Agent skill

API Gateway

by itsmostafa in itsmostafa/aws-agent-skills

AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

MITAuto-check passedBackend & APIs

Install API Gateway

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill api-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills api-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-gateway .claude/skills/api-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-gateway
GitHub stars
1.2k
Used in
1 other repo
Token cost
~2.2k tokens
SKILL.md length
406 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

  • Configuring integrations
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws; reaches cognito-idp.us-east-1.amazonaws.com
  • Setting up authorization

What it does

API Gateway is an agent skill from itsmostafa/aws-agent-skills. AWS API Gateway for REST and HTTP API management. Use when creating APIs, configuring integrations, setting up authorization, managing stages, implementing rate limiting, or troubleshooting API issues.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `integration-patterns.md`).

It sits in Backend & APIs, covering Microservices, REST APIs and Rate limiting. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Configuring integrations
  • Setting up authorization
  • Managing stages
  • Implementing rate limiting

Example prompts

  • “/api-gateway”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cognito-idp.us-east-1.amazonaws.com

    Also links to:

    • docs.aws.amazon.com
    • boto3.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Gateway loads about 2.2k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 406 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 406 words, ~2,237 tokens.

Download SKILL.mdSave it as .claude/skills/api-gateway/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
api-gateway
description
AWS API Gateway for REST and HTTP API management. Use when creating APIs, configuring integrations, setting up authorization, managing stages, implementing rate limiting, or troubleshooting API issues.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/apigateway/latest/developerguide/

AWS API Gateway

Amazon API Gateway is a fully managed service for creating, publishing, and securing APIs at any scale. Supports REST APIs, HTTP APIs, and WebSocket APIs.

Table of Contents

Core Concepts

API Types
TypeDescriptionUse Case
HTTP APILow-latency, cost-effectiveSimple APIs, Lambda proxy
REST APIFull-featured, more controlComplex APIs, transformation
WebSocket APIBidirectional communicationReal-time apps, chat
Key Components
  • Resources: URL paths (/users, /orders/{id})
  • Methods: HTTP verbs (GET, POST, PUT, DELETE)
  • Integrations: Backend connections (Lambda, HTTP, AWS services)
  • Stages: Deployment environments (dev, prod)
Integration Types
TypeDescription
Lambda ProxyPass-through to Lambda (recommended)
Lambda CustomTransform request/response
HTTP ProxyPass-through to HTTP endpoint
AWS ServiceDirect integration with AWS services
MockReturn static response

Common Patterns

Create HTTP API with Lambda

AWS CLI:

bash
# Create HTTP API
aws apigatewayv2 create-api \
  --name my-api \
  --protocol-type HTTP \
  --target arn:aws:lambda:us-east-1:123456789012:function:MyFunction

# Get API endpoint
aws apigatewayv2 get-api --api-id abc123 --query 'ApiEndpoint'

SAM Template:

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31

Resources:
  MyApi:
    Type: AWS::Serverless::HttpApi
    Properties:
      StageName: prod

  MyFunction:
    Type: AWS::Serverless::Function
    Properties:
      Handler: app.handler
      Runtime: python3.12
      Events:
        ApiEvent:
          Type: HttpApi
          Properties:
            ApiId: !Ref MyApi
            Path: /items
            Method: GET
Create REST API with Lambda Proxy
bash
# Create REST API
aws apigateway create-rest-api \
  --name my-rest-api \
  --endpoint-configuration types=REGIONAL

API_ID=abc123

# Get root resource ID
ROOT_ID=$(aws apigateway get-resources --rest-api-id $API_ID --query 'items[0].id' --output text)

# Create resource
aws apigateway create-resource \
  --rest-api-id $API_ID \
  --parent-id $ROOT_ID \
  --path-part items

RESOURCE_ID=xyz789

# Create method
aws apigateway put-method \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method GET \
  --authorization-type NONE

# Create Lambda integration
aws apigateway put-integration \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method GET \
  --type AWS_PROXY \
  --integration-http-method POST \
  --uri arn:aws:apigateway:us-east-1:lambda:path/2015-03-31/functions/arn:aws:lambda:us-east-1:123456789012:function:MyFunction/invocations

