Agent skill

Spring Boot REST API Standards

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides REST API design standards and best practices for Spring Boot projects.

MITAuto-check: notesBackend & APIs

Install Spring Boot REST API Standards

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-rest-api-standards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit spring-boot-rest-api-standards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-java/skills/spring-boot-rest-api-standards .claude/skills/spring-boot-rest-api-standards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-boot-rest-api-standards
GitHub stars
357
Token cost
~2k tokens
SKILL.md length
473 words
Files
8 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides REST API design standards and best practices for Spring Boot projects.

  • Works in 3 steps: Use Constructor Injection → Prefer Immutable DTOs (Java Records or… → Implement Proper Transaction Management
  • Reviewing REST endpoints
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spring Boot REST API Standards is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/architecture-patterns.md`, `references/examples.md` and `references/http-reference.md`).

It sits in Backend & APIs, covering REST APIs and Backend development. It works with Spring Boot. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Reviewing REST endpoints
  • Security headers
  • HATEOAS and architecture patterns

Example prompts

  • “Use the spring-boot-rest-api-standards skill to provide REST API design standards and best practices for Spring Boot projects”
  • “/spring-boot-rest-api-standards”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Use Constructor Injection
  2. Prefer Immutable DTOs (Java Records or @Value)
  3. Implement Proper Transaction Management

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Boot REST API Standards loads about 2k tokens when it runs, and up to ~25k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 473 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~25k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 473 words, ~1,990 tokens.

Download SKILL.mdSave it as .claude/skills/spring-boot-rest-api-standards/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
spring-boot-rest-api-standards
description
Provides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
allowed-tools
Read, Write, Edit, Bash, Glob, Grep

Spring Boot REST API Standards

Overview

REST API design standards for Spring Boot covering URL design, HTTP methods, status codes, DTOs, validation, error handling, pagination, and security headers.

When to Use

  • Creating REST endpoints and API routes
  • Designing DTOs and API contracts
  • Implementing error handling and validation
  • Setting up pagination and filtering
  • Configuring security headers and CORS
  • Reviewing REST API architecture

Instructions

To Build RESTful API Endpoints

Follow these steps to create well-designed REST API endpoints:

  1. Design Resource-Based URLs

    • Use plural nouns for resource names
    • Follow REST conventions: GET /users, POST /users, PUT /users/{id}
    • Avoid action-based URLs like /getUserList
  2. Implement Proper HTTP Methods

    • GET: Retrieve resources (safe, idempotent)
    • POST: Create resources (not idempotent)
    • PUT: Replace entire resources (idempotent)
    • PATCH: Partial updates (not idempotent)
    • DELETE: Remove resources (idempotent)
  3. Use Appropriate Status Codes

    • 200 OK: Successful GET/PUT/PATCH
    • 201 Created: Successful POST with Location header
    • 204 No Content: Successful DELETE
    • 400 Bad Request: Invalid request data
    • 404 Not Found: Resource doesn't exist
    • 409 Conflict: Duplicate resource
    • 500 Internal Server Error: Unexpected errors
  4. Create Request/Response DTOs

    • Separate API contracts from domain entities
    • Use Java records or Lombok @Data/@Value
    • Apply Jakarta validation annotations
    • Keep DTOs immutable when possible
  5. Implement Validation

    • Use @Valid annotation on @RequestBody parameters
    • Apply validation constraints (@NotBlank, @Email, @Size, etc.)
    • Handle validation errors with MethodArgumentNotValidException
  6. Set Up Error Handling

    • Use @RestControllerAdvice for global exception handling
    • Return standardized error responses with status, error, message, and timestamp
    • Use ResponseStatusException for specific HTTP status codes
  7. Configure Pagination

    • Use Pageable for large datasets
    • Include page, size, sort parameters
    • Return metadata with total elements, totalPages, etc.
  8. Add Security Headers

    • Configure CORS policies
    • Set content security policy
    • Include X-Frame-Options, X-Content-Type-Options

Validation checkpoints:

  • After step 1-2: Verify URL structure follows REST conventions (/users not /getUsers)
  • After step 3: Test each endpoint returns correct status codes
  • After step 4-5: Validate DTOs with curl or HTTPie before proceeding
  • After step 6: Confirm error responses match standardized format
Show full SKILL.md (149 more words)Show less

