---
name: api-patterns
description: "API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination. Use when choosing between REST, GraphQL and tRPC, or shaping response formats, versioning and pagination."
risk: unknown
source: community
date_added: "2026-02-27"
---

# API Patterns

> API design principles and decision-making for 2025.
> **Learn to THINK, not copy fixed patterns.**

## 📑 Topics

| Topic | Covers | When it applies |
|------|-------------|--------------|
| API style | REST vs GraphQL vs tRPC decision tree | Choosing API type |
| REST | Resource naming, HTTP methods, status codes | Designing REST API |
| Response shape | Envelope pattern, error format, pagination | Response structure |
| GraphQL | Schema design, when to use, security | Considering GraphQL |
| tRPC | TypeScript monorepo, type safety | TS fullstack projects |
| Versioning | URI/Header/Query versioning | API evolution planning |
| Auth | JWT, OAuth, Passkey, API Keys | Auth pattern selection |
| Rate limiting | Token bucket, sliding window | API protection |
| Documentation | OpenAPI/Swagger best practices | Documentation |
| Security testing | OWASP API Top 10, auth/authz testing | Security audits |

---

## 🔗 Related Skills

| Need | Skill |
|------|-------|
| API implementation | `@[skills/backend-development]` |
| Data structure | `@[skills/database-design]` |
| Security details | `@[skills/security-hardening]` |

---

## ✅ Decision Checklist

Before designing an API:

- [ ] **Asked user about API consumers?**
- [ ] **Chosen API style for THIS context?** (REST/GraphQL/tRPC)
- [ ] **Defined consistent response format?**
- [ ] **Planned versioning strategy?**
- [ ] **Considered authentication needs?**
- [ ] **Planned rate limiting?**
- [ ] **Documentation approach defined?**

---

## ❌ Anti-Patterns

**DON'T:**
- Default to REST for everything
- Use verbs in REST endpoints (/getUsers)
- Return inconsistent response formats
- Expose internal errors to clients
- Skip rate limiting

**DO:**
- Choose API style based on context
- Ask about client requirements
- Document thoroughly
- Use appropriate status codes

---

## When to Use
This skill is applicable to execute the workflow or actions described in the overview.
