Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
asyrafhussin avatar

Api Design Patterns

  • 371 installs
  • 60 repo stars
  • Updated May 16, 2026
  • asyrafhussin/agent-skills

api-design-patterns is a version 2.0.0 agent skill with 38 REST API rules across seven categories covering resources, errors, security, pagination, versioning, responses, and OpenAPI docs.

About

api-design-patterns is a MIT-licensed version 2.0.0 skill from asyrafhussin/agent-skills encoding RESTful API design principles for consistent, developer-friendly HTTP services. It organizes 38 rules across seven priority categories: resource design (nouns, plural resources, HTTP methods, status codes, idempotency, HATEOAS), error handling (machine-readable codes, validation details, request IDs), security (OAuth2/JWT, RBAC, rate limiting, CORS, HTTPS), pagination and filtering (cursor and offset), versioning (URL and header strategies), response format conventions, and OpenAPI documentation with changelogs. Prefixes like rest-, error-, sec-, page-, ver-, resp-, and doc- tag each rule for quick reference during reviews. Developers reach for api-design-patterns when designing new endpoints, reviewing existing routes, implementing error envelopes, or planning deprecation. Triggers include design API, review API, REST best practices, and API patterns prompts. The skill suits backend engineers and agent-tool authors who need predictable contracts before clients integrate.

  • REST and GraphQL layout guidance
  • Versioning, pagination, and filtering patterns
  • Auth, rate limits, and error response standards
  • Naming and resource modeling conventions
  • Agent-tool API contract alignment

Api Design Patterns by the numbers

  • 371 all-time installs (skills.sh)
  • Ranked #1,153 of 4,347 Backend & APIs skills by installs in the Skillselion catalog
  • Data as of Aug 3, 2026 (Skillselion catalog sync)
npx skills add https://github.com/asyrafhussin/agent-skills --skill api-design-patterns

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs371
repo stars60
Last updatedMay 16, 2026
Repositoryasyrafhussin/agent-skills

How do you design consistent REST API endpoints?

Design REST/GraphQL endpoints, versioning, auth, pagination, and error contracts before or while implementing backend services and agent-exposed tools.

Who is it for?

Backend engineers designing or reviewing REST APIs who need checklist-driven rules for resources, errors, security, pagination, and OpenAPI documentation.

Skip if: GraphQL-only schemas or gRPC/protobuf services where REST resource conventions and HTTP status-code rules do not apply.

When should I use this skill?

User asks to design APIs, review endpoints, implement error responses, set up pagination, or apply REST best practices.

What you get

REST endpoint specs with error envelopes, pagination parameters, versioning strategy, security controls, and OpenAPI documentation aligned to 38 rules.

  • endpoint specifications
  • error response contracts
  • OpenAPI documentation outline

By the numbers

  • Contains 38 rules across 7 categories in version 2.0.0
  • Seven priority categories from critical resource design through documentation

Files

SKILL.mdMarkdownGitHub ↗

API Design Patterns

RESTful API design principles for building consistent, developer-friendly APIs. Contains 38 rules across 7 categories covering resource design, error handling, security, pagination, versioning, response format, and documentation.

Metadata

  • Version: 2.0.0
  • Rule Count: 38 rules across 7 categories
  • License: MIT

When to Apply

Reference these guidelines when:

  • Designing new API endpoints
  • Reviewing existing API structure
  • Implementing error handling and validation
  • Setting up pagination, filtering, and sorting
  • Planning API versioning strategy
  • Configuring API security (auth, CORS, rate limiting)
  • Writing API documentation (OpenAPI/Swagger)

Rule Categories by Priority

PriorityCategoryImpactPrefix
1Resource DesignCRITICALrest-
2Error HandlingCRITICALerror-
3SecurityCRITICALsec-
4Pagination & FilteringHIGHpage-, filter-, sort-
5VersioningHIGHver-
6Response FormatMEDIUMresp-
7DocumentationMEDIUMdoc-

Quick Reference

1. Resource Design (CRITICAL)

  • rest-nouns-not-verbs - Use nouns for endpoints, not verbs
  • rest-plural-resources - Use plural resource names
  • rest-http-methods - Correct HTTP method usage (GET, POST, PUT, PATCH, DELETE)
  • rest-nested-resources - Proper resource nesting (max 2 levels)
  • rest-status-codes - Appropriate HTTP status codes
  • rest-idempotency - Idempotent operations with idempotency keys
  • rest-hateoas - Hypermedia links for discoverability
  • rest-resource-actions - Non-CRUD actions as sub-resources

