Agent skill

Route Tester

by blencorp in blencorp/claude-code-kit

Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices.

MITAuto-check passedBackend & APIs

Install Route Tester

skills CLI
$ npx skills add blencorp/claude-code-kit --skill route-tester -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blencorp/claude-code-kit route-tester --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blencorp/claude-code-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli/core/skills/route-tester .claude/skills/route-tester && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
route-tester
GitHub stars
106
Token cost
~3k tokens
SKILL.md length
332 words
Files
5
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices.

  • Works in 6 steps: Test Types for API Routes → Authentication Testing Patterns → HTTP Method Testing → …
  • Tasks that involve Authentication
  • SKILL.md covers Core Testing Principles, Framework-Specific Testing…, Best Practices and Common Pitfalls, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Route Tester is an agent skill from blencorp/claude-code-kit. Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices. Supports REST APIs with JWT cookie authentication and other common auth patterns.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `resources/api-integration-testing.md`, `resources/authentication-testing.md` and `resources/http-testing-fundamentals.md`).

It sits in Backend & APIs, covering Authentication, REST APIs and Test strategy. The repository describes itself as: Claude Code infrastructure with auto-activating skills and framework-specific kits. Install complete Claude Code infrastructure in 30 seconds with automatic framework detection… The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve REST APIs
  • Tasks that involve Test strategy

Example prompts

  • “/route-tester”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Test Types for API Routes
  2. Authentication Testing Patterns
  3. HTTP Method Testing
  4. Response Validation
  5. Error Handling Tests
  6. Test Setup and Teardown

What it can do on your machine

Read from SKILL.md and the folder at commit d1b17ed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Route Tester loads about 3k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blencorp/claude-code-kit at commit d1b17ed, republished under its MIT licence (© blencorp). 332 words, ~2,989 tokens.

Download SKILL.mdSave it as .claude/skills/route-tester/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
route-tester
description
Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices. Supports REST APIs with JWT cookie authentication and other common auth patterns.
displayName
API Route Testing

API Route Testing Skill

This skill provides framework-agnostic guidance for testing HTTP API routes and endpoints across any backend framework (Express, Next.js API Routes, FastAPI, Django REST, Flask, etc.).

Core Testing Principles

1. Test Types for API Routes

Unit Tests

  • Test individual route handlers in isolation
  • Mock dependencies (database, external APIs)
  • Fast execution (< 50ms per test)
  • Focus on business logic

Integration Tests

  • Test full request/response cycle
  • Real database (test instance)
  • Authentication flow included
  • Slower but more comprehensive

End-to-End Tests

  • Test from client perspective
  • Full authentication flow
  • Real services (or close replicas)
  • Most realistic, slowest execution
2. Authentication Testing Patterns
typescript
// Common pattern across frameworks
describe('Protected Route Tests', () => {
  let authCookie: string;

  beforeEach(async () => {
    // Login and get JWT cookie
    const loginResponse = await request(app)
      .post('/api/auth/login')
      .send({ email: 'test@example.com', password: 'password123' });

    authCookie = loginResponse.headers['set-cookie'][0];
  });

  it('should access protected route with valid cookie', async () => {
    const response = await request(app)
      .get('/api/protected/resource')
      .set('Cookie', authCookie);

    expect(response.status).toBe(200);
  });

  it('should reject access without cookie', async () => {
    const response = await request(app)
      .get('/api/protected/resource');

    expect(response.status).toBe(401);
  });
});
JWT Bearer Token Authentication
typescript
describe('Bearer Token Auth', () => {
  let token: string;

  beforeEach(async () => {
    const response = await request(app)
      .post('/api/auth/login')
      .send({ email: 'test@example.com', password: 'password123' });

    token = response.body.token;
  });

  it('should authenticate with bearer token', async () => {
    const response = await request(app)
      .get('/api/protected/resource')
      .set('Authorization', `Bearer ${token}`);

    expect(response.status).toBe(200);
  });
});
3. HTTP Method Testing

GET Requests

typescript
describe('GET /api/users', () => {
  it('should return paginated users', async () => {
    const response = await request(app)
      .get('/api/users?page=1&limit=10');

    expect(response.status).toBe(200);
    expect(response.body).toHaveProperty('data');
    expect(response.body).toHaveProperty('pagination');
    expect(Array.isArray(response.body.data)).toBe(true);
  });

  it('should filter users by query params', async () => {
    const response = await request(app)
      .get('/api/users?role=admin');

    expect(response.status).toBe(200);
    expect(response.body.data.every(u => u.role === 'admin')).toBe(true);
  });
});

