一键导入
api-patterns
API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | api-patterns |
| description | API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination. |
| risk | unknown |
| source | community |
| date_added | 2026-02-27 |
API design principles and decision-making for 2025. Learn to THINK, not copy fixed patterns.
Read ONLY files relevant to the request! Check the content map, find what you need.
| File | Description | When to Read |
|---|---|---|
api-style.md | REST vs GraphQL vs tRPC decision tree | Choosing API type |
rest.md | Resource naming, HTTP methods, status codes | Designing REST API |
response.md | Envelope pattern, error format, pagination | Response structure |
graphql.md | Schema design, when to use, security | Considering GraphQL |
trpc.md | TypeScript monorepo, type safety | TS fullstack projects |
versioning.md | URI/Header/Query versioning | API evolution planning |
auth.md | JWT, OAuth, Passkey, API Keys | Auth pattern selection |
rate-limiting.md | Token bucket, sliding window | API protection |
documentation.md | OpenAPI/Swagger best practices | Documentation |
security-testing.md | OWASP API Top 10, auth/authz testing | Security audits |
| Need | Skill |
|---|---|
| API implementation | @[skills/backend-development] |
| Data structure | @[skills/database-design] |
| Security details | @[skills/security-hardening] |
Before designing an API:
DON'T:
DO:
| Script | Purpose | Command |
|---|---|---|
scripts/api_validator.py | API endpoint validation | python scripts/api_validator.py <project_path> |
This skill is applicable to execute the workflow or actions described in the overview.
Implement advanced Symfony 8.1 components: async/queues with Messenger (#[AsMessageHandler], transports, retry, failed messages), Serializer (serialize/deserialize, groups, context), Workflow & state machines (places/transitions, guards, transition listeners), Mercure realtime updates, Lock (mutexes/critical sections), HTTP Client (HttpClientInterface), Cache pools (CacheInterface, tags), Rate Limiter (RateLimiterFactoryInterface), Scheduler (#[AsSchedule], RecurringMessage), and Webhook/RemoteEvent consumers. Use whenever a task mentions queues, background jobs, async processing, message bus, serialization to JSON, state machines, realtime/SSE, distributed locks, calling external APIs, caching, throttling/rate limiting, cron/recurring tasks, or incoming webhooks.
Use for ANY Symfony AI task: integrating LLMs/AI into a Symfony or PHP app via the Symfony AI components. Covers the Platform component (unified interface to OpenAI, Anthropic Claude, Google Gemini, Azure, Mistral, Ollama), building an AI Agent, tool calling with the #[AsTool] attribute, Retrieval Augmented Generation (RAG) with a vector Store and embeddings, the Chat component and conversation memory, configuring everything through the AI Bundle YAML (config/packages/ai.yaml), and exposing or consuming an MCP server (MCP Bundle / Mate). Trigger on symfony/ai, ai-bundle, AsTool, MessageBag, vectorizer, SimilaritySearch, McpTool, or any "add AI/chatbot/embeddings/RAG to Symfony".
Build and wire the core architecture of a Symfony 8.1 app. Use this whenever you work with the service container, dependency injection, autowiring, service tags, factories, service decoration, the event dispatcher (listeners/subscribers), bundles, the kernel, or app configuration (config/packages, environment variables, secrets, parameters). Reach for this skill before creating a service class, injecting a dependency, hooking into a kernel event, or editing config.
Use when building Symfony 8.1 web pages and features: creating routes, controllers, Twig templates, Doctrine entities and CRUD, forms, and validation. Reach for this skill whenever you create a page, wire a URL to a controller, render HTML with Twig, persist or query data with Doctrine entities/repositories, build a Symfony form, or add validation constraints.
Use for Symfony 8.1 deployment, production configuration, and operations. Covers deploying (APP_ENV=prod, composer install --no-dev --optimize-autoloader, cache:clear/warmup, dump-env), performance tuning (OPcache, realpath cache, preloading, container single-file, classmap-authoritative), HTTP caching (Cache-Control, Expires, ETag, Last-Modified, Vary, reverse proxy, invalidation/PURGE), profiler and debugging, logging with Monolog (handlers, channels, fingers_crossed), testing with PHPUnit (WebTestCase, KernelTestCase, assertions, database), and Symfony best practices. Trigger whenever a task mentions deploy, prod env, opcache, performance, HTTP cache, reverse proxy, profiler, Monolog/logs, PHPUnit tests, or production hardening of a Symfony app.
Use for ALL Symfony 8.1 security work: authentication and authorization, login (form_login, json_login, http_basic, login link), firewalls and security.yaml, user providers, roles and role_hierarchy, password hashing, access control (access_control, #[IsGranted], denyAccessUnlessGranted), voters, CSRF protection, logout, and custom authenticators. Trigger whenever a task mentions login, secure a route, protect an endpoint, roles, permissions, hashing passwords, who can access, firewall, or security.yaml.