Agent skill

Add API Endpoint

by willdady in willdady/platypus

Guide for adding new API endpoints to the Platypus backend using Hono.js — routing, tenant scoping middleware, validation, and database access.

MITAuto-check passedBackend & APIs

Install Add API Endpoint

skills CLI
$ npx skills add willdady/platypus --skill add-api-endpoint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install willdady/platypus add-api-endpoint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/willdady/platypus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-api-endpoint .claude/skills/add-api-endpoint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-api-endpoint
GitHub stars
116
Token cost
~955 tokens
SKILL.md length
421 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Guide for adding new API endpoints to the Platypus backend using Hono.js — routing, tenant scoping middleware, validation, and database access.

  • Works in 4 steps: Create the route module in the backend's… → Mount it on the app in the backend's… → Define the request schemas in the shared… → …
  • Tasks that involve REST APIs
  • SKILL.md covers Steps, Choosing the scope, Database access and Responses
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Add API Endpoint is an agent skill from willdady/platypus. Guide for adding new API endpoints to the Platypus backend using Hono.js — routing, tenant scoping middleware, validation, and database access.

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs. It works with Hono. The repository describes itself as: Self-hosted AI Agents for your whole team — on your infrastructure, your models, around the clock. The licence is MIT.

When your agent uses it

  • Tasks that involve REST APIs

Example prompts

  • “/add-api-endpoint”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Create the route module in the backend's routes area — a Hono instance
  2. Mount it on the app in the backend's server module. The mount path
  3. Define the request schemas in the shared schemas package, following the
  4. Compose each route: authenticate, scope, validate, handle — in that

What it can do on your machine

Read from SKILL.md and the folder at commit 2147848. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add API Endpoint loads about 955 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 421 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~955

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from willdady/platypus at commit 2147848, republished under its MIT licence (© willdady). 421 words, ~955 tokens.

Download SKILL.mdSave it as .claude/skills/add-api-endpoint/SKILL.md (or your agent's skills folder).
name
add-api-endpoint
description
Guide for adding new API endpoints to the Platypus backend using Hono.js — routing, tenant scoping middleware, validation, and database access.

Adding New API Endpoints

Authenticated is not scoped. requireAuth proves who the caller is and nothing about what they may reach. Platypus is multi-tenant — Organization → Workspace → resource — so an endpoint carrying only requireAuth is reachable by any logged-in user against any tenant's data. Scope is a separate, mandatory decision, taken per route.

Steps

  1. Create the route module in the backend's routes area — a Hono instance exported for mounting.

  2. Mount it on the app in the backend's server module. The mount path carries the tenancy, so the hierarchy lives in the URL and the middleware reads the ids from it:

    typescript
    app.route("/organizations/:orgId/workspaces/:workspaceId/agents", agent);
  3. Define the request schemas in the shared schemas package, following the full / create / update variants each domain model already has.

  4. Compose each route: authenticate, scope, validate, handle — in that order, as arguments to the route, not as a blanket .use("*"). Scope is per route because two routes in one file rarely deserve the same access.

    typescript
    agent.post(
      "/",
      requireAuth,
      requireOrgAccess(),
      requireWorkspaceAccess,
      sValidator("json", agentCreateSchema),
      async (c) => {
        const data = c.req.valid("json");
        const scope = workspaceScopeOf(c);
        // ...
      },
    );

Done when every route in the module names its scoping middleware explicitly, and you can say which tenant each one is confined to.

Show full SKILL.md (240 more words)Show less

Choosing the scope

Pick the narrowest that admits the callers you intend:

MiddlewareAdmits
requireOrgAccess()any member of the Organization in the path
requireOrgAccess(["admin"])members holding one of the named Organization roles
requireWorkspaceAccesscallers permitted in the Workspace in the path
requireWorkspaceOwnerthe Workspace's Owner
requireWorkspaceConfigAccess()credential- or reach-bearing Workspace config, admin-only
requireWorkspaceConfigAccess(flag)the same, plus the Owner when that Workspace flag is set
requireSuperAdminplatform operators only

Org and Workspace scoping compose — the Workspace check assumes the Org check ran ahead of it. Super admins bypass the Org membership check by design, so a route may legitimately resolve with no Organization to scope to.

Read the resolved scope through the scope accessors (workspaceScopeOf, orgScopeOf) rather than re-reading path params: the accessor hands you the scope the middleware already decided, so the query cannot disagree with the authorization.

Database access

Import the shared db instance from the backend entry module, the way the route modules already do, and query it with Drizzle. The request context also carries a db, but that is a narrow exception rather than the house pattern.

Never scope a query by a raw path param. Take the tenant ids from the resolved scope, so an unscoped read cannot be written by accident.

Responses

Response body shape — the error key, the message key, and when to throw a typed error instead of returning one — is covered by the api-conventions skill. Load it rather than inventing a shape.

© willdady, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/add-api-endpoint of willdady/platypus.

