Agent skill

Azure Apim Architecture

by thomast1906 in thomast1906/github-copilot-agent-skills

Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…

MITAuto-check passedBackend & APIs

Install Azure Apim Architecture

skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thomast1906/github-copilot-agent-skills azure-apim-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azure-apim-architecture .claude/skills/azure-apim-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-apim-architecture
GitHub stars
202
Token cost
~5k tokens
SKILL.md length
1,807 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…

  • Works in 11 steps: Azure Front Door Premium (Not… → VNet Internal Mode (Not External) → Separate APIM Instances per Environment… → …
  • Discussing APIM component selection
  • SKILL.md covers When to Use This Skill, Core Knowledge, Total Cost Summary and Steps to Apply This Skill, plus 3 more sections
  • Reaches learn.microsoft.com and login.microsoftonline.com

What it does

Azure Apim Architecture is an agent skill from thomast1906/github-copilot-agent-skills. Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies. Use when discussing APIM component selection, network topology, cost optimization, or comparing alternatives like workspaces vs instances, VNet Internal vs External mode, or Front Door vs Application Gateway.

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Azure API Management and Microsoft Azure. The repository describes itself as: Repo containing my GitHub Copilot Agent & Skills - continually experimenting! The licence is MIT.

When your agent uses it

  • Discussing APIM component selection
  • Network topology
  • Cost optimization
  • Comparing alternatives like workspaces vs instances

Example prompts

  • “Use the azure-apim-architecture skill to analyz and explains Azure API Management architecture decisions for enterprise API marketplace…”
  • “/azure-apim-architecture”

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. Azure Front Door Premium (Not Application Gateway)
  2. VNet Internal Mode (Not External)
  3. Separate APIM Instances per Environment (Not Workspaces)
  4. Hybrid Authentication (OAuth + Subscription Keys)
  5. Azure API Center Included
  6. UK South Single-Region
  7. Understand Current Architecture Question
  8. Reference Knowledge Base
  9. Structure Response
  10. Cite Sources
  11. Include Cost Context

What it can do on your machine

Read from SKILL.md and the folder at commit 554ac0b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and xml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com
    • login.microsoftonline.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Apim Architecture loads about 5k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 1,807 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thomast1906/github-copilot-agent-skills at commit 554ac0b, republished under its MIT licence (© thomast1906). 1,807 words, ~5,048 tokens.

Download SKILL.mdSave it as .claude/skills/azure-apim-architecture/SKILL.md (or your agent's skills folder).
name
azure-apim-architecture
description
Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies. Use when discussing APIM component selection, network topology, cost optimization, or comparing alternatives like workspaces vs instances, VNet Internal vs External mode, or Front Door vs Application Gateway.
license
MIT
metadata.author
Thomas Thornton
metadata.version
1.0.0
metadata.last-updated
2026-05-19
metadata.azure-services
api-management, front-door, vnet, private-link, api-center

Azure APIM Architecture Skill

Provides comprehensive guidance on Azure API Management architecture patterns for enterprise API marketplaces, including component selection, network topology, cost optimization, and design decision rationale.

When to Use This Skill

Activate this skill when users ask questions related to:

  • Component selection: "Should I use Azure Front Door or Application Gateway?"
  • Network architecture: "VNet Internal mode vs External mode?"
  • Multi-environment strategy: "Separate APIM instances or workspaces for dev/test/prod?"
  • Cost optimization: "How much will this cost in UK South?"
  • Authentication patterns: "OAuth vs subscription keys for public APIs?"
  • Design rationale: "Why did you choose X instead of Y?"

