APIs & Backend Logic

Prompt API endpoints and backend logic with the contract spelled out: methods, schemas, validation, errors, and auth.

TL;DR

  1. Spell out the contract: method, path, request and response schemas, status codes, and errors.
  2. Require input validation and explicit error responses; backends fail at the edges.
  3. State the auth and authorization rules; the model will not guess your security model correctly.

Define The Contract

    Method & Path

    State the verb and route, including params.

    "PATCH /api/orders/:id"
    Request Shape

    Give the body, query, and params as types.

    body: { status: 'paid' | 'cancelled' }
    params: { id: string }
    Response Shape

    Define the success body and status code.

    200 -> { id, status, updatedAt }

Validate Input

    Schema Validation

    Validate the body and params with your tool before using them.

    "Validate with zod; 400 + field
    errors on failure."
    Bounds & Types

    State required fields, types, and allowed values.

    "status must be one of the enum;
    id must be a cuid."
    Never Trust Input

    Treat all client input as hostile until validated.

    Parse, don't assume. Reject early.

Errors & Status

    Map The Cases

    List each failure and its status code.

    404 not found, 401 unauth,
    403 forbidden, 400 invalid
    No Leaks

    Return safe messages; never expose stack traces or internals.

    "500 returns a generic message;
    log the detail server-side."
    Consistent Shape

    Use one structured error body across endpoints.

    { error: { code, message } }

Auth & Safety

    Who Can Call

    State authentication and the authorization rule.

    "Auth required; only the order owner
    or an admin may update."
    Side Effects

    Name writes, events, and idempotency needs.

    "Idempotent: repeated PATCH to the
    same status is a no-op."
    Rate & Limits

    Mention limits where abuse or cost is a concern.

    "Rate-limit to 10/min per user."

Tips

  1. Give the request and response shapes as types or schemas so the endpoint matches your API.
  2. Name the error cases and their status codes so failures are handled, not left to 500s.

Warnings

  1. Models write happy-path handlers that trust input; always require validation and error handling.
  2. Generated endpoints often omit authz checks and leak internals in error messages; demand both be handled.

In Practice

FAQ