Agent skill

API Gateway Builder

by FerroxLabs in FerroxLabs/wayland

Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions.

Apache-2.0Auto-check passedBackend & APIs

Install API Gateway Builder

skills CLI
$ npx skills add FerroxLabs/wayland --skill api-gateway-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland api-gateway-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/backend-systems/api-gateway-builder .claude/skills/api-gateway-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-gateway-builder
GitHub stars
608
Token cost
~2.9k tokens
SKILL.md length
347 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions.

  • Works in 3 steps: Gateway is the front door - It handles… → Fail open vs fail closed -… → Keep the gateway thin - Route,…
  • The user asks about api gateway builder
  • SKILL.md covers Core Principles, Gateway Selection, Kong Configuration and AWS API Gateway, plus 12 more sections
  • Calls aws

What it does

API Gateway Builder is an agent skill from FerroxLabs/wayland. Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions. Covers rate limiting, authentication, routing, throttling, request transformation, caching, and production deployment patterns. Use when the user asks about api gateway builder, api gateway builder best practices, or needs guidance on api gateway builder implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Microservices and Rate limiting. It works with Amazon Web Services. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about api gateway builder
  • Api gateway builder best practices
  • Needs guidance on api gateway builder implementation
  • The user needs a different specialized skill

Example prompts

  • “/api-gateway-builder”

Requirements

  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Gateway is the front door - It handles cross-cutting concerns so services do not have to.
  2. Fail open vs fail closed - Authentication must fail closed; rate limiting can fail open under extreme load.
  3. Keep the gateway thin - Route, authenticate, rate limit, transform. Never put business logic in the gateway.

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Gateway Builder loads about 2.9k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 347 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~130
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 347 words, ~2,926 tokens.

Download SKILL.mdSave it as .claude/skills/api-gateway-builder/SKILL.md (or your agent's skills folder).
name
api-gateway-builder
description
Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions. Covers rate limiting, authentication, routing, throttling, request transformation, caching, and production deployment patterns. Use when the user asks about api gateway builder, api gateway builder best practices, or needs guidance on api gateway builder implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
backend api-design guide
metadata.category
backend-systems
metadata.subcategory
api-design
metadata.disclaimer
none
metadata.difficulty
advanced

API Gateway Builder

You are an expert in designing and operating API gateway infrastructure. You guide teams through gateway selection, routing configuration, rate limiting, authentication integration, request/response transformation, and production operations for both self-managed and cloud-native API gateways.

Core Principles

  1. Gateway is the front door - It handles cross-cutting concerns so services do not have to.
  2. Fail open vs fail closed - Authentication must fail closed; rate limiting can fail open under extreme load.
  3. Keep the gateway thin - Route, authenticate, rate limit, transform. Never put business logic in the gateway.

Gateway Selection

GATEWAY              TYPE            BEST FOR                   COST MODEL
---------------------------------------------------------------------------
AWS API GW (HTTP)    Managed         Serverless, low complexity $1/million reqs
AWS API GW (REST)    Managed         WebSocket, caching, WAF    $3.50/million
Kong                 Self-managed    Multi-cloud, plugins, K8s  Open source/EE
Envoy / Istio        Self-managed    Service mesh, gRPC         Free (infra cost)
Traefik              Self-managed    Docker/K8s auto-discovery  Open source/EE
NGINX                Self-managed    Max performance, mature    Open source/Plus
CHOOSE AWS API GW:  Serverless backend, AWS-native, <10K req/s
CHOOSE KONG:        Multi-cloud, complex plugins, Kubernetes-native
CHOOSE ENVOY:       Service mesh, gRPC-native, fine-grained traffic control
CHOOSE NGINX:       Maximum raw performance, simple routing needs

Kong Configuration

Declarative Config (kong.yml)
yaml
_format_version: "3.0"

services:
  - name: user-service
    url: [reference URL]
    connect_timeout: 5000
    read_timeout: 30000
    retries: 3
    routes:
      - name: user-routes
        paths: [/api/v1/users]
        methods: [GET, POST, PUT, DELETE]
        strip_path: false
        protocols: [https]

plugins:
  - name: rate-limiting
    config:
      minute: 100
      hour: 5000
      policy: redis
      redis_host: redis
      fault_tolerant: true        # Fail open if Redis down

  - name: correlation-id
    config:
      header_name: X-Request-ID
      generator: uuid
      echo_downstream: true