Core Knowledge

1. Azure Front Door Premium (Not Application Gateway)

Decision: Use Azure Front Door Premium as ingress layer

Rationale:

  • Built-in DDoS protection: Platform-level, included at no extra cost (saves £2,644/month vs separate Azure DDoS Standard)
  • Private Link support: Secure backend connectivity to APIM VNet Internal mode without public internet exposure
  • Global capabilities: Multi-POP network, future-proof for geographic expansion
  • WAF included: Managed OWASP rulesets for application security
  • Better for APIs: Optimized for HTTP/HTTPS routing, lower latency than App Gateway

Cost: £378/month (UK South) vs Application Gateway WAF v2 ~£350/month (similar cost, AFD offers more features)

Microsoft Docs: Azure Front Door Overview

Alternatives Rejected:

  • Application Gateway: No global capabilities, requires separate DDoS (£2,644/mo), less optimized for API workloads
  • Direct APIM exposure: Not secure, no DDoS protection layer

2. VNet Internal Mode (Not External)

Decision: Deploy all APIM instances in VNet Internal mode

Rationale:

  • Maximum security: No public IP exposure, gateway endpoints accessible only within VNet via internal load balancer
  • Zero-trust architecture: All external access via Front Door → Private Link → APIM internal endpoint (Azure backbone, no internet)
  • Simplified attack surface: Only Front Door is internet-facing (single point of defense)
  • Compliance: Meets data residency and security requirements (no data leaving Azure network)
  • Internal API security: Private APIs accessible only within VNet without separate APIM instance

Microsoft Guidance:

"Use the internal VNet mode when you want to expose your API Management instance only to clients within the VNet. This mode provides maximum security by ensuring the gateway and management endpoints are accessible only via private IPs." - APIM VNet Modes

Network Flow:

Internet User → Azure Front Door (WAF, DDoS)
    ↓ Private Link (Azure backbone, no internet)
APIM Internal Endpoint (10.1.1.4, no public IP)
    ↓ VNet connectivity
Backend APIs (within VNet or peered VNets)

Key Implications:

  • Gateway endpoint: 10.1.1.4 (internal IP only, not registered in public DNS)
  • Developer portal: Accessed via VNet or Front Door with Private Link
  • Management endpoint: Requires VPN/Bastion or Azure portal (no public access)
  • Private DNS zones: azure-api.net resolves to internal IP within VNet
  • Warning: Complexity: Requires proper VNet configuration, Private DNS setup, Private Link approval

External Mode Rejected:

  • Gateway has public IP (even if restricted by NSGs)
  • Larger attack surface
  • Cannot enforce 100% private traffic flow

Microsoft Docs: APIM VNet Integration


3. Separate APIM Instances per Environment (Not Workspaces)

Decision: Use 3 separate APIM instances for dev/test/prod, not workspaces within a single instance

Rationale:

  • Cost optimization: Developer tier for dev/test (£45/month) vs Premium shared cost (£648/workspace if conceptually split)
  • Blast radius isolation: Dev changes cannot impact production (separate compute, configuration, secrets, networking)
  • Independent scaling: Scale prod (3 units zone-redundant) separately from dev (1 unit)
  • Environment-specific configuration: Different backends, rate limits, policies, secrets per environment without risk of cross-contamination
  • Deployment safety: Test promotes confidence before prod (true replica environments, not logical separation)
  • Compliance: Some frameworks require physical separation of production from non-production

Microsoft Guidance:

"Workspaces provide logical isolation within a single API Management instance for organizing APIs, products, and subscriptions by team or project. They're ideal for multi-tenant scenarios within the same environment, but don't provide compute or infrastructure isolation." - APIM Workspaces

Cost Comparison:

ApproachDevTestProdTotal
Separate Instances (recommended)£45£45£1,944£2,034/mo
Workspaces in Single Premium£648*£648*£648*£1,944/mo

*Workspaces share same Premium instance cost (£1,944/month), lack infrastructure isolation

When to Use Workspaces:

  • Logical separation within an environment (e.g., Team A APIs vs Team B APIs in same prod APIM)
  • RBAC per workspace (Team A can't see Team B APIs)
  • NOT for dev/test/prod separation (no compute, network, or secret isolation)

Configuration:

Development:
- APIM: apim-api-marketplace-dev-uks (Developer tier, 1 unit)
- VNet: vnet-dev-uks (10.0.0.0/16)
- Cost: £45/month + supporting services (~£55) = ~£100/month total

