Agent skill

REST API Expert

by cin12211 in cin12211/orca-q

REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation.

MITAuto-check passedBackend & APIs

Install REST API Expert

skills CLI
$ npx skills add cin12211/orca-q --skill rest-api-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cin12211/orca-q rest-api-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cin12211/orca-q.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agent/skills/rest-api-expert .claude/skills/rest-api-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rest-api-expert
GitHub stars
224
Token cost
~3.2k tokens
SKILL.md length
434 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation.

  • Works in 4 steps: Identify the API design issue or… → Apply RESTful principles and best… → Consider backward compatibility and… → …
  • Tasks that involve REST APIs
  • SKILL.md covers When Invoked, Problem Playbooks, Code Review Checklist and Anti-Patterns to Avoid
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

REST API Expert is an agent skill from cin12211/orca-q. REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation. Use PROACTIVELY for API architecture decisions, endpoint design issues, HTTP status code selection, or API documentation needs.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs, Technical documentation and OpenAPI specifications. It works with OpenAPI. The repository describes itself as: The open source | Next Generation database editor. The licence is MIT.

When your agent uses it

  • Tasks that involve REST APIs
  • Tasks that involve Technical documentation
  • Tasks that involve OpenAPI specifications

Example prompts

  • “/rest-api-expert”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the API design issue or requirement
  2. Apply RESTful principles and best practices
  3. Consider backward compatibility and versioning
  4. Validate with appropriate testing

What it can do on your machine

Read from SKILL.md and the folder at commit 3142fe6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • restfulapi.net
    • ics.uci.edu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

REST API Expert loads about 3.2k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 434 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cin12211/orca-q at commit 3142fe6, republished under its MIT licence (© cin12211). 434 words, ~3,195 tokens.

Download SKILL.mdSave it as .claude/skills/rest-api-expert/SKILL.md (or your agent's skills folder).
name
rest-api-expert
description
REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation. Use PROACTIVELY for API architecture decisions, endpoint design issues, HTTP status code selection, or API documentation needs.

REST API Expert

You are an expert in REST API design and development with deep knowledge of HTTP semantics, resource modeling, versioning strategies, error handling, and API documentation.

When Invoked

Step 0: Recommend Specialist and Stop

If the issue is specifically about:

  • GraphQL APIs: Stop and consider GraphQL patterns
  • gRPC/Protocol Buffers: Stop and recommend appropriate expert
  • Authentication implementation: Stop and recommend auth-expert
  • Database query optimization: Stop and recommend database-expert
Environment Detection
bash
# Check for API framework
grep -r "express\|fastify\|koa\|nestjs\|hono" package.json 2>/dev/null

# Check for OpenAPI/Swagger
ls -la swagger.* openapi.* 2>/dev/null
find . -name "*.yaml" -o -name "*.json" | xargs grep -l "openapi" 2>/dev/null | head -3

# Check existing API routes
find . -type f \( -name "*.ts" -o -name "*.js" \) -path "*/routes/*" -o -path "*/controllers/*" | head -10
Apply Strategy
  1. Identify the API design issue or requirement
  2. Apply RESTful principles and best practices
  3. Consider backward compatibility and versioning
  4. Validate with appropriate testing

Problem Playbooks

Endpoint Design

Common Issues:

  • Non-RESTful URL patterns (verbs in URLs)
  • Inconsistent naming conventions
  • Poor resource hierarchy
  • Missing or unclear resource relationships

Prioritized Fixes:

  1. Minimal: Rename endpoints to use nouns, not verbs
  2. Better: Restructure to proper resource hierarchy
  3. Complete: Implement full HATEOAS with links

RESTful URL Design:

typescript
// ❌ BAD: Verb-based endpoints
GET    /getUsers
POST   /createUser
PUT    /updateUser/123
DELETE /deleteUser/123
GET    /getUserOrders/123

// ✅ GOOD: Resource-based endpoints
GET    /users              # List users
POST   /users              # Create user
GET    /users/123          # Get user
PUT    /users/123          # Update user (full)
PATCH  /users/123          # Update user (partial)
DELETE /users/123          # Delete user
GET    /users/123/orders   # User's orders (nested resource)

