api_clientlisted
Install: claude install-skill jxoesneon/Ciel
# api_client
HTTP REST / GraphQL client with auth and retry.
## Operations
- `api.request(method, url, headers?, body?, auth?)`
- `api.graphql(endpoint, query, vars?, auth?)`
- `api.with_retry(call, strategy)` — exponential backoff, idempotency keys.
## Auth
Auth credentials pulled via `secrets_manager/SKILL.md` by name — never inline. Bearer, Basic, OAuth2, API-key header, HMAC.
## I/O Contract
```yaml
io_contract:
input: { method, url, "headers?", "body?", "auth_ref?" }
output: { status, body, headers }
idempotent: depends_on_method
side_effects: [network]
```
## Safety
- State-mutating methods (POST/PUT/PATCH/DELETE) to external endpoints are at least mid-risk.
- Sending to internal / production endpoints is high/critical.
- Request/response bodies stored hashed, not raw, for audit.