Node.js · Express

Node.js and Express rules for Cursor

Routing, validation and error-handling rules for Express APIs.

The rule

Save as .cursor/rules/express.mdc. Cursor picks it up on the next request.

.cursor/rules/express.mdc

---
description: Express API conventions
globs: src/**/*.js, src/**/*.ts
alwaysApply: false
---

- Validate every request body and query with a schema before using it.
- Keep route handlers thin; put business logic in services that can be tested without HTTP.
- Pass errors to next(err) and handle them in one error middleware.
- Never log secrets, tokens or full request bodies.
- Use environment variables through one config module.

Using another agent too?

The same instructions work as plain Markdown in AGENTS.md, which Codex, Gemini CLI, GitHub Copilot and most other coding agents read.

AGENTS.md (section)

## Node.js and Express

- Validate every request body and query with a schema before using it.
- Keep route handlers thin; put business logic in services that can be tested without HTTP.
- Pass errors to next(err) and handle them in one error middleware.
- Never log secrets, tokens or full request bodies.
- Use environment variables through one config module.

More templates

Reviewed Oct 6, 2026. Written by AgentAtlas. Adapt it to your codebase before relying on it.