Backend Developer Skill
Purpose
Provides comprehensive expertise in server-side application development across multiple frameworks, languages, and deployment strategies. Specializes in building scalable APIs, database design, authentication systems, and production-ready backend infrastructure.
When to Use
- Building REST or GraphQL APIs
- Designing database schemas and models
- Implementing authentication and authorization
- Setting up server infrastructure
- Creating microservices or monolithic backends
- Optimizing backend performance
- Deploying server applications to production
- Need multi-framework backend guidance (Express, FastAPI, Django, Spring)
Quick Start
Invoke this skill when:
- Building server-side APIs (REST, GraphQL) in Node.js, Python, Java, or Go
- Implementing authentication/authorization (JWT, OAuth2, session-based)
- Designing database schemas and ORM integration
- Setting up backend testing (unit, integration, E2E)
- Implementing middleware (logging, validation, error handling)
- Deploying backend services to Kubernetes, AWS, GCP, or Azure
- Optimizing backend performance (caching, query optimization, rate limiting)
Do NOT invoke when:
- Only frontend development needed → Use frontend-developer or nextjs-developer
- Database-specific optimization required → Use database-optimizer or postgres-pro
- API design without implementation → Use api-designer
- GraphQL-specific architecture → Use graphql-architect
- DevOps/infrastructure only → Use devops-engineer or cloud-architect
Framework Support
Node.js/TypeScript
- Express.js, NestJS, Koa.js, Fastify
Python
- FastAPI, Django, Flask, Tornado
Java
- Spring Boot, Quarkus, Micronaut
Go
Decision Framework
Backend Framework Selection
Backend Framework Selection
├─ JavaScript/TypeScript
│ ├─ Need rapid development + type safety → NestJS
│ ├─ Need lightweight/fast performance → Fastify
│ └─ Need simplicity + ecosystem → Express.js
│
├─ Python
│ ├─ Need async + high performance → FastAPI
│ └─ Need batteries-included → Django (+ DRF)
│
├─ Java
│ └─ Enterprise-ready → Spring Boot
│
└─ Go
└─ High-performance services → Gin or Fiber
Authentication Strategy Matrix
| Scenario |
Strategy |
Complexity |
Security |
| Stateless API (mobile, SPA) |
JWT |
Low |
Medium |
| Third-party login |
OAuth 2.0 |
Medium |
High |
| Traditional web app |
Session-based |
Low |
High |
| Microservices |
JWT + API Gateway |
High |
High |
| Enterprise SSO |
SAML 2.0 |
High |
Very High |
Database & ORM Selection
Database & ORM Decision
├─ Relational (SQL)
│ ├─ Node.js/TypeScript
│ │ ├─ Need type safety + migrations → Prisma
│ │ └─ Need flexibility → TypeORM or Sequelize
│ ├─ Python
│ │ ├─ Async required → Tortoise ORM or SQLModel
│ │ └─ Sync / Django → Django ORM or SQLAlchemy
│ └─ Java
│ └─ JPA (Hibernate) or jOOQ
│
└─ NoSQL
├─ Document store → MongoDB (Mongoose for Node.js)
└─ Key-value → Redis (caching, sessions)
Best Practices
- Always validate input - Use provided validation middleware
- Handle errors gracefully - Use generated error handlers
- Write tests - Use test templates for consistency
- Use environment variables - Never hardcode secrets
- Implement logging - Use provided logging configuration
- Monitor performance - Set up metrics and alerts
- Security first - Use provided authentication setup
- Version your API - Follow versioning patterns
- Document your code - Generate API docs automatically
- Deploy safely - Use provided deployment scripts
Common Patterns
Repository Pattern
- Separation of concerns
- Easy testing
- Swappable implementations
Service Layer
- Centralized business rules
- Transaction management
- Error handling
Middleware Stack
- Authentication
- Authorization
- Validation
- Logging
- Error handling
Troubleshooting
Common Issues
Database connection errors
- Check connection string
- Verify database is running
- Check network connectivity
- Review connection pool settings
Authentication failures
- Verify JWT secret
- Check token expiration
- Validate token format
- Review middleware order
Build failures
- Check TypeScript configuration
- Verify dependencies are installed
- Review error messages
- Check for syntax errors
Deployment issues
- Verify Docker image builds
- Check Kubernetes pods
- Review logs
- Verify environment variables
Quality Checklist
Security
Authentication & Authorization
Error Handling
Performance
Testing
Additional Resources
- Detailed Technical Reference: See REFERENCE.md
- Code Examples & Patterns: See EXAMPLES.md
1---2name: backend-developer-23description: Comprehensive backend development for building production-ready server-side applications with multiple frameworks, databases, and deployment strategies. Use when building APIs, services, databases, or server infrastructure.4---5
6# Backend Developer Skill
7
8## Purpose
9
10Provides comprehensive expertise in server-side application development across multiple frameworks, languages, and deployment strategies. Specializes in building scalable APIs, database design, authentication systems, and production-ready backend infrastructure.
