Agent skill

Web API

by managedcode in managedcode/dotnet-skills

Build or maintain controller-based ASP.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns.

MITAuto-check passedDevelopment

Install Web API

skills CLI
$ npx skills add managedcode/dotnet-skills --skill web-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/dotnet-skills web-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/Frameworks/Web-API/skills/web-api .claude/skills/web-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web-api
GitHub stars
486
Token cost
~2.1k tokens
SKILL.md length
324 words
Files
4 (incl. references)
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Build or maintain controller-based ASP.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns.

  • Works in 6 steps: Use controllers when the API needs… → Keep controllers thin: map HTTP concerns… → Use clear DTO boundaries, explicit… → …
  • : working on controller-based APIs in ASP.NET Core
  • SKILL.md covers Trigger On, Workflow, Current Upstream Notes and Deliver, plus 7 more sections
  • Reaches tools.ietf.org

What it does

Web API is an agent skill from managedcode/dotnet-skills. Build or maintain controller-based ASP.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns. USE FOR: working on controller-based APIs in ASP.NET Core; needing controller-specific extensibility or conventions; migrating or reviewing existing API controllers and filters. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `manifest.json`, `references/anti-patterns.md` and `references/patterns.md`). Compatibility notes: Requires an ASP.NET Core API project that uses or should use controllers.

It sits in Development, covering Codebase knowledge for agents. It works with ASP.NET Core and OpenAPI. The repository describes itself as: Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini. The licence is MIT.

When your agent uses it

  • : working on controller-based APIs in ASP.NET Core
  • Needing controller-specific extensibility
  • Reviewing existing API controllers and filters
  • : unrelated stacks

Example prompts

  • “/web-api”

Requirements

  • Compatibility (from SKILL.md): Requires an ASP.NET Core API project that uses or should use controllers.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Use controllers when the API needs controller-centric features, not simply because older templates did so.
  2. Keep controllers thin: map HTTP concerns to application services or handlers, and avoid embedding data access and business rules directly…
  3. Use clear DTO boundaries, explicit validation, and predictable HTTP status behavior.
  4. Review authentication and authorization at both controller and endpoint levels so the API surface is not accidentally inconsistent.
  5. Keep OpenAPI generation, versioning, and error contract behavior deliberate rather than incidental.
  6. Use minimal-apis for new simple APIs instead of defaulting to controllers out of habit.

What it can do on your machine

Read from SKILL.md and the folder at commit 535dd55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • tools.ietf.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires an ASP.NET Core API project that uses or should use controllers.

    From compatibility in the SKILL.md frontmatter.

Context cost

Web API loads about 2.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 152 tokens; SKILL.md has 324 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/dotnet-skills at commit 535dd55, republished under its MIT licence (© managedcode). 324 words, ~2,088 tokens.

Download SKILL.mdSave it as .claude/skills/web-api/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
web-api
description
Build or maintain controller-based ASP.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns. USE FOR: working on controller-based APIs in ASP.NET Core; needing controller-specific extensibility or conventions; migrating or reviewing existing API controllers and filters. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
compatibility
Requires an ASP.NET Core API project that uses or should use controllers.

ASP.NET Core Web API

Trigger On

  • working on controller-based APIs in ASP.NET Core
  • needing controller-specific extensibility or conventions
  • migrating or reviewing existing API controllers and filters

Workflow

  1. Use controllers when the API needs controller-centric features, not simply because older templates did so.
  2. Keep controllers thin: map HTTP concerns to application services or handlers, and avoid embedding data access and business rules directly in actions.
  3. Use clear DTO boundaries, explicit validation, and predictable HTTP status behavior.
  4. Review authentication and authorization at both controller and endpoint levels so the API surface is not accidentally inconsistent.
  5. Keep OpenAPI generation, versioning, and error contract behavior deliberate rather than incidental.
  6. Use minimal-apis for new simple APIs instead of defaulting to controllers out of habit.

Current Upstream Notes

  • dotnet/aspnetcore v10.0.11 is servicing and updates the OpenAPI stack to 2.7.5; controller-based API guidance still depends on conventions, advanced model binding, OData, JsonPatch, and existing filters. Re-run generated-document and client contract checks after upgrading.
  • The August 2026 aspnetcore-10.0 overview keeps controller APIs alongside Minimal APIs rather than replacing them. Use the dedicated routing, OpenAPI, auth, and hosting pages before changing public API contracts.

