Skip to content
Back to skills

Api Patterns

ASecurity

Patterns for Server Actions, route handlers with schema validation, and calls to external REST APIs. Use when adding an endpoint or Server Action, or wiring an external API.

  • 80 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 28, 2026
ai-agentsapi

Works with

  • cursor
  • api

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add monkilabs/opencastle --skill api-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Patterns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Patterns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/monkilabs-api-patterns/badge)](https://www.skillsdirectory.com/skills/monkilabs-api-patterns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-patterns
description: "Patterns for Server Actions, route handlers with schema validation, and calls to external REST APIs. Use when adding an endpoint or Server Action, or wiring an external API."
---

# API Patterns

Project-specific config: `.opencastle/stack/api-config.md`, when the project has one.

## Architecture

| Layer | Use for |
|-------|---------|
| **Server Actions** (preferred) | mutations, form submissions, data writes, auth |
| **Route Handlers** (`route.ts`) | analytics, autocomplete, external integrations |
| **Proxy layer** | IP rate limiting, fingerprinting, bot detection |

Route files live at `app/api/<name>/route.ts` or `app/<segment>/route.ts`.

## Rules

- Validate every input with Zod on the server at the top of the handler; 400 on parse failure.
- Response envelope: `{ "data": ..., "meta": { "total": 42, "page": 1 } }`
- Error shape: `{ "error": { "code": "VALIDATION_ERROR", "message": "...", "details": [...] } }` — never leak stack traces. Status codes: 400, 401, 403, 404, 422, 429, 500.
- RESTful nouns, versioned: `/api/v1/places/:slug`. Add fields only — never remove or rename; deprecation headers before removal.
- Pagination: cursor-based preferred; params `limit`, `cursor`, `sort`, `order`.
- Retry external API calls twice with linear backoff (500 ms × attempt).
- Rate-limit public endpoints; set `Cache-Control` and `ETag`/`If-None-Match`.

Smoke-test a new route with `curl -fsS "http://localhost:3000/api/<name>?query=test"`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…