// ✅ GOOD: Filtering, sorting, pagination
GET    /users?status=active&sort=-createdAt&page=2&limit=20

// ✅ GOOD: Search as sub-resource
GET    /users/search?q=john&fields=name,email

// ✅ GOOD: Actions as sub-resources (when needed)
POST   /users/123/activate    # Action on resource
POST   /orders/456/cancel     # State transition

Resources:

HTTP Methods & Status Codes

Common Issues:

  • Using GET for state-changing operations
  • Inconsistent status code usage
  • Missing appropriate error codes
  • Ignoring idempotency

HTTP Methods Semantics:

typescript
// Method characteristics
// GET     - Safe, Idempotent, Cacheable
// POST    - Not Safe, Not Idempotent
// PUT     - Not Safe, Idempotent
// PATCH   - Not Safe, Not Idempotent
// DELETE  - Not Safe, Idempotent

// Express example with proper methods
import { Router } from 'express';

const router = Router();

// GET - Retrieve resources (safe, idempotent)
router.get('/products', listProducts);
router.get('/products/:id', getProduct);

// POST - Create resources (not idempotent)
router.post('/products', createProduct);

// PUT - Replace entire resource (idempotent)
router.put('/products/:id', replaceProduct);

// PATCH - Partial update (not idempotent typically)
router.patch('/products/:id', updateProduct);

// DELETE - Remove resource (idempotent)
router.delete('/products/:id', deleteProduct);

Status Code Guide:

typescript
// 2xx Success
200 OK              // GET success, PUT/PATCH success with body
201 Created         // POST success (include Location header)
204 No Content      // DELETE success, PUT/PATCH success without body

// 3xx Redirection
301 Moved Permanently  // Resource URL changed permanently
304 Not Modified       // Cached response is still valid

// 4xx Client Errors
400 Bad Request     // Invalid request body/params
401 Unauthorized    // Missing or invalid authentication
403 Forbidden       // Authenticated but not authorized
404 Not Found       // Resource doesn't exist
405 Method Not Allowed  // HTTP method not supported
409 Conflict        // State conflict (e.g., duplicate)
422 Unprocessable Entity  // Validation errors
429 Too Many Requests    // Rate limit exceeded

// 5xx Server Errors
500 Internal Server Error  // Unexpected server error
502 Bad Gateway           // Upstream service error
503 Service Unavailable   // Temporary overload/maintenance
Error Handling

Common Issues:

  • Inconsistent error response formats
  • Exposing internal error details
  • Missing error codes for client handling
  • No error documentation

Standard Error Response Format:

typescript
// Error response structure
interface ApiError {
  status: number;          // HTTP status code
  code: string;            // Application-specific error code
  message: string;         // Human-readable message
  details?: ErrorDetail[]; // Field-level errors (for validation)
  requestId?: string;      // For debugging/support
  timestamp?: string;      // ISO 8601
}

interface ErrorDetail {
  field: string;
  message: string;
  code: string;
}

// Example responses
// 400 Bad Request - Validation Error
{
  "status": 400,
  "code": "VALIDATION_ERROR",
  "message": "Request validation failed",
  "details": [
    { "field": "email", "message": "Invalid email format", "code": "INVALID_EMAIL" },
    { "field": "age", "message": "Must be at least 18", "code": "MIN_VALUE" }
  ],
  "requestId": "req_abc123",
  "timestamp": "2024-01-15T10:30:00Z"
}

// 404 Not Found
{
  "status": 404,
  "code": "RESOURCE_NOT_FOUND",
  "message": "User with ID '123' not found",
  "requestId": "req_def456",
  "timestamp": "2024-01-15T10:30:00Z"
}

// 500 Internal Server Error
{
  "status": 500,
  "code": "INTERNAL_ERROR",
  "message": "An unexpected error occurred. Please try again later.",
  "requestId": "req_ghi789",
  "timestamp": "2024-01-15T10:30:00Z"
}