Deliver

  • controller APIs with explicit contracts and policies
  • reduced controller bloat
  • tests or smoke checks for critical API behavior

Validate

  • controller features are actually justified
  • actions do not hide business logic and persistence details
  • HTTP semantics stay predictable across endpoints

Controller Structure

Use primary constructors (C# 12+) for dependency injection and keep controllers focused on HTTP concerns:

csharp
[ApiController]
[Route("api/[controller]")]
public class OrdersController(
    IOrderService orderService,
    ILogger<OrdersController> logger) : ControllerBase
{
    [HttpGet("{id:guid}")]
    [ProducesResponseType<OrderDto>(StatusCodes.Status200OK)]
    [ProducesResponseType(StatusCodes.Status404NotFound)]
    public async Task<IActionResult> GetById(Guid id, CancellationToken ct)
    {
        var order = await orderService.GetByIdAsync(id, ct);
        return order is null ? NotFound() : Ok(order);
    }

    [HttpPost]
    [ProducesResponseType<OrderDto>(StatusCodes.Status201Created)]
    [ProducesResponseType<ValidationProblemDetails>(StatusCodes.Status400BadRequest)]
    public async Task<IActionResult> Create(CreateOrderRequest request, CancellationToken ct)
    {
        var order = await orderService.CreateAsync(request, ct);
        return CreatedAtAction(nameof(GetById), new { id = order.Id }, order);
    }
}

Model Binding

Explicitly declare binding sources for clarity:

csharp
[HttpGet("{id:guid}")]
public async Task<IActionResult> GetWithOptions(
    [FromRoute] Guid id,
    [FromQuery] bool includeDeleted = false,
    [FromHeader(Name = "X-Correlation-Id")] string? correlationId = null,
    CancellationToken ct = default)
{
    // Route: id, Query: includeDeleted, Header: X-Correlation-Id
}

Use record types with required members for request DTOs:

csharp
public record CreateProductRequest
{
    public required string Name { get; init; }
    public required decimal Price { get; init; }
    public string? Description { get; init; }
    public IReadOnlyList<string> Tags { get; init; } = [];
}

Validation

Prefer FluentValidation for complex validation rules:

csharp
public class CreateOrderRequestValidator : AbstractValidator<CreateOrderRequest>
{
    public CreateOrderRequestValidator(IProductRepository products)
    {
        RuleFor(x => x.CustomerId)
            .NotEmpty()
            .WithMessage("Customer ID is required");

        RuleFor(x => x.Items)
            .NotEmpty()
            .WithMessage("Order must contain at least one item");

        RuleForEach(x => x.Items).ChildRules(item =>
        {
            item.RuleFor(i => i.ProductId)
                .NotEmpty()
                .MustAsync(async (id, ct) => await products.ExistsAsync(id, ct))
                .WithMessage("Product does not exist");

            item.RuleFor(i => i.Quantity)
                .GreaterThan(0)
                .LessThanOrEqualTo(100);
        });
    }
}

Configure consistent Problem Details responses:

csharp
builder.Services.Configure<ApiBehaviorOptions>(options =>
{
    options.InvalidModelStateResponseFactory = context =>
    {
        var problemDetails = new ValidationProblemDetails(context.ModelState)
        {
            Type = "https://tools.ietf.org/html/rfc7231#section-6.5.1",
            Title = "One or more validation errors occurred.",
            Status = StatusCodes.Status400BadRequest,
            Instance = context.HttpContext.Request.Path
        };

        return new BadRequestObjectResult(problemDetails);
    };
});

API Versioning

Configure URL path versioning:

csharp
builder.Services.AddApiVersioning(options =>
{
    options.DefaultApiVersion = new ApiVersion(1, 0);
    options.AssumeDefaultVersionWhenUnspecified = true;
    options.ReportApiVersions = true;
    options.ApiVersionReader = new UrlSegmentApiVersionReader();
})
.AddApiExplorer(options =>
{
    options.GroupNameFormat = "'v'VVV";
    options.SubstituteApiVersionInUrl = true;
});

[ApiController]
[Route("api/v{version:apiVersion}/products")]
[ApiVersion("1.0")]
public class ProductsV1Controller(IProductService productService) : ControllerBase
{
    [HttpGet("{id}")]
    public async Task<IActionResult> Get(int id, CancellationToken ct)
    {
        var product = await productService.GetAsync(id, ct);
        return Ok(product);
    }
}

Exception Handling

Use global exception handlers for consistent error responses:

csharp
public class GlobalExceptionHandler(
    ILogger<GlobalExceptionHandler> logger) : IExceptionHandler
{
    public async ValueTask<bool> TryHandleAsync(
        HttpContext httpContext,
        Exception exception,
        CancellationToken cancellationToken)
    {
        logger.LogError(exception, "Unhandled exception occurred");

        var problemDetails = exception switch
        {
            ValidationException validationEx => new ProblemDetails
            {
                Status = StatusCodes.Status400BadRequest,
                Title = "Validation Error",
                Detail = validationEx.Message
            },
            NotFoundException notFoundEx => new ProblemDetails
            {
                Status = StatusCodes.Status404NotFound,
                Title = "Resource Not Found",
                Detail = notFoundEx.Message
            },
            _ => new ProblemDetails
            {
                Status = StatusCodes.Status500InternalServerError,
                Title = "Internal Server Error"
            }
        };

        problemDetails.Extensions["traceId"] = httpContext.TraceIdentifier;

        httpContext.Response.StatusCode = problemDetails.Status ?? 500;
        await httpContext.Response.WriteAsJsonAsync(problemDetails, cancellationToken);

        return true;
    }
}

References

  • patterns.md - Controller patterns, model binding, validation, versioning, response handling, and filter patterns
  • anti-patterns.md - Common API mistakes to avoid including fat controllers, inconsistent errors, missing cancellation tokens, and improper HTTP semantics

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in catalog/Frameworks/Web-API/skills/web-api of managedcode/dotnet-skills.

