Agent skill

Designing APIs

by CloudAI-X in CloudAI-X/opencode-workflow

Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices.

MITAuto-check passedBackend & APIs

Install Designing APIs

skills CLI
$ npx skills add CloudAI-X/opencode-workflow --skill designing-apis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CloudAI-X/opencode-workflow designing-apis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/designing-apis .claude/skills/designing-apis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
designing-apis
GitHub stars
275
Token cost
~2.2k tokens
SKILL.md length
388 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices.

  • Works in 7 steps: Verbs in URLs - Use /users not /getUsers → Ignoring HTTP Methods - Use proper… → Inconsistent Naming - Pick snake_case or… → …
  • Designing endpoints
  • SKILL.md covers When to Use This Skill, REST API Design Principles, Request Design and Response Design, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Designing APIs is an agent skill from CloudAI-X/opencode-workflow. Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices. Use when building APIs, designing endpoints, or reviewing API contracts.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: opencode

It sits in Backend & APIs, covering GraphQL and API design. It works with GraphQL. The licence is MIT.

When your agent uses it

  • Designing endpoints
  • Reviewing API contracts

Example prompts

  • “Use the designing-apis skill to guide REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices”
  • “/designing-apis”

Requirements

  • Compatibility (from SKILL.md): opencode

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Verbs in URLs - Use /users not /getUsers
  2. Ignoring HTTP Methods - Use proper methods, not POST for everything
  3. Inconsistent Naming - Pick snake_case or camelCase, stick with it
  4. Leaking Implementation - Don't expose internal IDs or DB structure
  5. Missing Pagination - Always paginate collections
  6. Ignoring Idempotency - PUT/DELETE must be idempotent
  7. No Versioning - Plan for API evolution from day one

What it can do on your machine

Read from SKILL.md and the folder at commit 0128ca6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json, graphql and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Designing APIs loads about 2.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 388 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CloudAI-X/opencode-workflow at commit 0128ca6, republished under its MIT licence (© CloudAI-X). 388 words, ~2,243 tokens.

Download SKILL.mdSave it as .claude/skills/designing-apis/SKILL.md (or your agent's skills folder).
name
designing-apis
description
Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices. Use when building APIs, designing endpoints, or reviewing API contracts.
compatibility
opencode
license
MIT
metadata.category
design
metadata.audience
developers

Designing APIs

Principles and patterns for designing clean, consistent, and maintainable APIs.

When to Use This Skill

  • Designing new API endpoints
  • Reviewing API contracts
  • Planning API versioning strategies
  • Defining request/response schemas
  • Building GraphQL schemas
  • Documenting APIs

REST API Design Principles

Resource-Oriented Design

APIs should be organized around resources, not actions:

GOOD (Resource-oriented):
GET    /users           → List users
GET    /users/123       → Get user 123
POST   /users           → Create user
PUT    /users/123       → Update user 123
DELETE /users/123       → Delete user 123

BAD (Action-oriented):
POST   /getUsers
POST   /createUser
POST   /updateUser
POST   /deleteUser
HTTP Method Semantics
MethodPurposeIdempotentSafeRequest Body
GETRetrieve resource(s)YesYesNo
POSTCreate resourceNoNoYes
PUTReplace resourceYesNoYes
PATCHPartial updateYesNoYes
DELETERemove resourceYesNoOptional
URL Structure Patterns
Collection:     /users
Item:           /users/{id}
Nested:         /users/{id}/posts
Action:         /users/{id}/activate (POST only, for non-CRUD)
Filter:         /users?status=active&role=admin
Pagination:     /users?page=2&limit=20
Sort:           /users?sort=created_at&order=desc

Request Design

Path Parameters vs Query Parameters
UsePath ParametersQuery Parameters
Resource identification/users/123-
Required filters/orgs/456/users-
Optional filters-?status=active
Pagination-?page=2&limit=20
Sorting-?sort=name&order=asc
Search-?q=searchterm
Request Body Patterns
json
// POST /users - Create
{
  "email": "user@example.com",
  "name": "John Doe",
  "role": "admin"
}

