Agent skill

API Design Conventions

by makifbaysal in makifbaysal/tasktrooper

A skill your agent uses when you design or change an endpoint's errors, status codes, pagination, idempotency or concurrency behaviour — one error shape, the status-code table, bounded lists, safe…

Apache-2.0Auto-check passedBackend & APIs

Install API Design Conventions

skills CLI
$ npx skills add makifbaysal/tasktrooper --skill api-design-conventions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install makifbaysal/tasktrooper api-design-conventions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/agents/backend-developer/skills/api-design-conventions .claude/skills/api-design-conventions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-design-conventions
GitHub stars
112
Token cost
~1.4k tokens
SKILL.md length
631 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when you design or change an endpoint's errors, status codes, pagination, idempotency or concurrency behaviour — one error shape, the status-code table, bounded lists, safe…

  • Change an endpoints errors
  • SKILL.md covers Overview, One error shape, Status code table and Mapping database errors (Go,…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Concurrency behaviour — one error shape

What it does

API Design Conventions is an agent skill from makifbaysal/tasktrooper. Use when you design or change an endpoint's errors, status codes, pagination, idempotency or concurrency behaviour — one error shape, the status-code table, bounded lists, safe retries

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API design. The repository describes itself as: Local-first agent platform: board + role agents + agent CLI runs (Claude Code, Cursor, Antigravity, OpenCode) or local and API models (Ollama, LM Studio), all on your own Mac. The licence is Apache-2.0.

When your agent uses it

  • Change an endpoints errors
  • Concurrency behaviour — one error shape
  • The status-code table

Example prompts

  • “/api-design-conventions”

What it can do on your machine

Read from SKILL.md and the folder at commit c4496d5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Design Conventions loads about 1.4k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 631 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from makifbaysal/tasktrooper at commit c4496d5, republished under its Apache-2.0 licence (© makifbaysal). 631 words, ~1,367 tokens.

Download SKILL.mdSave it as .claude/skills/api-design-conventions/SKILL.md (or your agent's skills folder).
name
api-design-conventions
description
Use when you design or change an endpoint's errors, status codes, pagination, idempotency or concurrency behaviour — one error shape, the status-code table, bounded lists, safe retries
category
api
tech_stack
Go
source
Zalando RESTful API Guidelines (CC-BY-4.0), IETF idempotency-key-header draft, RFC 9457, adapted

API Design Conventions

Overview

Most backend-caused QA bounces are inconsistency, not bugs: a 422 here and a 400 there, an unbounded list, a create that isn't safe to retry. This skill is the shared vocabulary so every endpoint in a service answers these the same way.

Core principle: the repository's existing choice wins (rule repo-conventions-win); these are the defaults for a new repo or an endpoint with nothing established yet.

One error shape

Default for a repo with no convention yet: RFC 9457 application/problem+json — {type, title, status, detail, instance} plus an extension array for field errors, e.g. errors: [{field, message}]. Never a bare string, never a stack trace, never a raw framework exception body. Map it in ONE place (fiber-rest-api's central ErrorHandler, Spring @RestControllerAdvice + ProblemDetail/spring.mvc.problemdetails.enabled=true, Quarkus @ServerExceptionMapper) — not per handler.

Status code table

CodeWhenNote
200 / 201success / created201 includes Location of the new resource
204success with no body (e.g. delete)
400unparseable or invalid inputor 422 if the repo already standardizes on it — don't introduce a second convention
401 / 403unauthenticated / forbidden
404missing, OR present-but-not-yours (BOLA, api-security-checklist)
409duplicate or invalid state transitione.g. a unique-constraint violation (pgx 23505)
412a conditional request's precondition failedIf-Match version mismatch
413body too large
429rate-limitedinclude Retry-After
500genuinely unexpected onlynever for validation or not-found

The task's acceptance criteria or an existing contract always wins over this table.

Mapping database errors (Go, pgx)

Do the translation in the adapter, never in the handler:

go
switch {
case errors.Is(err, pgx.ErrNoRows):
    return domain.ErrNotFound
case isPGCode(err, "23505"):          // unique_violation
    return domain.ErrConflict
case isPGCode(err, "23503"):          // foreign_key_violation
    return domain.ErrInvalidReference
}

Pagination

  • Every list endpoint has a default page size (e.g. 20–50) and a enforced maximum (e.g. 100) — clamp silently or reject with 400, whichever the repo already does.
  • Deterministic order: ORDER BY created_at DESC, id DESC (a tiebreaker column prevents duplicate/missing rows across pages when timestamps collide).
  • Prefer keyset pagination over offset for anything that can grow past a few thousand rows: WHERE (created_at, id) < ($1, $2) ORDER BY created_at DESC, id DESC LIMIT $3+1, use the extra row to compute has_more, return an opaque next_cursor (base64 of the last row's sort key). Offset pagination (LIMIT/OFFSET) is fine for small, bounded tables only.
Show full SKILL.md (279 more words)Show less

Idempotency and concurrency

  • PUT and DELETE are idempotent by construction — calling them twice with the same input produces the same end state.
  • Make POST/create idempotent where duplicates are a real risk: a natural unique key with INSERT ... ON CONFLICT (key) DO NOTHING RETURNING ..., or an Idempotency-Key request header backed by a dedupe table, following the draft semantics: same key + same payload → replay the stored response; same key + different payload → 422; a second request with the same in-flight key → 409; a required key that's missing → 400.
  • Concurrent read-modify-write: optimistic locking with a version column (UPDATE ... SET ..., version = version + 1 WHERE id = $1 AND version = $2; zero rows affected → 409/412) or JPA @Version (java-persistence); or SELECT ... FOR UPDATE inside one transaction when the operation must serialize.