Examples

Basic CRUD Controller
java
@RestController
@RequestMapping("/v1/users")
@RequiredArgsConstructor
@Slf4j
public class UserController {
    private final UserService userService;

    @GetMapping
    public ResponseEntity<Page<UserResponse>> getAllUsers(
            @RequestParam(defaultValue = "0") int page,
            @RequestParam(defaultValue = "10") int pageSize) {
        log.debug("Fetching users page {} size {}", page, pageSize);
        Page<UserResponse> users = userService.getAll(page, pageSize);
        return ResponseEntity.ok(users);
    }

    @GetMapping("/{id}")
    public ResponseEntity<UserResponse> getUserById(@PathVariable Long id) {
        return ResponseEntity.ok(userService.getById(id));
    }

    @PostMapping
    public ResponseEntity<UserResponse> createUser(@Valid @RequestBody CreateUserRequest request) {
        UserResponse created = userService.create(request);
        return ResponseEntity.status(HttpStatus.CREATED).body(created);
    }

    @PutMapping("/{id}")
    public ResponseEntity<UserResponse> updateUser(
            @PathVariable Long id,
            @Valid @RequestBody UpdateUserRequest request) {
        return ResponseEntity.ok(userService.update(id, request));
    }

    @DeleteMapping("/{id}")
    public ResponseEntity<Void> deleteUser(@PathVariable Long id) {
        userService.delete(id);
        return ResponseEntity.noContent().build();
    }
}
Request/Response DTOs
java
// Request DTO
@Data
@NoArgsConstructor
@AllArgsConstructor
public class CreateUserRequest {
    @NotBlank(message = "User name cannot be blank")
    private String name;

    @Email(message = "Valid email required")
    private String email;
}

// Response DTO
@Data
@NoArgsConstructor
@AllArgsConstructor
public class UserResponse {
    private Long id;
    private String name;
    private String email;
    private LocalDateTime createdAt;
}
Global Exception Handler
java
@RestControllerAdvice
@Slf4j
public class GlobalExceptionHandler {

    @ExceptionHandler(MethodArgumentNotValidException.class)
    public ResponseEntity<ErrorResponse> handleValidationException(
            MethodArgumentNotValidException ex, WebRequest request) {
        String errors = ex.getBindingResult().getFieldErrors().stream()
                .map(f -> f.getField() + ": " + f.getDefaultMessage())
                .collect(Collectors.joining(", "));

        ErrorResponse errorResponse = new ErrorResponse(
                HttpStatus.BAD_REQUEST.value(),
                "Validation Error",
                "Validation failed: " + errors,
                request.getDescription(false).replaceFirst("uri=", "")
        );
        return new ResponseEntity<>(errorResponse, HttpStatus.BAD_REQUEST);
    }

    @ExceptionHandler(ResponseStatusException.class)
    public ResponseEntity<ErrorResponse> handleResponseStatusException(
            ResponseStatusException ex, WebRequest request) {
        ErrorResponse error = new ErrorResponse(
            ex.getStatusCode().value(),
            ex.getStatusCode().toString(),
            ex.getReason(),
            request.getDescription(false).replaceFirst("uri=", "")
        );
        return new ResponseEntity<>(error, ex.getStatusCode());
    }
}

Best Practices

1. Use Constructor Injection
java
@Service
@RequiredArgsConstructor
public class UserService {
    private final UserRepository userRepository;
}
2. Prefer Immutable DTOs (Java Records or @Value)
java
public record UserResponse(Long id, String name, String email) {}
3. Implement Proper Transaction Management
java
@Service
@Transactional
public class UserService {
    @Transactional(readOnly = true)
    public Optional<User> findById(Long id) { return userRepository.findById(id); }

    @Transactional
    public User create(User user) { return userRepository.save(user); }
}

Constraints and Warnings

  1. Never expose entities directly - Use DTOs to separate API contracts from domain models
  2. Follow REST conventions - Use nouns for resources (/users), correct HTTP methods, plural names, proper status codes
  3. Handle all exceptions globally - Use @RestControllerAdvice, never let raw exceptions bubble up
  4. Always paginate large result sets - Prevent performance issues and DDoS vulnerabilities
  5. Validate all input data - Use Jakarta validation annotations on request DTOs
  6. Never expose sensitive data - Don't log or expose passwords, tokens, PII

