Official agent skill

API Types

by supabase in supabase/supabase

Maintain Supabase API types. An agent skill from supabase/supabase.

OfficialApache-2.0Auto-check passedBackend & APIs

Install API Types

skills CLI
$ npx skills add supabase/supabase --skill api-types -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install supabase/supabase api-types --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/supabase/supabase.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/api-types .claude/skills/api-types && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-types
GitHub stars
111k
Token cost
~557 tokens
SKILL.md length
295 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maintain Supabase API types. An agent skill from supabase/supabase.

  • Works in 4 steps: Make the API/schema change and ensure it… → Update the committed types, either → Inspect and commit only the intended… → …
  • Changing generated API type declarations
  • SKILL.md covers Update types, Interpret verification and Pull requests
  • Calls pnpm

What it does

API Types is an agent skill from supabase/supabase, published by the product's own GitHub organization. Maintain Supabase API types. Use when changing generated API type declarations, OpenAPI schemas, or investigating API type deployment drift.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OpenAPI specifications. It works with Supabase, OpenAPI and pnpm. The repository describes itself as: The Postgres development platform. Supabase gives you a dedicated Postgres database to build your web, mobile, and AI applications. The licence is Apache-2.0.

When your agent uses it

  • Changing generated API type declarations
  • OpenAPI schemas
  • Investigating API type deployment drift

Example prompts

  • “/api-types”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Make the API/schema change and ensure it is deployed to production before relying on a type PR. Production is the merge-gate source of…
  2. Update the committed types, either
  3. Inspect and commit only the intended generated type changes.
  4. Run pnpm api:verify-types. It fetches the three production OpenAPI specs, regenerates types with the repository tooling, and compares them…

What it can do on your machine

Read from SKILL.md and the folder at commit 26c838a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Types loads about 557 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 295 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~557

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from supabase/supabase at commit 26c838a, republished under its Apache-2.0 licence (© supabase). 295 words, ~557 tokens.

Download SKILL.mdSave it as .claude/skills/api-types/SKILL.md (or your agent's skills folder).
name
api-types
description
Maintain Supabase API types. Use when changing generated API type declarations, OpenAPI schemas, or investigating API type deployment drift.

API types

The generated API contract has three specs: API v1, API v2, and Platform. Their committed outputs are packages/api-types/types/api-v1.d.ts, packages/api-types/types/api-v2.d.ts, and packages/api-types/types/platform.d.ts.

Update types

  1. Make the API/schema change and ensure it is deployed to production before relying on a type PR. Production is the merge-gate source of truth.
  2. Update the committed types, either:
    • Run pnpm api:codegen against a running local API environment. It fetches all three local OpenAPI specs and updates the committed files.
    • Or, if you don't have a local API environment running, run pnpm api:codegen:prod. It fetches the three production OpenAPI specs directly and overwrites the committed files with them (no diffing — it always writes).
  3. Inspect and commit only the intended generated type changes.
  4. Run pnpm api:verify-types. It fetches the three production OpenAPI specs, regenerates types with the repository tooling, and compares them with the committed files.

Complete the update only when pnpm api:verify-types passes after the production deployment is available. If you used api:codegen:prod, this should already pass since the committed files came straight from production.

Interpret verification

  • A pass means the committed generated declarations match all three production specs at the time of the check.
  • A mismatch means production and the committed files differ. If the API is not deployed, deploy it and rerun the check. If production is correct, regenerate and review the changed files.
  • A fetch failure means the production schema endpoint could not be read; fix or retry the endpoint before treating the result as a type mismatch.

Pull requests

The Verify production API types CI job runs when packages/api-types/types/** changes and performs the same production comparison. It is a required merge check. Run the local verifier before requesting review and treat a failed CI verification as production drift that must be resolved.

© supabase, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/api-types of supabase/supabase.

Open the folder on GitHubat commit 26c838a

Compare with similar skills

API Types next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Types compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Types this skillsupabase/supabase111k—~557Automated safety check: PassApache-2.0
Land TS MonoUKGovernmentBEIS/inspect_ai3k—~3kAutomated safety check: PassMIT
Aliyun Rds Supabasecinience/alicloud-skills397—~971Automated safety check: PassMIT
Cloud Agents Starterscalar/scalar16k—~1.4kAutomated safety check: PassMIT
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0
Step Partsearthtojake/text-to-cad18k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Land TS Mono

    UKGovernmentBEIS/inspect_ai

    Land a PR that requires a coordinated ts-mono submodule change.

    3k GitHub stars~3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Aliyun Rds Supabase

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud RDS Supabase (RDS AI Service 2025-05-07) via OpenAPI, including creating, starting/stopping/restarting instances, resetting passwords, querying…

    397 GitHub stars~971 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Minimal starter runbook for cloud agents to install dependencies, run packages, execute tests, and troubleshoot the Scalar monorepo quickly.

    16k GitHub stars~1.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Step Parts

    earthtojake/text-to-cad

    Find, evaluate, and download common purchasable CAD parts from step.parts, including named off-the-shelf actuators, servos, motors, electronics boards, connectors, screws, bolts, nuts, washers…

    18k GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed

More from supabase/supabase

All 22 skills in this repo
  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    Auto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Review The Docs

    supabase/supabase

    Official

    Review Supabase docs changes locally in your supabase/supabase checkout — either an open PR (triage, classify, verify) or your own branch before opening a PR (local self-review).

    111k GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Vitest

    supabase/supabase

    Official

    Vitest API and config reference (Jest-compatible) — mocking with vi., spies, fake timers, coverage configuration, fixtures, snapshots, and test filtering.

    111k GitHub starsUsed in 12 repos~1.1k tokens
    Auto-check passed
  • Safe SQL Execution

    supabase/supabase

    Official

    A skill your agent uses whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix…

    111k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Studio E2E Tests

    supabase/supabase

    Official

    Write and run Playwright E2E tests for Supabase Studio (e2e/studio).

    111k GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about API Types

What does API Types do?

Maintain Supabase API types. An agent skill from supabase/supabase. API Types is an agent skill from supabase/supabase, published by the product's own GitHub organization. Maintain Supabase API types.

When should I use API Types?

API Types fits situations like: changing generated API type declarations; openAPI schemas; investigating API type deployment drift.

How do I install API Types in Claude Code?

Run `npx skills add supabase/supabase --skill api-types -a claude-code`. Or copy the skill folder (.agents/skills/api-types in supabase/supabase) into .claude/skills/api-types in your project. Claude Code loads it when a task matches its description.

How do I install API Types in Codex?

Run `npx skills add supabase/supabase --skill api-types -a codex`. Or copy the skill folder (.agents/skills/api-types in supabase/supabase) into .agents/skills/api-types in your project. Codex loads it when a task matches its description.

Can I use API Types in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add supabase/supabase --skill api-types -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-types, .gemini/skills/api-types, .github/skills/api-types and .opencode/skills/api-types in your project.

What does API Types need to run?

Going by SKILL.md and its folder, API Types needs the command-line tools its instructions call (pnpm).

Does API Types access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Types safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Types use?

API Types is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Types use?

About 557 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Types?

Skills that share tags, products or a category with API Types: Land TS Mono (UKGovernmentBEIS/inspect_ai, 3k stars), Aliyun Rds Supabase (cinience/alicloud-skills, 397 stars), Cloud Agents Starter (scalar/scalar, 16k stars) and ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Types?

supabase (a GitHub organization, an official publisher) maintains it in supabase/supabase, which has 111,222 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.

Source: supabase/supabase on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.