{
  "format": "skilldb.starter-bundle",
  "schemaVersion": 1,
  "bundle": {
    "slug": "api-service",
    "title": "API service",
    "url": "https://skilldb.dev/bundles/api-service"
  },
  "summary": "Define a resource contract, identify callers, and make failures predictable.",
  "scope": "A design and review starting point for an HTTP service. It does not provision a backend or supply a complete security implementation.",
  "review": {
    "date": "2026-10-04",
    "revision": "0a89389d0ec3e4f12e694baab71bdb56134eeb7e",
    "scope": "Selection reviewed for topic coverage and overlap. Code examples and task outcomes have not been evaluated.",
    "evaluationStatus": "pending"
  },
  "contentIncluded": false,
  "installationIncluded": false,
  "exportNotice": "Reference manifest only: selection notes, skill IDs, and public catalog links. No skill bodies, executable code, credentials, or host configuration are included. Downloading does not install or enable skills.",
  "rightsNotice": "Source licenses have not been verified for redistribution. Catalog pages provide a public reference; access does not grant redistribution rights. Verify the original license and attribution requirements before copying or packaging skill content.",
  "overlap": "REST Design establishes resources and response conventions. API Authentication addresses identity and scopes. API Error Handling expands the failure contract; use one agreed status-code policy across all three.",
  "evaluation": {
    "status": "pending",
    "task": "Design a small projects API, then test create and read operations with valid, expired, missing, and insufficiently scoped credentials.",
    "checks": [
      "Verify authentication and resource ownership separately, including a cross-account request.",
      "Check malformed input, unavailable dependencies, and consistent non-success status codes.",
      "Confirm that responses and logs omit secrets and internal stack traces."
    ]
  },
  "skills": [
    {
      "id": "api-design-skills/rest-design.md",
      "title": "REST Design",
      "role": "Resource and HTTP contract",
      "rationale": "Provides a compact reference for resource naming, method semantics, filtering, and response codes.",
      "reviewNote": "Treat versioning and nesting suggestions as design choices to discuss, not universal requirements.",
      "catalogUrl": "https://skilldb.dev/skills/api-design-skills/rest-design",
      "maintainerProvenance": {
        "repository": "latentsmurf/SkillDB",
        "access": "private; maintainer access required",
        "revision": "0a89389d0ec3e4f12e694baab71bdb56134eeb7e",
        "path": "packs/api-design-skills/rest-design.md"
      },
      "licenseStatus": "not-verified-for-redistribution"
    },
    {
      "id": "api-design-skills/api-authentication.md",
      "title": "API Authentication",
      "role": "Caller identity and permissions",
      "rationale": "Compares API keys, tokens, and OAuth, then introduces per-endpoint scope checks.",
      "reviewNote": "The OAuth sketch is incomplete for implementation, and the JWT snippet does not enforce every claim discussed in the prose. Use maintained libraries and current provider guidance; add ownership checks.",
      "catalogUrl": "https://skilldb.dev/skills/api-design-skills/api-authentication",
      "maintainerProvenance": {
        "repository": "latentsmurf/SkillDB",
        "access": "private; maintainer access required",
        "revision": "0a89389d0ec3e4f12e694baab71bdb56134eeb7e",
        "path": "packs/api-design-skills/api-authentication.md"
      },
      "licenseStatus": "not-verified-for-redistribution"
    },
    {
      "id": "api-design-skills/api-error-handling.md",
      "title": "API Error Handling",
      "role": "Failure responses",
      "rationale": "Adds a consistent error envelope, request correlation, validation failures, and rate-limit feedback.",
      "reviewNote": "Do not echo sensitive field values from the example error details. Adapt the illustrative handler to your framework.",
      "catalogUrl": "https://skilldb.dev/skills/api-design-skills/api-error-handling",
      "maintainerProvenance": {
        "repository": "latentsmurf/SkillDB",
        "access": "private; maintainer access required",
        "revision": "0a89389d0ec3e4f12e694baab71bdb56134eeb7e",
        "path": "packs/api-design-skills/api-error-handling.md"
      },
      "licenseStatus": "not-verified-for-redistribution"
    }
  ]
}