  - name: request-size-limiting
    config:
      allowed_payload_size: 10    # MB
Service-Level Plugins
yaml
plugins:
  - name: rate-limiting
    route: login-route
    config:
      minute: 10                  # Strict limit on login attempts

  - name: jwt
    service: user-service
    config:
      claims_to_verify: [exp]
      header_names: [Authorization]

  - name: request-transformer
    service: user-service
    config:
      add:
        headers: ["X-Gateway-Version:1.0"]
      remove:
        headers: [Cookie]
Kong in Kubernetes
yaml
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
  name: rate-limit-api
plugin: rate-limiting
config:
  minute: 100
  policy: local
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: user-api
  annotations:
    konghq.com/plugins: rate-limit-api,jwt-auth
spec:
  ingressClassName: kong
  rules:
    - host: api.example.com
      http:
        paths:
          - path: /api/v1/users
            pathType: Prefix
            backend:
              service: { name: user-service, port: { number: 8080 } }

AWS API Gateway

yaml
Resources:
  HttpApi:
    Type: AWS::Serverless::HttpApi
    Properties:
      StageName: prod
      CorsConfiguration:
        AllowOrigins: ["[reference URL]"]
        AllowMethods: [GET, POST, PUT, DELETE]
        AllowHeaders: [Authorization, Content-Type]
      Auth:
        DefaultAuthorizer: JWTAuthorizer
        Authorizers:
          JWTAuthorizer:
            IdentitySource: $request.header.Authorization
            JwtConfiguration:
              issuer: [reference URL]
              audience: [api.example.com]
      DefaultRouteSettings:
        ThrottlingBurstLimit: 200
        ThrottlingRateLimit: 100
REST API with Usage Plans
yaml
  UsagePlan:
    Type: AWS::ApiGateway::UsagePlan
    Properties:
      Throttle:
        BurstLimit: 200
        RateLimit: 100
      Quota:
        Limit: 100000
        Period: MONTH

Rate Limiting

Algorithm Comparison
ALGORITHM           HOW IT WORKS                    TRADE-OFF
---------------------------------------------------------------------------
Fixed Window        Count per time window            Simple; burst at edges
Sliding Window      Weighted current + previous      Good accuracy/memory
Token Bucket        Tokens refill at steady rate     Allows controlled bursts
Leaky Bucket        Process at fixed rate, queue     Smooth; no bursts
Multi-Tier Strategy
TIER        KEY              LIMIT           PURPOSE
--------------------------------------------------------------
Global      -                10,000 req/s    Protect infrastructure
Per-IP      client IP        100 req/min     Prevent abuse
Per-User    auth token/key   1,000 req/hr    Fair usage
Per-Route   path + method    50 req/min      Protect heavy endpoints
Rate Limit Response
HTTP/1.1 429 Too Many Requests
Retry-After: 30
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1705312800

Authentication Patterns

Gateway Auth Flow
Client -> Gateway -> [Auth Plugin] -> Backend Service
                         |
                    Validate token
                    Extract claims
                    Inject headers:
                      X-User-ID, X-User-Role, X-Tenant-ID
                         |
                    Strip Authorization header
                    (backend trusts gateway headers)
API Key Authentication
yaml
plugins:
  - name: key-auth
    service: api-service
    config:
      key_names: [X-API-Key, apikey]
      key_in_header: true
      key_in_query: true
      hide_credentials: true      # Remove key before proxying

Request/Response Transformation

yaml
# Add security headers to all responses
plugins:
  - name: response-transformer
    config:
      add:
        headers:
          - "Strict-Transport-Security:max-age=31536000; includeSubDomains"
          - "X-Content-Type-Options:nosniff"
          - "X-Frame-Options:DENY"
      remove:
        headers: [Server, X-Powered-By]

Routing Patterns

PATH-BASED:
  /api/v1/users/*     -> user-service:8080
  /api/v1/orders/*    -> order-service:8080
  /api/v2/users/*     -> user-service-v2:8080

HEADER-BASED (e.g., mobile vs web):
  X-Client-Type: mobile  -> user-service-mobile
  X-Client-Type: web     -> user-service-web

CANARY RELEASES:
  10% traffic -> canary backend
  90% traffic -> stable backend
  Sticky routing per consumer for consistency

Caching

yaml
plugins:
  - name: proxy-cache
    config:
      strategy: redis
      content_type: [application/json]
      request_method: [GET, HEAD]
      response_code: [200, 301]
      cache_ttl: 300
      vary_headers: [Authorization, Accept-Encoding]
      cache_control: true         # Respect Cache-Control headers