# Deploy to stage
aws apigateway create-deployment \
  --rest-api-id $API_ID \
  --stage-name prod
Lambda Handler for API Gateway
python
import json

def handler(event, context):
    # HTTP API event
    http_method = event.get('requestContext', {}).get('http', {}).get('method')
    path = event.get('rawPath', '')
    query_params = event.get('queryStringParameters', {})
    body = event.get('body', '')

    if body and event.get('isBase64Encoded'):
        import base64
        body = base64.b64decode(body).decode('utf-8')

    # Process request
    response_body = {'message': 'Success', 'path': path}

    return {
        'statusCode': 200,
        'headers': {
            'Content-Type': 'application/json'
        },
        'body': json.dumps(response_body)
    }
Configure CORS

HTTP API:

bash
aws apigatewayv2 update-api \
  --api-id abc123 \
  --cors-configuration '{
    "AllowOrigins": ["https://example.com"],
    "AllowMethods": ["GET", "POST", "PUT", "DELETE"],
    "AllowHeaders": ["Content-Type", "Authorization"],
    "MaxAge": 86400
  }'

REST API:

bash
# Enable CORS on resource
aws apigateway put-method \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method OPTIONS \
  --authorization-type NONE

aws apigateway put-integration \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method OPTIONS \
  --type MOCK \
  --request-templates '{"application/json": "{\"statusCode\": 200}"}'

aws apigateway put-method-response \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method OPTIONS \
  --status-code 200 \
  --response-parameters '{
    "method.response.header.Access-Control-Allow-Headers": true,
    "method.response.header.Access-Control-Allow-Methods": true,
    "method.response.header.Access-Control-Allow-Origin": true
  }'

aws apigateway put-integration-response \
  --rest-api-id $API_ID \
  --resource-id $RESOURCE_ID \
  --http-method OPTIONS \
  --status-code 200 \
  --response-parameters '{
    "method.response.header.Access-Control-Allow-Headers": "'\''Content-Type,Authorization'\''",
    "method.response.header.Access-Control-Allow-Methods": "'\''GET,POST,PUT,DELETE,OPTIONS'\''",
    "method.response.header.Access-Control-Allow-Origin": "'\''*'\''"
  }'
JWT Authorization (HTTP API)
bash
aws apigatewayv2 create-authorizer \
  --api-id abc123 \
  --name jwt-authorizer \
  --authorizer-type JWT \
  --identity-source '$request.header.Authorization' \
  --jwt-configuration '{
    "Issuer": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123",
    "Audience": ["client-id"]
  }'

CLI Reference

HTTP API (apigatewayv2)
CommandDescription
aws apigatewayv2 create-apiCreate API
aws apigatewayv2 get-apisList APIs
aws apigatewayv2 create-routeCreate route
aws apigatewayv2 create-integrationCreate integration
aws apigatewayv2 create-stageCreate stage
aws apigatewayv2 create-authorizerCreate authorizer
REST API (apigateway)
CommandDescription
aws apigateway create-rest-apiCreate API
aws apigateway get-rest-apisList APIs
aws apigateway create-resourceCreate resource
aws apigateway put-methodCreate method
aws apigateway put-integrationCreate integration
aws apigateway create-deploymentDeploy API

Best Practices

Show full SKILL.md (171 more words)Show less
Performance
  • Use HTTP APIs for simple use cases (70% cheaper, lower latency)
  • Enable caching for REST APIs
  • Use regional endpoints unless global distribution needed
  • Implement pagination for list endpoints
Security
  • Use authorization on all endpoints
  • Enable WAF for REST APIs
  • Use API keys for rate limiting (not authentication)
  • Enable access logging
  • Use HTTPS only
Reliability
  • Set up throttling to protect backends
  • Configure timeout appropriately
  • Use canary deployments for updates
  • Monitor with CloudWatch

Troubleshooting

403 Forbidden

Causes:

  • Missing authorization
  • Invalid API key
  • WAF blocking
  • Resource policy denying

