Official agent skill

API Gateway

by awslabs in awslabs/agent-plugins

Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).

OfficialApache-2.0Auto-check passedBackend & APIs

Install API Gateway

skills CLI
$ npx skills add awslabs/agent-plugins --skill api-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awslabs/agent-plugins api-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-serverless/skills/api-gateway .claude/skills/api-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-gateway
GitHub stars
912
Token cost
~4.9k tokens
SKILL.md length
1,793 words
Files
19 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).

  • Works in 6 steps: Design the API → Implement the API → Configure Performance and Scaling → …
  • Phrases like: API Gateway
  • SKILL.md covers How to Use This Skill, Quick Decision: Which API Type?, Instructions and Response Format, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Gateway is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket). Triggers on phrases like: API Gateway, REST API, HTTP API, WebSocket API, custom domain, Lambda authorizer, usage plan, throttling, CORS, VPC link, private API. Also covers troubleshooting API Gateway errors (4xx, 5xx, timeout, CORS failures) and IaC templates containing API Gateway resources. For general REST API design unrelated to AWS, do not trigger.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/architecture-patterns.md`, `references/authentication.md` and `references/custom-domains-routing.md`).

It sits in Backend & APIs, covering Microservices, REST APIs and Realtime and WebSockets. It works with Amazon Web Services. The repository describes itself as: Agent Plugins for AWS equip AI coding agents with the skills to help you architect, deploy, and operate on AWS. The licence is Apache-2.0.

When your agent uses it

  • Phrases like: API Gateway
  • Lambda authorizer

Example prompts

  • “/api-gateway”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Design the API
  2. Implement the API
  3. Configure Performance and Scaling
  4. Set Up Observability
  5. Deploy
  6. Apply Governance

What it can do on your machine

Read from SKILL.md and the folder at commit da51970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Gateway loads about 4.9k tokens when it runs, and up to ~60k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,793 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~60k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awslabs/agent-plugins at commit da51970, republished under its Apache-2.0 licence (© awslabs). 1,793 words, ~4,942 tokens.

Download SKILL.mdSave it as .claude/skills/api-gateway/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
api-gateway
description
Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket). Triggers on phrases like: API Gateway, REST API, HTTP API, WebSocket API, custom domain, Lambda authorizer, usage plan, throttling, CORS, VPC link, private API. Also covers troubleshooting API Gateway errors (4xx, 5xx, timeout, CORS failures) and IaC templates containing API Gateway resources. For general REST API design unrelated to AWS, do not trigger.
metadata.tags
api-gateway, serverless, aws, rest-api, http-api, websocket

Amazon API Gateway Development

Expert guidance for building, managing, governing, and operating APIs with Amazon API Gateway. Covers REST APIs (v1), HTTP APIs (v2), and WebSocket APIs.

How to Use This Skill

When answering API Gateway questions:

  1. Read the relevant reference file(s) before responding, do not rely solely on this summary
  2. For tasks spanning multiple concerns (e.g., "private API with mTLS and custom domain"), read all relevant references
  3. When the user needs IaC templates, consult references/sam-cloudformation.md or references/sam-service-integrations.md and provide complete, working SAM/CloudFormation YAML
  4. Always mention relevant pitfalls and limits that affect the user's design

Quick Decision: Which API Type?

Choose the right API type first. This decision affects every downstream choice.

REST API is the full-featured API management platform for enterprises. It provides the governance, security, monetization, and operational controls that organizations need to build, publish, and manage APIs at scale, including usage plans with per-consumer throttling and quotas, API keys, request validation, WAF integration, resource policies, caching, canary deployments, and private endpoints.

HTTP API is the lightweight, low-cost proxy optimized for simpler API workloads. It offers ~70% lower cost and lower latency but trades away the API management features. Choose HTTP API when you need a fast, lightweight proxy to Lambda or HTTP backends and don't require the enterprise controls above.

