# API service — SkillDB starter bundle

Development preview · Evaluation pending

Define a resource contract, identify callers, and make failures predictable.

A design and review starting point for an HTTP service. It does not provision a backend or supply a complete security implementation.

Selection review: 2026-10-04. Selection reviewed for topic coverage and overlap. Code examples and task outcomes have not been evaluated.
Maintainer provenance: private repository latentsmurf/SkillDB, revision 0a89389d0ec3e4f12e694baab71bdb56134eeb7e. Maintainer access required; this is not a public source link. Catalog pages may change after the selection review.

## Export and source rights

Reference manifest only: selection notes, skill IDs, and public catalog links. No skill bodies, executable code, credentials, or host configuration are included. Downloading does not install or enable skills.

Source licenses have not been verified for redistribution. Catalog pages provide a public reference; access does not grant redistribution rights. Verify the original license and attribution requirements before copying or packaging skill content.

This is a reading and review plan, not an agent skill or host configuration. Start with the public catalog pages and review available instructions before use.

## Why these skills fit together

REST Design establishes resources and response conventions. API Authentication addresses identity and scopes. API Error Handling expands the failure contract; use one agreed status-code policy across all three.

## 1. REST Design

Role: Resource and HTTP contract

Provides a compact reference for resource naming, method semantics, filtering, and response codes.

Review note: Treat versioning and nesting suggestions as design choices to discuss, not universal requirements.

Skill ID: api-design-skills/rest-design.md
Public catalog: https://skilldb.dev/skills/api-design-skills/rest-design
Maintainer provenance path (private repository; maintainer access required): packs/api-design-skills/rest-design.md

## 2. API Authentication

Role: Caller identity and permissions

Compares API keys, tokens, and OAuth, then introduces per-endpoint scope checks.

Review note: The OAuth sketch is incomplete for implementation, and the JWT snippet does not enforce every claim discussed in the prose. Use maintained libraries and current provider guidance; add ownership checks.

Skill ID: api-design-skills/api-authentication.md
Public catalog: https://skilldb.dev/skills/api-design-skills/api-authentication
Maintainer provenance path (private repository; maintainer access required): packs/api-design-skills/api-authentication.md

## 3. API Error Handling

Role: Failure responses

Adds a consistent error envelope, request correlation, validation failures, and rate-limit feedback.

Review note: Do not echo sensitive field values from the example error details. Adapt the illustrative handler to your framework.

Skill ID: api-design-skills/api-error-handling.md
Public catalog: https://skilldb.dev/skills/api-design-skills/api-error-handling
Maintainer provenance path (private repository; maintainer access required): packs/api-design-skills/api-error-handling.md

## Suggested evaluation — not yet run

Design a small projects API, then test create and read operations with valid, expired, missing, and insufficiently scoped credentials.

- [ ] Verify authentication and resource ownership separately, including a cross-account request.
- [ ] Check malformed input, unavailable dependencies, and consistent non-success status codes.
- [ ] Confirm that responses and logs omit secrets and internal stack traces.

Compare the same task with and without these references using the same environment and checks. Record outcomes before claiming an improvement.