// PATCH /users/123 - Partial update
{
  "name": "Jane Doe"
}

// Bulk operations - POST /users/bulk
{
  "operations": [
    { "action": "create", "data": { "email": "..." } },
    { "action": "update", "id": "123", "data": { "name": "..." } }
  ]
}

Response Design

Consistent Response Envelope
json
// Success response
{
  "data": { ... },
  "meta": {
    "timestamp": "2024-01-15T10:30:00Z",
    "requestId": "abc123"
  }
}

// Collection response with pagination
{
  "data": [ ... ],
  "meta": {
    "total": 100,
    "page": 2,
    "limit": 20,
    "hasMore": true
  }
}

// Error response
{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Invalid request data",
    "details": [
      { "field": "email", "message": "Invalid email format" }
    ]
  },
  "meta": {
    "timestamp": "2024-01-15T10:30:00Z",
    "requestId": "abc123"
  }
}
HTTP Status Code Guidelines
RangeCategoryCommon Codes
2xxSuccess200 OK, 201 Created, 204 No Content
3xxRedirect301 Moved, 304 Not Modified
4xxClient Error400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 422 Unprocessable
5xxServer Error500 Internal, 502 Bad Gateway, 503 Unavailable
Status Code Decision Tree
Success?
├─ Yes
│  ├─ Returning data? → 200 OK
│  ├─ Created resource? → 201 Created
│  └─ No content? → 204 No Content
└─ No
   ├─ Client's fault?
   │  ├─ Bad syntax? → 400 Bad Request
   │  ├─ Not authenticated? → 401 Unauthorized
   │  ├─ Not authorized? → 403 Forbidden
   │  ├─ Not found? → 404 Not Found
   │  └─ Validation failed? → 422 Unprocessable Entity
   └─ Server's fault? → 500 Internal Server Error

API Versioning Strategies

/api/v1/users
/api/v2/users

Pros: Explicit, easy to understand, easy to route Cons: URL changes between versions

Header Versioning
GET /api/users
Accept: application/vnd.myapi.v2+json

Pros: Clean URLs Cons: Hidden version, harder to test

Query Parameter Versioning
/api/users?version=2

Pros: Flexible, easy to test Cons: Can be forgotten, pollutes query string


GraphQL Design Patterns

Schema-First Design
graphql
type User {
  id: ID!
  email: String!
  name: String!
  posts: [Post!]!
  createdAt: DateTime!
}

type Post {
  id: ID!
  title: String!
  content: String!
  author: User!
  createdAt: DateTime!
}

type Query {
  user(id: ID!): User
  users(filter: UserFilter, page: PageInput): UserConnection!
}

type Mutation {
  createUser(input: CreateUserInput!): User!
  updateUser(id: ID!, input: UpdateUserInput!): User!
  deleteUser(id: ID!): Boolean!
}
Input Types Pattern
graphql
input CreateUserInput {
  email: String!
  name: String!
  role: Role = USER
}

input UpdateUserInput {
  email: String
  name: String
  role: Role
}

input UserFilter {
  status: UserStatus
  role: Role
  search: String
}
Show full SKILL.md (154 more words)Show less
Pagination Patterns
graphql
# Cursor-based (recommended for large datasets)
type UserConnection {
  edges: [UserEdge!]!
  pageInfo: PageInfo!
}

type UserEdge {
  node: User!
  cursor: String!
}

type PageInfo {
  hasNextPage: Boolean!
  hasPreviousPage: Boolean!
  startCursor: String
  endCursor: String
}

# Offset-based (simpler, for smaller datasets)
type UserList {
  items: [User!]!
  total: Int!
  page: Int!
  limit: Int!
}

