API Gateway
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).
$ npx skills add awslabs/agent-plugins --skill api-gateway -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awslabs/agent-plugins api-gateway --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .claude/skills/api-gateway && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .claude/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gatewayType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awslabs/agent-plugins --skill api-gateway -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awslabs/agent-plugins api-gateway --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .agents/skills/api-gateway && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .agents/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awslabs/agent-plugins --skill api-gateway -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awslabs/agent-plugins api-gateway --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .cursor/skills/api-gateway && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .cursor/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awslabs/agent-plugins.git --path plugins/aws-serverless/skills/api-gateway--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awslabs/agent-plugins --skill api-gateway -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awslabs/agent-plugins api-gateway --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .gemini/skills/api-gateway && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .gemini/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awslabs/agent-plugins api-gatewayInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awslabs/agent-plugins --skill api-gateway -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .github/skills/api-gateway && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .github/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awslabs/agent-plugins --skill api-gateway -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awslabs/agent-plugins api-gateway --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .opencode/skills/api-gateway && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "api-gateway" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/aws-serverless/skills/api-gateway into .opencode/skills/api-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-gateway", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
api-gatewayBuild, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).
API Gateway is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket). Triggers on phrases like: API Gateway, REST API, HTTP API, WebSocket API, custom domain, Lambda authorizer, usage plan, throttling, CORS, VPC link, private API. Also covers troubleshooting API Gateway errors (4xx, 5xx, timeout, CORS failures) and IaC templates containing API Gateway resources. For general REST API design unrelated to AWS, do not trigger.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/architecture-patterns.md`, `references/authentication.md` and `references/custom-domains-routing.md`).
It sits in Backend & APIs, covering Microservices, REST APIs and Realtime and WebSockets. It works with Amazon Web Services. The repository describes itself as: Agent Plugins for AWS equip AI coding agents with the skills to help you architect, deploy, and operate on AWS. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit da51970. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
API Gateway loads about 4.9k tokens when it runs, and up to ~60k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,793 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awslabs/agent-plugins at commit da51970, republished under its Apache-2.0 licence (© awslabs). 1,793 words, ~4,942 tokens.
.claude/skills/api-gateway/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.Expert guidance for building, managing, governing, and operating APIs with Amazon API Gateway. Covers REST APIs (v1), HTTP APIs (v2), and WebSocket APIs.
When answering API Gateway questions:
references/sam-cloudformation.md or references/sam-service-integrations.md and provide complete, working SAM/CloudFormation YAMLChoose the right API type first. This decision affects every downstream choice.
REST API is the full-featured API management platform for enterprises. It provides the governance, security, monetization, and operational controls that organizations need to build, publish, and manage APIs at scale, including usage plans with per-consumer throttling and quotas, API keys, request validation, WAF integration, resource policies, caching, canary deployments, and private endpoints.
HTTP API is the lightweight, low-cost proxy optimized for simpler API workloads. It offers ~70% lower cost and lower latency but trades away the API management features. Choose HTTP API when you need a fast, lightweight proxy to Lambda or HTTP backends and don't require the enterprise controls above.
| Factor | REST API (v1) | HTTP API (v2) | WebSocket API |
|---|---|---|---|
| Positioning | Full API management | Low-cost proxy | Real-time bidirectional |
| Cost | Higher | ~70% cheaper | Per-message pricing |
| Latency | Higher | Lower | Persistent connection |
| Max timeout | 50ms-29s (up to 300s Regional/Private) | 30s hard limit | 29s |
| Payload | 10 MB | 10 MB | 128 KB message / 32 KB frame |
| API Management | |||
| Usage plans/API keys | Yes | No | No |
| Request validation | Yes (JSON Schema draft 4) | No | No |
| Caching | Yes (0.5-237 GB) | No | No |
| Custom gateway responses | Yes | No | No |
| VTL mapping templates | Yes | No (parameter mapping only) | Yes |
| Security & Governance | |||
| WAF | Yes | No (use CloudFront + WAF) | No |
| Resource policies | Yes | No | No |
| Private endpoints | Yes | No | No |
| mTLS | Yes (Regional custom domain only) | Yes (Regional custom domain only) | Via CloudFront viewer mTLS |
| Auth | |||
| Lambda authorizer | Yes (TOKEN + REQUEST) | Yes (REQUEST only, simple + IAM policy format) | Yes (REQUEST on $connect only) |
| JWT authorizer | No (use Cognito authorizer) | Yes (native) | No |
| Cognito authorizer | Yes (native) | Use JWT authorizer | No |
| Operations | |||
| Canary deployments | Yes | No | No |
| Response streaming | Yes | No | No |
| X-Ray tracing | Yes | No | No |
| Execution logging | Yes | No | Yes |
| Custom domain sharing | Not with WebSocket | Not with WebSocket | Not with REST/HTTP |
Use REST API when: you are building APIs for external consumers, partners, or multi-tenant platforms; need to enforce per-consumer rate limits and quotas; require request validation, caching, or WAF at the API layer; need private endpoints, resource policies, or canary deployments; or are building an API product with monetization and governance requirements.