Error Handling Middleware:

typescript
// Express error handler
import { Request, Response, NextFunction } from 'express';

class AppError extends Error {
  constructor(
    public status: number,
    public code: string,
    message: string,
    public details?: ErrorDetail[]
  ) {
    super(message);
  }
}

function errorHandler(
  err: Error,
  req: Request,
  res: Response,
  next: NextFunction
) {
  const requestId = req.headers['x-request-id'] || generateRequestId();
  
  if (err instanceof AppError) {
    return res.status(err.status).json({
      status: err.status,
      code: err.code,
      message: err.message,
      details: err.details,
      requestId,
      timestamp: new Date().toISOString(),
    });
  }
  
  // Log unexpected errors
  console.error('Unexpected error:', err);
  
  // Don't expose internal errors to clients
  return res.status(500).json({
    status: 500,
    code: 'INTERNAL_ERROR',
    message: 'An unexpected error occurred',
    requestId,
    timestamp: new Date().toISOString(),
  });
}
Pagination

Common Issues:

  • Inconsistent pagination parameters
  • Missing total count for UI
  • No cursor-based option for large datasets
  • Performance issues with offset pagination

Pagination Strategies:

typescript
// 1. Offset-based pagination (simple, but slow for large offsets)
GET /products?page=2&limit=20

{
  "data": [...],
  "pagination": {
    "page": 2,
    "limit": 20,
    "total": 150,
    "totalPages": 8,
    "hasNext": true,
    "hasPrev": true
  }
}

// 2. Cursor-based pagination (efficient for large datasets)
GET /products?cursor=eyJpZCI6MTAwfQ&limit=20

{
  "data": [...],
  "pagination": {
    "limit": 20,
    "nextCursor": "eyJpZCI6MTIwfQ",
    "prevCursor": "eyJpZCI6ODB9",
    "hasNext": true,
    "hasPrev": true
  }
}

// Implementation example
async function paginateWithCursor(
  cursor: string | null,
  limit: number = 20
) {
  const decodedCursor = cursor 
    ? JSON.parse(Buffer.from(cursor, 'base64').toString())
    : null;
    
  const items = await prisma.product.findMany({
    take: limit + 1, // Fetch one extra to check hasNext
    cursor: decodedCursor ? { id: decodedCursor.id } : undefined,
    skip: decodedCursor ? 1 : 0,
    orderBy: { id: 'asc' },
  });
  
  const hasNext = items.length > limit;
  const data = hasNext ? items.slice(0, -1) : items;
  
  return {
    data,
    pagination: {
      limit,
      nextCursor: hasNext 
        ? Buffer.from(JSON.stringify({ id: data[data.length - 1].id })).toString('base64')
        : null,
      hasNext,
    },
  };
}
API Versioning

Common Issues:

  • No versioning strategy
  • Breaking changes without version bump
  • Inconsistent versioning across endpoints
  • No deprecation communication

Versioning Strategies:

typescript
// 1. URL Path Versioning (recommended)
GET /api/v1/users
GET /api/v2/users

// Implementation
import { Router } from 'express';

const v1Router = Router();
const v2Router = Router();

// V1 routes
v1Router.get('/users', getUsersV1);

// V2 routes with breaking changes
v2Router.get('/users', getUsersV2);

app.use('/api/v1', v1Router);
app.use('/api/v2', v2Router);

// 2. Header Versioning
GET /api/users
Accept: application/vnd.myapi.v2+json

// 3. Query Parameter (not recommended for APIs)
GET /api/users?version=2

Deprecation Headers:

typescript
// Communicate deprecation
res.setHeader('Deprecation', 'true');
res.setHeader('Sunset', 'Sat, 01 Jun 2025 00:00:00 GMT');
res.setHeader('Link', '</api/v2/users>; rel="successor-version"');
Show full SKILL.md (179 more words)Show less
Request/Response Design

Common Issues:

  • Inconsistent field naming (camelCase vs snake_case)
  • Missing content type headers
  • No request validation
  • Overly verbose responses

Request/Response Best Practices:

typescript
// Consistent naming convention (pick one, stick to it)
// JavaScript/TypeScript typically uses camelCase

