AddThisFeature

API Explorer

Let developers try real API requests from inside the app.

involved Developer Experience

What it adds

An in-app request builder that runs calls against your API and shows the exact request and response.

What your agent is told to do

6
  1. 1

    Generate the request form from the API's own schema so parameters, types, and required fields cannot drift from the real endpoints.

  2. 2

    Execute calls through a server-side proxy that attaches credentials, so a key is never placed in browser-visible code or the network tab.

  3. 3

    Restrict the proxy to your own documented API endpoints only. An explorer that will call an arbitrary URL is an SSRF hole with a nice UI.

  4. 4

    Run requests with the current user's real permissions and show endpoints they cannot call as denied rather than hiding them — a silent omission reads as a missing feature.

  5. 5

    Mark unsafe methods clearly and confirm before sending. A POST from a documentation page still creates real data.

  6. 6

    Do NOT store request or response bodies in history without redacting authorization headers, tokens, and any field the API marks sensitive.

Edge cases it handles

6
  • Copyable curl and code samples must contain a placeholder, never the live credential the proxy used.
  • Very large responses will freeze the browser if rendered whole. Truncate with a way to download the full body.
  • Requests must time out and be cancellable, or a slow endpoint hangs the panel indefinitely.
  • Explorer traffic counts against rate limits. Label it distinctly so a developer can tell exploration from production usage.
  • The explorer must follow the API version the account is pinned to, and say which version it is calling.
  • Where the API has a sandbox or test mode, default the explorer to it and make switching to live an explicit, obvious act.

Definition of done

8
  • The request form is generated from the API schema, not hand-maintained.
  • Credentials are attached server-side and never exposed to the browser.
  • Only documented first-party endpoints are reachable through the proxy.
  • Permission-denied endpoints are shown as denied rather than omitted.
  • Stored history has authorization headers and sensitive fields redacted.
  • Generated code samples use credential placeholders.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.