Scalar

codewithmukesh/dotnet-claude-kit/skills/scalar

by codewithmukesh23300897f4d1No license754 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 2 months ago

Scalar API documentation UI for .NET 10 applications. Covers setup, themes, authentication prefill, multiple documents, layout options, and security. A modern replacement for Swagger UI. Load this skill when setting up API documentation UI, or when the user mentions "Scalar", "MapScalarApiReference", "API reference", "Swagger UI replacement", "API documentation UI", "Scalar theme", "interactive API docs", or "Try It".

Instructions only

Scalar

Core Principles

  1. Scalar replaces Swagger UI — Scalar is the recommended API documentation UI for .NET 10. Faster rendering, built-in dark mode, code generation for dozens of languages, and full OpenAPI 3.1 support.
  2. Development only by default — Wrap MapScalarApiReference() in an IsDevelopment() check. API documentation exposes internal structure. If needed in production, add authorization.
  3. Disable the proxy for sensitive APIs — Scalar's "Try It" feature routes through proxy.scalar.com by default. Disable it with .WithProxy(null) to keep auth headers local.
  4. Security schemes come from OpenAPI — Scalar reads security schemes from the OpenAPI document. Configure them via document transformers, not in Scalar directly.

Patterns

Basic Setup

csharp
using Scalar.AspNetCore;
var builder = WebApplication.CreateBuilder(args);builder.Services.AddOpenApi();
var app = builder.Build();
if (app.Environment.IsDevelopment()){    app.MapOpenApi();    app.MapScalarApiReference();  // UI at /scalar/v1}
app.Run();

Customized Configuration

csharp
app.MapScalarApiReference(options =>{    options        .WithTitle("Checkout API")        .WithTheme(ScalarTheme.Mars)        .WithDefaultHttpClient(ScalarTarget.CSharp, ScalarClient.HttpClient)        .WithPreferredScheme("Bearer")        .WithProxy(null)  // Disable external proxy        .WithSidebar(true);});

Authentication Prefill (Development Only)

Pre-fill credentials so developers don't have to paste tokens manually. The OpenAPI document must already include the security scheme via a document transformer.

csharp
if (app.Environment.IsDevelopment()){    app.MapScalarApiReference(options =>    {        options            .WithPreferredScheme("Bearer")            .AddHttpAuthentication("Bearer", auth =>            {                auth.Token = "dev-only-test-token";            });    });}

Other auth types:

csharp
// API Keyoptions.WithApiKeyAuthentication(apiKey =>{    apiKey.Token = "dev-api-key";});
// OAuth2options.WithOAuth2Authentication(oauth =>{    oauth.ClientId = "your-client-id";    oauth.Scopes = ["openid", "profile"];});

Available Themes

csharp
// ScalarTheme options: Default, Moon, Purple, BluePlanet, Saturn, Mars, DeepSpace, Kepler, Solarized, Laserwaveoptions.WithTheme(ScalarTheme.Mars);

Multiple API Documents

csharp
// Register multiple OpenAPI documentsbuilder.Services.AddOpenApi("v1");builder.Services.AddOpenApi("v2-beta");
// Scalar picks them up automaticallyapp.MapOpenApi();app.MapScalarApiReference();// Available at /scalar/v1 and /scalar/v2-beta

Or configure documents explicitly:

csharp
app.MapScalarApiReference(options =>{    options        .AddDocument("v1", "Production API")        .AddDocument("v2-beta", "Beta API", isDefault: true);});

Custom Route Prefix

csharp
// Default is /scalar/{documentName}app.MapScalarApiReference("/api-docs");// Now at /api-docs/v1

Production with Authorization

csharp
// When partners need access to docs in productionapp.MapOpenApi().RequireAuthorization("ApiDocs");app.MapScalarApiReference().RequireAuthorization("ApiDocs");

Force Dark Mode

csharp
options.ForceDarkMode();

Classic Layout (Swagger-like)

csharp
options.WithClassicLayout();

Anti-patterns

Don't Expose Scalar in Production Without Auth

csharp
// BAD — anyone can see your API structureapp.MapOpenApi();app.MapScalarApiReference();
// GOOD — development onlyif (app.Environment.IsDevelopment()){    app.MapOpenApi();    app.MapScalarApiReference();}
// GOOD — production with authapp.MapOpenApi().RequireAuthorization("ApiDocs");app.MapScalarApiReference().RequireAuthorization("ApiDocs");

