Good day.

This page stays with you, wherever you opened it.

Free Cursor rule

Contract-first APIs

Write the request and the response before the handler, and validate both sides.

Download contract-first-apis.mdc

The rule

---
description: Define an API contract before writing the handler.
globs: "**/*.{ts,tsx}"
alwaysApply: false
---

# Contract-first APIs

- Name the method, the path, the request fields, and the response fields before you write the handler.
- Validate input on the server even if the form already checked it.
- Return one error shape. Do not leak stack traces, keys, or database details to the browser.
- Do not log passwords, tokens, or other secrets.
- If the payload is sensitive, encrypt it before it leaves the client and keep the keys off the public bundle.

How to use it

Copy the rule into .cursor/rules/contract-first-apis.mdc in your own project. It is free to use. It is a working habit from [Wann Labs](/), the public notes of BrandMatchGrowth, not a promise that your codebase will pass an audit.

If you want the same standard applied to a product people pay for, book a working session. The public product that came out of this shop-and-software work is OpenSign.