Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Builds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability.
.claude/skills/api-endpoint-builder/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | — | — |
| case-12 | ✗→✓ | ▲ Improved | — | — |
| case-13 | ✗→✓ | ▲ Improved | — | — |
| case-16 | ✗→✓ | ▲ Improved | — | — |
| case-07 | ✗→✓ | ▲ Improved | — | — |
Build complete, production-ready REST API endpoints with proper validation, error handling, authentication, and documentation.
For each endpoint, you create:
javascript// Express example router.post('/api/users', authenticate, validateUser, createUser); // Fastify example fastify.post('/api/users', { preHandler: [authenticate], schema: userSchema }, createUser);
Always validate before processing:
javascriptconst validateUser = (req, res, next) => { const { email, name, password } = req.body; if (!email || !email.includes('@')) { return res.status(400).json({ error: 'Valid email required' }); } if (!name || name.length < 2) { return res.status(400).json({ error: 'Name must be at least 2 characters' }); } if (!password || password.length < 8) { return res.status(400).json({ error: 'Password must be at least 8 characters' }); } next(); };
javascriptconst createUser = async (req, res) => { try { const { email, name, password } = req.body; // Check if user exists const existing = await db.users.findOne({ email }); if (existing) { return res.status(409).json({ error: 'User already exists' }); } // Hash password const hashedPassword = await bcrypt.hash(password, 10); // Create user const user = await db.users.create({ email, name, password: hashedPassword, createdAt: new Date() }); // Don't return password const { password: _, ...userWithoutPassword } = user; res.status(201).json({ success: true, data: userWithoutPassword }); } catch (error) { console.error('Create user error:', error); res.status(500).json({ error: 'Internal server error' }); } };
200 - Success (GET, PUT, PATCH)201 - Created (POST)204 - No Content (DELETE)400 - Bad Request (validation failed)401 - Unauthorized (not authenticated)403 - Forbidden (not authorized)404 - Not Found409 - Conflict (duplicate)500 - Internal Server ErrorConsistent structure:
javascript// Success { "success": true, "data": { ... } } // Error { "error": "Error message", "details": { ... } // optional } // List with pagination { "success": true, "data": [...], "pagination": { "page": 1, "limit": 20, "total": 100 } }
javascript// Centralized error handler app.use((err, req, res, next) => { console.error(err.stack); // Don't leak error details in production const message = process.env.NODE_ENV === 'production' ? 'Internal server error' : err.message; res.status(err.status || 500).json({ error: message }); });
javascript// Create POST /api/resources Body: { name, description } // Read (list) GET /api/resources?page=1&limit=20 // Read (single) GET /api/resources/:id // Update PUT /api/resources/:id Body: { name, description } // Delete DELETE /api/resources/:id
javascriptconst getResources = async (req, res) => { const page = parseInt(req.query.page) || 1; const limit = parseInt(req.query.limit) || 20; const skip = (page - 1) * limit; const [resources, total] = await Promise.all([ db.resources.find().skip(skip).limit(limit), db.resources.countDocuments() ]); res.json({ success: true, data: resources, pagination: { page, limit, total, pages: Math.ceil(total / limit) } }); };
javascriptconst getResources = async (req, res) => { const { status, sort = '-createdAt' } = req.query; const filter = {}; if (status) filter.status = status; const resources = await db.resources .find(filter) .sort(sort) .limit(20); res.json({ success: true, data: resources }); };
javascript/** * @route POST /api/users * @desc Create a new user * @access Public * * @body {string} email - User email (required) * @body {string} name - User name (required) * @body {string} password - Password, min 8 chars (required) * * @returns {201} User created successfully * @returns {400} Validation error * @returns {409} User already exists * @returns {500} Server error * * @example * POST /api/users * { * "email": "user@example.com", * "name": "John Doe", * "password": "securepass123" * } */
javascriptdescribe('POST /api/users', () => { it('should create a new user', async () => { const response = await request(app) .post('/api/users') .send({ email: 'test@example.com', name: 'Test User', password: 'password123' }); expect(response.status).toBe(201); expect(response.body.success).toBe(true); expect(response.body.data.email).toBe('test@example.com'); expect(response.body.data.password).toBeUndefined(); }); it('should reject invalid email', async () => { const response = await request(app) .post('/api/users') .send({ email: 'invalid', name: 'Test User', password: 'password123' }); expect(response.status).toBe(400); expect(response.body.error).toContain('email'); }); });
@security-auditor - Security review@test-driven-development - Testing@database-design - Data modeling| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +32 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.