Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
pluginagentmarketplace avatar

Java Spring Boot

  • 11.5k installs
  • 40 repo stars
  • Updated January 5, 2026
  • pluginagentmarketplace/custom-plugin-java

Spring Boot is a framework for building production-ready Java applications with embedded containers, auto-configuration, and opinionated defaults for REST APIs, security, and data access.

About

This skill teaches Spring Boot development for production applications, covering REST API creation with Spring MVC/WebFlux, security configuration (OAuth2, JWT), data persistence via Spring Data JPA, and operational monitoring with Actuator. Developers use it to build stateless APIs, configure authentication/authorization, set up database repositories with pagination, and enable health checks and metrics. Key workflows include controller patterns with validation, SecurityFilterChain configuration for permission-based access, JPA repository queries with transactions, and Micrometer/Prometheus integration for observability.

  • REST controller patterns with @RestController, @RequestMapping, and ResponseEntity for HTTP operations
  • Spring Security configuration including OAuth2/JWT authentication and method-level authorization
  • Spring Data JPA repositories with query methods, pagination, sorting, and transaction management
  • Actuator endpoints for health checks, metrics collection, and Prometheus integration
  • Exception handling via @RestControllerAdvice and ProblemDetail for standardized error responses

Java Spring Boot by the numbers

  • 11,517 all-time installs (skills.sh)
  • +43 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #69 of 4,386 Backend & APIs skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

java-spring-boot capabilities & compatibility

Capabilities
rest api generation with controllers and request · security filter chain configuration for oauth2 a · jpa repository pattern with query methods and tr · health checks and metrics exposure via actuator · exception handling with centralized advice · profile based configuration management
Works with
jira · github · aws · kubernetes
Use cases
api development · security audit · devops
Platforms
macOS · Windows · Linux · WSL
Runs
Remote server
Pricing
Free
From the docs

What java-spring-boot says it does

Build production-ready Spring Boot applications with modern best practices.
SKILL.md#overview
npx skills add https://github.com/pluginagentmarketplace/custom-plugin-java --skill java-spring-boot

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs11.5k
repo stars40
Security audit3 / 3 scanners passed
Last updatedJanuary 5, 2026
Repositorypluginagentmarketplace/custom-plugin-java

What it does

Build production REST APIs and microservices with Spring Boot 3.x, security, data access, and monitoring.

Who is it for?

Building REST APIs, microservices, OAuth2/JWT authentication, JPA-based data access, health monitoring, cloud-native applications

Skip if: CLI tools, frontend development, static site generation, real-time messaging systems without additional frameworks

When should I use this skill?

Starting a new REST API project, adding security to Spring applications, configuring data repositories, implementing health checks and metrics

What you get

Developers can create production Spring Boot 3.x applications with secure REST endpoints, JPA data layers, and operational metrics.

  • Functional REST API endpoints
  • Security filter chain configuration
  • JPA repository implementations

By the numbers

  • Spring Boot 3.2+ required for modern JWT and SecurityFilterChain patterns
  • Actuator metrics include health, info, metrics endpoints (minimum 3 exposed for production)
  • Supports 5 module focuses: web, security, data, actuator, cloud

Files

SKILL.mdMarkdownGitHub ↗

Java Spring Boot Skill

Build production-ready Spring Boot applications with modern best practices.

Overview

This skill covers Spring Boot development including REST APIs, security configuration, data access, actuator monitoring, and cloud integration. Follows Spring Boot 3.x patterns with emphasis on production readiness.

When to Use This Skill

Use when you need to:

  • Create REST APIs with Spring MVC/WebFlux
  • Configure Spring Security (OAuth2, JWT)
  • Set up database access with Spring Data
  • Enable monitoring with Actuator
  • Integrate with Spring Cloud

Topics Covered

Spring Boot Core

  • Auto-configuration and starters
  • Application properties and profiles
  • Bean lifecycle and configuration
  • DevTools and hot reload

REST API Development

  • @RestController and @RequestMapping
  • Request/response handling
  • Validation with Bean Validation
  • Exception handling with @ControllerAdvice

