← Cursor Slash Commands · ENGINEERING
/build-api
API Endpoint & Route Generator
Type-safe REST/GraphQL routes with Zod schema validation and error envelopes.
/build-api POST /api/v1/teams with member invite validation and email dispatchWhere it installs
# .cursor/commands/build-api.md
# no frontmatter, the file opens with its H1 title# .claude/commands/build-api.md
---
description: ...
argument-hint: [resource or endpoint description]
allowed-tools: Read, Grep, Glob, Skill, TodoWrite, Task, ...
---What it does
/build-api is a Cursor slash command. Type it in chat to run a saved workflow: API Endpoint & Route Generator.
Generates robust backend API routes with strict request payload validation, database transactions, standardized JSON error envelopes, and rate limiting.
Type-safe REST/GraphQL routes with Zod schema validation and error envelopes. Unlike a skill, a command is something you invoke on purpose. The agent does not decide to run /build-api for you.
Why it exists
Founders retype the same multi-step prompt until it rots. /build-api exists so the pipeline, all 4 steps of it, is a file in .cursor/commands, versioned with the repo.
It ships in the Engineering Kit. It is wired to API Integration Specialist (api-engineer), Senior Backend Architect (backend-architect), and App Security Auditor (security-auditor). Required skills: REST & API Route Design Patterns; Resilient Error Handling & Fault Tolerance; Authentication & Session Security Patterns.
When to use it
- Use when creating new backend endpoints, controller handlers, or webhook receivers.
- Use /build-api when you want that pipeline, not a freeform chat. If you only need one step, use a narrower command or a single agent.
- Start a new chat. Do not run this command in a thread that just wrote marketing copy.
When not to use it
- Do not run /build-api as a substitute for reading the diff. The command produces files; you still gate them.
- Do not chain it into a 40-turn chat. Fresh context is part of the design.
- Do not run it if you have not filled CURSOR.md. The pipeline will invent a stack.
Example workflow
- Define request and response TypeScript interfaces and Zod validation schemas
- Implement route handler with auth session verification and workspace permission check
- Execute database transactions using Drizzle ORM / Prisma
- Return standardized HTTP responses with appropriate status codes and error handles
Example usage
Type this in Cursor chat: /build-api POST /api/v1/teams with member invite validation and email dispatch
The command file tells the session which agents to adopt and which skills to read. You should see phase headers, not a single dump of code.
If a phase fails its gate, stop. Do not add 'just continue'.
Example output
- Expected artifact: src/app/api/.../route.ts
- Expected artifact: src/lib/validations/...
- Expected artifact: src/types/...
Best practices
- Keep the prompt specific. /build-api POST /api/v1/teams with member invite validation and email dispatch is the shape: object, constraint, and outcome.
- Let the listed agents work in order: api-engineer → backend-architect → security-auditor.
- Save outputs in the repo. Chat-only answers evaporate.
- Engineering commands should leave tests or an audit note, not only implementation files.
Common mistakes
- Typing /build-api with no object ('do the thing'). The pipeline will guess.
- Re-running the command in the same chat after a failed gate instead of fixing the failing file.
- Editing the command file to skip review so it 'goes faster'.
- Skipping the REST & API Route Design Patterns skill that the command depends on.
Frequently asked questions
What does /build-api do in Cursor?
Generates robust backend API routes with strict request payload validation, database transactions, standardized JSON error envelopes, and rate limiting.When should I run /build-api?
Use when creating new backend endpoints, controller handlers, or webhook receivers.What is an example /build-api prompt?
/build-api POST /api/v1/teams with member invite validation and email dispatchWhich skills does /build-api load?
REST & API Route Design Patterns; Resilient Error Handling & Fault Tolerance; Authentication & Session Security PatternsIs /build-api a Cursor skill?
No. /build-api is a slash command you type. Skills are playbooks the agent may load. Use both: the command runs the workflow, the skills constrain how it writes.
Run /build-api from your own repo
AgenticKit installs 47 slash commands, 46 agents, and 61 skills. One command installation.