Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .claude/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .agents/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .cursor/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .gemini/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .github/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "azure-apim-architecture" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/azure-apim-architecture into .opencode/skills/azure-apim-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-apim-architecture", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
azure-apim-architecture
GitHub stars
202
Token cost
~5k tokens
SKILL.md length
1,807 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT
At a glance
Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…
Works in 11 steps: Azure Front Door Premium (Not… → VNet Internal Mode (Not External) → Separate APIM Instances per Environment… → …
Discussing APIM component selection
SKILL.md covers When to Use This Skill, Core Knowledge, Total Cost Summary and Steps to Apply This Skill, plus 3 more sections
Reaches learn.microsoft.com and login.microsoftonline.com
What it does
Azure Apim Architecture is an agent skill from thomast1906/github-copilot-agent-skills. Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies. Use when discussing APIM component selection, network topology, cost optimization, or comparing alternatives like workspaces vs instances, VNet Internal vs External mode, or Front Door vs Application Gateway.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication. It works with Azure API Management and Microsoft Azure. The repository describes itself as: Repo containing my GitHub Copilot Agent & Skills - continually experimenting! The licence is MIT.
When your agent uses it
Discussing APIM component selection
Network topology
Cost optimization
Comparing alternatives like workspaces vs instances
Example prompts
“Use the azure-apim-architecture skill to analyz and explains Azure API Management architecture decisions for enterprise API marketplace…”
“/azure-apim-architecture”
Workflow steps
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 554ac0b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and xml).
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
learn.microsoft.com
login.microsoftonline.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Azure Apim Architecture loads about 5k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 1,807 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~110
When it runs· the whole SKILL.md, loaded when a task matches
~5k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/azure-apim-architecture/SKILL.md (or your agent's skills folder).
name
azure-apim-architecture
description
Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies. Use when discussing APIM component selection, network topology, cost optimization, or comparing alternatives like workspaces vs instances, VNet Internal vs External mode, or Front Door vs Application Gateway.
Provides comprehensive guidance on Azure API Management architecture patterns for enterprise API marketplaces, including component selection, network topology, cost optimization, and design decision rationale.
When to Use This Skill
Activate this skill when users ask questions related to:
Component selection: "Should I use Azure Front Door or Application Gateway?"
Network architecture: "VNet Internal mode vs External mode?"
Multi-environment strategy: "Separate APIM instances or workspaces for dev/test/prod?"
Cost optimization: "How much will this cost in UK South?"
Authentication patterns: "OAuth vs subscription keys for public APIs?"
Design rationale: "Why did you choose X instead of Y?"
Core Knowledge
1. Azure Front Door Premium (Not Application Gateway)
Decision: Use Azure Front Door Premium as ingress layer
Rationale:
Built-in DDoS protection: Platform-level, included at no extra cost (saves £2,644/month vs separate Azure DDoS Standard)
Private Link support: Secure backend connectivity to APIM VNet Internal mode without public internet exposure
Global capabilities: Multi-POP network, future-proof for geographic expansion
WAF included: Managed OWASP rulesets for application security
Better for APIs: Optimized for HTTP/HTTPS routing, lower latency than App Gateway
Cost: £378/month (UK South) vs Application Gateway WAF v2 ~£350/month (similar cost, AFD offers more features)
Application Gateway: No global capabilities, requires separate DDoS (£2,644/mo), less optimized for API workloads
Direct APIM exposure: Not secure, no DDoS protection layer
2. VNet Internal Mode (Not External)
Decision: Deploy all APIM instances in VNet Internal mode
Rationale:
Maximum security: No public IP exposure, gateway endpoints accessible only within VNet via internal load balancer
Zero-trust architecture: All external access via Front Door → Private Link → APIM internal endpoint (Azure backbone, no internet)
Simplified attack surface: Only Front Door is internet-facing (single point of defense)
Compliance: Meets data residency and security requirements (no data leaving Azure network)
Internal API security: Private APIs accessible only within VNet without separate APIM instance
Microsoft Guidance:
"Use the internal VNet mode when you want to expose your API Management instance only to clients within the VNet. This mode provides maximum security by ensuring the gateway and management endpoints are accessible only via private IPs." - APIM VNet Modes
Network Flow:
Internet User → Azure Front Door (WAF, DDoS)
↓ Private Link (Azure backbone, no internet)
APIM Internal Endpoint (10.1.1.4, no public IP)
↓ VNet connectivity
Backend APIs (within VNet or peered VNets)
Key Implications:
Gateway endpoint: 10.1.1.4 (internal IP only, not registered in public DNS)
