Agent skill

Cb Realtime API

by BlkLeg in BlkLeg/CircuitBreaker

How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

MITAuto-check passedBackend & APIs

Install Cb Realtime API

skills CLI
$ npx skills add BlkLeg/CircuitBreaker --skill cb-realtime-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BlkLeg/CircuitBreaker cb-realtime-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-realtime-api .claude/skills/cb-realtime-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cb-realtime-api
GitHub stars
201
Token cost
~1.7k tokens
SKILL.md length
719 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

  • Works in 4 steps: Client connects. → Client sends the JWT as the first text… → Server validates, checks session… → …
  • Tasks that involve Realtime and WebSockets
  • SKILL.md covers The transports, and which one…, NATS subjects are constants,…, WebSocket endpoints share one… and Frontend stream hooks, plus 1 more section
  • Needs NATS_AUTH_TOKEN

What it does

Cb Realtime API is an agent skill from BlkLeg/CircuitBreaker. How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and the axios API client. Use this whenever adding or changing a WebSocket or SSE endpoint, publishing or subscribing to a NATS subject, wiring a React hook to live data, adding or renaming a REST endpoint or response field, debugging a stream that will not connect or reconnect, or auditing whether the frontend and backend…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Realtime and WebSockets, API design and Event-driven systems. It works with Redis. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.

When your agent uses it

  • Tasks that involve Realtime and WebSockets
  • Tasks that involve API design
  • Tasks that involve Event-driven systems

Example prompts

  • “/cb-realtime-api”

Requirements

  • Python 3
  • Docker
  • A credential in NATS_AUTH_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Client connects.
  2. Client sends the JWT as the first text message, raw — not a header, not JSON.
  3. Server validates, checks session revocation, and replies {"status": "connected"}.
  4. Only then do events flow.

What it can do on your machine

Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, json and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NATS_AUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cb Realtime API loads about 1.7k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 719 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 719 words, ~1,699 tokens.

Download SKILL.mdSave it as .claude/skills/cb-realtime-api/SKILL.md (or your agent's skills folder).
name
cb-realtime-api
description
How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and the axios API client. Use this whenever adding or changing a WebSocket or SSE endpoint, publishing or subscribing to a NATS subject, wiring a React hook to live data, adding or renaming a REST endpoint or response field, debugging a stream that will not connect or reconnect, or auditing whether the frontend and backend still agree on an API contract.

Circuit Breaker — Realtime & API Contract

The transports, and which one to reach for

Three mechanisms, each with a job. Picking the wrong one is the most common mistake here, so start from the question "who needs this, and when?"

TransportUse it forWhere
NATSBackend-internal fan-out between API, workers, and agentscore/nats_client.py, subjects in core/subjects.py
Redis pub/subBacking store for WS push; last-value cachecore/redis.py
WebSocketBidirectional browser streams where the client subscribesapi/ws_*.py
SSEOne-way server→browser append streams (logs, events)api/events.py, api/logs.py
RESTEverything elseapi/*.py ↔ apps/frontend/src/api/*.js

NATS is the internal bus and never reaches the browser directly. A worker publishes to a subject; the API process subscribes and relays to connected sockets. Authentication is NATS_AUTH_TOKEN, which docker-compose.yml requires with :? — there is no unauthenticated bus.

NATS subjects are constants, not strings

Every subject lives in app/core/subjects.py under <domain>.<entity>.<event>:

python
from app.core.subjects import DISCOVERY_SCAN_PROGRESS, TELEMETRY_INGEST

await nats.publish(DISCOVERY_SCAN_PROGRESS, {"scan_id": scan_id, "pct": 42})
await nats.publish(TELEMETRY_INGEST.format(hardware_id=hw.id), payload)

Import the constant rather than typing the string. A hard-coded subject is invisible to the subscriber side when someone renames an event, and the failure mode is silent: the publish succeeds, nobody is listening, and the feature just stops updating. Subjects with {...} placeholders are formatted at publish time and have a matching .> wildcard for subscribers.