Don't Pre-fill Real Credentials

csharp
// BAD — real tokens visible in browseroptions.AddHttpAuthentication("Bearer", auth =>{    auth.Token = "eyJhbG...real-production-token";});
// GOOD — dev-only test tokensif (app.Environment.IsDevelopment()){    options.AddHttpAuthentication("Bearer", auth =>    {        auth.Token = "dev-only-test-token";    });}

Don't Forget the Security Scheme Transformer

csharp
// BAD — no auth UI in Scalar because OpenAPI doc has no security schemesbuilder.Services.AddOpenApi();app.MapScalarApiReference(options =>{    options.WithPreferredScheme("Bearer"); // Does nothing!});
// GOOD — register the document transformer firstbuilder.Services.AddOpenApi(options =>{    options.AddDocumentTransformer<BearerSecuritySchemeTransformer>();});app.MapScalarApiReference(options =>{    options.WithPreferredScheme("Bearer");});

Don't Leave the Proxy Enabled for Sensitive APIs

csharp
// BAD — auth headers flow through proxy.scalar.comapp.MapScalarApiReference();
// GOOD — disable proxy for APIs with sensitive dataapp.MapScalarApiReference(options =>{    options.WithProxy(null);});

Don't Use Swagger UI for New .NET 10 Projects

csharp
// BAD — Swashbuckle removed from templates, maintenance concernsbuilder.Services.AddSwaggerGen();app.UseSwaggerUI();
// GOOD — built-in OpenAPI + Scalarbuilder.Services.AddOpenApi();app.MapOpenApi();app.MapScalarApiReference();

Decision Guide

ScenarioRecommendation
API documentation UIMapScalarApiReference() with MapOpenApi()
Development environmentDefault setup with IsDevelopment() guard
Production API docsAdd .RequireAuthorization() to both endpoints
Auth testing in devAddHttpAuthentication() with test tokens
Dark theme preference.ForceDarkMode() or .WithTheme(ScalarTheme.Moon)
Multiple API versionsMultiple AddOpenApi() calls — Scalar detects automatically
Sensitive APIs.WithProxy(null) to disable external proxy
Swagger-like layout.WithClassicLayout()
Custom routeapp.MapScalarApiReference("/api-docs")

Source and attribution

Source:codewithmukesh/dotnet-claude-kitinskills/scalarat commit2330089

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from codewithmukesh/dotnet-claude-kit

Wrap Up

codewithmukesh

Captures end-of-session work, pending tasks and learnings into a handoff file, and reloads it at session start.

Productivity & Workflow754updated 2 months ago

Workflow Mastery

codewithmukesh

Claude Code workflow mastery for .NET developers. Covers parallel execution with git worktrees, plan mode strategy, verification loops, auto-formatting hooks, permission setup for dotnet CLI, prompting techniques, subagent patterns, and context discipline — token budget management, MCP-first navigation, lazy loading, and subagent isolation — all adapted for the .NET ecosystem. Load this skill when setting up Claude Code for a .NET project, optimizing workflows, running parallel sessions, when context is running low or sessions feel sluggish, when exploring a large codebase efficiently, or when the user mentions "productivity", "workflow", "parallel", "worktree", "plan mode", "permissions", "hooks", "10x", "setup Claude Code", "speed up development", "context", "tokens", "budget", "running out of context", "too many files", or "large codebase". Inspired by tips from Boris Cherny (creator of Claude Code) and the Anthropic team.

Awaiting classification754updated 2 months ago

Vertical Slice

codewithmukesh

Guides .NET developers in structuring applications with Vertical Slice Architecture, covering feature folders, endpoint grouping and handler patterns.

Software Development754updated 2 months ago

Testing

codewithmukesh

Testing strategy for .NET 10 applications. Covers xUnit v3, WebApplicationFactory for integration tests, Testcontainers for real database testing, Verify for snapshot testing, and the AAA pattern. Load this skill when writing tests, setting up test infrastructure, reviewing test coverage, or when the user mentions "test", "xUnit", "WebApplicationFactory", "Testcontainers", "integration test", "unit test", "bUnit", "snapshot test", "Verify", "test coverage", "AAA pattern", "WireMock", or "FakeTimeProvider".

Awaiting classification754updated 2 months ago

Tdd

codewithmukesh

Guided test-driven development workflow for .NET 10 using xUnit v3, WebApplicationFactory, Testcontainers, and Verify snapshots. Follows the strict red-green-refactor cycle. Use when: "TDD", "test-driven", "let's TDD this", "red green refactor", "write the test first", or when building a feature with clear acceptance criteria.

Awaiting classification754updated 2 months ago

Spec

codewithmukesh

Turns a vague feature idea into an agreed, persisted specification file through structured questioning rounds.

Productivity & Workflow754updated 2 months ago