11
12## When to Use
13
14- Building REST or GraphQL APIs
15- Designing database schemas and models
16- Implementing authentication and authorization
17- Setting up server infrastructure
18- Creating microservices or monolithic backends
19- Optimizing backend performance
20- Deploying server applications to production
21- Need multi-framework backend guidance (Express, FastAPI, Django, Spring)
22
23## Quick Start
24
25**Invoke this skill when:**
26- Building server-side APIs (REST, GraphQL) in Node.js, Python, Java, or Go
27- Implementing authentication/authorization (JWT, OAuth2, session-based)
28- Designing database schemas and ORM integration
29- Setting up backend testing (unit, integration, E2E)
30- Implementing middleware (logging, validation, error handling)
31- Deploying backend services to Kubernetes, AWS, GCP, or Azure
32- Optimizing backend performance (caching, query optimization, rate limiting)
33
34**Do NOT invoke when:**
35- Only frontend development needed → Use frontend-developer or nextjs-developer
36- Database-specific optimization required → Use database-optimizer or postgres-pro
37- API design without implementation → Use api-designer
38- GraphQL-specific architecture → Use graphql-architect
39- DevOps/infrastructure only → Use devops-engineer or cloud-architect
40
41## Framework Support
42
43### Node.js/TypeScript
44- Express.js, NestJS, Koa.js, Fastify
45
46### Python
47- FastAPI, Django, Flask, Tornado
48
49### Java
50- Spring Boot, Quarkus, Micronaut
51
52### Go
53- Gin, Echo, Fiber
54
55## Decision Framework
56
57### Backend Framework Selection
58
59```
60Backend Framework Selection
61├─ JavaScript/TypeScript
62│ ├─ Need rapid development + type safety → NestJS
63│ ├─ Need lightweight/fast performance → Fastify
64│ └─ Need simplicity + ecosystem → Express.js
65│
66├─ Python
67│ ├─ Need async + high performance → FastAPI
68│ └─ Need batteries-included → Django (+ DRF)
69│
70├─ Java
71│ └─ Enterprise-ready → Spring Boot
72│
73└─ Go
74 └─ High-performance services → Gin or Fiber
75```
76
77### Authentication Strategy Matrix
78
79| Scenario | Strategy | Complexity | Security |
80|----------|----------|------------|----------|
81| Stateless API (mobile, SPA) | JWT | Low | Medium |
82| Third-party login | OAuth 2.0 | Medium | High |
83| Traditional web app | Session-based | Low | High |
84| Microservices | JWT + API Gateway | High | High |
85| Enterprise SSO | SAML 2.0 | High | Very High |
86
87### Database & ORM Selection
88
89```
90Database & ORM Decision
91├─ Relational (SQL)
92│ ├─ Node.js/TypeScript
93│ │ ├─ Need type safety + migrations → Prisma
94│ │ └─ Need flexibility → TypeORM or Sequelize
95│ ├─ Python
96│ │ ├─ Async required → Tortoise ORM or SQLModel
97│ │ └─ Sync / Django → Django ORM or SQLAlchemy
98│ └─ Java
99│ └─ JPA (Hibernate) or jOOQ
100│
101└─ NoSQL
102 ├─ Document store → MongoDB (Mongoose for Node.js)
103 └─ Key-value → Redis (caching, sessions)
104```
105
106## Best Practices
107
1081. **Always validate input** - Use provided validation middleware
1092. **Handle errors gracefully** - Use generated error handlers
1103. **Write tests** - Use test templates for consistency
1114. **Use environment variables** - Never hardcode secrets
1125. **Implement logging** - Use provided logging configuration
1136. **Monitor performance** - Set up metrics and alerts
1147. **Security first** - Use provided authentication setup
1158. **Version your API** - Follow versioning patterns
1169. **Document your code** - Generate API docs automatically
11710. **Deploy safely** - Use provided deployment scripts
118
119## Common Patterns
120
121### Repository Pattern
122- Separation of concerns
123- Easy testing
124- Swappable implementations
125
126### Service Layer
127- Centralized business rules
128- Transaction management
129- Error handling
130
131### Middleware Stack
132- Authentication
133- Authorization
134- Validation
135- Logging
136- Error handling
137
138## Troubleshooting
139
140### Common Issues
141
142**Database connection errors**
143- Check connection string
144- Verify database is running
145- Check network connectivity
146- Review connection pool settings
147
148**Authentication failures**
149- Verify JWT secret
150- Check token expiration
151- Validate token format
152- Review middleware order
153
154**Build failures**
155- Check TypeScript configuration
156- Verify dependencies are installed
157- Review error messages
158- Check for syntax errors
159
160**Deployment issues**
161- Verify Docker image builds
162- Check Kubernetes pods
163- Review logs
164- Verify environment variables
165
166## Quality Checklist
167
168### Security
169- [ ] Input validation on all endpoints (Zod/Joi)
170- [ ] Password hashing (bcrypt cost 10+ or Argon2)
171- [ ] SQL injection prevention (parameterized queries)
172- [ ] Rate limiting on auth endpoints
173- [ ] Security headers (Helmet.js)
174- [ ] Environment variables for secrets
175
176### Authentication & Authorization
177- [ ] Strong JWT secret (256-bit)
178- [ ] Short-lived access tokens (15min)
179- [ ] Refresh token rotation
180- [ ] Authorization checks on protected routes
181
182### Error Handling
183- [ ] Global error handler
184- [ ] Async error handling (express-async-errors)
185- [ ] Clear validation error messages
186- [ ] 404 handling for unknown endpoints
187
188### Performance
189- [ ] Database connection pooling
190- [ ] Query optimization (no N+1)
191- [ ] Caching (Redis for sessions, rate limiting)
192- [ ] Response compression (gzip/brotli)
193
194### Testing
195- [ ] Unit tests for services/repositories
196- [ ] Integration tests for API endpoints
197- [ ] >80% coverage for critical paths
198- [ ] Separate test database
199
200## Additional Resources
201
202- **Detailed Technical Reference**: See [REFERENCE.md](REFERENCE.md)
203- **Code Examples & Patterns**: See [EXAMPLES.md](EXAMPLES.md)