OpenAPI 3.x best practices
Help teams produce maintainable OpenAPI 3.x contracts that stay aligned with HTTP semantics and consumer needs.
What is covered in this Skill?
- Document structure:
openapi, info, servers, tags, and consistent resource grouping
- Path and operation design: parameters, request bodies, response matrices,
operationId, status codes
- Reusable
components (schemas, parameters, responses, security schemes) and examples
- Validation and CI: spec linting, breaking-change checks, pre-codegen gates
- Security modeling in the contract (schemes, scopes, global vs operation security)
- Clear boundaries between contract-first design and runtime implementation concerns
Scope: Contract-first quality only. Focus this skill on OpenAPI design, quality, and governance guidance.
Constraints
Keep recommendations at the OpenAPI layer unless the user explicitly asks for Java framework integration. After editing this repository's XML sources, regenerate skills and verify the build.
- MANDATORY: Run
./mvnw compile or mvn compile before proposing Java or Maven changes in the same change set
- FRAMEWORK: Keep guidance contract-centric; do not prescribe framework-specific controller wiring or runtime exposure details
- FUZZING: Keep fuzzing guidance high-level and contract-focused without linking to external skill identifiers
- MANDATORY: Regenerate skills with
./mvnw clean install -pl skills-generator after editing skill or system-prompt XML in this repo
- VERIFY: Run
./mvnw clean verify or mvn clean verify before promoting changes
- EDGE CASE: If the user goal is ambiguous, stop and ask a clarifying question before editing files or running project-wide commands
- EDGE CASE: If required context, files, credentials, or tools are missing, report the blocker explicitly and ask whether to proceed with setup or fallback guidance
- EDGE CASE: If requested changes conflict with project constraints or safety boundaries, explain the conflict and ask for user confirmation on the preferred trade-off
When to use this skill
- Review an OpenAPI
- Improve an OpenAPI
- Improve API contract
- Improve API schema design
- Validate an OpenAPI spec
Workflow
- Read reference and assess project context
Read references/701-technologies-openapi.md and inspect current API/context artifacts before proposing changes.
- Gather scope and decide target improvements
Identify requested outcomes, constraints, and the minimum safe set of changes to apply.
- Apply technology-aligned changes
Implement or refactor artifacts following the reference patterns and project conventions.
- Run verification and report results
Execute appropriate checks and summarize what changed, what was verified, and any follow-up actions.
Reference
For detailed guidance, examples, and constraints, see references/701-technologies-openapi.md.
1---2name: 701-technologies-openapi-23description: Use when you need framework-agnostic OpenAPI 3.x guidance — spec structure, metadata and versioning, paths and operations, reusable schemas, security schemes, examples, documentation quality, contract validation (e.g. Spectral), breaking-change awareness, and handoffs to codegen — without choosing Spring Boot, Quarkus, or Micronaut. This should trigger for requests such as Review an OpenAPI; Improve an OpenAPI; Improve API contract; Improve API schema design. Part of cursor-rules-java project4license: Apache-2.05---6# OpenAPI 3.x best practices78Help teams produce maintainable **OpenAPI 3.x** contracts that stay aligned with HTTP semantics and consumer needs.910**What is covered in this Skill?**1112- Document structure: `openapi`, `info`, `servers`, `tags`, and consistent resource grouping13- Path and operation design: parameters, request bodies, response matrices, `operationId`, status codes14- Reusable `components` (schemas, parameters, responses, security schemes) and examples15- Validation and CI: spec linting, breaking-change checks, pre-codegen gates16- Security modeling in the contract (schemes, scopes, global vs operation security)17- Clear boundaries between contract-first design and runtime implementation concerns1819**Scope:** Contract-first quality only. Focus this skill on OpenAPI design, quality, and governance guidance.2021## Constraints2223Keep recommendations at the OpenAPI layer unless the user explicitly asks for Java framework integration. After editing this repository's XML sources, regenerate skills and verify the build.2425- **MANDATORY**: Run `./mvnw compile` or `mvn compile` before proposing Java or Maven changes in the same change set26- **FRAMEWORK**: Keep guidance contract-centric; do not prescribe framework-specific controller wiring or runtime exposure details27- **FUZZING**: Keep fuzzing guidance high-level and contract-focused without linking to external skill identifiers28- **MANDATORY**: Regenerate skills with `./mvnw clean install -pl skills-generator` after editing skill or system-prompt XML in this repo29- **VERIFY**: Run `./mvnw clean verify` or `mvn clean verify` before promoting changes30- **EDGE CASE**: If the user goal is ambiguous, stop and ask a clarifying question before editing files or running project-wide commands31- **EDGE CASE**: If required context, files, credentials, or tools are missing, report the blocker explicitly and ask whether to proceed with setup or fallback guidance32- **EDGE CASE**: If requested changes conflict with project constraints or safety boundaries, explain the conflict and ask for user confirmation on the preferred trade-off3334## When to use this skill3536- Review an OpenAPI37- Improve an OpenAPI38- Improve API contract39- Improve API schema design40- Validate an OpenAPI spec4142## Workflow43441. **Read reference and assess project context**4546Read `references/701-technologies-openapi.md` and inspect current API/context artifacts before proposing changes.47482. **Gather scope and decide target improvements**4950Identify requested outcomes, constraints, and the minimum safe set of changes to apply.51523. **Apply technology-aligned changes**5354Implement or refactor artifacts following the reference patterns and project conventions.55564. **Run verification and report results**5758Execute appropriate checks and summarize what changed, what was verified, and any follow-up actions.5960## Reference6162For detailed guidance, examples, and constraints, see [references/701-technologies-openapi.md](references/701-technologies-openapi.md).