LearnThatStack Ace your next interview
Part of System Design Concepts

API Design.

Start free Change topic Change

Practise API Design one question at a time. Answer out loud or in writing, get graded, and see exactly what you missed.

Try one question

What is REST and what are its core principles?

The answer

REST (Representational State Transfer) is an architectural style for distributed systems, defined by Roy Fielding in 2000. It is a set of constraints, not a protocol or a standard.

Six constraints define the style:

  • Client-server: the two sides evolve on their own.
  • Stateless: each request carries everything the server needs.
  • Cacheable: responses must say if they can be stored and reused.
  • Uniform interface: one consistent way to address and act on resources.
  • Layered system: a client cannot tell if it talks to the origin server.
  • Code on demand (optional): the server may send runnable code, like JavaScript.

Every request stands alone, as this one does:

GET /articles/42 HTTP/1.1
Host: api.example.com
Authorization: Bearer <token>
Accept: application/json

Statelessness is the main trade-off. Any server node can handle any request, but each call must resend auth and context.

Get your own answers graded

Sign up free. Your account comes with 50 credits for grading, and it remembers what you missed.

What it covers

  • REST and resource design
  • HTTP methods, status codes and errors
  • Collections and payload design
  • Authentication and authorization
  • API security and rate limiting
  • Versioning and compatibility
  • API styles and real-time delivery
  • gRPC fundamentals
  • Performance, reliability and observability
  • Testing, documentation and developer experience
  • Scale and distributed systems
  • gRPC in production
All 110 questions · each on its own page
  1. What is REST and what are its core principles?
  2. Explain the concept of resources in REST API design.
  3. Explain the difference between PUT and POST methods.
  4. What are the most important HTTP status codes for APIs?
  5. What is the difference between authentication and authorization?
  6. How do you handle validation errors in APIs?
  7. What is CORS and how do you handle it in APIs?
  8. What are the main HTTP methods used in REST APIs and their purposes?
  9. What are HTTP status codes and give examples of common ones?
  10. What makes an API RESTful?
  11. What is the difference between URI, URL, and URN?
  12. What are query parameters and path parameters? Pro
  13. What is JSON and why is it commonly used in REST APIs? Pro
  14. What is Content-Type header and why is it important? Pro
  15. What are Protocol Buffers and why does gRPC use them?
  16. How does gRPC differ from REST APIs?
  17. What are the main advantages of using HTTP/2 in gRPC?
  18. What types of service methods does gRPC support?
  19. How do you define a gRPC service in a .proto file? Pro
  20. What is code generation in gRPC and why is it important? Pro
  21. What is a gRPC client stub? Pro
  22. What is the difference between REST and SOAP?
  23. What is HATEOAS and why is it important?
  24. When would you use PATCH vs PUT?
  25. Explain idempotency in API design. Pro
  26. Compare different API authentication methods. Pro
  27. How would you implement role-based access control (RBAC) in an API? Pro
  28. What are the different API versioning strategies? Pro
  29. When should you introduce a new API version? Pro
  30. How should you structure error responses in APIs? Pro
  31. How do you implement pagination in APIs? Pro
  32. What caching strategies can you apply to APIs? Pro
  33. How do you implement rate limiting in APIs? Pro
  34. What are common API security vulnerabilities? Pro
  35. How do you secure API endpoints? Pro
  36. How do you implement API key management? Pro
  37. What is an API Gateway and when would you use one? Pro
  38. Explain the difference between synchronous and asynchronous APIs. Pro
  39. How do you design APIs for mobile applications? Pro
  40. What are webhooks and how do you implement them? Pro
  41. How do you handle file uploads in APIs? Pro
  42. Compare REST vs GraphQL APIs. Pro
  43. How do you handle API documentation and ensure it stays up-to-date? Pro
  44. How do you implement API analytics and usage tracking? Pro
  45. What are API design anti-patterns to avoid? Pro
  46. How do you implement API testing strategies? Pro
  47. How do you design filtering, sorting, and search on a collection endpoint? Pro
  48. How should an API client retry a failed request without making the outage worse? Pro
  49. How would you push real-time updates to API clients? Compare polling, long polling, Server-Sent Events, and WebSockets. Pro
  50. What is idempotency in REST APIs and which HTTP methods are idempotent? Pro
  51. What are the different types of API authentication methods? Pro
  52. What is content negotiation in REST APIs? Pro
  53. How do you handle errors in REST APIs? Pro
  54. What are HTTP response headers commonly used in REST APIs? Pro
  55. What is rate limiting and how is it implemented? Pro
  56. What is pagination and what are different pagination techniques? Pro
  57. What is CORS and how does it affect REST APIs? Pro
  58. What are the considerations for API deprecation? Pro
  59. How do you implement search functionality in REST APIs? Pro
  60. What are the differences between API-first and code-first approaches? Pro
  61. How do you implement real-time features with REST APIs? Pro
  62. What are the security headers important for REST APIs? Pro
  63. How do you handle errors in gRPC? Pro
  64. What is gRPC metadata and how is it used? Pro
  65. What are gRPC interceptors and what are they used for? Pro
  66. How do timeouts and deadlines work in gRPC? Pro
  67. What is connection pooling in gRPC and how does it work? Pro
  68. How do you implement authentication in gRPC? Pro
  69. What are the different load balancing strategies in gRPC? Pro
  70. How do you handle streaming in gRPC? Pro
  71. What is gRPC health checking and how do you implement it? Pro
  72. How do you model a non-CRUD action, like cancelling an order, in a REST API? Pro
  73. How do retries work in gRPC, and which calls are safe to retry? Pro
  74. What is gRPC and when would you use it? Pro
  75. What are microservices and how do REST APIs fit into microservices architecture? Pro
  76. How do you handle backward compatibility in APIs? Pro
  77. How do you optimize API response times?
  78. How do you implement API monitoring and observability? Pro
  79. How do you design APIs for high availability? Pro
  80. What is API contract testing and how do you implement it? Pro
  81. What are the challenges of API deprecation and how do you manage them? Pro
  82. How do you design APIs for third-party integrations?
  83. How do you handle data consistency in distributed API systems? Pro
  84. What strategies do you use for API performance testing? Pro
  85. How do you implement microservices communication patterns? Pro
  86. How do you design APIs for scalability? Pro
  87. How do you design a multi-tenant API so one tenant can never read another tenant's data? Pro
  88. Walk through the OAuth 2.0 authorization code flow with PKCE, and explain when you would use it. Pro
  89. How would you design a REST API for a complex domain with relationships? Pro
  90. What are the security considerations for REST APIs? Pro
  91. What are webhooks and how do they differ from polling? Pro
  92. How do you implement API documentation and what are the best practices? Pro
  93. What is API orchestration vs choreography? Pro
  94. What are API gateways and service mesh, and how do they differ? Pro
  95. What are the best practices for API error handling and debugging? Pro
  96. How do you optimize gRPC performance for high-throughput scenarios? Pro
  97. How do you implement custom load balancing in gRPC? Pro
  98. What is gRPC reflection and when would you use it? Pro
  99. How do you handle gRPC streaming backpressure? Pro
  100. How do you implement circuit breakers with gRPC? Pro
  101. How do you implement distributed tracing in gRPC? Pro
  102. What are the security best practices for gRPC in production? Pro
  103. How do you handle gRPC service discovery in a microservices architecture? Pro
  104. How do you implement graceful shutdown for gRPC servers? Pro
  105. How do you implement request validation in gRPC? Pro
  106. How do you debug and troubleshoot gRPC issues? Pro
  107. What is gRPC-Web and when would you use it? Pro
  108. How do you implement caching strategies with gRPC? Pro
  109. How do you handle versioning in gRPC services? Pro
  110. How do you implement comprehensive monitoring for gRPC services? Pro
Practice · Questions