Test:
- APIM: apim-api-marketplace-test-uks (Developer tier, 1 unit)
- VNet: vnet-test-uks (10.1.0.0/16)
- Cost: £45/month + supporting services (~£55) = ~£100/month total

Production:
- APIM: apim-api-marketplace-prod-uks (Premium tier, 3 units, zone-redundant)
- VNet: vnet-prod-uks (10.2.0.0/16)
- Cost: £1,944/month + Front Door £378 + monitoring £270 + API Center £135 + other = ~£3,230/month

Microsoft Docs: APIM Workspaces Overview


4. Hybrid Authentication (OAuth + Subscription Keys)

Decision: Use hybrid authentication strategy - OAuth 2.0 for sensitive/internal APIs, subscription keys for simple public APIs

Rationale:

  • Flexibility: Different API types have different security and UX needs
  • User experience: Public read-only APIs don't need complex OAuth flows (lower barrier to entry, faster onboarding)
  • Security: Sensitive data (PII, financial) protected by OAuth with proven user identity
  • Partner compatibility: Some B2B partners prefer traditional API keys over OAuth client credentials
  • Rate limiting options: Can limit per-user (OAuth sub claim) or per-subscription (shared keys)

Authentication Decision Matrix:

API TypeAuth MethodJustificationExample
Public Read-OnlySubscription KeysLow security risk, easy onboarding, no PIIWeather API, Public Holidays
Internal CorporateOAuth 2.0 (Entra ID)User identity required, RBAC, audit trailEmployee Directory, HR Systems
Sensitive PublicOAuth 2.0 (Entra External ID B2C)Handles PII/financial, user consentPayment Processing, Health Records
Partner B2BOAuth 2.0 Client CredentialsMachine-to-machine, mTLS optionalOrder Management, Inventory Sync

Rate Limiting Strategy:

  • OAuth authenticated users: 1000 requests/hour per user (sub claim from JWT)
  • Subscription key users: 500 requests/hour per subscription (shared if multi-user app)
  • Rationale: OAuth users have proven identity (higher trust), subscription keys might be shared

Policy Implementation (abbreviated):

xml
<choose>
    <when condition="@(context.Request.Headers.GetValueOrDefault('Authorization','').StartsWith('Bearer'))">
        <validate-jwt header-name="Authorization">
            <openid-config url="https://login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration" />
        </validate-jwt>
        <rate-limit-by-key calls="1000" renewal-period="3600" 
                           counter-key="@(context.Request.Headers.GetValueOrDefault('Authorization','').AsJwt()?.Subject)" />
    </when>
    <otherwise>
        <check-header name="Ocp-Apim-Subscription-Key" />
        <rate-limit-by-key calls="500" renewal-period="3600" 
                           counter-key="@(context.Subscription.Key)" />
    </otherwise>
</choose>

Microsoft Docs: Protect backend with Entra ID


5. Azure API Center Included

Decision: Deploy Azure API Center (Standard tier) at £135/month for centralized API governance

Rationale:

  • Multiple environments: Need visibility across dev/test/prod APIM instances (3 separate instances)
  • Scale: Expecting 50+ APIs at maturity across all environments
  • Governance: Centralized compliance checking, breaking change detection, API linting
  • Discovery: Developers need to find APIs across environments from single catalog
  • Cost: £135/month (4% of total prod budget) justified for governance value

Microsoft Guidance:

"Azure API Center enables organizations to develop and maintain a structured and standardized API inventory. API Center enables tracking all APIs in the organization, along with their versions, deployments, and dependencies." - API Center Overview

When API Center Adds Value:

  • 50+ APIs: Manual tracking becomes unmanageable
  • Multiple teams: Different teams publishing APIs, need central registry
  • Multiple environments: 3 APIM instances (dev/test/prod) need unified view
  • Compliance requirements: Need audit trail of API changes, versions, owners
  • Breaking change detection: Auto-detect when API schemas change incompatibly

