Skip to content
Back to skills

Api Patterns

ASecurity

API design principles and decision-making. REST vs GraphQL vs tRPC selection,

  • 6 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 10, 2026
developmenttypescriptpythontestingapidatabasebackendfullstacksecuritydocumentation

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 12 files and shows the line behind each finding

Scanned September 10, 2026

npx -y skills add JantonioFC/skillsbank --skill api-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Patterns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Patterns
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/jantoniofc-api-patterns/badge)](https://www.skillsdirectory.com/skills/jantoniofc-api-patterns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-patterns
description: API design principles and decision-making. REST vs GraphQL vs tRPC selection,
  response formats, versioning, pagination.
allowed-tools: Read, Write, Edit, Glob, Grep
risk: safe
source: community
license: MIT
---
# API Patterns

> API design principles and decision-making for 2025.
> **Learn to THINK, not copy fixed patterns.**

## 🎯 Selective Reading Rule

**Read ONLY files relevant to the request!** Check the content map, find what you need.

---

## πŸ“‘ Content Map

| File | Description | When to Read |
|------|-------------|--------------|
| `api-style.md` | REST vs GraphQL vs tRPC decision tree | Choosing API type |
| `rest.md` | Resource naming, HTTP methods, status codes | Designing REST API |
| `response.md` | Envelope pattern, error format, pagination | Response structure |
| `graphql.md` | Schema design, when to use, security | Considering GraphQL |
| `trpc.md` | TypeScript monorepo, type safety | TS fullstack projects |
| `versioning.md` | URI/Header/Query versioning | API evolution planning |
| `auth.md` | JWT, OAuth, Passkey, API Keys | Auth pattern selection |
| `rate-limiting.md` | Token bucket, sliding window | API protection |
| `documentation.md` | OpenAPI/Swagger best practices | Documentation |
| `security-testing.md` | OWASP API Top 10, auth/authz testing | Security audits |

---

## πŸ”— Related Skills

| Need | Skill |
|------|-------|
| API implementation | `@[skills/backend-development]` |
| Data structure | `@[skills/database-design]` |
| Security details | `@[skills/security-hardening]` |

---

## βœ… Decision Checklist

Before designing an API:

- [ ] **Asked user about API consumers?**
- [ ] **Chosen API style for THIS context?** (REST/GraphQL/tRPC)
- [ ] **Defined consistent response format?**
- [ ] **Planned versioning strategy?**
- [ ] **Considered authentication needs?**
- [ ] **Planned rate limiting?**
- [ ] **Documentation approach defined?**

---

## ❌ Anti-Patterns

**DON'T:**
- Default to REST for everything
- Use verbs in REST endpoints (/getUsers)
- Return inconsistent response formats
- Expose internal errors to clients
- Skip rate limiting

**DO:**
- Choose API style based on context
- Ask about client requirements
- Document thoroughly
- Use appropriate status codes

---

## Script

| Script | Purpose | Command |
|--------|---------|---------|
| `scripts/api_validator.py` | API endpoint validation | `python scripts/api_validator.py <project_path>` |

## When to Use

API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.

Covers: 🎯 Selective Reading Rule, πŸ“‘ Content Map, πŸ”— Related Skills, βœ… Decision Checklist, ❌ Anti-Patterns.

Files in this skill

  • SKILL.md2.7 KB
  • api-style.md1.1 KB
  • auth.md576 B
  • documentation.md549 B
  • graphql.md977 B
  • rate-limiting.md726 B
  • response.md921 B
  • rest.md1.3 KB
  • scripts/api_validator.py7.4 KB
  • security-testing.md2.8 KB
  • trpc.md801 B
  • versioning.md651 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…