Compatibility

Evolve additively; prefer a new optional field over renaming one in place; readers should ignore fields they don't recognise rather than failing closed (api-contract-openapi has the breaking-change procedure).

Formats

RFC 3339 timestamps in UTC; money as a decimal string or integer minor units, never a float; ids as strings even when they're numeric internally, so a client never silently loses precision.

Worked Example

❌ POST /tasks twice with the same client-generated request → two rows, two 201s
✅ POST /tasks with Idempotency-Key: <uuid> twice → first 201, second replays the same 201 body

❌ GET /tasks?page=50 on a 2M-row table → OFFSET 500000, a sequential scan
✅ GET /tasks?after=<cursor>&limit=50 → keyset WHERE, index-only scan

Common Mistakes

  • Two different error shapes in the same service.
  • A list endpoint with a default page size but no enforced maximum.
  • A create endpoint with no idempotency story on a client that can legitimately retry (mobile, flaky network).
  • Offset pagination on a table that will outgrow a few thousand rows.
  • Money stored/returned as a float.

Red Flags

  • A 500 response body that is actually a validation failure.
  • OFFSET climbing past five digits in a hot path.
  • A version/@Version field present on the entity but never checked in the update query.

© makifbaysal, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in catalog/agents/backend-developer/skills/api-design-conventions of makifbaysal/tasktrooper.

Open the folder on GitHubat commit c4496d5

Compare with similar skills

API Design Conventions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Design Conventions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Design Conventions this skillmakifbaysal/tasktrooper112—~1.4kAutomated safety check: PassApache-2.0
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
Backend PatternshellangleZ/burn-in-cceverywhere-ralph11217 repos~3.3kAutomated safety check: PassNone
API Design Principlesjh941213/my-cc-harness12618 repos~3.4kAutomated safety check: PassNone

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated today
    Backend & APIsAuto-check passed
  • Backend Patterns

    hellangleZ/burn-in-cceverywhere-ralph

    Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

    112 GitHub starsUsed in 17 repos~3.3k tokens
    Backend & APIsAuto-check passed
  • API Design Principles

    jh941213/my-cc-harness

    REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.

    126 GitHub starsUsed in 18 repos~3.4k tokens
    Backend & APIsAuto-check passed
  • API And Interface Design

    dzhalaevd/Donatello

    Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 8 repos~2.6k tokens
    Backend & APIsAuto-check passed

More from makifbaysal/tasktrooper

All 12 skills in this repo
  • Acceptance Criteria Gwt

    makifbaysal/tasktrooper

    A skill your agent uses when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases

    112 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Access Control And Idor

    makifbaysal/tasktrooper

    A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

    112 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Check

    makifbaysal/tasktrooper

    A skill your agent uses when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task

    112 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Analiz Gate

    makifbaysal/tasktrooper

    A skill your agent uses when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation

    112 GitHub stars~679 tokensUpdated yesterday
    Auto-check passed
  • Analiz HTML Report

    makifbaysal/tasktrooper

    A skill your agent uses when you write or revise the analiz deliverable - the ONE self-contained HTML report (spec and plan as sections) a human reviews passage by passage

    112 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Analiz Human Review Gate

    makifbaysal/tasktrooper

    A skill your agent uses when you finish an analiz report - the human must approve the analysis before any implementation task is created, via the analizreview column

    112 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about API Design Conventions

What does API Design Conventions do?

A skill your agent uses when you design or change an endpoint's errors, status codes, pagination, idempotency or concurrency behaviour — one error shape, the status-code table, bounded lists, safe…. API Design Conventions is an agent skill from makifbaysal/tasktrooper.

When should I use API Design Conventions?

API Design Conventions fits situations like: change an endpoints errors; concurrency behaviour — one error shape; the status-code table.

How do I install API Design Conventions in Claude Code?

Run `npx skills add makifbaysal/tasktrooper --skill api-design-conventions -a claude-code`. Or copy the skill folder (catalog/agents/backend-developer/skills/api-design-conventions in makifbaysal/tasktrooper) into .claude/skills/api-design-conventions in your project. Claude Code loads it when a task matches its description.

How do I install API Design Conventions in Codex?

Run `npx skills add makifbaysal/tasktrooper --skill api-design-conventions -a codex`. Or copy the skill folder (catalog/agents/backend-developer/skills/api-design-conventions in makifbaysal/tasktrooper) into .agents/skills/api-design-conventions in your project. Codex loads it when a task matches its description.

Can I use API Design Conventions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add makifbaysal/tasktrooper --skill api-design-conventions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-design-conventions, .gemini/skills/api-design-conventions, .github/skills/api-design-conventions and .opencode/skills/api-design-conventions in your project.

What does API Design Conventions need to run?

SKILL.md names no scripts, command-line tools or credentials: API Design Conventions is instructions for the agent only.

Does API Design Conventions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Design Conventions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Design Conventions use?

API Design Conventions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Design Conventions use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Design Conventions?

Skills that share tags, products or a category with API Design Conventions: Nodejs Backend Patterns (ever-works/ever-works, 162 stars), API Designer (Jeffallan/claude-skills, 12k stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars) and Backend Patterns (hellangleZ/burn-in-cceverywhere-ralph, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Design Conventions?

makifbaysal (a GitHub user) maintains it in makifbaysal/tasktrooper, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: makifbaysal/tasktrooper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.