FactorREST API (v1)HTTP API (v2)WebSocket API
PositioningFull API managementLow-cost proxyReal-time bidirectional
CostHigher~70% cheaperPer-message pricing
LatencyHigherLowerPersistent connection
Max timeout50ms-29s (up to 300s Regional/Private)30s hard limit29s
Payload10 MB10 MB128 KB message / 32 KB frame
API Management
Usage plans/API keysYesNoNo
Request validationYes (JSON Schema draft 4)NoNo
CachingYes (0.5-237 GB)NoNo
Custom gateway responsesYesNoNo
VTL mapping templatesYesNo (parameter mapping only)Yes
Security & Governance
WAFYesNo (use CloudFront + WAF)No
Resource policiesYesNoNo
Private endpointsYesNoNo
mTLSYes (Regional custom domain only)Yes (Regional custom domain only)Via CloudFront viewer mTLS
Auth
Lambda authorizerYes (TOKEN + REQUEST)Yes (REQUEST only, simple + IAM policy format)Yes (REQUEST on $connect only)
JWT authorizerNo (use Cognito authorizer)Yes (native)No
Cognito authorizerYes (native)Use JWT authorizerNo
Operations
Canary deploymentsYesNoNo
Response streamingYesNoNo
X-Ray tracingYesNoNo
Execution loggingYesNoYes
Custom domain sharingNot with WebSocketNot with WebSocketNot with REST/HTTP

Use REST API when: you are building APIs for external consumers, partners, or multi-tenant platforms; need to enforce per-consumer rate limits and quotas; require request validation, caching, or WAF at the API layer; need private endpoints, resource policies, or canary deployments; or are building an API product with monetization and governance requirements.

Use HTTP API when: you are building lightweight APIs or simple backend proxies; cost and latency are the primary concerns; you don't need per-consumer throttling, request validation, caching, or WAF at the API layer; and native JWT authorization with OIDC/OAuth 2.0 meets your auth needs. Accept the hard 30s timeout and lack of API management features. For WAF, edge caching, or edge compute, place a CloudFront distribution in front of the HTTP API.

Use WebSocket API when you need: persistent bidirectional connections for real-time use cases (chat, notifications, live dashboards).

Instructions

Step 1: Design the API

Before implementation, gather requirements systematically. Consult references/requirements-gathering.md for the full requirements workflow covering endpoints, auth, data models, performance, security, and deployment needs.

Key design decisions:

  1. API type: Use the decision table above
  2. Endpoint type: Edge-optimized (default for global clients; optimizes TCP connections via CloudFront POPs but does not cache at the edge), Regional (same-region clients, or global clients needing their own CloudFront distribution for edge caching, edge compute, granular WAF control, or geo-based routing), Private (VPC-only access, REST API only)
  3. Topology: Centralized (single domain, path-based routing) vs Distributed (subdomains per service)
  4. Authentication: See references/authentication.md for the decision tree
Step 2: Implement the API

Consult these references based on what you're building:

  • Architecture patterns: references/architecture-patterns.md: topology, multi-tenant SaaS, hybrid workloads, private APIs, multi-region, streaming
  • WebSocket API: references/websocket.md: route selection, @connections management, session management, client resilience, SAM templates, limits, multi-region
  • Service integrations: references/service-integrations.md: direct AWS service integrations (EventBridge, SQS, SNS, DynamoDB, Kinesis, Step Functions, S3), HTTP proxy, mock, VTL mapping templates, binary media types, Lambda sync/async invocation
  • Custom domains and routing: references/custom-domains-routing.md: base path mappings, routing rules, header-based versioning
  • Security: references/security.md: mTLS (API Gateway native + CloudFront viewer mTLS), TLS policies, resource policies, WAF, HttpOnly cookies, CRL checks
  • SAM/CloudFormation: references/sam-cloudformation.md: IaC patterns, OpenAPI extensions, VTL reference, binary data
  • SAM service integration templates: references/sam-service-integrations.md: EventBridge, SQS, DynamoDB CRUD, Kinesis, Step Functions (REST + WebSocket) templates
Step 3: Configure Performance and Scaling
  • Throttling: Account-level default is 10,000 rps / 5,000 burst (adjustable; request increases via AWS Support). Configure stage-level and method-level throttling via usage plans. See references/performance-scaling.md
  • Caching (REST only): Default TTL 300s, max 3600s. Only GET methods cached by default. Max cached response 1 MB
  • Edge caching (all API types): For edge caching, place a self-managed CloudFront distribution in front of a Regional API. CloudFront reduces latency, backend load, AND cost (cached responses never reach API Gateway). Also enables edge compute (CloudFront Functions, Lambda@Edge) and granular cache behaviors per path. Use a Regional endpoint, not edge-optimized, when pairing with your own CloudFront distribution
  • Scaling: API Gateway scales automatically but plan the entire stack (Lambda concurrency, DynamoDB capacity)
Step 4: Set Up Observability

