API Design Reviewer

SkillSecurity

Review REST and GraphQL API designs for consistency, usability, and best practices. Covers naming conventions, versioning strategy, error format, pagination, authentication patterns, and breaking change detection. Use when reviewing API specs, designing new APIs, or auditing existing endpoints.

Use API Design Reviewer in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add API Design Reviewer and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the API Design Reviewer skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

API Design ReviewerStart free

What this skill tells your AI

The instructions your AI receives, as published by hoavdc/codexkit in skills/codexkit-api-design-reviewer/SKILL.md and read by ahel’s review.

When to Use

  • When reviewing an OpenAPI/Swagger specification before implementation
  • When auditing existing API endpoints for consistency
  • When designing a new API from scratch
  • When preparing APIs for external/partner consumption

Procedure

Step 1 — Naming & Convention Check

CheckRuleExample
Resource namingPlural nouns, kebab-case✅ /api/v1/order-items ❌ /api/v1/getOrderItem
HTTP methodsGET=read, POST=create, PUT=replace, PATCH=partial, DELETE=remove✅ POST /orders ❌ POST /create-order
Query paramscamelCase for filters/sorting✅ ?sortBy=createdAt ❌ ?sort_by=created_at
Status codesUse standard codes correctly✅ 201 Created, 204 No Content ❌ 200 for everything
ConsistencySame pattern across all endpointsCheck all resources follow same naming

Step 2 — Versioning Strategy

StrategyWhen to UsePattern
URL pathSimple, widely adopted/api/v1/orders
HeaderCleaner URLs, harder to testAccept: application/vnd.api+json;version=1
Query paramEasy to test, but less RESTful/api/orders?version=1

Verify:

  • Version is present in all endpoints
  • Deprecation policy documented
  • Migration guide for version bumps

Step 3 — Error Format

Errors should follow a consistent structure:

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Human-readable description",
    "details": [
      {
        "field": "email",
        "issue": "Invalid format",
        "expected": "Valid email address"
      }
    ],
    "request_id": "req_abc123",
    "docs_url": "https://docs.api.com/errors/VALIDATION_ERROR"
  }
}

Check:

  • Error format consistent across all endpoints
  • Machine-readable error codes (not just messages)
  • Request ID for traceability
  • No sensitive data in error responses

Step 4 — Pagination

PatternBest ForImplementation
Cursor-basedLarge datasets, real-time data?cursor=abc&limit=20
Offset-basedSimple lists, admin UIs?page=2&per_page=20
KeysetTime-series data?after=2024-03-15T00:00:00Z&limit=20

Check:

  • Default page size set (and documented)
  • Maximum page size enforced
  • Total count available (or explicitly omitted for performance)
  • Links to next/prev pages in response

Step 5 — Security Patterns

CheckDetails
AuthenticationBearer token, API key, OAuth2 — documented per endpoint
AuthorizationRole-based access noted per endpoint
Rate limitingHeaders: X-RateLimit-Limit, X-RateLimit-Remaining, Retry-After
Input validationMax lengths, allowed characters, type checking
CORSAppropriate origins, methods, headers

Step 6 — Breaking Change Detection

Identify potential breaking changes:

  • ❌ Removing a field from response
  • ❌ Changing a field type (string → integer)
  • ❌ Making an optional field required
  • ❌ Changing endpoint URL
  • ✅ Adding a new optional field
  • ✅ Adding a new endpoint
  • ✅ Adding a new optional query parameter

Inputs

InputRequiredFormat
API specificationYesOpenAPI/Swagger YAML/JSON or endpoint list
Business contextRecommendedWho consumes this API
Existing APIRecommendedFor breaking change detection

Output

## API Review — [API Name]

### Summary
**Endpoints reviewed:** 24 | **Issues found:** 8 | **Breaking changes:** 0

### Issues

| # | Severity | Category | Endpoint | Issue | Fix |
|---|----------|----------|----------|-------|-----|
| 1 | High | Naming | POST /createUser | Verb in URL | POST /users |
| 2 | Medium | Errors | All | No request_id | Add tracing ID |
| 3 | Low | Pagination | GET /logs | No max page size | Enforce limit ≤ 100 |

### Recommendations
[Summary of patterns to adopt or fix]

Definition of Done

  • Naming conventions checked across all endpoints
  • Versioning strategy reviewed
  • Error format consistency verified
  • Pagination patterns assessed
  • Security patterns checked
  • Breaking changes flagged

Quality Criteria

  • Feedback is specific and references exact locations in the reviewed material
  • Each critique includes a concrete improvement suggestion
  • Severity is categorized (critical / important / nice-to-have)
  • Positive aspects are acknowledged alongside areas for improvement

Verification (4C)

CheckQuestion
CorrectnessIs the feedback technically accurate and properly contextualized?
CompletenessWere all major sections of the reviewed material addressed?
Context-fitIs the review granularity appropriate for the material's maturity level?
ConsequenceIf the author implemented all feedback literally, what could go wrong?

Edge Cases

  • Material is too early-stage for detailed review — Provide structural feedback only. Note that content review is deferred until it matures.
  • Reviewer lacks domain expertise — Focus on structure, clarity, and consistency. Flag domain-specific claims as 'Needs SME verification'.
  • Author is defensive or resistant to feedback — Lead with what works well. Frame changes as questions rather than mandates.

Changelog

  • v1.0.0 — Initial release

Signals

GitHub stars
25
Forks
13
Last commit
Oct 2026
Advanced
Item type
skill
Key
codexkit-api-design-reviewer
Source
github.com/hoavdc/codexkit