References

  • See references/ directory for comprehensive reference material including HTTP status codes, Spring annotations, and detailed examples
  • Refer to the developer-kit-java:spring-boot-code-review-expert agent for code review guidelines
  • Review spring-boot-dependency-injection/SKILL.md for dependency injection patterns
  • Check ../spring-boot-test-patterns/SKILL.md for testing REST APIs

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in plugins/developer-kit-java/skills/spring-boot-rest-api-standards of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/architecture-patterns.md
  • references/examples.md
  • references/http-reference.md
  • references/pagination-and-filtering.md
  • references/references.md
  • references/security-headers.md
  • references/spring-web-annotations.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Spring Boot REST API Standards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Boot REST API Standards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Boot REST API Standards this skillgiuseppe-trisciuoglio/developer-kit357—~2kAutomated safety check: NotesMIT
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Grails Developer Guideapache/grails-core2.9k—~4.9kAutomated safety check: PassApache-2.0
Spring Boot Skillpiomin/sample-spring-modulith144—~668Automated safety check: PassNone
Progensivaprasadreddy/sivalabs-agent-skills188—~2.7kAutomated safety check: NotesMIT
Springboot Patternsaffaan-m/ECC277k5 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Spring Boot Skill

    piomin/sample-spring-modulith

    Build Spring Boot 4.x applications following the best practices.

    144 GitHub stars~668 tokensUpdated 15 days ago
    Backend & APIsAuto-check passed
  • Progen

    sivaprasadreddy/sivalabs-agent-skills

    A skill your agent uses when the user wants to create/generate/scaffold a new Spring Boot project (Maven or Gradle, REST API / Web App / Spring Boot + Angular full stack).

    188 GitHub stars~2.7k tokensUpdated 6 days ago
    Backend & APIsAuto-check: notes
  • Spring Boot architecture patterns, REST API design, layered services, data access, caching, async processing, and logging.

    277k GitHub starsUsed in 5 repos~2.5k tokens
    Backend & APIsAuto-check passed
  • Spring Boot Skill

    sivaprasadreddy/sivalabs-agent-skills

    Build Spring Boot 4.x applications following the best practices.

    188 GitHub stars~1.1k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Spring Boot REST API Standards

What does Spring Boot REST API Standards do?

Provides REST API design standards and best practices for Spring Boot projects. Spring Boot REST API Standards is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides REST API design standards and best practices for Spring Boot projects.

When should I use Spring Boot REST API Standards?

Spring Boot REST API Standards fits situations like: reviewing REST endpoints; security headers; HATEOAS and architecture patterns.

How do I install Spring Boot REST API Standards in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-rest-api-standards -a claude-code`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-rest-api-standards in giuseppe-trisciuoglio/developer-kit) into .claude/skills/spring-boot-rest-api-standards in your project. Claude Code loads it when a task matches its description.

How do I install Spring Boot REST API Standards in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-rest-api-standards -a codex`. Or copy the skill folder (plugins/developer-kit-java/skills/spring-boot-rest-api-standards in giuseppe-trisciuoglio/developer-kit) into .agents/skills/spring-boot-rest-api-standards in your project. Codex loads it when a task matches its description.

Can I use Spring Boot REST API Standards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill spring-boot-rest-api-standards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-boot-rest-api-standards, .gemini/skills/spring-boot-rest-api-standards, .github/skills/spring-boot-rest-api-standards and .opencode/skills/spring-boot-rest-api-standards in your project.

What does Spring Boot REST API Standards need to run?

SKILL.md names no scripts, command-line tools or credentials: Spring Boot REST API Standards is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep.

Does Spring Boot REST API Standards access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spring Boot REST API Standards safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Spring Boot REST API Standards use?

Spring Boot REST API Standards is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Boot REST API Standards use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Spring Boot REST API Standards?

Skills that share tags, products or a category with Spring Boot REST API Standards: Dr Jskill (jdubois/dr-jskill, 342 stars), Grails Developer Guide (apache/grails-core, 2.9k stars), Spring Boot Skill (piomin/sample-spring-modulith, 144 stars) and Progen (sivaprasadreddy/sivalabs-agent-skills, 188 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Boot REST API Standards?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.