Always configure access logging. For REST and WebSocket APIs, also enable execution logging (ERROR level for production, INFO only for debugging). HTTP API does not support execution logging; use access logs with enhanced observability variables instead.

Consult the observability references based on what you need:

  • Logging setup, log formats, retention: references/observability-logging.md
  • Metrics, alarms, metric filters, X-Ray tracing: references/observability-metrics-alarms.md
  • Log analysis and insights, analytics pipeline, cross-account, control plane logs: references/observability-analytics.md
Step 5: Deploy
  • Use Infrastructure as Code (SAM, CDK, CloudFormation, Terraform) for production
  • Canary deployments (REST only): Route a percentage of traffic to test new versions
  • Blue/green deployments: Use custom domain API mappings to switch between environments with zero downtime
  • Routing rules (preferred for new domains): Declarative header/path-based routing on custom domains for versioning, A/B testing, gradual rollouts, and cell-based routing
  • See references/deployment.md for detailed patterns
Step 6: Apply Governance

For organization-wide API standards, see references/governance.md covering:

  • Preventative controls (SCPs, IAM policies)
  • Proactive controls (CloudFormation Hooks, Guard rules)
  • Detective controls (AWS Config rules, EventBridge)
  • Specific enforcement examples for security, observability, and management
Show full SKILL.md (717 more words)Show less

Response Format

When responding to API Gateway questions, structure your answer as:

  1. Recommendation: Lead with the recommended approach and why
  2. Code: Include SAM/CloudFormation YAML or code when the user needs implementation (always read the relevant reference file first)
  3. Pitfalls: Warn about relevant gotchas from the pitfalls below or from references/pitfalls.md
  4. Limits: Mention any service limits that constrain the design

Troubleshooting Quick Reference

When diagnosing API Gateway errors, consult references/troubleshooting.md for detailed resolution steps. Here are the most common issues:

ErrorMost Common CauseQuick Fix
400 Bad RequestProtocol mismatch (HTTP/HTTPS) with ALBMatch protocol to listener type
401 UnauthorizedWrong token type (ID vs access) or missing identity sourcesCheck token type matches scope config; verify all identity sources sent
403 Missing Auth TokenStage name in URL when using custom domainRemove stage name from URL path
403 from VPCPrivate DNS on VPC endpoint intercepts ALL API callsUse custom domain names for public APIs
403 Access DeniedResource policy + auth type mismatch or missing redeploymentReview policy, check auth type, redeploy API
403 mTLSCertificate issuer not in truststore or weak signature algorithmVerify CA in truststore, use SHA-256+
429 Too Many RequestsAccount/stage/method throttle limits exceededImplement jittered exponential backoff; request limit increase
500 Internal ErrorMissing Lambda invoke permission (especially with stage variables)Add resource-based policy to Lambda function
502 Bad GatewayLambda response not in required proxy formatReturn {statusCode, headers, body} from Lambda
504 TimeoutBackend exceeds 29s (REST, increasable) or 30s (HTTP, hard). HTTP API body says "Service Unavailable" but status is 504Optimize backend, request timeout increase (REST Regional/Private), or switch to async invocation
CORS errorsMissing CORS headers on Gateway Responses (4XX/5XX)Add CORS headers to DEFAULT_4XX and DEFAULT_5XX gateway responses
SSL/PKIX errorsIncomplete certificate chain on backendProvide full cert chain; use insecureSkipVerification only for testing