All questions

Showing of 110
Beginner 22
01

What is REST and what are its core principles?

Visual

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain
Visual

REST (Representational State Transfer) is an architectural style for distributed systems, defined by Roy Fielding in 2000. It is a set of constraints, not a protocol or a standard.

Six constraints define the style:

  • Client-server: the two sides evolve on their own.
  • Stateless: each request carries everything the server needs.
  • Cacheable: responses must say if they can be stored and reused.
  • Uniform interface: one consistent way to address and act on resources.
  • Layered system: a client cannot tell if it talks to the origin server.
  • Code on demand (optional): the server may send runnable code, like JavaScript.

Every request stands alone, as this one does:

GET /articles/42 HTTP/1.1
Host: api.example.com
Authorization: Bearer <token>
Accept: application/json

Statelessness is the main trade-off. Any server node can handle any request, but each call must resend auth and context.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

02

Explain the concept of resources in REST API design.

Visual

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain
Visual

Resources are the key abstraction in REST. A resource is any information that can be named and addressed. Resources should be:

  • Nouns, not verbs: Use /users not /getUsers
  • Hierarchical: /users/123/orders/456
  • Consistent: Use plural nouns (/users, not /user)
  • Meaningful: Clear and descriptive names

Resources represent entities in your domain model and should map to business objects or data entities.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

03

Explain the difference between PUT and POST methods.

