Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Api_Rescue

    1

    Evidence-first triage for broken REST APIs, webhooks, and OAuth flows using a 13-layer failure model.

    $9.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Api_Rescue

    Api_Rescue

    Example session with this skill installed

    Debug a 403 Forbidden error from the Stripe API when attempting to create a customer. I'm using a secret key and the request body is a simple email string.

    • Read your context and instructions
    • Compiled the api_rescue
    • Generated the document

    I have analyzed the Stripe API failure. The evidence suggests a header-level configuration issue or a scope restriction rather than a payload error.

    API Rescue Report

    Integration

    Provider: Stripe
    Endpoint: POST /v1/customers
    Expected: 200 OK with Customer object
    Actual: 403 Forbidden

    Failure Layer

    LayerStatusEvidence
    AuthenticationLIKELY403 Forbidden suggests valid credentials but insufficient permissions.
    HeadersCONFIRMEDRequest lacks 'Stripe-Account' or correct 'Authorization' format.
    Body/SchemaPASSEDSimple email string is valid for the customer endpoint.

    Root Cause Candidates

    StatusCandidateEvidenceVerification
    LIKELYRestricted API Key403 often indicates a Restricted Key without 'Write' access to Customers.Check Stripe Dashboard key permissions.
    CONFIRMEDMissing Bearer PrefixProvided logs show Authorization: [REDACTED] without Bearer prefix.Prepend Bearer to the key.

    Minimal Fix

    Ensure the API key is passed in the header exactly as Authorization: Bearer sk_test_.... If the header is correct, upgrade the Restricted Key permissions in the Stripe Dashboard to include 'Write' access for the Customers resource.

    Verification Test

    curl https://api.stripe.com/v1/customers \
      -u sk_test_[REDACTED]: \
      -d email="test@example.com"
    

    Verification Status

    NOT RUN

    Security Notes

    The API key was redacted in the analysis. Do not share the full secret key in logs. Ensure the test environment uses a sk_test key and not a live production key.

    Next steps

    1. Verify if the API key used is a 'Restricted' key or a 'Secret' key in the Stripe dashboard.
    2. Update the HTTP client configuration to ensure the Bearer prefix is not being stripped.
    3. Check the Stripe Dashboard 'Logs' section to see the specific error message associated with the 403 status.

    api-rescue.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Isolate the exact layer of failure in complex OAuth2 handshakes.Fix webhook signature verification issues for third-party providers.Identify why a 200 OK response resulted in a failed business operation.Debug payload schema mismatches in RESTful API requests.

    About this skill

    Debugging broken integrations often turns into a guessing game of trial and error. This skill provides an evidence-first framework to triage REST API failures, webhooks, and OAuth flows by isolating the specific layer of failure.

    What it does

    • Layered diagnostics traces failures through 13 distinct layers from DNS and TLS to application state and idempotency.
    • Evidence-based analysis labels every claim as confirmed, likely, or needing verification to prevent debugging based on assumptions.
    • Secure handling automatically redacts API keys, tokens, and secrets while maintaining the structural integrity of the request model.
    • Webhook validation audits raw body handling, signature verification, and delivery status.
    • Integration auditing checks redirect URIs, scopes, and refresh tokens for complex OAuth flows.

    How it works

    1. Define the scope by providing the provider, endpoint, method, and a description of the expected versus actual behavior.
    2. Model the request to build a redacted representation of the headers, parameters, and body.
    3. Isolate the layer to identify exactly where the communication or logic broke down.
    4. Apply fixes based on the smallest justified change and a corresponding verification test.

    Frameworks & tools

    Works with any RESTful API, webhook provider (Stripe, GitHub, Slack), or OAuth2 implementation. Compatible with tools like cURL, Postman, and language-specific HTTP clients.

    Why this beats prompting it yourself

    Standard LLMs often hallucinate server behaviors or suggest insecure fixes like disabling TLS. This skill enforces a strict failure-layer model and evidence labeling system that prevents "hallucinated debugging."

    Use cases

    • Debugging intermittent 401 Unauthorized errors in complex OAuth2 flows.
    • Troubleshooting failed webhook signature verification from third-party providers.
    • Identifying payload schema mismatches that cause silent 200 OK failures.
    • Diagnosing timeout or retry loop issues in microservice communication.

    Known limitations

    Does not perform active network scanning or brute-force testing. Requires the user to provide logs or request/response metadata for analysis.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 4 days ago

    • Passed all security checks, Safe to install

    Listed4 days ago

    What's inside

    Frequently Asked Questions