2. Error Handling (CRITICAL)

  • error-consistent-format - Consistent error response structure
  • error-meaningful-messages - Helpful, actionable error messages
  • error-validation-details - Field-level validation errors
  • error-error-codes - Machine-readable error codes
  • error-no-stack-traces - Never expose stack traces in production
  • error-request-id - Include request IDs for debugging

3. Security (CRITICAL)

  • sec-authentication - Proper auth implementation (OAuth2/JWT)
  • sec-authorization - Resource-level permissions (RBAC)
  • sec-rate-limiting - Prevent abuse with rate limiting
  • sec-input-validation - Validate and sanitize all input
  • sec-cors-config - CORS configuration with whitelists
  • sec-https-only - Enforce HTTPS for all traffic
  • sec-sensitive-data - Protect passwords, tokens, PII

4. Pagination & Filtering (HIGH)

  • page-cursor-based - Cursor pagination for large datasets
  • page-offset-based - Offset pagination for simple cases
  • page-consistent-params - Consistent parameter naming
  • page-metadata - Include pagination metadata in responses
  • filter-query-params - Filter via query parameters
  • sort-flexible - Flexible sorting with - prefix for descending

5. Versioning (HIGH)

  • ver-url-path - Version in URL path (/api/v1/)
  • ver-header-based - Version via Accept header
  • ver-backward-compatible - Maintain backward compatibility
  • ver-deprecation - Deprecation strategy with Sunset header

6. Response Format (MEDIUM)

  • resp-consistent-structure - Consistent response envelope
  • resp-json-conventions - JSON naming conventions
  • resp-partial-responses - Field selection (sparse fieldsets)
  • resp-compression - Response compression (gzip/Brotli)

7. Documentation (MEDIUM)

  • doc-openapi - OpenAPI/Swagger specification
  • doc-examples - Request/response examples
  • doc-changelog - API changelog

Essential Guidelines

Resource Naming

# ❌ Verbs in URLs
GET    /getUsers
POST   /createUser

# ✅ Nouns with HTTP methods
GET    /users          # List users
POST   /users          # Create user
GET    /users/123      # Get user
PUT    /users/123      # Update user (full)
PATCH  /users/123      # Update user (partial)
DELETE /users/123      # Delete user

Error Response Format

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "The request contains invalid data",
    "details": [
      {
        "field": "email",
        "code": "INVALID_FORMAT",
        "message": "Please provide a valid email address"
      }
    ],
    "request_id": "req_abc123"
  }
}

Pagination

{
  "data": [...],
  "meta": {
    "current_page": 2,
    "per_page": 20,
    "total_pages": 10,
    "total_count": 195
  },
  "links": {
    "first": "/users?page=1&per_page=20",
    "prev": "/users?page=1&per_page=20",
    "next": "/users?page=3&per_page=20",
    "last": "/users?page=10&per_page=20"
  }
}

Rate Limiting Headers

HTTP/1.1 200 OK
X-RateLimit-Limit: 1000
X-RateLimit-Remaining: 998
X-RateLimit-Reset: 1640995200

How to Use

Read individual rule files for detailed explanations:

rules/rest-http-methods.md
rules/error-consistent-format.md
rules/page-cursor-based.md
rules/sec-authentication.md
rules/ver-url-path.md
rules/doc-openapi.md

References

Full Compiled Document

For the complete guide with all rules expanded: AGENTS.md

Related skills

How it compares

Use api-design-patterns for REST checklist reviews; use OpenAPI generator tools when the schema file itself is the primary deliverable.

FAQ

How many rules does api-design-patterns include?

api-design-patterns version 2.0.0 bundles 38 rules across seven categories: resource design, error handling, security, pagination and filtering, versioning, response format, and documentation with OpenAPI guidance.

What API areas does api-design-patterns prioritize?

api-design-patterns marks resource design, error handling, and security as critical priorities, then pagination, versioning, response format, and documentation. Each rule uses prefixes like rest-, error-, and sec- for targeted reviews.

Backend & APIsbackendintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.