalDomainName and regionalHostedZoneId from the create-domain-name response.
If the authorizer denies all requests, verify the stage variable was set with aws apigateway get-stage --rest-api-id {api_id} --stage-name {stage_name} --query 'variables'. The StageVar1 variable must be set to stageValue1.
IAM role propagation is eventually consistent. Wait at least 10 seconds after role creation before creating Lambda functions. Verify the role ARN with aws iam get-role --role-name {role_name}.
Verify with aws apigateway get-base-path-mappings --domain-name {custom_domain_name}. The base path (none) maps the domain root to the stage. Ensure the deployment to the stage completed successfully.
headerValue1, queryValue1, stageValue1) in the Lambda authorizer are for demonstration only and are NOT suitable for production. Replace with proper authentication mechanisms (JWT validation, API keys from AWS Secrets Manager, or OAuth) before deploying to production.aws apigateway update-stage --rest-api-id {api_id} --stage-name {stage_name} --patch-operations op=replace,path=/throttle/rateLimit,value=1000 op=replace,path=/throttle/burstLimit,value=2000aws logs associate-kms-key --log-group-name /aws/lambda/request-authorizer --kms-key-arn <KMS_KEY_ARN>aws wafv2 associate-web-acl --web-acl-arn <WAF_ACL_ARN> --resource-arn arn:aws:apigateway:{region}::/restapis/{api_id}/stages/{stage_name}© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit 188af2f
Deploying Custom Domain REST API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deploying Custom Domain REST API this skillaws/agent-toolkit-for-aws | 2.8k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| AWS Serverless Edazxkane/aws-skills | 367 | 4 repos | ~3.2k | Automated safety check: Pass | MIT | |
| AWS Lambda Durable Functionsawslabs/agent-plugins | 915 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| AWS Lambda Java Integrationgiuseppe-trisciuoglio/developer-kit | 355 | — | ~1.9k | Automated safety check: Notes | MIT | |
| AWS Lambda Php Integrationgiuseppe-trisciuoglio/developer-kit | 355 | — | ~2.3k | Automated safety check: Notes | MIT | |
| AWS Lambda Python Integrationgiuseppe-trisciuoglio/developer-kit | 355 | — | ~2.4k | Automated safety check: Notes | MIT |
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
awslabs/agent-plugins
Build resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic, and orchestration for long-running executions.
giuseppe-trisciuoglio/developer-kit
Provides AWS Lambda integration patterns for Java with cold start optimization.
giuseppe-trisciuoglio/developer-kit
Provides AWS Lambda integration patterns for PHP with Symfony using the Bref framework.
giuseppe-trisciuoglio/developer-kit
Provides AWS Lambda integration patterns for Python with cold start optimization.
giuseppe-trisciuoglio/developer-kit
Provides AWS Lambda integration patterns for TypeScript with cold start optimization.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Works with
Categories
Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI. Deploying Custom Domain REST API is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.
Deploying Custom Domain REST API fits situations like: keywords: custom domain; regional endpoint; request authorizer; base path mapping.
Run `npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a claude-code`. Or copy the skill folder (skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api in aws/agent-toolkit-for-aws) into .claude/skills/deploying-custom-domain-rest-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a codex`. Or copy the skill folder (skills/specialized-skills/serverless-skills/deploying-custom-domain-rest-api in aws/agent-toolkit-for-aws) into .agents/skills/deploying-custom-domain-rest-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill deploying-custom-domain-rest-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-custom-domain-rest-api, .gemini/skills/deploying-custom-domain-rest-api, .github/skills/deploying-custom-domain-rest-api and .opencode/skills/deploying-custom-domain-rest-api in your project.
Going by SKILL.md and its folder, Deploying Custom Domain REST API needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (aws, curl and python3). Our summary lists: Python 3; Node.js; A Bash shell.
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Deploying Custom Domain REST API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deploying Custom Domain REST API: AWS Serverless Eda (zxkane/aws-skills, 367 stars), AWS Lambda Durable Functions (awslabs/agent-plugins, 915 stars), AWS Lambda Java Integration (giuseppe-trisciuoglio/developer-kit, 355 stars) and AWS Lambda Php Integration (giuseppe-trisciuoglio/developer-kit, 355 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.