Module 05 of 10

Building APIs

Lessons

About This Module

An API is how the rest of the world talks to your backend. Frontends, mobile apps, and other services all send requests to your API and get data back, which makes it the layer where your database, your business logic, and your users finally meet. This module covers how to design and build one.

You'll start with REST, the architectural style behind most web APIs: resources, URLs, and HTTP methods. From there you'll look at the design practices that keep an API predictable, then build a working RESTful API with Node.js and Express. The module finishes with GraphQL, a query language that offers a different take on fetching data, and CORS, the browser rule that trips up almost every developer the first time a frontend calls an API on another origin.

With endpoints up and running, you'll be ready to protect them in Authentication & Security, the next module in this course.

Lessons

6 videos
01

What Is a REST API?

A whiteboard walkthrough of what REST is, how a client and server exchange resources over HTTP, and why REST became the standard way to build web APIs.

02

REST API Examples and How to Use Them

A quick, example-driven look at how a REST API is used in practice: resources, HTTP methods, and the request and response cycle.

03

API Design 101: From Basics to Best Practices

The fundamentals of API design and the practices that make an API clean, scalable, and secure, so the endpoints you write are easy to use and hard to misuse.

04

Build a RESTful API with Node.js and Express

What an API and REST are, then a build-along in Node.js and Express: setting up endpoints, handling different HTTP methods, and a first look at the OpenAPI specification.

05

GraphQL Explained in 100 Seconds

A quick look at GraphQL, how it compares to REST, and why developers like this query language for reading and changing data through an API.

06

CORS in 100 Seconds

What Cross-Origin Resource Sharing is, why browsers block requests to other origins by default, and how a server opts in to allow them.