Development preview · Evaluation pending
API service starter bundle
Define a resource contract, identify callers, and make failures predictable.
A design and review starting point for an HTTP service. It does not provision a backend or supply a complete security implementation.
Download the reference plan
Reference manifest only: selection notes, skill IDs, and public catalog links. No skill bodies, executable code, credentials, or host configuration are included. Downloading does not install or enable skills.
Markdown is a reading plan; JSON is a SkillDB reference manifest. Neither is a host-specific install package.
Why these skills fit together
REST Design establishes resources and response conventions. API Authentication addresses identity and scopes. API Error Handling expands the failure contract; use one agreed status-code policy across all three.
1. Resource and HTTP contract
REST Design
Provides a compact reference for resource naming, method semantics, filtering, and response codes.
Review note: Treat versioning and nesting suggestions as design choices to discuss, not universal requirements.
API Design · Open catalog reference
2. Caller identity and permissions
API Authentication
Compares API keys, tokens, and OAuth, then introduces per-endpoint scope checks.
Review note: The OAuth sketch is incomplete for implementation, and the JWT snippet does not enforce every claim discussed in the prose. Use maintained libraries and current provider guidance; add ownership checks.
API Design · Open catalog reference
3. Failure responses
API Error Handling
Adds a consistent error envelope, request correlation, validation failures, and rate-limit feedback.
Review note: Do not echo sensitive field values from the example error details. Adapt the illustrative handler to your framework.
API Design · Open catalog reference
Try a representative task
Design a small projects API, then test create and read operations with valid, expired, missing, and insufficiently scoped credentials.
- Verify authentication and resource ownership separately, including a cross-account request.
- Check malformed input, unavailable dependencies, and consistent non-success status codes.
- Confirm that responses and logs omit secrets and internal stack traces.
This evaluation has not been run. Compare the same task with and without these references using the same environment and checks, and record outcomes before claiming an improvement.