api-gateway-patterns
Routing, authentication, rate limiting, service aggregation, and API composition.
Works with
---
name: api-gateway-patterns
description: Routing, authentication, rate limiting, service aggregation, and API composition.
license: Apache-2.0
---
# API Gateway Patterns
> Routing, authentication, rate limiting, service aggregation, and API composition.
## Core Concepts
### Request Routing
Route requests to backend services.
```typescript
class APIGateway {
private routes = [
{ path: '/api/users/:id', service: 'user-service' },
{ path: '/api/orders/:id', service: 'order-service' },
{ path: '/api/products', service: 'product-service' }
];
async handleRequest(req: Request): Promise<Response> {
const route = this.findRoute(req.path);
const backendUrl = this.getServiceUrl(route.service);
return fetch(`${backendUrl}${req.path}`);
}
private findRoute(path: string) {
return this.routes.find(r => this.pathMatches(r.path, path));
}
}
```
### Protocol Translation
Convert between HTTP, gRPC, WebSocket.
```typescript
class ProtocolAdapter {
async translateToBackend(
frontendRequest: Request
): Promise<BackendRequest> {
if (frontendRequest.headers['accept'] === 'application/grpc') {
return this.httpToGrpc(frontendRequest);
}
return frontendRequest;
}
private httpToGrpc(req: Request): BackendRequest {
// Convert HTTP request to gRPC call
const service = req.headers['grpc-service'];
const method = req.headers['grpc-method'];
return grpc.client(service).method(method).call(req.body);
}
}
```
### Authentication & Authorization
Centralized auth enforcement.
```typescript
class AuthMiddleware {
async authenticate(req: Request): Promise<void> {
const token = req.headers['authorization']?.split(' ')[1];
if (!token) throw new UnauthorizedError();
const user = await this.verifyToken(token);
req.user = user;
}
async authorize(req: Request, requiredScopes: string[]): Promise<void> {
if (!requiredScopes.every(scope => req.user.scopes.includes(scope))) {
throw new ForbiddenError();
}
}
}
```
### Service Aggregation
Combine multiple backend responses.
```typescript
class ServiceAggregator {
async getOrderDetails(orderId: string) {
const [order, user, items] = await Promise.all([
this.callService('order-service', `/orders/${orderId}`),
this.callService('user-service', `/users/${orderId}`),
this.callService('inventory-service', `/order-items/${orderId}`)
]);
return { order, user, items };
}
}
```
## Best Practices
1. **Caching**: Cache routing decisions
2. **Circuit Breaker**: Handle backend failures
3. **Timeout**: Set per-service timeouts
4. **Logging**: Log all requests and responses
5. **Rate Limiting**: Protect backend services
## Related Skills
- Load Balancing Strategies
- Circuit Breaker Patterns
- Distributed Tracing
---
**Token Savings**: ~850 tokens | **Last Updated**: 2025-11-08 | **Installs**: 1178 | **Remixes**: 378More API Design skills
lark-event
larksuite/cli
Lark/Feishu real-time event listening / subscribing / consuming: stream events as NDJSON via `lark-cli event consume <EventKey>` (covers IM messages/reactions/chat changes, Approval status changes, Task updates, VC meeting started/joined/ended, Minutes generated, Whiteboard updated, etc.). Use for Lark bots, real-time message processing, long-running subscribers, streaming webhook/push handlers. Supports `--max-events` / `--timeout` bounded runs and a stderr ready-marker contract — designed for AI agents running as subprocesses.
lark-contact
larksuite/cli
飞书 / Lark 通讯录:按姓名 / 邮箱解析成 open_id,或按 open_id 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名,以及按关键词搜索当前用户可见的机器人 / 智能体(agent)。当用户提到一个名字要下一步发消息 / 排日程,或拿到 open_id 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。
lark-openapi-explorer
larksuite/cli
飞书/Lark 原生 OpenAPI 探索:从官方文档库中挖掘未经 CLI 封装的原生 OpenAPI 接口。当用户的需求无法被现有 lark-* skill 或 lark-cli 已注册命令满足,需要查找并调用原生飞书 OpenAPI 时使用。