Developer portal: Accessed via VNet or Front Door with Private Link
Management endpoint: Requires VPN/Bastion or Azure portal (no public access)
Private DNS zones: azure-api.net resolves to internal IP within VNet
Warning: Complexity: Requires proper VNet configuration, Private DNS setup, Private Link approval
External Mode Rejected:
Gateway has public IP (even if restricted by NSGs)
3. Separate APIM Instances per Environment (Not Workspaces)
Decision: Use 3 separate APIM instances for dev/test/prod, not workspaces within a single instance
Rationale:
Cost optimization: Developer tier for dev/test (£45/month) vs Premium shared cost (£648/workspace if conceptually split)
Blast radius isolation: Dev changes cannot impact production (separate compute, configuration, secrets, networking)
Independent scaling: Scale prod (3 units zone-redundant) separately from dev (1 unit)
Environment-specific configuration: Different backends, rate limits, policies, secrets per environment without risk of cross-contamination
Deployment safety: Test promotes confidence before prod (true replica environments, not logical separation)
Compliance: Some frameworks require physical separation of production from non-production
Microsoft Guidance:
"Workspaces provide logical isolation within a single API Management instance for organizing APIs, products, and subscriptions by team or project. They're ideal for multi-tenant scenarios within the same environment, but don't provide compute or infrastructure isolation." - APIM Workspaces
Cost Comparison:
Approach
Dev
Test
Prod
Total
Separate Instances (recommended)
£45
£45
£1,944
£2,034/mo
Workspaces in Single Premium
£648*
£648*
£648*
£1,944/mo
*Workspaces share same Premium instance cost (£1,944/month), lack infrastructure isolation
When to Use Workspaces:
Logical separation within an environment (e.g., Team A APIs vs Team B APIs in same prod APIM)
RBAC per workspace (Team A can't see Team B APIs)
NOT for dev/test/prod separation (no compute, network, or secret isolation)
Decision: Deploy Azure API Center (Standard tier) at £135/month for centralized API governance
Rationale:
Multiple environments: Need visibility across dev/test/prod APIM instances (3 separate instances)
Scale: Expecting 50+ APIs at maturity across all environments
Governance: Centralized compliance checking, breaking change detection, API linting
Discovery: Developers need to find APIs across environments from single catalog
Cost: £135/month (4% of total prod budget) justified for governance value
Microsoft Guidance:
"Azure API Center enables organizations to develop and maintain a structured and standardized API inventory. API Center enables tracking all APIs in the organization, along with their versions, deployments, and dependencies." - API Center Overview
When API Center Adds Value:
50+ APIs: Manual tracking becomes unmanageable
Multiple teams: Different teams publishing APIs, need central registry
Multiple environments: 3 APIM instances (dev/test/prod) need unified view
Compliance requirements: Need audit trail of API changes, versions, owners
Breaking change detection: Auto-detect when API schemas change incompatibly
When You DON'T Need API Center:
<20 APIs: Manual tracking in spreadsheet is sufficient
Single team: Team knows all their APIs
No compliance requirements: No audit/governance needs
Key Features Used:
API Inventory: All APIs from dev/test/prod APIM instances registered
Metadata Management: Owner, domain, data classification per API
Compliance Checking: APIs tagged with frameworks (GDPR, PCI-DSS)
Version Tracking: All API versions visible (v1, v2, deprecated status)
Breaking Change Detection: Schema comparison between versions
API Linting: OpenAPI spec validation, naming convention enforcement
Cost: Standard tier £135/month UK South (includes unlimited APIs, compliance, linting)
Developer tier for dev/test: Saves £1,206/month vs Premium (93% savings)
No separate DDoS Standard: Front Door includes platform DDoS (saves £2,644/month)
Single region: No multi-region replication (saves £1,944/month)
Entra External ID: First 50k MAU free (saves £1,000+/month vs paid auth solution)
Total Architectural Savings: ~£5,850/month through design optimization
Steps to Apply This Skill
Step 1: Understand Current Architecture Question
Ask yourself:
Is user asking about component selection? (Front Door vs App Gateway, VNet mode, etc.)
Is user asking about cost? (How much will this cost?)
Is user asking for rationale? (Why did you choose X?)
Is user comparing alternatives? (Workspaces or separate instances?)
Step 2: Reference Knowledge Base
Match question to relevant section above:
Front Door vs App Gateway → Section 1
VNet Internal vs External → Section 2
Workspaces vs Instances → Section 3
OAuth vs Subscription Keys → Section 4
API Center justification → Section 5
Single-region strategy → Section 6
Cost breakdown → Total Cost Summary
Step 3: Structure Response
Format response with:
Decision or Recommendation (clear statement)
Rationale (3-5 bullet points)
Microsoft Documentation Link (with quote if applicable)
Cost Implications (in GBP UK South)
Alternatives Considered (with reasons for rejection)
Reference to Documentation (which document section for details)
Step 4: Cite Sources
Always reference:
Primary source: DESIGN_DECISIONS_REFERENCE.md (for "why" with alternatives)
Secondary source: ARCHITECTURE_DESIGN.md (for "how" with technical details)
Microsoft documentation: Official Azure docs with links
Step 5: Include Cost Context
When discussing any component, always mention:
Monthly cost in GBP for UK South region
How it fits into total budget (£3,430/month all environments)
Any cost optimization decisions made
Example Usage
Example 1: Component Selection
User: "Should I use Azure Front Door or Application Gateway?"