// Request validation with Zod
import { z } from 'zod';

const CreateUserSchema = z.object({
  email: z.string().email(),
  name: z.string().min(2).max(100),
  age: z.number().int().min(18).optional(),
  role: z.enum(['user', 'admin']).default('user'),
});

// Validate in middleware
function validate(schema: z.ZodSchema) {
  return (req: Request, res: Response, next: NextFunction) => {
    try {
      req.body = schema.parse(req.body);
      next();
    } catch (error) {
      if (error instanceof z.ZodError) {
        return res.status(400).json({
          status: 400,
          code: 'VALIDATION_ERROR',
          message: 'Request validation failed',
          details: error.errors.map(e => ({
            field: e.path.join('.'),
            message: e.message,
            code: e.code,
          })),
        });
      }
      next(error);
    }
  };
}

// Response envelope for consistency
interface ApiResponse<T> {
  data: T;
  meta?: {
    pagination?: PaginationInfo;
    [key: string]: any;
  };
}

// Partial responses (field selection)
GET /users/123?fields=id,name,email

Code Review Checklist

Endpoint Design
  • URLs use nouns, not verbs
  • Consistent naming convention (kebab-case or snake_case)
  • Proper resource hierarchy
  • No deeply nested resources (max 2 levels)
HTTP Semantics
  • Correct HTTP methods for operations
  • Appropriate status codes
  • Idempotency for PUT/DELETE
  • Safe methods (GET) don't modify state
Error Handling
  • Consistent error response format
  • Meaningful error codes
  • Validation errors include field details
  • No internal errors exposed to clients
Performance
  • Pagination for list endpoints
  • Field selection supported
  • Appropriate caching headers
  • Rate limiting implemented
Documentation
  • OpenAPI/Swagger spec up to date
  • Examples for all endpoints
  • Error codes documented
  • Deprecation warnings for old versions

Anti-Patterns to Avoid

  1. RPC-style URLs: /createUser, /updateProduct → Use nouns with HTTP methods
  2. Ignoring HTTP Semantics: Using POST for everything
  3. Exposing Internal IDs: Use UUIDs or opaque IDs instead of auto-increment
  4. Overfetching: Return only requested/needed fields
  5. Version in Response Body: Version in URL is cleaner
  6. Tight Coupling: API should be independent of frontend implementation

© cin12211, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agent/skills/rest-api-expert of cin12211/orca-q.

Open the folder on GitHubat commit 3142fe6

Compare with similar skills

REST API Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

REST API Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
REST API Expert this skillcin12211/orca-q224—~3.2kAutomated safety check: PassMIT
API Documenteralirezarezvani/claude-code-tresor777—~1.5kAutomated safety check: PassMIT
OpenAPI Spec Generationwshobson/agents40k10 repos~511Automated safety check: PassMIT
Document API Endpointgetsentry/skills1k—~1.1kAutomated safety check: PassApache-2.0
Spring Boot Openapi Documentationgiuseppe-trisciuoglio/developer-kit3551 repos~2.6kAutomated safety check: NotesMIT
REST API Designcuriositech/some_claude_skills2431 repos~3.1kAutomated safety check: PassMIT

Similar skills

  • API Documenter

    alirezarezvani/claude-code-tresor

    Auto-generate API documentation from code and comments. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Create, validate and maintain OpenAPI 3.1 specs for REST APIs, whether designed first or generated from existing code, and use them for docs and client SDKs.

    40k GitHub starsUsed in 10 repos~511 tokens
    Backend & APIsAuto-check passed
  • Document API Endpoint

    getsentry/skills

    Official

    Document and type a Sentry API endpoint. An agent skill from getsentry/skills.

    1k GitHub stars~1.1k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Spring Boot Openapi Documentation

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to generate comprehensive REST API documentation using SpringDoc OpenAPI 3.0 and Swagger UI in Spring Boot 3.x applications.

    355 GitHub starsUsed in 1 repo~2.6k tokens
    Backend & APIsAuto-check: notes
  • REST API Design

    curiositech/some_claude_skills

    Design REST API endpoints with Zod validation and OpenAPI documentation.

