Agent skill

API Design

by selmakcby in selmakcby/claude-agents-skills

Backend API design specialist. An agent skill from selmakcby/claude-agents-skills.

MITAuto-check passedBackend & APIs

Install API Design

skills CLI
$ npx skills add selmakcby/claude-agents-skills --skill api-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install selmakcby/claude-agents-skills api-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/selmakcby/claude-agents-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/my-project-demo/.claude/skills/api-design .claude/skills/api-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-design
GitHub stars
136
Token cost
~1.1k tokens
SKILL.md length
369 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Backend API design specialist. An agent skill from selmakcby/claude-agents-skills.

  • Building REST/GraphQL APIs
  • SKILL.md covers When to trigger, Core RESTful principles, Endpoint design patterns and Security (mandatory), plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Designing endpoints

What it does

API Design is an agent skill from selmakcby/claude-agents-skills. Backend API design specialist. Use when building REST/GraphQL APIs, designing endpoints, data models, or backend architecture. Covers RESTful principles, HTTP semantics, error handling, versioning, and OWASP-aligned security.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API design, REST APIs and GraphQL. The repository describes itself as: Multi-Agent Claude Code setup — 4 uzman ajan (planner · ui-agent · builder · reviewer) + skills + Next.js demo projesi. YouTube Bölüm 1 video materyalleri. The licence is MIT.

When your agent uses it

  • Building REST/GraphQL APIs
  • Designing endpoints
  • Backend architecture

Example prompts

  • “/api-design”

What it can do on your machine

Read from SKILL.md and the folder at commit ddcfb0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Design loads about 1.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 369 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from selmakcby/claude-agents-skills at commit ddcfb0c, republished under its MIT licence (© selmakcby). 369 words, ~1,072 tokens.

Download SKILL.mdSave it as .claude/skills/api-design/SKILL.md (or your agent's skills folder).
name
api-design
description
Backend API design specialist. Use when building REST/GraphQL APIs, designing endpoints, data models, or backend architecture. Covers RESTful principles, HTTP semantics, error handling, versioning, and OWASP-aligned security.
<!--
  Source: wshobson/agents (backend-development plugin)
  File:   https://github.com/wshobson/agents/tree/main/plugins/backend-development/skills/api-design-principles
  Used by: builder agent (backend)
-->

API Design Principles

When to trigger

  • Designing a new API endpoint
  • Adding routes to existing API
  • Database schema work that affects API contract
  • Keywords: "endpoint", "API", "route", "backend", "server", "REST", "GraphQL"

Core RESTful principles

Resource-oriented URLs
  • Nouns, not verbs: /users/123, not /getUser?id=123
  • Pluralize resources: /orders, not /order
  • Nest only when expressing parent/child: /users/:id/orders
  • Max 2 levels deep — beyond that, use query params
HTTP methods (correct semantics)
MethodUse forIdempotentSafe
GETReadYesYes
POSTCreateNoNo
PUTReplace (full update)YesNo
PATCHPartial updateNo*No
DELETERemoveYesNo

* PATCH can be idempotent depending on semantics.

Status codes (correct use)
  • 200 OK — successful GET/PUT/PATCH with body
  • 201 Created — successful POST creating resource
  • 204 No Content — successful DELETE or action with no body
  • 400 Bad Request — validation failure
  • 401 Unauthorized — missing/invalid auth
  • 403 Forbidden — authenticated but not authorized
  • 404 Not Found — resource doesn't exist
  • 409 Conflict — version mismatch, duplicate resource
  • 422 Unprocessable Entity — semantic validation failure
  • 429 Too Many Requests — rate limited
  • 500 Internal Server Error — unhandled server fault
Response envelope

Consistent shape for all responses:

typescript
{
  success: boolean
  data: T | null
  error: string | null
  metadata?: { total, page, limit }
}

Endpoint design patterns

Pagination
  • Cursor-based for large/changing sets: ?cursor=abc&limit=20
  • Offset-based for small stable sets: ?page=1&limit=20
  • Always cap limit server-side (max 100)
Filtering
  • Query params: ?status=active&created_after=2024-01-01
  • Sort: ?sort=-created_at (minus prefix = descending)
Show full SKILL.md (159 more words)Show less
Versioning
  • URL path: /v1/users, /v2/users (easiest to deprecate)
  • Never introduce breaking changes to existing version

Security (mandatory)

  • Authentication — every non-public endpoint checks auth first
  • Authorization — row-level checks, not just auth-exists
  • Input validation — Zod schema on every request body + query
  • Rate limiting — public routes + AI/LLM routes especially
  • CORS — whitelist, not *
  • Output filtering — never leak internal IDs or PII in error messages
  • Webhook signatures — verify signature before trusting payload

