API Endpoint Scaffolder
Instructions
When creating a new API endpoint:
- Identify the framework (Express, Next.js, FastAPI, etc.)
- Determine HTTP method (GET, POST, PUT, PATCH, DELETE)
- Define request/response types
- Implement with best practices
Templates
Next.js App Router (TypeScript)
// app/api/[resource]/route.ts
import { NextRequest, NextResponse } from 'next/server';
import { z } from 'zod';
const RequestSchema = z.object({
// Define your schema
});
export async function GET(request: NextRequest) {
try {
const { searchParams } = new URL(request.url);
// Implementation
return NextResponse.json({ data }, { status: 200 });
} catch (error) {
console.error('[API] Error:', error);
return NextResponse.json(
{ error: 'Internal server error' },
{ status: 500 }
);
}
}
export async function POST(request: NextRequest) {
try {
const body = await request.json();
const validated = RequestSchema.parse(body);
// Implementation
return NextResponse.json({ data }, { status: 201 });
} catch (error) {
if (error instanceof z.ZodError) {
return NextResponse.json(
{ error: 'Validation failed', details: error.errors },
{ status: 400 }
);
}
return NextResponse.json(
{ error: 'Internal server error' },
{ status: 500 }
);
}
}
Express (TypeScript)
import { Router, Request, Response, NextFunction } from 'express';
import { z } from 'zod';
const router = Router();
const CreateSchema = z.object({
// Define schema
});
router.post('/', async (req: Request, res: Response, next: NextFunction) => {
try {
const data = CreateSchema.parse(req.body);
// Implementation
res.status(201).json({ success: true, data });
} catch (error) {
next(error);
}
});
export default router;
Best Practices
- Always validate input using Zod, Yup, or similar
- Use proper HTTP status codes:
- 200: Success
- 201: Created
- 400: Bad Request
- 401: Unauthorized
- 403: Forbidden
- 404: Not Found
- 500: Server Error
- Log errors but don't expose internals to clients
- Use consistent response format
- Add rate limiting for public endpoints
- Document with OpenAPI/Swagger when possible
1---2name: api-endpoint-scaffolder3description: Generate REST API endpoints with proper structure, validation, error handling, and types. Use when creating new API routes, endpoints, or backend services.4---56# API Endpoint Scaffolder78## Instructions910When creating a new API endpoint:11121. **Identify the framework** (Express, Next.js, FastAPI, etc.)132. **Determine HTTP method** (GET, POST, PUT, PATCH, DELETE)143. **Define request/response types**154. **Implement with best practices**1617## Templates1819### Next.js App Router (TypeScript)2021```typescript22// app/api/[resource]/route.ts23import { NextRequest, NextResponse } from 'next/server';24import { z } from 'zod';2526const RequestSchema = z.object({27 // Define your schema28});2930export async function GET(request: NextRequest) {31 try {32 const { searchParams } = new URL(request.url);33 // Implementation34 return NextResponse.json({ data }, { status: 200 });35 } catch (error) {36 console.error('[API] Error:', error);37 return NextResponse.json(38 { error: 'Internal server error' },39 { status: 500 }40 );41 }42}4344export async function POST(request: NextRequest) {45 try {46 const body = await request.json();47 const validated = RequestSchema.parse(body);48 // Implementation49 return NextResponse.json({ data }, { status: 201 });50 } catch (error) {51 if (error instanceof z.ZodError) {52 return NextResponse.json(53 { error: 'Validation failed', details: error.errors },54 { status: 400 }55 );56 }57 return NextResponse.json(58 { error: 'Internal server error' },59 { status: 500 }60 );61 }62}63```6465### Express (TypeScript)6667```typescript68import { Router, Request, Response, NextFunction } from 'express';69import { z } from 'zod';7071const router = Router();7273const CreateSchema = z.object({74 // Define schema75});7677router.post('/', async (req: Request, res: Response, next: NextFunction) => {78 try {79 const data = CreateSchema.parse(req.body);80 // Implementation81 res.status(201).json({ success: true, data });82 } catch (error) {83 next(error);84 }85});8687export default router;88```8990## Best Practices91921. **Always validate input** using Zod, Yup, or similar932. **Use proper HTTP status codes**:94 - 200: Success95 - 201: Created96 - 400: Bad Request97 - 401: Unauthorized98 - 403: Forbidden99 - 404: Not Found100 - 500: Server Error1013. **Log errors** but don't expose internals to clients1024. **Use consistent response format**1035. **Add rate limiting** for public endpoints1046. **Document with OpenAPI/Swagger** when possible