When You DON'T Need API Center:

  • <20 APIs: Manual tracking in spreadsheet is sufficient
  • Single team: Team knows all their APIs
  • No compliance requirements: No audit/governance needs

Key Features Used:

  1. API Inventory: All APIs from dev/test/prod APIM instances registered
  2. Metadata Management: Owner, domain, data classification per API
  3. Compliance Checking: APIs tagged with frameworks (GDPR, PCI-DSS)
  4. Version Tracking: All API versions visible (v1, v2, deprecated status)
  5. Breaking Change Detection: Schema comparison between versions
  6. API Linting: OpenAPI spec validation, naming convention enforcement

Cost: Standard tier £135/month UK South (includes unlimited APIs, compliance, linting)

Microsoft Docs: API Center Overview


Show full SKILL.md (690 more words)Show less
6. UK South Single-Region

Decision: Deploy all resources in UK South only, no multi-region/DR to other regions

Rationale:

  • Data residency: UK data must stay in UK (regulatory requirement)
  • Simplicity: No cross-region replication complexity or latency
  • Cost optimization: Multi-region APIM Premium would be £1,944 × 2 = £3,888/month
  • Zone redundancy sufficient: APIM Premium with 3 units across 3 availability zones in UK South provides 99.99% SLA (4.38 minutes downtime/month)
  • Business requirement: All consumers in UK/Europe, low latency from UK South sufficient

High Availability Strategy (Single-Region):

  • APIM Premium: 3 units across 3 availability zones → 99.99% SLA
  • Azure Front Door: Multi-POP global network (but origin in UK South only)
  • Zone failure: Auto-failover within UK South zones (no manual intervention)
  • Backups: Geo-redundant storage (GRS) to UK West (disaster recovery)

When Multi-Region WOULD Be Needed:

  • Global user base (US, Asia) requiring <100ms latency globally
  • Business continuity requires < 1 hour RTO (single-region outage)
  • Compliance requires active-active across geographies
  • Traffic > 10,000 requests/second (need geo-distribution)

DR Strategy (Without Multi-Region Active-Active):

  1. Backups: Nightly APIM backup to Storage (GRS to UK West)
  2. IaC: All infrastructure in Bicep/Terraform (can redeploy to UK West in ~2 hours)
  3. APIOps: All API configs in Git (restore from source control)
  4. RTO/RPO: RTO 4 hours, RPO 24 hours (acceptable for business)

Cost Avoidance: Saves ~£2,100/month by staying single-region

Microsoft Docs: APIM High Availability


Total Cost Summary

All Environments (GBP UK South)
EnvironmentAPIM TierMonthly Cost
DevelopmentDeveloper~£100
TestDeveloper~£100
ProductionPremium (3u)~£3,230
TOTAL~£3,430/month (~£41,160/year)
Production Environment Breakdown (£3,230/month)
ComponentConfigurationMonthly Cost
API Management (Premium)3 units (zone-redundant)£1,944
Azure Front Door (Premium)100GB, 1M requests£378
Microsoft Entra ID (P2)100 users£270
Entra External ID (B2C)50k MAU£0 (free tier)
Azure Monitor + App Insights100GB logs£270
Azure API CenterStandard£135
VNet + Private Link10 endpoints£90
Key Vault + Misc£143
Cost Optimization Decisions
  1. Developer tier for dev/test: Saves £1,206/month vs Premium (93% savings)
  2. No separate DDoS Standard: Front Door includes platform DDoS (saves £2,644/month)
  3. Single region: No multi-region replication (saves £1,944/month)
  4. Entra External ID: First 50k MAU free (saves £1,000+/month vs paid auth solution)

Total Architectural Savings: ~£5,850/month through design optimization


Steps to Apply This Skill

Step 1: Understand Current Architecture Question

Ask yourself:

