laravel-api
Build REST endpoints with API Resources, Sanctum authentication, and versioned route groups in Laravel. Use when creating JsonResource classes, adding token-based auth, or defining rate-limited API routes.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 3
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 e85ee9a687c6aa31… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Laravel API
Priority: P1 (HIGH)
Workflow: Create New API Endpoint
- Generate resource —
php artisan make:resource UserResource. - Define toArray() — Specify exact output fields; never return raw models.
- Add route — Register in
routes/api.phpwith version prefix and throttle middleware. - Secure with Sanctum — Apply
auth:sanctummiddleware to protected routes. - Return proper status codes — 201 for Created, 422 for Validation, 204 for No Content.
API Resource Example
See implementation examples for complete API Resource with collection usage.
Implementation Guidelines
API Resources & Transformation
- API Resources: Always use
ApiResourceclasses extendingJsonResourcefor data transformation. - Collections: Use
UserResource::collection($users)for lists. Never useresponse()->json($model)or return raw models directly. - Data Definition: Implement
toArray($request)to define specific output fields and prevent sensitive data leakage. - Generation: Use
php artisan make:resource UserResourceto scaffold new resources.
Authentication & Security
- Sanctum: Use
auth:sanctummiddleware inroutes/api.phpfor SPAs or mobile app authentication. - Traits: Add
HasApiTokenstrait to yourUsermodel to enable token-based authentication. - Token Management: Issue tokens using
$user->createToken('token-name')->plainTextToken. - OAuth2: Use Passport only if standard OAuth2 flows or client grants required.
Routing & Performance
- Versioning: Group routes with
Route::prefix('v1')->group(...)and use versioned namespaces (e.g.,App\Http\Controllers\Api\V1). - Rate Limiting: Define
RateLimiter::for('api', ...)usingLimit::perMinute(60)inAppServiceProvider. - Middleware: Apply
throttle:apimiddleware to route groups inroutes/api.php. - Status Codes: Return 201 for Created, 422 for Validation errors, and 204 for No Content.
Anti-Patterns
- No raw model returns: Use API Resources; prevents data leakage.
- No
response()->json(): Use API Resource classes instead. - No session auth for APIs: Use Sanctum or Passport tokens.
- No static URLs in JSON: Use route names or HATEOAS links.
References
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
-
ApiResource
-
routes/api.php
-
toArray()
-
Additional task-grounded exact anchors: UserResource
Files
3- SKILL.md
0fa33e80793.1 KB - evals/evals.json
83efd222a54.0 KB - references/implementation.md
1942c51716955 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from HoangNguyen0403/agent-skills-standard8
Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.
Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow implementation to their spec
Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.
Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.
Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.
Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes, persistence/notifications, and unit-test reci
Configure release signing, R8 obfuscation, and App Bundle publishing for Android. Use when setting up signing configs, enabling minification, adding ProGuard keep rules, or preparing for Play Store submission.
Enforce Material Design 3 theming and design token usage in Jetpack Compose. Use when implementing M3 components, color schemes, typography, or design tokens.
Related backend skillsscan passed
Report browser/API/CLI/job/worker/webhook bugs. (gstack)
PostHog error tracking for Ruby on Rails
Verify a local agent API, temporary gateway tunnel, and remote sandbox callback with a tool-free task, then restore the original app connection.
This skill should be used when the user asks to "build an MCP server", "create an MCP", "make an MCP integration", "wrap an API for Claude", "expose tools to Claude", "make an MCP app", or discusses building something with the Model Context Protocol. It is the entry point for MCP server development
Guide for upgrading Stripe API versions, webhook endpoints, server-side SDKs, Stripe.js, and mobile SDKs
Configure input and output validation with .input() and .output() using Zod, Yup, Superstruct, ArkType, Valibot, Effect, or custom validator functions. Chain multiple .input() calls to merge object schemas. Standard Schema protocol support. Output validation returns INTERNAL_SERVER_ERROR on failure.