Backend Capstone Projects
Build and ship complete backend services end to end.
The final course of the Backend Developer program, built like a stack of take-home assignments from real teams. Four staged projects give you less scaffolding each time: a URL shortener with migrations, collision-safe codes and a token bucket; a multi-tenant notes API with hashed passwords and sessions, tenant-scoped queries and ETags; an order processing backend with a transactional checkout, retries and a dead letter queue, a race test that proves the last unit sells once, and a verified payment webhook; and a final uptime monitor built from a brief and tests alone, with concurrent async checks, alerts and a status API. Between them come a security review of your own API against the OWASP API Security Top 10, and a system design review with estimates, consistent hashing, SLOs and the monolith or microservices question.
What you will learn
- Service design
- Schema migrations
- Repository pattern
- REST API design
- Authentication
- Authorization
- Transactions
- Background jobs
- Caching
- Rate limiting
- Concurrency
- Webhooks
- Async I/O
- Security review
- System design
Lessons
- 1
Project: URL Shortener Service
Build a production-shaped link shortener in five stages: migrations, a repository with an analytics query, collision-safe code generation, an HTTP API with error envelopes, and a token bucket rate limiter.
11 exercises
- 2
Project: Multi-tenant Notes API
Build an API that many customers share safely: hashed passwords, session tokens stored as hashes, tenant-scoped queries that survive an attack test, keyset pagination with search, and conditional requests with ETags.
13 exercises
- 3
Project: Order Processing Backend
Build the part of a shop that must never be wrong: a cached catalog, a checkout that reserves stock in one transaction, a job queue with retries and a dead letter queue, a sales report in SQL, a one tap purchase that cannot oversell, and a verified payment webhook.
12 exercises
- 4
Security Review: Audit a Service
Audit your notes API against the OWASP API Security Top 10 the way an interviewer would: find the planted issue in each endpoint, name its category, and fix it, from object and field level authorization to SSRF, resource limits and a forgotten route.
11 exercises
- 5
System Design and Interview Review
Scale the shortener in an interview: estimate from round numbers, shard with consistent hashing, route reads around replica lag, report percentiles against an SLO, argue monolith first, then answer rapid fire review questions and ship a Dockerfile a reviewer would approve.
20 exercises
- 6
Project: Uptime Monitor
The final, portfolio project, built from a brief and tests alone: SSRF-safe targets and a check log in SQLite, concurrent async checks with deadlines, retries and a concurrency limit, alerts on state changes, and a status API behind an admin key.
8 exercises
How you practice
You practice in the browser and every exercise gives you feedback right away. This course uses these formats:
- Code exercise: 28
- Fix the bug: 11
- Multiple choice: 8
- Predict the output: 7
- Fill in the blank: 7
- Type the answer: 6
- Select all that apply: 3
- Match the pairs: 3
- Spot the bug: 1
- Reorder lines: 1
Aligned to
- Security
- SEC-CodingSecure Coding
- SEC-EngineeringSecurity Analysis, Design, and Engineering
- Software Engineering
- SE-DesignSoftware Design
- SE-ConstructionSoftware Construction
- SE-ValidationSoftware Verification and Validation
- Parallel and Distributed Computing
- PDC-CoordinationCoordination
Proto Node Labs is not affiliated with or endorsed by ACM / IEEE-CS / AAAI. Exam names are trademarks of their owners.