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

POST:

  • Creates new resources
  • Not idempotent (multiple calls create multiple resources)
  • Server determines resource identifier
  • Example: POST /users creates a new user

PUT:

  • Creates or updates resources
  • Idempotent (multiple identical calls have same effect)
  • Client provides resource identifier
  • Example: PUT /users/123 creates or updates user with ID 123
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

04

What are the most important HTTP status codes for APIs?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

2xx Success:

  • 200 OK: Successful GET, PUT, PATCH
  • 201 Created: Successful POST
  • 204 No Content: Successful DELETE or PUT with no response body

4xx Client Error:

  • 400 Bad Request: Invalid request syntax
  • 401 Unauthorized: Authentication required
  • 403 Forbidden: Access denied
  • 404 Not Found: Resource doesn't exist
  • 409 Conflict: Resource conflict
  • 422 Unprocessable Entity: Validation errors

5xx Server Error:

  • 500 Internal Server Error: Generic server error
  • 503 Service Unavailable: Server temporarily unavailable
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

05

What is the difference between authentication and authorization?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Authentication: Verifies who the user is (identity verification)

  • "Are you really John Doe?"
  • Methods: passwords, biometrics, certificates

Authorization: Determines what the authenticated user can do (permission checking)

  • "Can John Doe access this resource?"
  • Methods: roles, permissions, ACLs

Both are typically required for secure APIs. Authentication happens first, then authorization checks permissions.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

06

How do you handle validation errors in APIs?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Return 422 Unprocessable Entity with detailed field-level errors:

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Validation failed",
    "details": [
      {
        "field": "email",
        "code": "INVALID_FORMAT",
        "message": "Email must be valid format"
      },
      {
        "field": "password",
        "code": "TOO_SHORT",
        "message": "Password must be at least 8 characters"
      }
    ]
  }
}

This helps clients understand exactly what needs to be fixed.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

07

What is CORS and how do you handle it in APIs?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

CORS (Cross-Origin Resource Sharing) allows controlled access to resources from different domains.

CORS Headers:

Access-Control-Allow-Origin: https://example.com
Access-Control-Allow-Methods: GET, POST, PUT, DELETE
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Max-Age: 3600

Preflight Requests: Browser sends OPTIONS request for complex requests.

Security Considerations:

  • Don't use * for credentials-enabled requests
  • Be specific with allowed origins
  • Validate origins server-side
  • Consider using CORS libraries
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

08

What are the main HTTP methods used in REST APIs and their purposes?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

The main HTTP methods (verbs) used in REST APIs are:

  • GET: Retrieves data from the server. Should be safe and idempotent.
  • POST: Creates new resources or submits data for processing.
  • PUT: Updates an entire resource or creates it if it doesn't exist. Should be idempotent.
  • PATCH: Partially updates a resource.
  • DELETE: Removes a resource. Should be idempotent.
  • HEAD: Similar to GET but returns only headers, not the body.
  • OPTIONS: Returns allowed methods for a resource.

Example:

GET /users/123        # Retrieve user with ID 123
POST /users           # Create a new user
PUT /users/123        # Update entire user 123
PATCH /users/123      # Partially update user 123
DELETE /users/123     # Delete user 123
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

09

What are HTTP status codes and give examples of common ones?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

HTTP status codes are three-digit numbers that indicate the result of an HTTP request. They are grouped into five categories:

1xx - Informational:

  • 100 Continue

2xx - Success:

  • 200 OK: Request successful
  • 201 Created: Resource successfully created
  • 204 No Content: Successful but no content to return

3xx - Redirection:

  • 301 Moved Permanently
  • 304 Not Modified

4xx - Client Error:

  • 400 Bad Request: Invalid request syntax
  • 401 Unauthorized: Authentication required
  • 403 Forbidden: Access denied
  • 404 Not Found: Resource doesn't exist
  • 409 Conflict: Request conflicts with current state

5xx - Server Error:

  • 500 Internal Server Error
  • 503 Service Unavailable
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

10

What makes an API RESTful?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

An API is considered RESTful when it adheres to REST architectural constraints:

  1. Uniform Interface: Consistent resource identification (URLs), manipulation through representations, self-descriptive messages, and HATEOAS
  2. Stateless: Each request is independent and contains all necessary information
  3. Cacheable: Responses indicate whether they can be cached
  4. Client-Server: Clear separation of concerns
  5. Layered System: Can include intermediary layers (proxies, gateways)
  6. Code on Demand (optional): Server can send executable code to client

Additionally, RESTful APIs typically:

  • Use standard HTTP methods appropriately
  • Return appropriate HTTP status codes
  • Use resource-based URLs (nouns, not verbs)
  • Support multiple representations (JSON, XML)
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