    243 GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • API Reference Documentation

    secondsky/claude-skills

    Creates professional API documentation using OpenAPI specifications with endpoints, authentication, and interactive examples.

    227 GitHub starsUsed in 1 repo~561 tokens
    Backend & APIsAuto-check passed

More from cin12211/orca-q

All 16 skills in this repo
  • Typescript Expert

    cin12211/orca-q

    TypeScript and JavaScript expert with deep knowledge of type-level programming, performance optimization, monorepo management, migration strategies, and modern tooling.

    224 GitHub starsUsed in 12 repos~3.7k tokens
    Auto-check passed
  • Database Expert

    cin12211/orca-q

    Database performance optimization, schema design, query analysis, and connection management across PostgreSQL, MySQL, MongoDB, and SQLite with ORM integration.

    224 GitHub stars~2.8k tokensUpdated 16 days ago
    Auto-check passed
  • Playwright Expert

    cin12211/orca-q

    Playwright E2E testing expert for browser automation, cross-browser testing, visual regression, network interception, and CI integration.

    224 GitHub stars~1.3k tokensUpdated 16 days ago
    Auto-check passed
  • Research Expert

    cin12211/orca-q

    Specialized research expert for parallel information gathering.

    224 GitHub stars~2k tokensUpdated 16 days ago
    Auto-check passed
  • Testing Orcaq

    cin12211/orca-q

    OrcaQ-specific testing guide. An agent skill from cin12211/orca-q.

    224 GitHub stars~1.6k tokensUpdated 16 days ago
    Auto-check passed
  • Postgres Expert

    cin12211/orca-q

    PostgreSQL query optimization, JSONB operations, advanced indexing strategies, partitioning, connection management, and database administration.

    224 GitHub stars~5.5k tokensUpdated 16 days ago
    Auto-check passed

Works with

Categories

Questions about REST API Expert

What does REST API Expert do?

REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation. REST API Expert is an agent skill from cin12211/orca-q. REST API design and development expert specializing in endpoint design, HTTP semantics, versioning, error handling, pagination, and OpenAPI documentation.

When should I use REST API Expert?

REST API Expert fits situations like: tasks that involve REST APIs; tasks that involve Technical documentation; tasks that involve OpenAPI specifications.

How do I install REST API Expert in Claude Code?

Run `npx skills add cin12211/orca-q --skill rest-api-expert -a claude-code`. Or copy the skill folder (.agent/skills/rest-api-expert in cin12211/orca-q) into .claude/skills/rest-api-expert in your project. Claude Code loads it when a task matches its description.

How do I install REST API Expert in Codex?

Run `npx skills add cin12211/orca-q --skill rest-api-expert -a codex`. Or copy the skill folder (.agent/skills/rest-api-expert in cin12211/orca-q) into .agents/skills/rest-api-expert in your project. Codex loads it when a task matches its description.

Can I use REST API Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cin12211/orca-q --skill rest-api-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rest-api-expert, .gemini/skills/rest-api-expert, .github/skills/rest-api-expert and .opencode/skills/rest-api-expert in your project.

What does REST API Expert need to run?

SKILL.md names no scripts, command-line tools or credentials: REST API Expert is instructions for the agent only.

Does REST API Expert access the network?

SKILL.md names 2 domains. As links in the text: restfulapi.net and ics.uci.edu. This is read from the text; nothing was executed.

Is REST API Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does REST API Expert use?

REST API Expert is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does REST API Expert use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to REST API Expert?

Skills that share tags, products or a category with REST API Expert: API Documenter (alirezarezvani/claude-code-tresor, 777 stars), OpenAPI Spec Generation (wshobson/agents, 40k stars), Document API Endpoint (getsentry/skills, 1k stars) and Spring Boot Openapi Documentation (giuseppe-trisciuoglio/developer-kit, 355 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains REST API Expert?

cin12211 (a GitHub user) maintains it in cin12211/orca-q, which has 224 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on September 21, 2026.

Source: cin12211/orca-q on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.