Open the folder on GitHubat commit 2147848

Compare with similar skills

Add API Endpoint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add API Endpoint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add API Endpoint this skillwilldady/platypus116—~955Automated safety check: PassMIT
Knowledge Interaction Surfaces Hono Server API And StreamingechoVic/blade-code180—~1.7kAutomated safety check: PassMIT
Bun Hono Integrationsecondsky/claude-skills227—~1.9kAutomated safety check: PassMIT
Project Docsjezweb/claude-skills1.1k—~1.6kAutomated safety check: NotesMIT
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Paperclippaperclipai/paperclip98k—~9.6kAutomated safety check: PassMIT

Similar skills

  • 覆盖 Blade Hono 服务的路由装配、Session/Task 控制器、SSE replay/live 切换、 WebSocket 终端、静态资源、认证、错误映射与资源关闭。进入时机:新增 HTTP API、 修改 Web 事件协议、处理同名 Session、调试断线重连、服务容量或 shutdown。

    180 GitHub stars~1.7k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Bun Hono Integration

    secondsky/claude-skills

    A skill your agent uses when building APIs with Hono framework on Bun, including routing, middleware, REST APIs, context handling, or web framework features.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Project Docs

    jezweb/claude-skills

    Generate project documentation from codebase analysis — ARCHITECTURE.md, APIENDPOINTS.md, DATABASESCHEMA.md.

    1.1k GitHub stars~1.6k tokensUpdated 2 days ago
    DatabasesAuto-check: notes
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Paperclip

    paperclipai/paperclip

    Interact with the Paperclip control plane API for task coordination and governance.

    98k GitHub stars~9.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed

More from willdady/platypus

  • API Conventions

    willdady/platypus

    Response-body conventions for the Platypus backend API — the error key for failures, the message key for 2xx status messages, and when to throw a typed error instead of returning a response.

    116 GitHub stars~655 tokensUpdated today
    Auto-check passed
  • Platypus Tools

    willdady/platypus

    Platypus tools and tool sets — writing a tool, contributing a tool set from a plugin, scoping tools to a workspace, sharing a tool across sets, chat icons, and custom tool UI.

    116 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Database Schema Changes

    willdady/platypus

    Guide for making database schema changes in Platypus using Drizzle ORM — editing the schema, pushing to a dev database, and generating the migration that ships.

    116 GitHub stars~527 tokensUpdated today
    Auto-check passed
  • Docs Audit

    willdady/platypus

    Audit one section of the docs content against the code, and report what is wrong, stale, fragile, off-voice, or missing.

    116 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Form Conventions

    willdady/platypus

    Post-save conventions for Platypus frontend forms — where a save lands the user, and what the submit button is called.

    116 GitHub stars~916 tokensUpdated today
    Auto-check passed
  • Pre Release Check

    willdady/platypus

    The final gate before a release is cut — go green, reconcile the release PR against what actually landed, sweep what CI can't see, check the roadmap and ADR statuses, optionally deep-review, then…

    116 GitHub stars~3.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Add API Endpoint

What does Add API Endpoint do?

Guide for adding new API endpoints to the Platypus backend using Hono.js — routing, tenant scoping middleware, validation, and database access. Add API Endpoint is an agent skill from willdady/platypus.js — routing, tenant scoping middleware, validation, and database access.

When should I use Add API Endpoint?

Add API Endpoint fits situations like: tasks that involve REST APIs.

How do I install Add API Endpoint in Claude Code?

Run `npx skills add willdady/platypus --skill add-api-endpoint -a claude-code`. Or copy the skill folder (.agents/skills/add-api-endpoint in willdady/platypus) into .claude/skills/add-api-endpoint in your project. Claude Code loads it when a task matches its description.

How do I install Add API Endpoint in Codex?

Run `npx skills add willdady/platypus --skill add-api-endpoint -a codex`. Or copy the skill folder (.agents/skills/add-api-endpoint in willdady/platypus) into .agents/skills/add-api-endpoint in your project. Codex loads it when a task matches its description.

Can I use Add API Endpoint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add willdady/platypus --skill add-api-endpoint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-api-endpoint, .gemini/skills/add-api-endpoint, .github/skills/add-api-endpoint and .opencode/skills/add-api-endpoint in your project.

What does Add API Endpoint need to run?

SKILL.md names no scripts, command-line tools or credentials: Add API Endpoint is instructions for the agent only.

Does Add API Endpoint access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add API Endpoint safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add API Endpoint use?

Add API Endpoint is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add API Endpoint use?

About 955 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add API Endpoint?

Skills that share tags, products or a category with Add API Endpoint: Knowledge Interaction Surfaces Hono Server API And Streaming (echoVic/blade-code, 180 stars), Bun Hono Integration (secondsky/claude-skills, 227 stars), Project Docs (jezweb/claude-skills, 1.1k stars) and API Designer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add API Endpoint?

willdady (a GitHub user) maintains it in willdady/platypus, which has 116 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: willdady/platypus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.