  • SKILL.md
  • manifest.json
  • references/anti-patterns.md
  • references/patterns.md

Open the folder on GitHubat commit 535dd55

Compare with similar skills

Web API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web API this skillmanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT
Workspacealinaqi/maggy707—~7.3kAutomated safety check: PassMIT
Tsp Csharpquerylenshq/ef-querylens225—~1.3kAutomated safety check: PassMIT
Speakeasy Contexttrycompai/comp2k—~221Automated safety check: PassApache-2.0
Codebase Contexthomarr-labs/homarr5k—~679Automated safety check: PassApache-2.0
API Versioningcodewithmukesh/dotnet-claude-kit7511 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Workspace

    alinaqi/maggy

    Dynamic multi-repo and monorepo awareness for Claude Code. An agent skill from alinaqi/maggy.

    707 GitHub stars~7.3k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Tsp Csharp

    querylenshq/ef-querylens

    Comprehensive C and .NET development skill for TSP projects.

    225 GitHub stars~1.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Speakeasy Context

    trycompai/comp

    Speakeasy workflow: run 'agent context' FIRST, do task, run 'agent feedback' LAST.

    2k GitHub stars~221 tokensUpdated today
    Backend & APIsAuto-check passed
  • Codebase Context

    homarr-labs/homarr

    Navigate Homarr's monorepo architecture and reuse shared packages.

    5k GitHub stars~679 tokensUpdated today
    DevelopmentAuto-check passed
  • API Versioning

    codewithmukesh/dotnet-claude-kit

    API versioning strategies for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.2k tokens
    Backend & APIsAuto-check passed
  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed

More from managedcode/dotnet-skills

All 81 skills in this repo
  • Analyzer Config

    managedcode/dotnet-skills

    Use a repo-root .editorconfig to configure free .NET analyzer and style rules.

    486 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Archunitnet

    managedcode/dotnet-skills

    Use the open-source free ArchUnitNET library for architecture rules in .NET tests.

    486 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aspire

    managedcode/dotnet-skills

    Build, upgrade, and operate Aspire 13.5.x C or TypeScript application hosts with the current CLI, AppHost, ServiceDefaults, integrations, dashboard, testing, MCP, and deployment patterns for…

    486 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Aspnet Core

    managedcode/dotnet-skills

    Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

    486 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Azure Functions

    managedcode/dotnet-skills

    Build, review, or migrate Azure Functions in .NET with correct execution model, isolated worker setup, bindings, DI, and Durable Functions patterns.

    486 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Web API

What does Web API do?

Build or maintain controller-based ASP.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns. Web API is an agent skill from managedcode/dotnet-skills.NET Core APIs when the project needs controller conventions, advanced model binding, validation extensions, OData, JsonPatch, or existing API patterns.

When should I use Web API?

Web API fits situations like: : working on controller-based APIs in ASP.NET Core; needing controller-specific extensibility; reviewing existing API controllers and filters; : unrelated stacks.

How do I install Web API in Claude Code?

Run `npx skills add managedcode/dotnet-skills --skill web-api -a claude-code`. Or copy the skill folder (catalog/Frameworks/Web-API/skills/web-api in managedcode/dotnet-skills) into .claude/skills/web-api in your project. Claude Code loads it when a task matches its description.

How do I install Web API in Codex?

Run `npx skills add managedcode/dotnet-skills --skill web-api -a codex`. Or copy the skill folder (catalog/Frameworks/Web-API/skills/web-api in managedcode/dotnet-skills) into .agents/skills/web-api in your project. Codex loads it when a task matches its description.

Can I use Web API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/dotnet-skills --skill web-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-api, .gemini/skills/web-api, .github/skills/web-api and .opencode/skills/web-api in your project.

What does Web API need to run?

SKILL.md names no scripts, command-line tools or credentials: Web API is instructions for the agent only. Compatibility (from SKILL.md): Requires an ASP.NET Core API project that uses or should use controllers..

Does Web API access the network?

SKILL.md names 1 domain. In commands or code: tools.ietf.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Web API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web API use?

Web API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web API use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.7k tokens, read only when the agent opens those files.

What are the alternatives to Web API?

Skills that share tags, products or a category with Web API: Workspace (alinaqi/maggy, 707 stars), Tsp Csharp (querylenshq/ef-querylens, 225 stars), Speakeasy Context (trycompai/comp, 2k stars) and Codebase Context (homarr-labs/homarr, 5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web API?

managedcode (a GitHub organization) maintains it in managedcode/dotnet-skills, which has 486 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.