Response using this skill:
markdown
## Recommendation: Azure Front Door Premium
**Decision**: Use Azure Front Door Premium as ingress layer
**Rationale**:
- Built-in DDoS protection (platform-level, saves £2,644/month vs separate Azure DDoS Standard)
- Private Link support to APIM (secure backend connectivity without public internet)
- Global load balancing capabilities (future-proof for expansion)
- WAF with managed OWASP rulesets
- Better optimized for API workloads (lower latency)
**Cost Comparison**:
- Azure Front Door Premium: £378/month
- Application Gateway WAF v2: ~£350/month
- Similar cost, but AFD offers more features for API workloads
**Microsoft Documentation**:
[Azure Front Door Overview](https://learn.microsoft.com/azure/frontdoor/front-door-overview)
**Alternatives Considered**:
- Application Gateway: No global capabilities, requires separate DDoS (£2,644/mo), less suitable for API workloads
- Direct APIM exposure: Not secure, no DDoS layer
**Architecture Flow**:
Internet Users → Front Door (WAF, DDoS) → Private Link → APIM (VNet Internal) → Backends
**Documentation**: See DESIGN_DECISIONS_REFERENCE.md Section 1.1 for complete analysis
Example 2: Cost Inquiry
User: "What's the total cost for all three environments?"
Response using this skill:
markdown
## Total Cost: All Environments (GBP UK South)
| Environment | APIM Tier | Monthly Cost |
|-------------|-----------|--------------|
| Development | Developer | ~£100 |
| Test | Developer | ~£100 |
| Production | Premium (3u) | ~£3,230 |
| **TOTAL** | | **~£3,430/month** (~£41,160/year) |
### Production Environment Detail (£3,230/month)
APIM Premium (3u): £1,944
Azure Front Door: £378
Entra ID P2: £270
Monitoring: £270
API Center: £135
VNet + Private Link: £90
Misc: £143
### Cost Optimization Highlights
- Developer tier for dev/test: **Saves £1,206/month** (93% vs Premium)
- No separate DDoS: **Saves £2,644/month** (Front Door includes platform DDoS)
- Single region: **Saves £1,944/month** (no multi-region APIM)
- Entra External ID free tier: **Saves £1,000+/month** (vs paid auth solution)
**Total Architectural Savings**: ~£5,850/month through design optimization
**Documentation**: See ARCHITECTURE_DESIGN.md Section 9.1 for detailed cost breakdown
Related Skills
apim-policy-authoring - Use after architecture decisions to implement policies
api-security-review - Use to validate security of chosen architecture
apiops-deployment - Use to deploy the architecture with IaC
Azure Apim Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Azure Apim Architecture compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Azure Apim Architecture this skillthomast1906/github-copilot-agent-skills
Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…
Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…
Guides creating, updating, reviewing and validating GitHub Copilot agent skills, from deciding whether a skill is the right tool to structuring bundled resources.
Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
Looks up live Azure retail prices by SKU, service or region through the Azure MCP pricing tool, estimates template costs and compares regions, price types and savings plans.
Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…. Azure Apim Architecture is an agent skill from thomast1906/github-copilot-agent-skills. Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies.
When should I use Azure Apim Architecture?
Azure Apim Architecture fits situations like: discussing APIM component selection; network topology; cost optimization; comparing alternatives like workspaces vs instances.
How do I install Azure Apim Architecture in Claude Code?
Run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a claude-code`. Or copy the skill folder (.github/skills/azure-apim-architecture in thomast1906/github-copilot-agent-skills) into .claude/skills/azure-apim-architecture in your project. Claude Code loads it when a task matches its description.
How do I install Azure Apim Architecture in Codex?
Run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a codex`. Or copy the skill folder (.github/skills/azure-apim-architecture in thomast1906/github-copilot-agent-skills) into .agents/skills/azure-apim-architecture in your project. Codex loads it when a task matches its description.
Can I use Azure Apim Architecture in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-apim-architecture, .gemini/skills/azure-apim-architecture, .github/skills/azure-apim-architecture and .opencode/skills/azure-apim-architecture in your project.
What does Azure Apim Architecture need to run?
SKILL.md names no scripts, command-line tools or credentials: Azure Apim Architecture is instructions for the agent only.
Does Azure Apim Architecture access the network?
SKILL.md names 2 domains. In commands or code: learn.microsoft.com and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Is Azure Apim Architecture safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Azure Apim Architecture use?
Azure Apim Architecture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Azure Apim Architecture use?
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Azure Apim Architecture?
Skills that share tags, products or a category with Azure Apim Architecture: API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Azure Mgmt Apimanagement Py (microsoft/skills, 3.1k stars), Auth (microsoft/apm, 4k stars) and Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Azure Apim Architecture?
thomast1906 (a GitHub user) maintains it in thomast1906/github-copilot-agent-skills, which has 202 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.