API Endpoint Creation Skill
When creating a new API endpoint, follow this procedure exactly:
1. REST Conventions
| Action | HTTP Verb | Route Pattern | Success Code |
|---|---|---|---|
| List resources | GET |
/api/v1/resources |
200 |
| Get single | GET |
/api/v1/resources/:id |
200 |
| Create resource | POST |
/api/v1/resources |
201 |
| Update resource | PATCH |
/api/v1/resources/:id |
200 |
| Replace resource | PUT |
/api/v1/resources/:id |
200 |
| Delete resource | DELETE |
/api/v1/resources/:id |
204 |
2. Request/Response Validation
- Define Zod schemas for both request body and response body.
- Validate at the middleware layer, before the handler executes.
const CreateUserSchema = z.object({
email: z.string().email(),
name: z.string().min(1).max(100),
role: z.enum(['admin', 'member', 'viewer']),
});
3. Standardised Error Response
All errors must return this shape:
{
"error": {
"code": "VALIDATION_ERROR",
"message": "Email format is invalid.",
"details": [{ "field": "email", "issue": "Invalid email format" }]
}
}
4. Middleware Chain
Every endpoint must pass through this middleware chain in order:
authenticate— Verify JWT, attachreq.user.authorize— Check RBAC permissions for the route.validate— Run Zod schema validation onreq.body/req.query.handler— Execute business logic.errorHandler— Catch and format any thrown errors.
5. OpenAPI Documentation
- Annotate every endpoint with JSDoc or decorators that generate OpenAPI 3.0 specs.
- Include request body schema, response schema, error codes, and authentication requirements.