REST API Design: Resources, Status Codes and Security

Design clean, predictable HTTP APIs: resources, status codes, pagination, versioning, authentication and errors. For backend and full-stack developers.

Start course →

What you'll learn

  • Name resources and URIs, and pick the right HTTP methods and status codes.
  • Design consistent request, response, pagination and error formats.
  • Version an API and manage breaking changes with a deprecation plan.
  • Secure endpoints with API keys, OAuth 2.0, JWTs, HTTPS, CORS and rate limits.
  • Document and test an API with OpenAPI, Postman and automated checks.

Syllabus

Module 1: Foundations

  1. What is REST?
  2. Resources & URIs
  3. Statelessness

Module 2: HTTP Basics for APIs

  1. HTTP Methods & CRUD
  2. HTTP Status Codes
  3. Headers & Content Negotiation

Module 3: Request & Response Design

  1. JSON as the Standard
  2. Consistent Shapes
  3. Field Naming Conventions

Module 4: Collections

  1. Pagination Strategies
  2. Filtering & Sorting

Module 5: Versioning

  1. Why APIs Need Versioning
  2. Versioning Strategies

Module 6: Authentication & Security

  1. HTTPS, CORS & Input Validation
  2. API Keys
  3. OAuth 2.0 at a Glance
  4. JWT-Based Auth
  5. Rate Limiting

Module 7: Error Handling

  1. Standard Error Responses

Module 8: Advanced Concepts

  1. Idempotency
  2. HATEOAS at a Glance
  3. Caching with ETags

Module 9: Documentation & Testing

  1. OpenAPI & Swagger
  2. Testing APIs

Module 10: Alternatives to REST

  1. GraphQL & gRPC