POST Requests

typescript
describe('POST /api/users', () => {
  it('should create new user with valid data', async () => {
    const newUser = {
      name: 'John Doe',
      email: 'john@example.com',
      role: 'user'
    };

    const response = await request(app)
      .post('/api/users')
      .set('Cookie', authCookie)
      .send(newUser);

    expect(response.status).toBe(201);
    expect(response.body).toMatchObject(newUser);
    expect(response.body).toHaveProperty('id');
  });

  it('should reject invalid data', async () => {
    const invalidUser = {
      name: 'John Doe'
      // Missing required email field
    };

    const response = await request(app)
      .post('/api/users')
      .set('Cookie', authCookie)
      .send(invalidUser);

    expect(response.status).toBe(400);
    expect(response.body).toHaveProperty('errors');
  });
});

PUT/PATCH Requests

typescript
describe('PATCH /api/users/:id', () => {
  it('should update user fields', async () => {
    const updates = { name: 'Jane Doe' };

    const response = await request(app)
      .patch('/api/users/123')
      .set('Cookie', authCookie)
      .send(updates);

    expect(response.status).toBe(200);
    expect(response.body.name).toBe('Jane Doe');
  });

  it('should return 404 for non-existent user', async () => {
    const response = await request(app)
      .patch('/api/users/999999')
      .set('Cookie', authCookie)
      .send({ name: 'Test' });

    expect(response.status).toBe(404);
  });
});

DELETE Requests

typescript
describe('DELETE /api/users/:id', () => {
  it('should delete user and return success', async () => {
    const response = await request(app)
      .delete('/api/users/123')
      .set('Cookie', authCookie);

    expect(response.status).toBe(204);
  });

  it('should prevent unauthorized deletion', async () => {
    const response = await request(app)
      .delete('/api/users/123');
      // No auth cookie

    expect(response.status).toBe(401);
  });
});
4. Response Validation

Status Codes

typescript
describe('HTTP Status Codes', () => {
  it('200 OK - Successful GET', async () => {
    const response = await request(app).get('/api/users');
    expect(response.status).toBe(200);
  });

  it('201 Created - Successful POST', async () => {
    const response = await request(app).post('/api/users').send(validData);
    expect(response.status).toBe(201);
  });

  it('204 No Content - Successful DELETE', async () => {
    const response = await request(app).delete('/api/users/123');
    expect(response.status).toBe(204);
  });

  it('400 Bad Request - Invalid input', async () => {
    const response = await request(app).post('/api/users').send({});
    expect(response.status).toBe(400);
  });

  it('401 Unauthorized - Missing auth', async () => {
    const response = await request(app).get('/api/protected');
    expect(response.status).toBe(401);
  });

  it('403 Forbidden - Insufficient permissions', async () => {
    const response = await request(app).delete('/api/admin/users/123').set('Cookie', userCookie);
    expect(response.status).toBe(403);
  });

  it('404 Not Found - Non-existent resource', async () => {
    const response = await request(app).get('/api/users/999999');
    expect(response.status).toBe(404);
  });

  it('500 Internal Server Error - Server failure', async () => {
    // Test error handling
    mockDatabase.findOne.mockRejectedValue(new Error('DB Error'));
    const response = await request(app).get('/api/users/123');
    expect(response.status).toBe(500);
  });
});

Response Schema Validation

typescript
describe('Response Schema', () => {
  it('should match expected schema', async () => {
    const response = await request(app).get('/api/users/123');

    expect(response.body).toEqual({
      id: expect.any(String),
      name: expect.any(String),
      email: expect.any(String),
      role: expect.stringMatching(/^(user|admin)$/),
      createdAt: expect.any(String),
      updatedAt: expect.any(String)
    });
  });
});
5. Error Handling Tests
typescript
describe('Error Handling', () => {
  it('should return structured error response', async () => {
    const response = await request(app)
      .post('/api/users')
      .send({ invalid: 'data' });

    expect(response.status).toBe(400);
    expect(response.body).toEqual({
      error: expect.any(String),
      message: expect.any(String),
      errors: expect.any(Array)
    });
  });

  it('should handle database errors gracefully', async () => {
    mockDatabase.findOne.mockRejectedValue(new Error('Connection lost'));

