| name | api-first-product-strategy |
| description | API-First Product Strategy treats APIs as first-class citizens in product Use when this capability is needed. |
| metadata | {"author":"amnadtaowsoam"} |
Api First Product Strategy
Skill Profile
(Select at least one profile to enable specific modules)
Overview
API-First Product Strategy treats APIs as first-class citizens in product design, enabling better integration, developer experience, and ecosystem growth. This approach is essential for modern SaaS products, platform businesses, and any product requiring third-party integration.
Why This Matters
Strategic Necessity:
- Developer Experience: Improve DX for API consumers with clear, consistent APIs
- Integration: Enable seamless third-party integration through well-documented contracts
- Ecosystem Growth: Foster partner and developer ecosystem growth
- Time-to-Market: Accelerate development through parallel API and UI work
- Flexibility: Support multiple client types (web, mobile, IoT) from single API
Core Concepts & Rules
1. Core Principles
- Follow established patterns and conventions
- Maintain consistency across codebase
- Document decisions and trade-offs
2. Implementation Guidelines
- Start with the simplest viable solution
- Iterate based on feedback and requirements
- Test thoroughly before deployment
Inputs / Outputs / Contracts
- Inputs:
- <e.g., env vars, request payload, file paths, schema>
- Entry Conditions:
- <Pre-requisites: e.g., Repo initialized, DB running, specific branch checked out>
- Outputs:
- <e.g., artifacts (PR diff, docs, tests, dashboard JSON)>
- Artifacts Required (Deliverables):
- <e.g., Code Diff, Unit Tests, Migration Script, API Docs>
- Acceptance Evidence:
- <e.g., Test Report (screenshot/log), Benchmark Result, Security Scan Report>
- Success Criteria:
- <e.g., p95 < 300ms, coverage ≥ 80%>
Skill Composition
- Depends on: None
- Compatible with: None
- Conflicts with: None
- Related Skills: None
Quick Start / Implementation Example
- Review requirements and constraints
- Set up development environment
- Implement core functionality following patterns
- Write tests for critical paths
- Run tests and fix issues
- Document any deviations or decisions
def example_function():
pass
Assumptions
- Product requirements are well-defined before API design
- Development team has API design expertise
- Target audience includes developers or partners
- Sufficient resources for documentation and SDK development
- API gateway infrastructure available
Compatibility & Prerequisites
- Supported Versions:
- Python 3.8+
- Node.js 16+
- Modern browsers (Chrome, Firefox, Safari, Edge)
- Required AI Tools:
- Code editor (VS Code recommended)
- Testing framework appropriate for language
- Version control (Git)
- Dependencies:
- Language-specific package manager
- Build tools
- Testing libraries
- Environment Setup:
.env.example keys: API_KEY, DATABASE_URL (no values)
Test Scenario Matrix
| Scenario | Description | Expected Outcome |
|---|
| API Design | Design API from product requirements | Complete endpoint definitions with schemas |
| Documentation Generation | Generate OpenAPI specification | Valid OpenAPI 3.0 spec with all endpoints |
| SDK Generation | Generate client SDKs | Working SDKs for JavaScript, Python, Java |
| Validation | Validate API design | No errors, minimal warnings |
| Developer Portal | Deploy interactive documentation | Working Swagger UI and Redoc |
| Versioning | Apply versioning strategy | Versioned endpoints with clear paths |
| Security | Apply authentication and rate limiting | All endpoints secured and rate-limited |
Technical Guardrails & Security Threat Model
1. Security & Privacy (Threat Model)
- Top Threats: Injection attacks, authentication bypass, data exposure
2. Performance & Resources
3. Architecture & Scalability
4. Observability & Reliability
Agent Directives
- Design Phase: Always design API before implementation
- Documentation First: Generate OpenAPI spec before coding
- Validation: Validate API design before proceeding
- Security: Apply security best practices to all endpoints
- Developer Experience: Prioritize developer experience in all decisions
Definition of Done (DoD) Checklist
Anti-patterns / Pitfalls
- ⛔ Don't: Log PII, catch-all exception, N+1 queries
- ⚠️ Watch out for: Common symptoms and quick fixes
- 💡 Instead: Use proper error handling, pagination, and logging
Reference Links & Examples
- Internal documentation and examples
- Official documentation and best practices
- Community resources and discussions
Versioning & Changelog
- Version: 1.0.0
- Changelog:
- 2026-02-22: Initial version with complete template structure
Converted and distributed by TomeVault — claim your Tome and manage your conversions.