Building Web APIs
Design REST APIs with validation, pagination and clean errors.
An API is a contract, and most of the cost of getting it wrong lands on other people. You will design resources and pick the status code each outcome deserves, validate every request at the edge, accept and return only the fields you allow, and answer with field level errors nobody has to guess at, page and filter a collection without dropping or repeating rows, move request ids, body limits, rate limits and ETags into middleware, keep your routes in step with an OpenAPI description, refuse bodies that are not JSON and speak RFC 9457 problem details, and test the whole thing through a test client. Everything runs on a small App, Request and Response framework, with the FastAPI equivalent shown beside it so the design transfers straight to a real project.
What you will learn
- REST design
- Status codes
- Validation
- Pagination
- Middleware
- ETags
- OpenAPI
- API testing
Lessons
- 1
Resource Design
Name resources instead of actions, pick the right method and status code for every operation, and answer with shapes clients can rely on.
11 exercises
- 2
Request Validation
Check every request at the edge, accept only the fields you allow, answer with field level errors a client can act on, and never let an exception become the message.
12 exercises
- 3
Pagination, Filtering and Sorting
Return a page of a collection without dropping or repeating rows: limit and offset, opaque cursors, allowlisted sort fields, a capped page size and filters clients can trust.
11 exercises
- 4
Middleware and Cross-Cutting Concerns
Move request ids, logging, body limits, CORS, rate limiting and caching out of your handlers and into a stack that wraps every request.
11 exercises
- 5
Contracts: OpenAPI, Content Types and Problem Details
Read the OpenAPI description that is your API's contract, keep the routes you serve in step with it, refuse bodies that are not JSON with 415, and speak RFC 9457 problem details.
9 exercises
- 6
Testing APIs
Test an API through a test client: the whole request path, the response shape, the error cases, and a suite that fails when the app is wrong.
10 exercises
- 7
Putting It Together
Build the tasks API end to end in four stages: resources and strict validation, a list endpoint with filters, sorting and paging, middleware for request ids and caching, and the test suite that proves it.
6 exercises
How you practice
You practice in the browser and every exercise gives you feedback right away. This course uses these formats:
- Code exercise: 28
- Fix the bug: 11
- Predict the output: 9
- Multiple choice: 5
- Fill in the blank: 4
- Type the answer: 4
- Select all that apply: 3
- Match the pairs: 3
- Reorder lines: 2
- Spot the bug: 1
Aligned to
- Networking and Communication
- NC-ApplicationsNetworked Applications
- Software Engineering
- SE-DesignSoftware Design
- API Security Risks
- API3Broken Object Property Level Authorization
- API4Unrestricted Resource Consumption
- API8Security Misconfiguration
- API9Improper Inventory Management
Proto Node Labs is not affiliated with or endorsed by ACM / IEEE-CS / AAAI and OWASP Foundation. Exam names are trademarks of their owners.