    const response = await request(app).get('/api/users/123');

    expect(response.status).toBe(500);
    expect(response.body.error).toBe('Internal Server Error');
  });

  it('should sanitize error messages in production', async () => {
    process.env.NODE_ENV = 'production';

    const response = await request(app).get('/api/error-prone-route');

    expect(response.status).toBe(500);
    expect(response.body.message).not.toContain('stack trace');
    expect(response.body.message).not.toContain('SQL');
  });
});
6. Test Setup and Teardown
typescript
describe('API Tests', () => {
  let testDatabase;

  beforeAll(async () => {
    // Initialize test database
    testDatabase = await initTestDatabase();
  });

  afterAll(async () => {
    // Clean up test database
    await testDatabase.close();
  });

  beforeEach(async () => {
    // Seed test data
    await testDatabase.seed();
  });

  afterEach(async () => {
    // Clear test data
    await testDatabase.clear();
  });

  // Tests...
});

Framework-Specific Testing Libraries

While this skill provides framework-agnostic patterns, here are common testing libraries per framework:

  • Express: supertest, jest, vitest
  • Next.js API Routes: @testing-library/react, next-test-api-route-handler
  • FastAPI: pytest, httpx
  • Django REST: django.test.TestCase, rest_framework.test
  • Flask: pytest, flask.testing

Best Practices

  1. Use descriptive test names - Test names should describe the scenario and expected outcome
  2. Test happy path and edge cases - Cover both success and failure scenarios
  3. Isolate tests - Each test should be independent and not rely on other tests
  4. Use realistic test data - Test data should mimic production data
  5. Clean up after tests - Always reset state between tests
  6. Mock external dependencies - Don't call real external APIs in tests
  7. Test authentication edge cases - Expired tokens, invalid tokens, missing tokens
  8. Validate response schemas - Ensure APIs return expected structure
  9. Test rate limiting - Verify rate limits work correctly
  10. Test CORS headers - Ensure CORS is configured correctly

Common Pitfalls

❌ Don't share state between tests

typescript
// Bad
let userId;
it('creates user', async () => {
  const response = await request(app).post('/api/users').send(userData);
  userId = response.body.id; // Shared state!
});

it('deletes user', async () => {
  await request(app).delete(`/api/users/${userId}`); // Depends on previous test
});

✅ Do create fresh state for each test

typescript
// Good
it('creates user', async () => {
  const response = await request(app).post('/api/users').send(userData);
  expect(response.status).toBe(201);
});

it('deletes user', async () => {
  const user = await createTestUser();
  const response = await request(app).delete(`/api/users/${user.id}`);
  expect(response.status).toBe(204);
});

Additional Resources

See the resources/ directory for more detailed guides:

  • http-testing-fundamentals.md - Deep dive into HTTP testing concepts
  • authentication-testing.md - Authentication strategies and edge cases
  • api-integration-testing.md - Integration testing patterns and tools

Quick Reference

Test Structure

typescript
describe('Resource Name', () => {
  describe('HTTP Method /path', () => {
    it('should describe expected behavior', async () => {
      // Arrange
      const testData = {...};

      // Act
      const response = await request(app)
        .method('/path')
        .set('Cookie', authCookie)
        .send(testData);

      // Assert
      expect(response.status).toBe(expectedStatus);
      expect(response.body).toMatchObject(expectedData);
    });
  });
});

Authentication Pattern

typescript
let authCookie: string;

beforeEach(async () => {
  const response = await request(app)
    .post('/api/auth/login')
    .send({ email: 'test@example.com', password: 'password123' });

  authCookie = response.headers['set-cookie'][0];
});

// Use authCookie in protected route tests
.set('Cookie', authCookie)

© blencorp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in cli/core/skills/route-tester of blencorp/claude-code-kit.

  • SKILL.md
  • resources/api-integration-testing.md
  • resources/authentication-testing.md
  • resources/http-testing-fundamentals.md
  • skill-rules-fragment.json

Open the folder on GitHubat commit d1b17ed

Compare with similar skills

Route Tester next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Route Tester compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Route Tester this skillblencorp/claude-code-kit106—~3kAutomated safety check: PassMIT
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Hybrid Cloud Test Gengetsentry/sentry46k—~2.6kAutomated safety check: PassCustom licence
API Patternsdilolabs/nosia2131 repos~2.5kAutomated safety check: PassMIT
Verify Authendpointsmadeyoga/AuthEndpoints121—~2.7kAutomated safety check: PassMIT
Nodejs Express Serverever-works/ever-works162—~965Automated safety check: PassAGPL-3.0

Similar skills

  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Hybrid Cloud Test Gen

    getsentry/sentry

    Official

    Generate hybrid cloud tests for the Sentry codebase. An agent skill from getsentry/sentry.