Spring Security

  • SecurityFilterChain configuration
  • OAuth2 and JWT authentication
  • Method security (@PreAuthorize)
  • CORS and CSRF configuration

Spring Data JPA

  • Repository pattern
  • Query methods and @Query
  • Pagination and sorting
  • Auditing and transactions

Actuator & Monitoring

  • Health checks and probes
  • Metrics with Micrometer
  • Custom endpoints
  • Prometheus integration

Quick Reference

// REST Controller
@RestController
@RequestMapping("/api/users")
@Validated
public class UserController {

    @GetMapping("/{id}")
    public ResponseEntity<User> getUser(@PathVariable Long id) {
        return userService.findById(id)
            .map(ResponseEntity::ok)
            .orElse(ResponseEntity.notFound().build());
    }

    @PostMapping
    public ResponseEntity<User> createUser(@Valid @RequestBody UserRequest request) {
        User user = userService.create(request);
        URI location = URI.create("/api/users/" + user.getId());
        return ResponseEntity.created(location).body(user);
    }
}

// Security Configuration
@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        return http
            .csrf(csrf -> csrf.disable())
            .sessionManagement(s -> s.sessionCreationPolicy(STATELESS))
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/health/**").permitAll()
                .requestMatchers("/api/public/**").permitAll()
                .anyRequest().authenticated())
            .oauth2ResourceServer(oauth2 -> oauth2.jwt(Customizer.withDefaults()))
            .build();
    }
}

// Exception Handler
@RestControllerAdvice
public class GlobalExceptionHandler {

    @ExceptionHandler(EntityNotFoundException.class)
    public ProblemDetail handleNotFound(EntityNotFoundException ex) {
        return ProblemDetail.forStatusAndDetail(NOT_FOUND, ex.getMessage());
    }
}

Configuration Templates

# application.yml
spring:
  application:
    name: ${APP_NAME:my-service}
  profiles:
    active: ${SPRING_PROFILES_ACTIVE:local}
  jpa:
    open-in-view: false
    properties:
      hibernate:
        jdbc.batch_size: 50

management:
  endpoints:
    web:
      exposure:
        include: health,info,metrics,prometheus
  endpoint:
    health:
      probes:
        enabled: true

server:
  error:
    include-stacktrace: never

Common Patterns

Layer Architecture

Controller → Service → Repository → Database
     ↓           ↓          ↓
   DTOs      Entities    Entities

Validation Patterns

public record CreateUserRequest(
    @NotBlank @Size(max = 100) String name,
    @Email @NotBlank String email,
    @NotNull @Min(18) Integer age
) {}

Troubleshooting

Common Issues

ProblemCauseSolution
Bean not foundMissing @ComponentAdd annotation or @Bean
Circular dependencyConstructor injectionUse @Lazy or refactor
401 UnauthorizedSecurity configCheck permitAll paths
Slow startupHeavy auto-configExclude unused starters

Debug Properties

debug=true
logging.level.org.springframework.security=DEBUG
spring.jpa.show-sql=true

Debug Checklist

□ Check /actuator/conditions
□ Verify active profiles
□ Review security filter chain
□ Check bean definitions
□ Test health endpoints

Usage

Skill("java-spring-boot")

Related Skills

  • java-testing - Spring test patterns
  • java-jpa-hibernate - Data access

Related skills

How it compares

Use java-spring-boot for opinionated Spring Boot 3 scaffolding; use generic Java skills when you only need Javadoc or documentation without service generation.

FAQ

What is the recommended security configuration for stateless APIs?

Use SecurityFilterChain with sessionCreationPolicy(STATELESS), disable CSRF, enable oauth2ResourceServer with JWT authentication, and configure permitAll for public endpoints like /actuator/health.

How do I structure a Spring Boot application?

Follow Controller → Service → Repository → Database layers; use DTOs for API contracts, entities for persistence, and @Validated on controllers for request validation.

What Actuator endpoints are essential for production?

Expose health, info, metrics, and prometheus endpoints; enable probes for Kubernetes liveness/readiness checks; never expose debug endpoints in production.

Is Java Spring Boot safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Backend & APIsbackendintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.