Use HTTP API when: you are building lightweight APIs or simple backend proxies; cost and latency are the primary concerns; you don't need per-consumer throttling, request validation, caching, or WAF at the API layer; and native JWT authorization with OIDC/OAuth 2.0 meets your auth needs. Accept the hard 30s timeout and lack of API management features. For WAF, edge caching, or edge compute, place a CloudFront distribution in front of the HTTP API.
Use WebSocket API when you need: persistent bidirectional connections for real-time use cases (chat, notifications, live dashboards).
Before implementation, gather requirements systematically. Consult references/requirements-gathering.md for the full requirements workflow covering endpoints, auth, data models, performance, security, and deployment needs.
Key design decisions:
references/authentication.md for the decision treeConsult these references based on what you're building:
references/architecture-patterns.md: topology, multi-tenant SaaS, hybrid workloads, private APIs, multi-region, streamingreferences/websocket.md: route selection, @connections management, session management, client resilience, SAM templates, limits, multi-regionreferences/service-integrations.md: direct AWS service integrations (EventBridge, SQS, SNS, DynamoDB, Kinesis, Step Functions, S3), HTTP proxy, mock, VTL mapping templates, binary media types, Lambda sync/async invocationreferences/custom-domains-routing.md: base path mappings, routing rules, header-based versioningreferences/security.md: mTLS (API Gateway native + CloudFront viewer mTLS), TLS policies, resource policies, WAF, HttpOnly cookies, CRL checksreferences/sam-cloudformation.md: IaC patterns, OpenAPI extensions, VTL reference, binary datareferences/sam-service-integrations.md: EventBridge, SQS, DynamoDB CRUD, Kinesis, Step Functions (REST + WebSocket) templatesreferences/performance-scaling.mdAlways configure access logging. For REST and WebSocket APIs, also enable execution logging (ERROR level for production, INFO only for debugging). HTTP API does not support execution logging; use access logs with enhanced observability variables instead.
Consult the observability references based on what you need:
references/observability-logging.mdreferences/observability-metrics-alarms.mdreferences/observability-analytics.mdreferences/deployment.md for detailed patternsFor organization-wide API standards, see references/governance.md covering:
When responding to API Gateway questions, structure your answer as:
references/pitfalls.mdWhen diagnosing API Gateway errors, consult references/troubleshooting.md for detailed resolution steps. Here are the most common issues:
| Error | Most Common Cause | Quick Fix |
|---|---|---|
| 400 Bad Request | Protocol mismatch (HTTP/HTTPS) with ALB | Match protocol to listener type |
| 401 Unauthorized | Wrong token type (ID vs access) or missing identity sources | Check token type matches scope config; verify all identity sources sent |
| 403 Missing Auth Token | Stage name in URL when using custom domain | Remove stage name from URL path |
| 403 from VPC | Private DNS on VPC endpoint intercepts ALL API calls | Use custom domain names for public APIs |
| 403 Access Denied | Resource policy + auth type mismatch or missing redeployment | Review policy, check auth type, redeploy API |
| 403 mTLS | Certificate issuer not in truststore or weak signature algorithm | Verify CA in truststore, use SHA-256+ |
| 429 Too Many Requests | Account/stage/method throttle limits exceeded | Implement jittered exponential backoff; request limit increase |
| 500 Internal Error | Missing Lambda invoke permission (especially with stage variables) | Add resource-based policy to Lambda function |
| 502 Bad Gateway | Lambda response not in required proxy format | Return {statusCode, headers, body} from Lambda |
| 504 Timeout | Backend exceeds 29s (REST, increasable) or 30s (HTTP, hard). HTTP API body says "Service Unavailable" but status is 504 | Optimize backend, request timeout increase (REST Regional/Private), or switch to async invocation |
| CORS errors | Missing CORS headers on Gateway Responses (4XX/5XX) | Add CORS headers to DEFAULT_4XX and DEFAULT_5XX gateway responses |
| SSL/PKIX errors | Incomplete certificate chain on backend | Provide full cert chain; use insecureSkipVerification only for testing |
{"message":"Service Unavailable"} while Lambda continues/ping and /sping are reserved paths. Do not use for API resourcesREQUEST_TOO_LARGE is the only gateway response that cannot be customized. Use DEFAULT_4XX as a catch-all to add CORS headers for all 4xx errors including 413maxItems/minItems not validated in REST API request validationsecurity in OpenAPI is ignored. Must set per-operationFor additional pitfalls (header handling, URL encoding, caching charges, canary deployments, usage plans), see references/pitfalls.md.
