HATEOAS (Hypermedia as the Engine of Application State) means that API responses should include links to related actions or resources. This makes APIs self-discoverable and reduces client-server coupling.
REST is constraints, not JSON over HTTP: address resources, let methods decide the action, send hypermedia links to what's next and more.
For this question · chapter 3 of 3Watch the _links block become buttons that change when the order is paid, and see what breaks for the client that ignored it.
3/3Links tell the client what it may do next
Links tell the client what it may do next
One constraint is still missing, and this is not commonly implemented in practice: the uniform interface also asks for links in the response. Two clients load the same order, status pending. Client A has a map of URLs and and got the Cancel and Pay buttons from that map. Client B relies on links in the response and has got nothing yet, as nothing in the response said what Client B may do.
The server adds a _links block with cancel and pay, then sends the value to client B. Client B reads the links and got two things it can do next, Cancel and Pay. Sending the links with the value is HATEOAS, hypermedia as the engine of application state. The order's state decides which links appear, and those links decide what the client offers.
The order is paid, so the response says paid and the links say refund. The new value reaches Client B. Client B stops getting Cancel and Pay and got Refund instead, with no code change. Client A still got Cancel and Pay, because its map from state to buttons does not know the order is now paid.
Client A sends Cancel from its own map of URLs and gets a 409. Client B sends Refund from a link the server sent and gets a 200. B never built a URL and never offered an action the server had not offered first, so the server can move URLs and rules without breaking B.
Client A keeps working without the links, but client B has nothing left to display. So why does almost nobody ship hypermedia? Most APIs stop at level 2 of the Richardson model: resources and methods, URLs in the docs and the SDK, no links in the body. Level 3 adds the links.
A generated SDK fails the build when a URL moves. The build failure is the protection level 3 would have given at runtime. Most teams make that trade on purpose: an HTTP API at level 2. They instead use OpenAPI spec to publish their URL map.
Chapter 3 · step 1 of 6
One constraint is still missing, and this is not commonly implemented in practice: the uniform interface also asks for links in the response. Two clients load the same order, status pending. Client A has a map of URLs and and got the Cancel and Pay buttons from that map. Client B relies on links in the response and has got nothing yet, as nothing in the response said what Client B may do.
REST is a set of constraints, and dropping one means you cannot call your API REST. In practice the uniform interface means addresses for things and methods for actions. Addresses nest one level deep to show ownership. Hypermedia is the constraint many APIs skip on purpose, so strictly speaking its an HTTP API at level 2.
Saved in this browser - sign in to keep your review list.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Keep going - a few more words and AI can grade it.
Interview lens
How interviewers actually use this question
Likely follow-ups
Why do so few real-world REST APIs implement HATEOAS?Name the costs: many clients hardcode URLs anyway, generic hypermedia clients are rare, and payloads and design work grow.
If clients shouldn't build URLs, how does a client know what each link means?The link relation name carries the meaning. Clients code against names like 'orders' or 'next', and formats like HAL fix where links live.
How would the links change as an order moves from placed to shipped?The server sends only the links valid right now, so 'cancel' drops out after shipping, and the client shows actions based on which links exist.
In your example, edit and delete share one URL. How does the client know which HTTP method to use?A plain link carries only a URL. The method comes from docs or from a richer format like Siren or HAL-FORMS that describes actions.
HATEOAS means an API response includes links to related resources and the actions you can take next, so the client finds its way from the response itself.
For example, fetching user 123 returns the name and email plus a _links block with self, orders, edit and delete.
The client follows those links instead of building URLs itself, so it depends on link names rather than on the server's URL layout.
That makes the API easier to discover, means clients lean less on documentation, and lets the server change URLs without breaking anyone who follows the links.
The catch is that it only helps when clients really follow the links, and most teams hardcode URLs anyway, so full HATEOAS is rare outside things like pagination links.
Weak answers to avoid
Expands the acronym and stopsSpelling out the name shows nothing. Say what goes in the response, give a link or two, and explain how following links lowers coupling.
Says links replace all documentationLinks say where to go, not what fields mean or what a rel name implies. The claim is less documentation, not none.
Lists every link on every responseThe point is that links reflect current state and permissions. A delete link on a record the user can't delete tells the client something false.
Claims every REST API uses itMost real APIs skip it or add only pagination links. Say so, and name the cost, which is bigger payloads plus clients that hardcode URLs anyway.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.