NatsClient.publish buffers on failure and resubscribes registered subjects after a reconnect, so a dropped bus recovers on its own. Do not add retry loops around it.

WebSocket endpoints share one auth handshake

Five streams, all mounted at /stream under their router prefix:

WS /api/v1/discovery/stream   ws_discovery.py
WS /api/v1/telemetry/stream   ws_telemetry.py
WS /api/v1/topology/stream    ws_topology.py
WS /api/v1/monitors/stream    ws_monitors.py
WS /api/v1/agents/stream      ws_agents.py

All five are mounted with Depends(require_auth) in main.py. The agent /enroll and /link sockets are the one router mounted without it, because their Noise IK handshake is the authentication — that exception is deliberate and documented at the mount site.

The handshake is identical everywhere, and new streams must match it:

  1. Client connects.
  2. Client sends the JWT as the first text message, raw — not a header, not JSON.
  3. Server validates, checks session revocation, and replies {"status": "connected"}.
  4. Only then do events flow.

Server-side that means token_from_websocket_scope, decode_token, is_session_revoked, and ws_require_wss from core/auth_cookie.py and core/security.py. There is no anonymous path — see the cb-security-hardening skill, which treats a WS handler without JWT validation as a security defect.

Policy rejections close with 1008 and an {"error": "..."} frame (unauthorized, auth_timeout, subscription_limit_exceeded). This matters because the client uses the code to decide whether to retry: 1008 must not trigger reconnection, or a revoked session becomes a reconnect storm.

Subscription frames follow the ws_telemetry.py shape:

json
{"subscribe": [5, 12, 34]}    {"unsubscribe": [12]}    {"type": "ping"}

Cap total distinct channels per connection and reject overflow rather than letting one socket subscribe to everything.

Show full SKILL.md (303 more words)Show less

Frontend stream hooks

Hooks live in apps/frontend/src/hooks/*.js — useDiscoveryStream, useTelemetryStream, useAgentLive, useConnectionState. Read useDiscoveryStream.js before writing a new one; its header documents the contract and it is the reference implementation.

Established behavior worth preserving:

  • One connection, mounted once at the app root (App.jsx), not per page — it must survive navigation, and per-component sockets multiply silently.
  • Exponential backoff starting at 2s, capped at 30s.
  • Never reconnect after 1008 / auth_timeout — the credential is the problem, and retrying only burns the server.
  • Application-level ping/pong both directions, so either side detects a half-open link that TCP still believes is alive.

Redis being unavailable degrades a stream to "connected but silent"; the client falls back to REST polling. Keep that path working rather than failing the socket outright.

REST contract between the two halves

Backend  : apps/backend/src/app/api/*.py
Frontend : apps/frontend/src/api/*.js     (axios, via client.jsx)

The frontend never calls fetch inline. api/client.jsx is the single axios instance and it already handles 401 session expiry, 422 field-error extraction into {field: message}, 5xx user-facing messages, and server clock recording. A new endpoint gets a function in the matching api/*.js module so every caller inherits that behavior.

API conventions: snake_case JSON both directions, errors as {"detail": "message"}, and 422 validation errors as the FastAPI array shape that extractFieldErrors already understands.

Auditing for drift

When OOBE breaks or a page renders empty fields, the usual cause is a schema that moved without its caller. Compare the two sides directly:

bash
grep -rhoE "'/[a-z0-9/_{}-]+'" apps/frontend/src/api/*.js | sort -u
grep -rhoE '@router\.(get|post|put|patch|delete)\("[^"]+"' apps/backend/src/app/api/*.py | sort -u

Report gaps as a table, then fix backend-first — schema, then service, then route, then the frontend module — so the frontend is never written against an endpoint that does not exist yet:

Frontend callBackend endpointGapFix

Changing a response field is a breaking change. Add the new field alongside the old one and migrate callers rather than renaming in place; self-hosted users upgrade on their own schedule and a half-updated deployment should still work.

© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cb-realtime-api of BlkLeg/CircuitBreaker.

Open the folder on GitHubat commit fc44f2e

Compare with similar skills

Cb Realtime API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cb Realtime API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cb Realtime API this skillBlkLeg/CircuitBreaker201—~1.7kAutomated safety check: PassMIT
Centrifugopedronauck/skills634—~3.1kAutomated safety check: PassNone
API Conventionshuangjia2019/claude-code-engineering1.1k1 repos~398Automated safety check: PassNone
WooCommerce Store API Routeswoocommerce/woocommerce11k—~932Automated safety check: PassCustom licence
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
Domain Webfjrevoredo/mini-diarium3081 repos~1kAutomated safety check: PassMIT

Similar skills

  • Centrifugo

    pedronauck/skills

    Centrifugo real-time messaging server expert for WebSocket PUB/SUB, channel management, JWT authentication, event proxying, and horizontal scaling with Redis/NATS.

    634 GitHub stars~3.1k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • API Conventions

    huangjia2019/claude-code-engineering

    API design patterns and conventions for this project. An agent skill from huangjia2019/claude-code-engineering.

    1.1k GitHub starsUsed in 1 repo~398 tokens
    Backend & APIsAuto-check passed
  • WooCommerce Store API Routes

    woocommerce/woocommerce

    Guidelines for adding or changing routes in the WooCommerce Store API under /wc/store/v1, covering authentication, REST design, schemas and variations.

    11k GitHub stars~932 tokensUpdated today
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Domain Web

    fjrevoredo/mini-diarium

    A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.

    308 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check passed
  • Project Map

    gjovanovicst/golang-auth-api

    Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

    130 GitHub stars~2.6k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from BlkLeg/CircuitBreaker

  • Cb Build Test

    BlkLeg/CircuitBreaker

    How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…

    201 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Cb Release

    BlkLeg/CircuitBreaker

    How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…

    201 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 3 days ago
    Auto-check passed
  • Cb Automation

    BlkLeg/CircuitBreaker

    The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…

    201 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Cb Realtime API

What does Cb Realtime API do?

How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…. Cb Realtime API is an agent skill from BlkLeg/CircuitBreaker. How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and the axios API client.

When should I use Cb Realtime API?

Cb Realtime API fits situations like: tasks that involve Realtime and WebSockets; tasks that involve API design; tasks that involve Event-driven systems.

How do I install Cb Realtime API in Claude Code?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-realtime-api -a claude-code`. Or copy the skill folder (.claude/skills/cb-realtime-api in BlkLeg/CircuitBreaker) into .claude/skills/cb-realtime-api in your project. Claude Code loads it when a task matches its description.

How do I install Cb Realtime API in Codex?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-realtime-api -a codex`. Or copy the skill folder (.claude/skills/cb-realtime-api in BlkLeg/CircuitBreaker) into .agents/skills/cb-realtime-api in your project. Codex loads it when a task matches its description.

Can I use Cb Realtime API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-realtime-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-realtime-api, .gemini/skills/cb-realtime-api, .github/skills/cb-realtime-api and .opencode/skills/cb-realtime-api in your project.

What does Cb Realtime API need to run?

Going by SKILL.md and its folder, Cb Realtime API needs credentials named NATS_AUTH_TOKEN. Our summary lists: Python 3; Docker; A credential in NATS_AUTH_TOKEN.

Does Cb Realtime API access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cb Realtime API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cb Realtime API use?

Cb Realtime API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cb Realtime API use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cb Realtime API?

Skills that share tags, products or a category with Cb Realtime API: Centrifugo (pedronauck/skills, 634 stars), API Conventions (huangjia2019/claude-code-engineering, 1.1k stars), WooCommerce Store API Routes (woocommerce/woocommerce, 11k stars) and Discover API (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cb Realtime API?

BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.