Default: CDK TypeScript
Override syntax:
When not specified, ALWAYS use CDK TypeScript.
See references/service-limits.md for the complete table. Most numeric quotas below are default values and adjustable; check with your AWS account team and the latest quotas page before using them for architectural decisions. Key limits:
| Resource | REST API | HTTP API | WebSocket |
|---|---|---|---|
| Payload size | 10 MB | 10 MB | 128 KB |
| Integration timeout | 50ms-29s (up to 300s Regional/Private) | 30s hard | 29s |
| APIs per region | 600 Regional/Private; 120 Edge-optimized | 600 | 600 |
| Stages per API | 10 | 10 | 10 |
| Routes/resources per API | 300 | 300 | 300 |
| Custom domains (public) | 120 | 120 | 120 |
| Account throttle | 10,000 rps / 5,000 burst | Same | Same (shared quota) |
| API keys per region | 10,000 | N/A | N/A |
| Usage plans per region | 300 | N/A | N/A |
| Cache sizes | 0.5 GB - 237 GB | N/A | N/A |
© awslabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 18 other files (references) in plugins/aws-serverless/skills/api-gateway of awslabs/agent-plugins.
Open the folder on GitHubat commit da51970
API Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| API Gateway this skillawslabs/agent-plugins | 912 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| API Gatewayitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Detecting Shadow API Endpointsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Deploying Custom Domain REST APIaws/agent-toolkit-for-aws | 2.8k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Connecting Lambda To API Gatewayaws/agent-toolkit-for-aws | 2.8k | — | ~422 | Automated safety check: Pass | Apache-2.0 | |
| Ak Cloud Deployyaalalabs/agent-kernel | 191 | — | ~14k | Automated safety check: Pass | Apache-2.0 |
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
mukul975/Anthropic-Cybersecurity-Skills
Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration…
aws/agent-toolkit-for-aws
Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.
aws/agent-toolkit-for-aws
Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration, permissions, and deployment.
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
ever-works/ever-works
Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.
awslabs/agent-plugins
Validates dataset formatting and quality for SageMaker model fine-tuning (SFT, DPO, or RLVR).
awslabs/agent-plugins
Generates code that transforms datasets between ML schemas for model training or evaluation.
awslabs/agent-plugins
Selects a fine-tuning technique (SFT, DPO, RLVR, or RLAIF) for the user's use case and validates it against the selected model's available recipes.
awslabs/agent-plugins
Evaluate, configure, and migrate workloads to AWS Lambda Managed Instances (LMI).
awslabs/agent-plugins
Generate comprehensive issue reports from HyperPod clusters (EKS and Slurm) by collecting diagnostic logs and configurations for troubleshooting and AWS Support cases.
awslabs/agent-plugins
Diagnose performance issues on Amazon SageMaker HyperPod clusters — uneven NCCL bandwidth across nodes and poor filesystem throughput.
Works with
Categories
Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket). API Gateway is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).
API Gateway fits situations like: phrases like: API Gateway; lambda authorizer.
Run `npx skills add awslabs/agent-plugins --skill api-gateway -a claude-code`. Or copy the skill folder (plugins/aws-serverless/skills/api-gateway in awslabs/agent-plugins) into .claude/skills/api-gateway in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awslabs/agent-plugins --skill api-gateway -a codex`. Or copy the skill folder (plugins/aws-serverless/skills/api-gateway in awslabs/agent-plugins) into .agents/skills/api-gateway in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awslabs/agent-plugins --skill api-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-gateway, .gemini/skills/api-gateway, .github/skills/api-gateway and .opencode/skills/api-gateway in your project.
SKILL.md names no scripts, command-line tools or credentials: API Gateway is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
API Gateway is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 55k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with API Gateway: API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Detecting Shadow API Endpoints (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Deploying Custom Domain REST API (aws/agent-toolkit-for-aws, 2.8k stars) and Connecting Lambda To API Gateway (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awslabs (a GitHub organization, an official publisher) maintains it in awslabs/agent-plugins, which has 912 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 5, 2026.
Source: awslabs/agent-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.