Authentication & Authorization

Authentication Patterns
PatternUse CaseHeader
Bearer TokenStandard API authAuthorization: Bearer <token>
API KeyServer-to-serverX-API-Key: <key>
Basic AuthSimple/legacy systemsAuthorization: Basic <base64>
OAuth 2.0Third-party integrationOAuth flow
Authorization Responses
Not authenticated → 401 Unauthorized
  (User identity unknown)

Not authorized → 403 Forbidden
  (User known, but lacks permission)

Error Handling Patterns

Standardized Error Format
json
{
  "error": {
    "code": "RESOURCE_NOT_FOUND",
    "message": "User with ID 123 not found",
    "target": "user",
    "details": [
      {
        "code": "INVALID_ID",
        "message": "The provided ID does not exist",
        "target": "id"
      }
    ],
    "innererror": {
      "trace": "abc123",
      "timestamp": "2024-01-15T10:30:00Z"
    }
  }
}
Common Error Codes
CodeHTTP StatusWhen
VALIDATION_ERROR400/422Request data invalid
UNAUTHORIZED401Auth required
FORBIDDEN403Insufficient permissions
NOT_FOUND404Resource doesn't exist
CONFLICT409State conflict (duplicate)
RATE_LIMITED429Too many requests
INTERNAL_ERROR500Server failure

API Documentation

OpenAPI/Swagger Structure
yaml
openapi: 3.0.3
info:
  title: My API
  version: 1.0.0

paths:
  /users:
    get:
      summary: List users
      parameters:
        - name: status
          in: query
          schema:
            type: string
            enum: [active, inactive]
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserList'

components:
  schemas:
    User:
      type: object
      required: [id, email]
      properties:
        id:
          type: string
        email:
          type: string
          format: email

Anti-Patterns to Avoid

  1. Verbs in URLs - Use /users not /getUsers
  2. Ignoring HTTP Methods - Use proper methods, not POST for everything
  3. Inconsistent Naming - Pick snake_case or camelCase, stick with it
  4. Leaking Implementation - Don't expose internal IDs or DB structure
  5. Missing Pagination - Always paginate collections
  6. Ignoring Idempotency - PUT/DELETE must be idempotent
  7. No Versioning - Plan for API evolution from day one

Quick Reference

RESOURCE DESIGN:
  /resources           → Collection
  /resources/{id}      → Item
  /resources/{id}/sub  → Nested

HTTP METHODS:
  GET     → Read (safe, idempotent)
  POST    → Create (not idempotent)
  PUT     → Replace (idempotent)
  PATCH   → Update (idempotent)
  DELETE  → Remove (idempotent)

STATUS CODES:
  200 OK, 201 Created, 204 No Content
  400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found
  500 Internal Server Error

VERSIONING:
  /api/v1/resources (recommended)

PAGINATION:
  ?page=2&limit=20 (offset)
  ?cursor=abc123&limit=20 (cursor)

© CloudAI-X, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/designing-apis of CloudAI-X/opencode-workflow.

Open the folder on GitHubat commit 0128ca6

Compare with similar skills

Designing APIs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Designing APIs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Designing APIs this skillCloudAI-X/opencode-workflow275—~2.2kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
API Design Principlesjh941213/my-cc-harness12618 repos~3.4kAutomated safety check: PassNone
API And Interface Designdzhalaevd/Donatello1358 repos~2.6kAutomated safety check: PassApache-2.0
Designing APIsCloudAI-X/claude-workflow-v21.4k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • API Design Principles

    jh941213/my-cc-harness

    REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.

    126 GitHub starsUsed in 18 repos~3.4k tokens
    Backend & APIsAuto-check passed
  • API And Interface Design

    dzhalaevd/Donatello

    Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 8 repos~2.6k tokens
    Backend & APIsAuto-check passed
  • Designing APIs

    CloudAI-X/claude-workflow-v2

    Designs REST and GraphQL APIs including endpoints, error handling, versioning, and documentation.