  • Is user asking about component selection? (Front Door vs App Gateway, VNet mode, etc.)
  • Is user asking about cost? (How much will this cost?)
  • Is user asking for rationale? (Why did you choose X?)
  • Is user comparing alternatives? (Workspaces or separate instances?)
Step 2: Reference Knowledge Base

Match question to relevant section above:

  1. Front Door vs App Gateway → Section 1
  2. VNet Internal vs External → Section 2
  3. Workspaces vs Instances → Section 3
  4. OAuth vs Subscription Keys → Section 4
  5. API Center justification → Section 5
  6. Single-region strategy → Section 6
  7. Cost breakdown → Total Cost Summary
Step 3: Structure Response

Format response with:

  1. Decision or Recommendation (clear statement)
  2. Rationale (3-5 bullet points)
  3. Microsoft Documentation Link (with quote if applicable)
  4. Cost Implications (in GBP UK South)
  5. Alternatives Considered (with reasons for rejection)
  6. Reference to Documentation (which document section for details)
Step 4: Cite Sources

Always reference:

  • Primary source: DESIGN_DECISIONS_REFERENCE.md (for "why" with alternatives)
  • Secondary source: ARCHITECTURE_DESIGN.md (for "how" with technical details)
  • Microsoft documentation: Official Azure docs with links
Step 5: Include Cost Context

When discussing any component, always mention:

  • Monthly cost in GBP for UK South region
  • How it fits into total budget (£3,430/month all environments)
  • Any cost optimization decisions made

Example Usage

Example 1: Component Selection

User: "Should I use Azure Front Door or Application Gateway?"

Response using this skill:

markdown
## Recommendation: Azure Front Door Premium

**Decision**: Use Azure Front Door Premium as ingress layer

**Rationale**:
- Built-in DDoS protection (platform-level, saves £2,644/month vs separate Azure DDoS Standard)
- Private Link support to APIM (secure backend connectivity without public internet)
- Global load balancing capabilities (future-proof for expansion)
- WAF with managed OWASP rulesets
- Better optimized for API workloads (lower latency)

**Cost Comparison**:
- Azure Front Door Premium: £378/month
- Application Gateway WAF v2: ~£350/month
- Similar cost, but AFD offers more features for API workloads

**Microsoft Documentation**:
[Azure Front Door Overview](https://learn.microsoft.com/azure/frontdoor/front-door-overview)

**Alternatives Considered**:
- Application Gateway: No global capabilities, requires separate DDoS (£2,644/mo), less suitable for API workloads
- Direct APIM exposure: Not secure, no DDoS layer

**Architecture Flow**:
Internet Users → Front Door (WAF, DDoS) → Private Link → APIM (VNet Internal) → Backends

**Documentation**: See DESIGN_DECISIONS_REFERENCE.md Section 1.1 for complete analysis

Example 2: Cost Inquiry

User: "What's the total cost for all three environments?"

Response using this skill:

markdown
## Total Cost: All Environments (GBP UK South)

| Environment | APIM Tier | Monthly Cost |
|-------------|-----------|--------------|
| Development | Developer | ~£100 |
| Test | Developer | ~£100 |
| Production | Premium (3u) | ~£3,230 |
| **TOTAL** | | **~£3,430/month** (~£41,160/year) |

### Production Environment Detail (£3,230/month)

APIM Premium (3u): £1,944  
Azure Front Door: £378  
Entra ID P2: £270  
Monitoring: £270  
API Center: £135  
VNet + Private Link: £90  
Misc: £143

### Cost Optimization Highlights

- Developer tier for dev/test: **Saves £1,206/month** (93% vs Premium)
- No separate DDoS: **Saves £2,644/month** (Front Door includes platform DDoS)
- Single region: **Saves £1,944/month** (no multi-region APIM)
- Entra External ID free tier: **Saves £1,000+/month** (vs paid auth solution)

**Total Architectural Savings**: ~£5,850/month through design optimization

**Documentation**: See ARCHITECTURE_DESIGN.md Section 9.1 for detailed cost breakdown

  • apim-policy-authoring - Use after architecture decisions to implement policies
  • api-security-review - Use to validate security of chosen architecture
  • apiops-deployment - Use to deploy the architecture with IaC


Skill Version: 1.0
Last Updated: 29 January 2026
Primary Documents: DESIGN_DECISIONS_REFERENCE.md, ARCHITECTURE_DESIGN.md
Related MCP Tools: azure_documental search, azure_bestpractices

© thomast1906, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/azure-apim-architecture of thomast1906/github-copilot-agent-skills.

