external-api-integration

external-api-integration is a skill for Claude Code, Codex from sandeepmvl/rails-skills. It costs 118 tokens per session (2,492 once invoked), scanned A, original, MIT.

A guide to calling external HTTP APIs from Ruby on Rails. It covers timeouts, retries, circuit breakers, testing, rate limits, logging, and service objects, which are classes that keep API-specific code in one place.

In plain words
What is it for?
Use it when Rails exchanges data with services such as CRM, payment, shipping, or analytics APIs.
Why use it?
It reduces failures and difficult debugging caused by slow or unreliable external services, missing timeouts, repeated writes, and unrecorded requests.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it when Rails exchanges data with services such as CRM, payment, shipping, or analytics APIs.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/sandeepmvl/rails-skills/32-external-api-integration
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add sandeepmvl/rails-skills --skill 32-external-api-integration
Clone the repo
git clone --depth 1 https://github.com/sandeepmvl/rails-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for external-api-integration

README.md
[![agentmods](https://agentmods.dev/badge/skills/sandeepmvl/rails-skills/32-external-api-integration/github.svg)](https://agentmods.dev/skills/sandeepmvl/rails-skills/32-external-api-integration)
Your own site
<a href="https://agentmods.dev/skills/sandeepmvl/rails-skills/32-external-api-integration"><img src="https://agentmods.dev/badge/skills/sandeepmvl/rails-skills/32-external-api-integration/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for external-api-integration

Your own site · 80×15
<a href="https://agentmods.dev/skills/sandeepmvl/rails-skills/32-external-api-integration"><img src="https://agentmods.dev/badge/skills/sandeepmvl/rails-skills/32-external-api-integration.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 118 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,492 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00118 $0.02492
Opus 5 $0.00059 $0.01246
Sonnet 5 $0.00024 $0.00498
Haiku 4.5 $0.00012 $0.00249

Measured 10d ago against content hash df7b04fcdbd6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

external-api-integration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/32-external-api-integration/SKILL.md · 264 lines

How it starts

The opening of the file, as written. The whole thing — 264 lines — stays where its author put it; the contents beside it link to each section on GitHub.

External API Integration

Calling external APIs is where Rails apps lose reliability. AI agents reach for Net::HTTP.get(URI(url)), no timeouts, no retries, no logging, no circuit breaker. Replace with Faraday + middleware + service object wrapper.

The opinion

Faraday for the HTTP client. Wrap every external API in a service object. Open timeout 3s, read timeout 10s (tune per API). Exponential retries (3 attempts) on idempotent verbs. Circuit breaker for chronically-flaky upstreams. VCR for tests. Log every call (sanitized) with correlation IDs. Idempotency keys on writes when the API supports them. Never put external calls in the request path if you can help it — use a job.

Core patterns

Pattern 1: The Faraday client wrapper

# Gemfile
gem "faraday"
gem "faraday-retry"
gem "stoplight"  # circuit breaker

# app/clients/hubspot_client.rb
class HubspotClient
  def initialize
    @conn = Faraday.new(url: "https://api.hubapi.com") do |f|
      f.request :json
      f.request :authorization, "Bearer", -> { Rails.application.credentials.hubspot_api_key }
      f.request :retry, max: 3, interval: 0.5, backoff_factor: 2,
                         retry_statuses: [429, 500, 502, 503, 504],
                         methods: %i[get put]  # idempotent verbs only
      f.response :raise_error  # raise on 4xx/5xx
      f.response :json
      f.response :logger, Rails.logger, headers: false, log_level: :info do |log|
        log.filter(/(Authorization: Bearer )(\S+)/i, '\1[FILTERED]')
      end
      f.options.open_timeout = 3
      f.options.timeout = 10
      f.adapter Faraday.default_adapter
    end
  end

  def upsert_contact(email:, attrs:)
    Stoplight("hubspot.upsert_contact") do
      @conn.post("/contacts/v1/contact/createOrUpdate/email/#{email}", { properties: attrs.map { |k, v| { property: k, value: v } } }).body
    end.with_threshold(5).with_cool_off_time(60).run
  end
end

Why every piece:

  • request :retry — handles transient failures without app-level code.
  • retry_statuses: [429, 500, ...] — only retry on transient failures, not on 401/422.
  • methods: %i[get put] — only retry idempotent operations. Don't auto-retry POST (might double-create).
  • response :raise_error — turn 4xx/5xx into exceptions; cleaner control flow.
  • response :logger with sanitization — visibility without leaking creds.
  • Timeouts — never hang on a flaky upstream.
  • Stoplight circuit breaker — after 5 failures in window, requests fail fast for 60s.

Read the full file on GitHub · 264 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 264 lines · 118 tokens per session scan A df7b04fcdbd6

Subscribe to this mod's changes

external-api-integration is a skill published in the GitHub repository sandeepmvl/rails-skills (21 stars, last pushed 3mo ago), licensed MIT. It adds 118 tokens to every session and 2,492 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

rails-expert

Rails 7+ specialist that optimizes Active Record queries with includes/eagerload, implements Turbo Frames and Turbo Streams for partial page updates, configures Action Cable for WebSocket connections, sets up Sidekiq workers for background job processing, and writes comprehensive RSpec test suites. Use when building…

Jeffallan/claude-skills · 104 tokens

new

Create a new project to start development quickly.

clacky-ai/openclacky · 10 tokens

rails-conventions

Rootstrap Rails conventions. Use when writing, reviewing, or editing any Rails code — controllers, models, migrations, routes, views, mailers, initializers, locale files, or Rails config. Covers routing, ActiveRecord, migrations, i18n, time zones, mailers, assets, Bundler groups, and logging.

rootstrap/rails_api_base · 71 tokens

ruby-rails

Conventions and best practices for building web applications with Ruby on Rails. Use when scaffolding Rails apps or generators, designing ActiveRecord models and migrations, wiring up Hotwire/Turbo/Stimulus interactivity, setting up background jobs or caching, or writing RSpec/Minitest coverage for Rails code.

Mindrally/skills · 65 tokens

ruby-expert

Expert-level Ruby development with Rails, modern features, testing, and best practices. Use when the user mentions Ruby on Rails, RSpec, gem, Sinatra, or metaprogramming, or when the task involves Ruby 3+ Features, Object-Oriented, Functional Features, or Pattern Matching.

personamanagmentlayer/pcl · 64 tokens

draper-decorators

This skill should be used when the user asks to "create a decorator", "write a decorator", "move logic into decorator", "clean logic out of the view", "isn't it decorator logic", "test a decorator", or mentions Draper, keeping views clean, or representation logic in decorators. Should also be used when editing…

hoblin/claude-ruby-marketplace · 131 tokens