PNL Learn

Building Web APIs

Design REST APIs with validation, pagination and clean errors.

An API is a contract, and most of the cost of getting it wrong lands on other people. You will design resources and pick the status code each outcome deserves, validate every request at the edge, accept and return only the fields you allow, and answer with field level errors nobody has to guess at, page and filter a collection without dropping or repeating rows, move request ids, body limits, rate limits and ETags into middleware, keep your routes in step with an OpenAPI description, refuse bodies that are not JSON and speak RFC 9457 problem details, and test the whole thing through a test client. Everything runs on a small App, Request and Response framework, with the FastAPI equivalent shown beside it so the design transfers straight to a real project.

IntermediatePython7 lessons70 exercisesAbout 5.5 h
Create a free account

What you will learn

  • REST design
  • Status codes
  • Validation
  • Pagination
  • Middleware
  • ETags
  • OpenAPI
  • API testing

Lessons

  1. 1

    Resource Design

    Name resources instead of actions, pick the right method and status code for every operation, and answer with shapes clients can rely on.

    11 exercises

  2. 2

    Request Validation

    Check every request at the edge, accept only the fields you allow, answer with field level errors a client can act on, and never let an exception become the message.

    12 exercises

  3. 3

    Pagination, Filtering and Sorting

    Return a page of a collection without dropping or repeating rows: limit and offset, opaque cursors, allowlisted sort fields, a capped page size and filters clients can trust.

    11 exercises

  4. 4

    Middleware and Cross-Cutting Concerns

    Move request ids, logging, body limits, CORS, rate limiting and caching out of your handlers and into a stack that wraps every request.

    11 exercises

  5. 5

    Contracts: OpenAPI, Content Types and Problem Details

    Read the OpenAPI description that is your API's contract, keep the routes you serve in step with it, refuse bodies that are not JSON with 415, and speak RFC 9457 problem details.

    9 exercises

  6. 6

    Testing APIs

    Test an API through a test client: the whole request path, the response shape, the error cases, and a suite that fails when the app is wrong.

    10 exercises

  7. 7

    Putting It Together

    Build the tasks API end to end in four stages: resources and strict validation, a list endpoint with filters, sorting and paging, middleware for request ids and caching, and the test suite that proves it.

    6 exercises

How you practice

You practice in the browser and every exercise gives you feedback right away. This course uses these formats:

  • Code exercise: 28
  • Fix the bug: 11
  • Predict the output: 9
  • Multiple choice: 5
  • Fill in the blank: 4
  • Type the answer: 4
  • Select all that apply: 3
  • Match the pairs: 3
  • Reorder lines: 2
  • Spot the bug: 1

Aligned to

CS2023ACM / IEEE-CS / AAAISource
  • Networking and Communication
    • NC-ApplicationsNetworked Applications
  • Software Engineering
    • SE-DesignSoftware Design
OWASP API Security Top 10 2023OWASP FoundationSource
  • API Security Risks
    • API3Broken Object Property Level Authorization
    • API4Unrestricted Resource Consumption
    • API8Security Misconfiguration
    • API9Improper Inventory Management

Proto Node Labs is not affiliated with or endorsed by ACM / IEEE-CS / AAAI and OWASP Foundation. Exam names are trademarks of their owners.