Open the folder on GitHubat commit 554ac0b

Compare with similar skills

Azure Apim Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Apim Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Apim Architecture this skillthomast1906/github-copilot-agent-skills202—~5kAutomated safety check: PassMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Azure Mgmt Apimanagement Pymicrosoft/skills3.1k5 repos~2.2kAutomated safety check: PassMIT
Authmicrosoft/apm4k—~756Automated safety check: PassMIT
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Azure Identity Pyaiskillstore/marketplace4334 repos~1.4kAutomated safety check: PassNone

Similar skills

  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Official

    Azure API Management SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Auth

    microsoft/apm

    Official

    Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

    4k GitHub stars~756 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Azure Identity Py

    aiskillstore/marketplace

    Azure Identity SDK for Python authentication. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 4 repos~1.4k tokens
    Backend & APIsAuto-check passed
  • Azure Identity Py

    microsoft/skills

    Official

    Azure Identity SDK for Python authentication with Microsoft Entra ID.

    3.1k GitHub stars~4.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from thomast1906/github-copilot-agent-skills

All 15 skills in this repo
  • Copilot Skill Creator

    thomast1906/github-copilot-agent-skills

    Guides creating, updating, reviewing and validating GitHub Copilot agent skills, from deciding whether a skill is the right tool to structuring bundled resources.

    202 GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Azure Draw.io MCP Diagrams

    thomast1906/github-copilot-agent-skills

    Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Azure Pricing Lookup

    thomast1906/github-copilot-agent-skills

    Looks up live Azure retail prices by SKU, service or region through the Azure MCP pricing tool, estimates template costs and compares regions, price types and savings plans.

    202 GitHub stars~4.9k tokensUpdated 3 days ago
    Auto-check passed

Questions about Azure Apim Architecture

What does Azure Apim Architecture do?

Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment…. Azure Apim Architecture is an agent skill from thomast1906/github-copilot-agent-skills. Analyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies.

When should I use Azure Apim Architecture?

Azure Apim Architecture fits situations like: discussing APIM component selection; network topology; cost optimization; comparing alternatives like workspaces vs instances.

How do I install Azure Apim Architecture in Claude Code?

Run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a claude-code`. Or copy the skill folder (.github/skills/azure-apim-architecture in thomast1906/github-copilot-agent-skills) into .claude/skills/azure-apim-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Azure Apim Architecture in Codex?

Run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a codex`. Or copy the skill folder (.github/skills/azure-apim-architecture in thomast1906/github-copilot-agent-skills) into .agents/skills/azure-apim-architecture in your project. Codex loads it when a task matches its description.

Can I use Azure Apim Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thomast1906/github-copilot-agent-skills --skill azure-apim-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-apim-architecture, .gemini/skills/azure-apim-architecture, .github/skills/azure-apim-architecture and .opencode/skills/azure-apim-architecture in your project.

What does Azure Apim Architecture need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Apim Architecture is instructions for the agent only.

Does Azure Apim Architecture access the network?

SKILL.md names 2 domains. In commands or code: learn.microsoft.com and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Apim Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Apim Architecture use?

Azure Apim Architecture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Apim Architecture use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Apim Architecture?

Skills that share tags, products or a category with Azure Apim Architecture: API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Azure Mgmt Apimanagement Py (microsoft/skills, 3.1k stars), Auth (microsoft/apm, 4k stars) and Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Apim Architecture?

thomast1906 (a GitHub user) maintains it in thomast1906/github-copilot-agent-skills, which has 202 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: thomast1906/github-copilot-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.