    1.4k GitHub starsUsed in 1 repo~1.2k tokens
    Backend & APIsAuto-check passed
  • API Design Reviewer

    oxbshw/LLM-Agents-Ecosystem-Handbook

    A skill your agent uses when reviewing a proposed REST or GraphQL API change before merge — checks contract clarity, backwards compatibility, errors, pagination, auth, and naming.

    552 GitHub stars~553 tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed

More from CloudAI-X/opencode-workflow

  • Analyzing Projects

    CloudAI-X/opencode-workflow

    Guides systematic project analysis, codebase exploration, and architecture pattern recognition.

    275 GitHub stars~1.8k tokensUpdated 9 mo ago
    Auto-check passed
  • Designing Architecture

    CloudAI-X/opencode-workflow

    Guides software architecture decisions, design patterns, and system design principles.

    275 GitHub stars~2.6k tokensUpdated 9 mo ago
    Auto-check passed
  • Designing Tests

    CloudAI-X/opencode-workflow

    Guides test strategy, TDD/BDD approaches, test coverage planning, and testing best practices.

    275 GitHub stars~2.9k tokensUpdated 9 mo ago
    Auto-check passed
  • Managing Git

    CloudAI-X/opencode-workflow

    Guides git workflows, branching strategies, commit conventions, and version control best practices.

    275 GitHub stars~2.5k tokensUpdated 9 mo ago
    Auto-check passed
  • Optimizing Performance

    CloudAI-X/opencode-workflow

    Guides performance optimization, profiling techniques, and bottleneck identification.

    275 GitHub stars~2.6k tokensUpdated 9 mo ago
    Auto-check passed
  • Parallel Execution

    CloudAI-X/opencode-workflow

    CRITICAL skill for executing multiple Task tool calls in a SINGLE message for true parallelism.

    275 GitHub stars~2.1k tokensUpdated 9 mo ago
    Auto-check passed

Works with

Categories

Questions about Designing APIs

What does Designing APIs do?

Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices. Designing APIs is an agent skill from CloudAI-X/opencode-workflow. Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices.

When should I use Designing APIs?

Designing APIs fits situations like: designing endpoints; reviewing API contracts.

How do I install Designing APIs in Claude Code?

Run `npx skills add CloudAI-X/opencode-workflow --skill designing-apis -a claude-code`. Or copy the skill folder (skills/designing-apis in CloudAI-X/opencode-workflow) into .claude/skills/designing-apis in your project. Claude Code loads it when a task matches its description.

How do I install Designing APIs in Codex?

Run `npx skills add CloudAI-X/opencode-workflow --skill designing-apis -a codex`. Or copy the skill folder (skills/designing-apis in CloudAI-X/opencode-workflow) into .agents/skills/designing-apis in your project. Codex loads it when a task matches its description.

Can I use Designing APIs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CloudAI-X/opencode-workflow --skill designing-apis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/designing-apis, .gemini/skills/designing-apis, .github/skills/designing-apis and .opencode/skills/designing-apis in your project.

What does Designing APIs need to run?

SKILL.md names no scripts, command-line tools or credentials: Designing APIs is instructions for the agent only. Compatibility (from SKILL.md): opencode.

Does Designing APIs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Designing APIs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Designing APIs use?

Designing APIs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Designing APIs use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Designing APIs?

Skills that share tags, products or a category with Designing APIs: Nodejs Backend Patterns (ever-works/ever-works, 162 stars), API Designer (Jeffallan/claude-skills, 12k stars), API Design Principles (jh941213/my-cc-harness, 126 stars) and API And Interface Design (dzhalaevd/Donatello, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Designing APIs?

CloudAI-X (a GitHub user) maintains it in CloudAI-X/opencode-workflow, which has 275 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on January 10, 2026.

Source: CloudAI-X/opencode-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.