scaffold-api

SkillSecurity

Generate a new authenticated Next.js API route following RDO project conventions

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the scaffold-api skill

What this skill tells your AI

The instructions your AI receives, as published by theastrelo/claude-pipeline in .agents/skills/scaffold-api/SKILL.md and read by ahel’s review.

Create a new Next.js API route at src/pages/api/$ARGUMENTS.ts following these project conventions exactly:

Required Structure

  1. Swagger JSDoc comment block at the top of the file:
/**
 * @swagger
 * /api/$ARGUMENTS:
 *   get:
 *     summary: <describe endpoint>
 *     description: <longer description>
 *     tags: [<Feature Area>]
 *     security:
 *       - BearerAuth: []
 *       - CookieAuth: []
 *     parameters: [...]
 *     responses:
 *       200: { description: Success }
 *       401: { description: Unauthorized }
 *       500: { description: Server error }
 */
  1. Imports — always use these exact patterns:
import type { NextApiResponse } from 'next';
import { requireAuth, AuthenticatedRequest } from '@infrastructure/auth/middleware';
import pool from '@infrastructure/database/connection';
  1. Handler function with method check and userId extraction:
async function handler(req: AuthenticatedRequest, res: NextApiResponse) {
  if (req.method !== 'GET') {
    return res.status(405).json({ error: 'Method not allowed' });
  }

  const userId = req.userId!;

  try {
    // Query logic here using pool.query()
    const { rows } = await pool.query('SELECT ...', [userId]);
    return res.status(200).json(rows);
  } catch (error) {
    console.error('[API_NAME] Error:', error);
    return res.status(500).json({ error: 'Internal server error' });
  }
}
  1. Default export with auth wrapper:
export default requireAuth(handler);

Rules

  • Use requireAdmin instead of requireAuth if the route is admin-only
  • Use AuthenticatedRequest type, never NextApiRequest
  • Access user via req.userId! (non-null assertion)
  • Use pool.query() for database access — no ORM
  • Never use do as a SQL alias (PostgreSQL reserved word) — use d instead
  • Parse numeric scores with parseFloat(String(value)).toFixed(1)
  • Define TypeScript interfaces for response shapes at the top of the file
  • Add proper query parameter validation before database queries

Signals

GitHub stars
46
Forks
14
Last commit
Sep 2026
Advanced
Item type
skill
Key
scaffold-api-theastrelo
Source
github.com/theastrelo/claude-pipeline