Critical Pitfalls

  1. REST API default timeout is 29 seconds (increasable up to 300s for Regional/Private endpoints via quota request). Lambda continues running but client gets 504. Request a timeout increase, or consider async patterns (SQS, EventBridge) for better user experience on long operations
  2. HTTP API hard timeout is 30 seconds. Returns {"message":"Service Unavailable"} while Lambda continues
  3. /ping and /sping are reserved paths. Do not use for API resources
  4. Execution log events truncated at 1,024 bytes. Use access logs for complete data
  5. 413 REQUEST_TOO_LARGE is the only gateway response that cannot be customized. Use DEFAULT_4XX as a catch-all to add CORS headers for all 4xx errors including 413
  6. maxItems/minItems not validated in REST API request validation
  7. Root-level security in OpenAPI is ignored. Must set per-operation
  8. JWT authorizer public keys cached 2 hours. Account for this in key rotation
  9. Management API rate limit: 10 rps / 40 burst. Heavy automation can hit this
  10. Always redeploy REST API after configuration changes. Changes don't take effect until deployed
  11. Edge-optimized endpoints do NOT cache at the edge — they only optimize TCP connections via CloudFront POPs. If you need edge caching, edge compute (CloudFront Functions, Lambda@Edge), or granular CloudFront control, use a Regional API with your own CloudFront distribution instead

For additional pitfalls (header handling, URL encoding, caching charges, canary deployments, usage plans), see references/pitfalls.md.

IaC Framework Selection

Default: CDK TypeScript

Override syntax:

  • "use SAM" → Generate SAM/CloudFormation YAML templates
  • "use CloudFormation" → Generate CloudFormation YAML templates
  • "use Terraform" → Generate Terraform HCL

When not specified, ALWAYS use CDK TypeScript.

Error Scenarios

MCP Server Unavailable
  • Inform user: "AWS Serverless MCP not responding"
  • Ask: "Proceed without MCP support?"
  • DO NOT continue without user confirmation

Service Limits Quick Reference

See references/service-limits.md for the complete table. Most numeric quotas below are default values and adjustable; check with your AWS account team and the latest quotas page before using them for architectural decisions. Key limits:

ResourceREST APIHTTP APIWebSocket
Payload size10 MB10 MB128 KB
Integration timeout50ms-29s (up to 300s Regional/Private)30s hard29s
APIs per region600 Regional/Private; 120 Edge-optimized600600
Stages per API101010
Routes/resources per API300300300
Custom domains (public)120120120
Account throttle10,000 rps / 5,000 burstSameSame (shared quota)
API keys per region10,000N/AN/A
Usage plans per region300N/AN/A
Cache sizes0.5 GB - 237 GBN/AN/A

© awslabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (references) in plugins/aws-serverless/skills/api-gateway of awslabs/agent-plugins.

  • SKILL.md
  • references/architecture-patterns.md
  • references/authentication.md
  • references/custom-domains-routing.md
  • references/deployment.md
  • references/governance.md
  • references/observability-analytics.md
  • references/observability-logging.md
  • references/observability-metrics-alarms.md
  • references/performance-scaling.md
  • references/pitfalls.md
  • references/requirements-gathering.md
  • references/sam-cloudformation.md
  • references/sam-service-integrations.md
  • references/security.md
  • references/service-integrations.md
  • references/service-limits.md
  • references/troubleshooting.md
  • references/websocket.md

Open the folder on GitHubat commit da51970

Compare with similar skills

API Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Gateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Gateway this skillawslabs/agent-plugins912—~4.9kAutomated safety check: PassApache-2.0
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Detecting Shadow API Endpointsmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Deploying Custom Domain REST APIaws/agent-toolkit-for-aws2.8k—~4.8kAutomated safety check: PassApache-2.0
Connecting Lambda To API Gatewayaws/agent-toolkit-for-aws2.8k—~422Automated safety check: PassApache-2.0
Ak Cloud Deployyaalalabs/agent-kernel191—~14kAutomated safety check: PassApache-2.0

Similar skills

  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Detecting Shadow API Endpoints

    mukul975/Anthropic-Cybersecurity-Skills

    Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Deploying Custom Domain REST API

    aws/agent-toolkit-for-aws

    Official

    Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.