Health Checks

yaml
upstreams:
  - name: user-service
    healthchecks:
      active:
        http_path: /health
        healthy: { interval: 5, successes: 3 }
        unhealthy: { interval: 5, http_failures: 3, timeouts: 3 }
      passive:
        healthy: { successes: 5 }
        unhealthy: { http_failures: 5, timeouts: 3 }
    targets:
      - { target: "user-service-1:8080", weight: 100 }
      - { target: "user-service-2:8080", weight: 100 }

Monitoring

METRIC                      ALERT CONDITION
------------------------------------------------------
Request rate                Sudden spike or drop
Error rate (5xx)            > 1% sustained
Latency (p99)               > 2s
Rate limit hits             Sustained high rate
Auth failures               Spike (possible attack)
Upstream health             Any backend unhealthy
Cache hit ratio             < 50%

Production Checklist

ROUTING:
  [ ] All routes use HTTPS
  [ ] API versioning implemented
  [ ] Health check endpoints excluded from auth

SECURITY:
  [ ] Auth enforced on all non-public routes
  [ ] Rate limiting (global, per-user, per-route)
  [ ] Request size limits set
  [ ] Security headers on all responses
  [ ] CORS with explicit allowed origins
  [ ] Sensitive headers stripped before proxying

RELIABILITY:
  [ ] Upstream health checks (active + passive)
  [ ] Timeouts on all upstream connections
  [ ] Circuit breaker for failing backends
  [ ] Graceful degradation documented

OBSERVABILITY:
  [ ] Access logging (structured JSON)
  [ ] Metrics exported (Prometheus/CloudWatch)
  [ ] Distributed tracing propagated
  [ ] Alerting on error rate, latency, rate limits

When to Use

Use this skill when:

  • Designing or implementing api gateway builder solutions
  • Reviewing or improving existing api gateway builder approaches
  • Making architectural or implementation decisions about api gateway builder
  • Learning api gateway builder patterns and best practices
  • Troubleshooting api gateway builder-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Api Gateway Builder Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement api gateway builder for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended api gateway builder approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When api gateway builder must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/backend-systems/api-gateway-builder of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

API Gateway Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Gateway Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Gateway Builder this skillFerroxLabs/wayland608—~2.9kAutomated safety check: PassApache-2.0
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Implementing API Gateway Security Controlsmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0
Securing API Gateway With AWS Wafmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Analyzing API Gateway Access Logsmukul975/Anthropic-Cybersecurity-Skills34k—~581Automated safety check: PassApache-2.0
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Implementing API Gateway Security Controls

    mukul975/Anthropic-Cybersecurity-Skills

    Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Securing API Gateway With AWS Waf

    mukul975/Anthropic-Cybersecurity-Skills

    Secures AWS API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, custom rate-limiting rules, bot control, IP reputation filtering, and WAF metric…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Analyzing API Gateway Access Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts.

    34k GitHub stars~581 tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about API Gateway Builder

What does API Gateway Builder do?

Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions. API Gateway Builder is an agent skill from FerroxLabs/wayland. Expert guide for designing and configuring API gateways including Kong, AWS API Gateway, and cloud-native solutions.

When should I use API Gateway Builder?

API Gateway Builder fits situations like: the user asks about api gateway builder; api gateway builder best practices; needs guidance on api gateway builder implementation; the user needs a different specialized skill.

How do I install API Gateway Builder in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill api-gateway-builder -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/backend-systems/api-gateway-builder in FerroxLabs/wayland) into .claude/skills/api-gateway-builder in your project. Claude Code loads it when a task matches its description.

How do I install API Gateway Builder in Codex?

Run `npx skills add FerroxLabs/wayland --skill api-gateway-builder -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/backend-systems/api-gateway-builder in FerroxLabs/wayland) into .agents/skills/api-gateway-builder in your project. Codex loads it when a task matches its description.

Can I use API Gateway Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill api-gateway-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-gateway-builder, .gemini/skills/api-gateway-builder, .github/skills/api-gateway-builder and .opencode/skills/api-gateway-builder in your project.

What does API Gateway Builder need to run?

Going by SKILL.md and its folder, API Gateway Builder needs the command-line tools its instructions call (aws). Our summary lists: Docker.

Does API Gateway Builder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Gateway Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Gateway Builder use?

API Gateway Builder is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Gateway Builder use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Gateway Builder?

Skills that share tags, products or a category with API Gateway Builder: API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Implementing API Gateway Security Controls (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Securing API Gateway With AWS Waf (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing API Gateway Access Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Gateway Builder?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.