Skip to content
Back to skills

Api Design Patterns Sraloff

ASecurity

Principles for REST, GraphQL, versioning, and API authentication.

  • 42 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 31, 2026
securityapi

Works with

  • api

Security analysis

A100/100

Scanned May 31, 2026

npx -y skills add diegosouzapw/awesome-omni-skill --skill api-design-patterns-sraloff --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Design Patterns Sraloff?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Design Patterns Sraloff
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/diegosouzapw-api-design-patterns-sraloff/badge)](https://www.skillsdirectory.com/skills/diegosouzapw-api-design-patterns-sraloff)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-design-patterns
description: Principles for REST, GraphQL, versioning, and API authentication.
---

# API Design Patterns

## When to use this skill
- Designing new API endpoints.
- Documenting APIs (OpenAPI/Swagger).
- Implementing authentication strategies.

## 1. RESTful Conventions
- **Nouns**: Use nouns for resources (`/users`, not `/getUsers`).
- **Verbs**: Use correct HTTP methods (`GET` read, `POST` create, `PUT` replace, `PATCH` update, `DELETE` remove).
- **Status Codes**: 200 OK, 201 Created, 400 Bad Request, 401 Unauth, 403 Forbidden, 404 Not Found, 422 Validation Error.

## 2. Response Structure
- **Envelope**: Standardize response JSON.
  ```json
  {
    "data": { ... },
    "meta": { "pagination": ... }
  }
  ```
- **Errors**: Return structured error objects, not just plain strings.

## 3. Versioning
- **URL**: `/api/v1/resource` is preferred for explicit versioning.
- **Breaking Changes**: Never introduce breaking changes to an existing version. Create v2.

## 4. Authentication
- **Bearer Token**: Use `Authorization: Bearer <token>` (JWT or Opaque).
- **Stateless**: API should rarely rely on session cookies (CSRF issues) unless it is a first-party SPA.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…