Skip to main content

Development preview · Evaluation pending

API service starter bundle

Define a resource contract, identify callers, and make failures predictable.

A design and review starting point for an HTTP service. It does not provision a backend or supply a complete security implementation.

Download the reference plan

Reference manifest only: selection notes, skill IDs, and public catalog links. No skill bodies, executable code, credentials, or host configuration are included. Downloading does not install or enable skills.

Markdown is a reading plan; JSON is a SkillDB reference manifest. Neither is a host-specific install package.

Why these skills fit together

REST Design establishes resources and response conventions. API Authentication addresses identity and scopes. API Error Handling expands the failure contract; use one agreed status-code policy across all three.

  1. 1. Resource and HTTP contract

    REST Design

    Provides a compact reference for resource naming, method semantics, filtering, and response codes.

    Review note: Treat versioning and nesting suggestions as design choices to discuss, not universal requirements.

    API Design · Open catalog reference

  2. 2. Caller identity and permissions

    API Authentication

    Compares API keys, tokens, and OAuth, then introduces per-endpoint scope checks.

    Review note: The OAuth sketch is incomplete for implementation, and the JWT snippet does not enforce every claim discussed in the prose. Use maintained libraries and current provider guidance; add ownership checks.

    API Design · Open catalog reference

  3. 3. Failure responses

    API Error Handling

    Adds a consistent error envelope, request correlation, validation failures, and rate-limit feedback.

    Review note: Do not echo sensitive field values from the example error details. Adapt the illustrative handler to your framework.

    API Design · Open catalog reference

Try a representative task

Design a small projects API, then test create and read operations with valid, expired, missing, and insufficiently scoped credentials.

  • Verify authentication and resource ownership separately, including a cross-account request.
  • Check malformed input, unavailable dependencies, and consistent non-success status codes.
  • Confirm that responses and logs omit secrets and internal stack traces.

This evaluation has not been run. Compare the same task with and without these references using the same environment and checks, and record outcomes before claiming an improvement.

Selection review: . Selection reviewed for topic coverage and overlap. Code examples and task outcomes have not been evaluated. Links open public catalog pages, which may change. Downloads retain the reviewed commit as maintainer provenance; the source repository is private and requires maintainer access.

Source licenses have not been verified for redistribution. Catalog pages provide a public reference; access does not grant redistribution rights. Verify the original license and attribution requirements before copying or packaging skill content.