building-api-gateway
Automates the setup of API gateways to manage routing and security across backend microservices.
Install
mkdir -p .claude/skills/building-api-gateway && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8165" && unzip -o skill.zip -d .claude/skills/building-api-gateway && rm skill.zipInstalls to .claude/skills/building-api-gateway
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Create API gateways with routing, load balancing, rate limiting, andKey capabilities
- →Configure path-based and header-based routing
- →Implement centralized authentication enforcement
- →Apply rate limiting per consumer
- →Execute response aggregation for composite endpoints
- →Manage circuit breakers for backend services
How it works
The gateway acts as a unified entry point that manages cross-cutting concerns like authentication, rate limiting, and routing before forwarding requests to backend services.
Inputs & outputs
When to use building-api-gateway
- →Managing multiple backend services
- →Adding rate limiting to APIs
- →Setting up unified authentication
About this skill
Building API Gateway
Overview
Create an API gateway that provides unified entry point routing, load balancing, authentication enforcement, rate limiting, request transformation, and response aggregation across multiple backend microservices. Support path-based and header-based routing, circuit breaker protection for downstream services, and centralized cross-cutting concern management.
Prerequisites
- Multiple backend API services with known endpoints, health check URLs, and authentication requirements
- Gateway framework: Express Gateway, Kong (declarative config), KrakenD, or custom Node.js/Go implementation
- Service registry or static upstream configuration for backend service discovery
- TLS certificates for gateway termination and optional mTLS for backend communication
- Centralized logging and metrics collection for gateway-level observability
Instructions
- Inventory all backend services using Read and Grep, documenting their base URLs, endpoint paths, authentication requirements, and health check endpoints.
- Define routing rules that map public-facing URL patterns to backend service endpoints: path-based (
/users/*-> user-service), header-based (X-API-Version: 2-> v2-service), or method-based routing. - Implement authentication at the gateway layer: validate JWT tokens, API keys, or OAuth2 tokens once at the gateway and forward authenticated user context to backend services via headers (
X-User-ID,X-User-Roles). - Add rate limiting at the gateway level with per-consumer quotas, applying limits before requests reach backend services to protect all downstream services uniformly.
- Configure request transformation: strip internal headers from incoming requests, add correlation IDs, rewrite URL paths for backend routing, and inject service-specific headers.
- Implement response aggregation for composite endpoints that fan out to multiple backend services, merge responses, and return a unified payload to the client.
- Add circuit breaker protection per backend service: open the circuit after configurable failure thresholds, return 503 with the failed service identified, and auto-recover after health check success.
- Configure health check aggregation: gateway
/healthendpoint reports overall status based on individual backend service health, with degraded state support for non-critical service failures. - Write integration tests covering routing correctness, auth enforcement, rate limiting, circuit breaker behavior, and response aggregation.
See ${CLAUDE_SKILL_DIR}/references/implementation.md for the full implementation guide.
Output
${CLAUDE_SKILL_DIR}/gateway/config/routes.yaml- Route mapping definitions (path -> service)${CLAUDE_SKILL_DIR}/gateway/middleware/auth.js- Gateway-level authentication enforcement${CLAUDE_SKILL_DIR}/gateway/middleware/rate-limiter.js- Centralized rate limiting${CLAUDE_SKILL_DIR}/gateway/middleware/circuit-breaker.js- Per-service circuit breaker${CLAUDE_SKILL_DIR}/gateway/middleware/transform.js- Request/response transformation logic${CLAUDE_SKILL_DIR}/gateway/aggregators/- Response aggregation for composite endpoints${CLAUDE_SKILL_DIR}/gateway/health.js- Aggregated health check endpoint${CLAUDE_SKILL_DIR}/tests/gateway/- Gateway integration test suite
Error Handling
| Error | Cause | Solution |
|---|---|---|
| 502 Bad Gateway | Backend service returned invalid response or connection refused | Return descriptive error identifying the failed backend; trigger circuit breaker if threshold met |
| 503 Circuit Open | Backend service circuit breaker is open due to repeated failures | Return Retry-After header; serve cached response if available; route to fallback service if configured |
| 504 Gateway Timeout | Backend service response exceeded gateway timeout threshold | Configure per-route timeout limits; implement timeout cascading shorter than client timeout |
| Routing miss | Request path does not match any configured route | Return 404 with list of available API paths; log unmatched routes for route configuration review |
| Auth header stripping | Proxy strips Authorization header before forwarding to backend | Configure gateway to preserve or transform auth headers; verify proxy proxy_pass_header settings |
Refer to ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error patterns.
Examples
Microservices gateway: Route /users/* to user-service (port 3001), /orders/* to order-service (port 3002), and /products/* to product-service (port 3003), with unified JWT validation and per-service circuit breakers.
BFF (Backend for Frontend): Gateway aggregates data from user-service, preferences-service, and notification-service into a single /dashboard response, reducing frontend API calls from 3 to 1.
API versioning gateway: Route requests to different backend deployments based on Accept-Version header, enabling blue-green deployments and gradual version migration without client-side URL changes.
See ${CLAUDE_SKILL_DIR}/references/examples.md for additional examples.
Resources
- Kong API Gateway: https://konghq.com/
- Express Gateway: https://www.express-gateway.io/
- KrakenD: https://www.krakend.io/
- API Gateway pattern: Microservices.io
When not to use it
- →When managing a single, non-distributed service
Prerequisites
Limitations
- →Requires TLS certificates for gateway termination
- →Requires centralized logging and metrics collection
How it compares
It centralizes management of cross-cutting concerns instead of implementing them individually in every microservice.
Compared to similar skills
building-api-gateway side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| building-api-gateway (this skill) | 0 | 27d | Review | Advanced |
| mcp-builder | 136 | 3mo | Review | Advanced |
| langchain-architecture | 8 | 2mo | Review | Intermediate |
| nodejs-backend-patterns | 12 | 2mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
mcp-builder
anthropics
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
langchain-architecture
wshobson
Design LLM applications using the LangChain framework with agents, memory, and tool integration patterns. Use when building LangChain applications, implementing AI agents, or creating complex LLM workflows.
nodejs-backend-patterns
wshobson
Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices. Use when creating Node.js servers, REST APIs, GraphQL backends, or microservices architectures.
backend-architect
sickn33
Expert backend architect specializing in scalable API design, microservices architecture, and distributed systems. Masters REST/GraphQL/gRPC APIs, event-driven architectures, service mesh patterns, and modern backend frameworks. Handles service boundary definition, inter-service communication, resilience patterns, and observability. Use PROACTIVELY when creating new backend services or APIs.
apollo-reference-architecture
jeremylongshore
Implement Apollo.io reference architecture. Use when designing Apollo integrations, establishing patterns, or building production-grade sales intelligence systems. Trigger with phrases like "apollo architecture", "apollo system design", "apollo integration patterns", "apollo best practices architecture".
customerio-reference-architecture
jeremylongshore
Implement Customer.io reference architecture. Use when designing integrations, planning architecture, or implementing enterprise patterns. Trigger with phrases like "customer.io architecture", "customer.io design", "customer.io enterprise", "customer.io integration pattern".