    2.8k GitHub stars~4.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Connecting Lambda To API Gateway

    aws/agent-toolkit-for-aws

    Official

    Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration, permissions, and deployment.

    2.8k GitHub stars~422 tokensUpdated today
    Backend & APIsAuto-check passed
  • Ak Cloud Deploy

    yaalalabs/agent-kernel

    Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.

    191 GitHub stars~14k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed

More from awslabs/agent-plugins

All 33 skills in this repo
  • Dataset Evaluation

    awslabs/agent-plugins

    Official

    Validates dataset formatting and quality for SageMaker model fine-tuning (SFT, DPO, or RLVR).

    912 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Dataset Transformation

    awslabs/agent-plugins

    Official

    Generates code that transforms datasets between ML schemas for model training or evaluation.

    912 GitHub starsUsed in 2 repos~3.5k tokens
    Auto-check passed
  • Finetuning Technique

    awslabs/agent-plugins

    Official

    Selects a fine-tuning technique (SFT, DPO, RLVR, or RLAIF) for the user's use case and validates it against the selected model's available recipes.

    912 GitHub starsUsed in 1 repo~604 tokens
    Auto-check passed
  • AWS Lambda Managed Instances

    awslabs/agent-plugins

    Official

    Evaluate, configure, and migrate workloads to AWS Lambda Managed Instances (LMI).

    912 GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Hyperpod Issue Report

    awslabs/agent-plugins

    Official

    Generate comprehensive issue reports from HyperPod clusters (EKS and Slurm) by collecting diagnostic logs and configurations for troubleshooting and AWS Support cases.

    912 GitHub stars~890 tokensUpdated yesterday
    Auto-check passed
  • Hyperpod Performance Debugger

    awslabs/agent-plugins

    Official

    Diagnose performance issues on Amazon SageMaker HyperPod clusters — uneven NCCL bandwidth across nodes and poor filesystem throughput.

    912 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about API Gateway

What does API Gateway do?

Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket). API Gateway is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).

When should I use API Gateway?

API Gateway fits situations like: phrases like: API Gateway; lambda authorizer.

How do I install API Gateway in Claude Code?

Run `npx skills add awslabs/agent-plugins --skill api-gateway -a claude-code`. Or copy the skill folder (plugins/aws-serverless/skills/api-gateway in awslabs/agent-plugins) into .claude/skills/api-gateway in your project. Claude Code loads it when a task matches its description.

How do I install API Gateway in Codex?

Run `npx skills add awslabs/agent-plugins --skill api-gateway -a codex`. Or copy the skill folder (plugins/aws-serverless/skills/api-gateway in awslabs/agent-plugins) into .agents/skills/api-gateway in your project. Codex loads it when a task matches its description.

Can I use API Gateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awslabs/agent-plugins --skill api-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-gateway, .gemini/skills/api-gateway, .github/skills/api-gateway and .opencode/skills/api-gateway in your project.

What does API Gateway need to run?

SKILL.md names no scripts, command-line tools or credentials: API Gateway is instructions for the agent only.

Does API Gateway access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is API Gateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Gateway use?

API Gateway is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Gateway use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 55k tokens, read only when the agent opens those files.

What are the alternatives to API Gateway?

Skills that share tags, products or a category with API Gateway: API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Detecting Shadow API Endpoints (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Deploying Custom Domain REST API (aws/agent-toolkit-for-aws, 2.8k stars) and Connecting Lambda To API Gateway (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Gateway?

awslabs (a GitHub organization, an official publisher) maintains it in awslabs/agent-plugins, which has 912 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 5, 2026.

Source: awslabs/agent-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.