Debug:

bash
# Check API key
aws apigateway get-api-key --api-key abc123 --include-value

# Check authorizer
aws apigatewayv2 get-authorizer --api-id abc123 --authorizer-id xyz789
502 Bad Gateway

Causes:

  • Lambda error
  • Integration timeout
  • Invalid response format

Lambda response format:

python
# Correct format
return {
    'statusCode': 200,
    'headers': {'Content-Type': 'application/json'},
    'body': json.dumps({'message': 'success'})
}

# Wrong - missing statusCode
return {'message': 'success'}
504 Gateway Timeout

Causes:

  • Backend timeout (Lambda max 29 seconds for REST API)
  • Integration timeout too short

Solutions:

  • Increase Lambda timeout
  • Use async processing for long operations
  • Increase integration timeout (max 29s for REST, 30s for HTTP)
CORS Errors

Debug:

  • Check OPTIONS method exists
  • Verify headers in response
  • Check origin matches allowed origins

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/api-gateway of itsmostafa/aws-agent-skills.

  • SKILL.md
  • integration-patterns.md

Open the folder on GitHubat commit e786d25

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in itsmostafa/aws-agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

API Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Gateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Gateway this skillitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Detecting Shadow API Endpointsmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Implementing API Gateway Security Controlsmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0
Securing API Gateway With AWS Wafmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Deploying Custom Domain REST APIaws/agent-toolkit-for-aws2.8k—~4.8kAutomated safety check: PassApache-2.0
API Gatewayawslabs/agent-plugins912—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Detecting Shadow API Endpoints

    mukul975/Anthropic-Cybersecurity-Skills

    Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing API Gateway Security Controls

    mukul975/Anthropic-Cybersecurity-Skills

    Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Securing API Gateway With AWS Waf

    mukul975/Anthropic-Cybersecurity-Skills

    Secures AWS API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, custom rate-limiting rules, bot control, IP reputation filtering, and WAF metric…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Deploying Custom Domain REST API

    aws/agent-toolkit-for-aws

    Official

    Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.

    2.8k GitHub stars~4.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Gateway

    awslabs/agent-plugins

    Official

    Build, manage, and operate APIs with Amazon API Gateway (REST, HTTP, and WebSocket).

    912 GitHub stars~4.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Connecting Lambda To API Gateway

    aws/agent-toolkit-for-aws

    Official

    Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration, permissions, and deployment.

    2.8k GitHub stars~422 tokensUpdated today
    Backend & APIsAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed
  • Dynamodb

    itsmostafa/aws-agent-skills

    AWS DynamoDB NoSQL database for scalable data storage. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub stars~4.7k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about API Gateway

What does API Gateway do?

AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills. API Gateway is an agent skill from itsmostafa/aws-agent-skills. AWS API Gateway for REST and HTTP API management.

When should I use API Gateway?

API Gateway fits situations like: configuring integrations; setting up authorization; managing stages; implementing rate limiting.

How do I install API Gateway in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill api-gateway -a claude-code`. Or copy the skill folder (skills/api-gateway in itsmostafa/aws-agent-skills) into .claude/skills/api-gateway in your project. Claude Code loads it when a task matches its description.

How do I install API Gateway in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill api-gateway -a codex`. Or copy the skill folder (skills/api-gateway in itsmostafa/aws-agent-skills) into .agents/skills/api-gateway in your project. Codex loads it when a task matches its description.

Can I use API Gateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill api-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-gateway, .gemini/skills/api-gateway, .github/skills/api-gateway and .opencode/skills/api-gateway in your project.

What does API Gateway need to run?

Going by SKILL.md and its folder, API Gateway needs the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does API Gateway access the network?

SKILL.md names 3 domains. In commands or code: cognito-idp.us-east-1.amazonaws.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.

Is API Gateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Gateway use?

API Gateway is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Gateway use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Gateway?

Skills that share tags, products or a category with API Gateway: Detecting Shadow API Endpoints (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing API Gateway Security Controls (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Securing API Gateway With AWS Waf (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Deploying Custom Domain REST API (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Gateway?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,160 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.