Error handling

  • Never expose stack traces to the client
  • Log server-side with request ID
  • Return structured error: { code: "INVALID_INPUT", message: "...", field: "email" }
  • HTTP status code must match error type

Output format

markdown
## API Design Summary

### Endpoint
`<METHOD> /path/to/resource`

### Purpose
<what it does, who uses it>

### Request
- **Auth:** <required | optional>
- **Body schema:** Zod
- **Query params:** ...

### Response
- **200:** <shape>
- **Error cases:** 400, 401, 403, 404, 422, 429, 500

### Security checks
- [ ] Auth verified
- [ ] Authorization verified (row-level)
- [ ] Input validated (Zod)
- [ ] Rate limit applied
- [ ] PII not leaked in errors

### Dependencies
- Database tables: <list>
- External services: <list>

Rules

  • RESTful first. Only use GraphQL / RPC if there's a concrete reason.
  • No breaking changes to existing API versions. Ever.
  • Every endpoint validates input — no "we'll add validation later".
  • Every endpoint has a test (unit for business logic, integration for HTTP layer).
  • Document before coding. OpenAPI spec or at least a Markdown contract.
  • Rate limit on day 1 — retrofitting is painful.

© selmakcby, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in my-project-demo/.claude/skills/api-design of selmakcby/claude-agents-skills.

Open the folder on GitHubat commit ddcfb0c

Compare with similar skills

API Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Design this skillselmakcby/claude-agents-skills136—~1.1kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15818 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
Backend FundamentalsDanielPodolsky/ownyourcode2901 repos~1.1kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated today
    Backend & APIsAuto-check passed
  • Backend Fundamentals

    DanielPodolsky/ownyourcode

    Reviews API design, REST conventions, and backend architecture.

    290 GitHub starsUsed in 1 repo~1.1k tokens
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • API Design Interviewer

    PrepLabsAI/InterviewMentor

    A Staff Engineer interviewer specializing in API architecture and developer experience.

    112 GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from selmakcby/claude-agents-skills

All 8 skills in this repo
  • Plan

    selmakcby/claude-agents-skills

    Implementation planning specialist. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~548 tokensUpdated 5 mo ago
    Auto-check passed
  • UI UX Pro Max

    selmakcby/claude-agents-skills

    UI/UX design intelligence for web and mobile. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~777 tokensUpdated 5 mo ago
    Auto-check passed
  • UI UX Pro Max

    selmakcby/claude-agents-skills

    UI/UX design intelligence. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~393 tokensUpdated 5 mo ago
    Auto-check passed
  • Code Review

    selmakcby/claude-agents-skills

    Senior code review specialist. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~746 tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review

    selmakcby/claude-agents-skills

    AI-powered security vulnerability detection. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~963 tokensUpdated 5 mo ago
    Auto-check passed
  • Code Review

    selmakcby/claude-agents-skills

    Senior code review specialist. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~363 tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about API Design

What does API Design do?

Backend API design specialist. An agent skill from selmakcby/claude-agents-skills. API Design is an agent skill from selmakcby/claude-agents-skills. Backend API design specialist.

When should I use API Design?

API Design fits situations like: building REST/GraphQL APIs; designing endpoints; backend architecture.

How do I install API Design in Claude Code?

Run `npx skills add selmakcby/claude-agents-skills --skill api-design -a claude-code`. Or copy the skill folder (my-project-demo/.claude/skills/api-design in selmakcby/claude-agents-skills) into .claude/skills/api-design in your project. Claude Code loads it when a task matches its description.

How do I install API Design in Codex?

Run `npx skills add selmakcby/claude-agents-skills --skill api-design -a codex`. Or copy the skill folder (my-project-demo/.claude/skills/api-design in selmakcby/claude-agents-skills) into .agents/skills/api-design in your project. Codex loads it when a task matches its description.

Can I use API Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add selmakcby/claude-agents-skills --skill api-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-design, .gemini/skills/api-design, .github/skills/api-design and .opencode/skills/api-design in your project.

What does API Design need to run?

SKILL.md names no scripts, command-line tools or credentials: API Design is instructions for the agent only.

Does API Design access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is API Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Design use?

API Design is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Design use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Design?

Skills that share tags, products or a category with API Design: Nodejs Backend Patterns (ever-works/ever-works, 158 stars), API Designer (Jeffallan/claude-skills, 12k stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars) and Backend Fundamentals (DanielPodolsky/ownyourcode, 290 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Design?

selmakcby (a GitHub user) maintains it in selmakcby/claude-agents-skills, which has 136 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 21, 2026.

Source: selmakcby/claude-agents-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.