Free Cursor rule
Contract-first APIs
Write the request and the response before the handler, and validate both sides.
Download contract-first-apis.mdc
The rule
---
description: Define an API contract before writing the handler.
globs: "**/*.{ts,tsx}"
alwaysApply: false
---
# Contract-first APIs
- Name the method, the path, the request fields, and the response fields before you write the handler.
- Validate input on the server even if the form already checked it.
- Return one error shape. Do not leak stack traces, keys, or database details to the browser.
- Do not log passwords, tokens, or other secrets.
- If the payload is sensitive, encrypt it before it leaves the client and keep the keys off the public bundle.
How to use it
Copy the rule into .cursor/rules/contract-first-apis.mdc in your own project. It is free to use. It is a working habit from [Wann Labs](/), the public notes of BrandMatchGrowth, not a promise that your codebase will pass an audit.
If you want the same standard applied to a product people pay for, book a working session. The public product that came out of this shop-and-software work is OpenSign.