    46k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Patterns

    dilolabs/nosia

    Builds REST APIs using respondto blocks with Jbuilder templates following the 37signals same-controllers-different-formats philosophy.

    213 GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • Verify Authendpoints

    madeyoga/AuthEndpoints

    Drive the AuthEndpoints HTTP API via the in-repo test host (cookie sessions, Identity bearer, Simple JWT, CSRF, ReAuth).

    121 GitHub stars~2.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    162 GitHub stars~965 tokensUpdated today
    Backend & APIsAuto-check passed
  • API Debugging

    ownpilot/OwnPilot

    Systematic approach to debugging REST APIs, HTTP errors, authentication issues, and network problems.

    426 GitHub stars~824 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from blencorp/claude-code-kit

All 11 skills in this repo
  • Mui

    blencorp/claude-code-kit

    Material-UI v7 component library patterns including sx prop styling, theme integration, responsive design, and MUI-specific hooks.

    106 GitHub starsUsed in 2 repos~2.4k tokens
    Auto-check passed
  • Express

    blencorp/claude-code-kit

    Express.js framework patterns including routing, middleware, request/response handling, and Express-specific APIs.

    106 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Nextjs

    blencorp/claude-code-kit

    Next.js 15+ App Router development patterns including Server Components, Client Components, data fetching, layouts, and server actions.

    106 GitHub stars~2.6k tokensUpdated 10 mo ago
    Auto-check passed
  • Nodejs

    blencorp/claude-code-kit

    Core Node.js backend patterns for TypeScript applications including async/await error handling, middleware concepts, configuration management, testing strategies, and layered architecture principles.

    106 GitHub stars~2.6k tokensUpdated 10 mo ago
    Auto-check passed
  • Prisma

    blencorp/claude-code-kit

    Prisma ORM patterns including Prisma Client usage, queries, mutations, relations, transactions, and schema management.

    106 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed
  • React

    blencorp/claude-code-kit

    Core React 19 patterns including hooks, Suspense, lazy loading, component structure, TypeScript best practices, and performance optimization.

    106 GitHub stars~2.5k tokensUpdated 10 mo ago
    Auto-check passed

Categories

Questions about Route Tester

What does Route Tester do?

Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices. Route Tester is an agent skill from blencorp/claude-code-kit. Framework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices.

When should I use Route Tester?

Route Tester fits situations like: tasks that involve Authentication; tasks that involve REST APIs; tasks that involve Test strategy.

How do I install Route Tester in Claude Code?

Run `npx skills add blencorp/claude-code-kit --skill route-tester -a claude-code`. Or copy the skill folder (cli/core/skills/route-tester in blencorp/claude-code-kit) into .claude/skills/route-tester in your project. Claude Code loads it when a task matches its description.

How do I install Route Tester in Codex?

Run `npx skills add blencorp/claude-code-kit --skill route-tester -a codex`. Or copy the skill folder (cli/core/skills/route-tester in blencorp/claude-code-kit) into .agents/skills/route-tester in your project. Codex loads it when a task matches its description.

Can I use Route Tester in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blencorp/claude-code-kit --skill route-tester -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/route-tester, .gemini/skills/route-tester, .github/skills/route-tester and .opencode/skills/route-tester in your project.

What does Route Tester need to run?

SKILL.md names no scripts, command-line tools or credentials: Route Tester is instructions for the agent only.

Does Route Tester access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Route Tester safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Route Tester use?

Route Tester is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Route Tester use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Route Tester?

Skills that share tags, products or a category with Route Tester: Laravel Specialist (Jeffallan/claude-skills, 12k stars), Hybrid Cloud Test Gen (getsentry/sentry, 46k stars), API Patterns (dilolabs/nosia, 213 stars) and Verify Authendpoints (madeyoga/AuthEndpoints, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Route Tester?

blencorp (a GitHub organization) maintains it in blencorp/claude-code-kit, which has 106 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on November 28, 2025.

Source: blencorp/claude-code-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.