Skip to content
Back to skills

Api Platform Resources

ASecurity

Configure API Platform resources (v5, 4.4, 4.3) with explicit operations, pagination, and typed OpenAPI for clean, versioned REST/GraphQL APIs

  • 221 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added August 31, 2026
developmentshellbashrailsapi

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add dev-toolings/superpowers-symfony --skill api-platform-resources --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Platform Resources?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Platform Resources
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dev-toolings-api-platform-resources/badge)](https://www.skillsdirectory.com/skills/dev-toolings-api-platform-resources)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-platform-resources
description: Configure API Platform resources (v5, 4.4, 4.3) with explicit operations, pagination, and typed OpenAPI for clean, versioned REST/GraphQL APIs
capabilities: [read, search, edit, shell]
tags: [api-platform]
# projected by `bun run build` — do not edit by hand
allowed-tools:
  - Read
  - Glob
  - Grep
  - Write
  - Edit
  - Bash
---

# Api Platform Resources (Symfony)

## Use when
- Exposing a new entity or class as an `#[ApiResource]`.
- Choosing exactly which of `Get`, `GetCollection`, `Post`, `Put`, `Patch`, and `Delete` the API offers.
- Tuning collection pagination (items per page, partial pagination, client control).
- Documenting operations with typed OpenAPI objects instead of `openapiContext` arrays.

## Default workflow
1. Install only the components you need: `api-platform/symfony`, `api-platform/doctrine-orm`, and optionally `api-platform/graphql`; on Symfony 6.4 LTS, pin them to `~4.3.0`.
2. List every operation in `operations:`, since declaring any one stops the automatic CRUD, and `Put` is never automatic.
3. Set `uriTemplate`, `requirements`, `status`, or `routePrefix` only where the defaults do not fit.
4. Configure pagination through resource attributes or `api_platform.defaults` in `config/packages/api_platform.yaml`.
5. Describe operations with `openapi:` model objects, set `validationContext` groups, then check the routes and the OpenAPI export.

## Guardrails
- Declaring one operation removes the default CRUD: an `operations: [new Get()]` resource has no collection, `Post`, or `Delete`.
- `openapiContext` arrays are deprecated in v4: use the typed `openapi:` option.
- `collectionOperations` and `itemOperations` no longer exist.
- `paginationClientEnabled` lets clients disable pagination: keep `paginationMaximumItemsPerPage` set.

## Progressive disclosure
- Use this file for execution posture and risk controls.
- Open references when deep implementation details are needed.

## Output contract
- The resource class with its explicit operation list and the routes it produces.
- Pagination and OpenAPI settings, with the reason for each override.
- Route listing and test results for each declared operation.

## References
- `reference.md`

Files in this skill

  • SKILL.md1.2 KB
  • reference.md6.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…