11

What is the difference between URI, URL, and URN?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

These are related but distinct concepts:

URI (Uniform Resource Identifier):

  • Generic term for any identifier that identifies a resource
  • Superset that includes both URLs and URNs
  • Example: mailto:john@example.com

URL (Uniform Resource Locator):

  • Type of URI that specifies location and method to access a resource
  • Includes protocol, domain, and path
  • Example: https://api.example.com/users/123

URN (Uniform Resource Name):

  • Type of URI that identifies a resource by name in a specific namespace
  • Location-independent identifier
  • Example: urn:isbn:0451450523

In REST APIs, we primarily work with URLs to locate and access resources over HTTP.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

12

What are query parameters and path parameters?

Part of Pro
13

What is JSON and why is it commonly used in REST APIs?

Part of Pro
14

What is Content-Type header and why is it important?

Part of Pro
15

What are Protocol Buffers and why does gRPC use them?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Protocol Buffers (protobuf) are Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data. gRPC uses protobuf for several reasons:

  • Efficiency: Binary serialization is faster and more compact than JSON/XML
  • Type Safety: Strongly typed schema prevents runtime errors
  • Code Generation: Automatically generates client and server code
  • Language Agnostic: Works across different programming languages
  • Schema Evolution: Supports backward and forward compatibility

Example protobuf definition:

syntax = "proto3";

message User {
  int32 id = 1;
  string name = 2;
  string email = 3;
}

service UserService {
  rpc GetUser(UserRequest) returns (User);
}
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

16

How does gRPC differ from REST APIs?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain
Aspect gRPC REST
Protocol HTTP/2 HTTP/1.1
Data Format Protocol Buffers (binary) JSON (text)
Performance Faster, lower latency Slower due to text parsing
Streaming Bidirectional streaming Limited streaming support
Browser Support Limited (needs gRPC-Web) Native support
Caching Limited caching capabilities HTTP caching support
Learning Curve Steeper Gentler
Use Case Microservices, real-time apps Web APIs, CRUD operations
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

17

What are the main advantages of using HTTP/2 in gRPC?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

HTTP/2 provides several advantages for gRPC:

  • Multiplexing: Multiple requests can be sent simultaneously over a single connection
  • Binary Protocol: More efficient parsing compared to HTTP/1.1 text protocol
  • Header Compression: Reduces overhead using HPACK compression
  • Server Push: Server can send multiple responses for a single request
  • Flow Control: Prevents overwhelming slower receivers
  • Connection Reuse: Reduces connection overhead and latency
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

18

What types of service methods does gRPC support?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

gRPC supports four types of service methods:

  1. Unary RPC: Client sends one request, server returns one response
rpc GetUser(UserRequest) returns (User);
  1. Server Streaming RPC: Client sends one request, server returns a stream of responses
rpc ListUsers(ListUsersRequest) returns (stream User);
  1. Client Streaming RPC: Client sends a stream of requests, server returns one response
rpc CreateUsers(stream User) returns (CreateUsersResponse);
  1. Bidirectional Streaming RPC: Both client and server send streams of messages
rpc Chat(stream ChatMessage) returns (stream ChatMessage);
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

19

How do you define a gRPC service in a .proto file?

Part of Pro
20

What is code generation in gRPC and why is it important?

Part of Pro
21

What is a gRPC client stub?

Part of Pro
22

What is the difference between REST and SOAP?

Beginner ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

SOAP is a protocol with a fixed XML message format, while REST is an architectural style. SOAP wraps every call in an XML envelope, and a SOAP service usually publishes a WSDL contract. REST APIs expose resources at URLs and act on them with standard HTTP methods, usually exchanging JSON.

SOAP REST
Kind Protocol Architectural style
Format XML only Any format, usually JSON
Contract Usually a WSDL Optional, often OpenAPI
Transport HTTP, SMTP and others Usually HTTP
Caching Rare, since calls are usually POST Standard HTTP caching
Security WS-Security at the message level TLS plus tokens such as OAuth

Choose REST for most web and mobile APIs, where lighter payloads and HTTP caching matter. SOAP still fits enterprise systems that need a formal contract or message-level security, such as older banking and insurance integrations.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

Intermediate 51
23

What is HATEOAS and why is it important?

Visual

Intermediate ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain
Visual

HATEOAS (Hypermedia as the Engine of Application State) means that API responses should include links to related actions or resources. This makes APIs self-discoverable and reduces client-server coupling.

Example response with HATEOAS:

{
  "id": 123,
  "name": "John Doe",
  "email": "john@example.com",
  "_links": {
    "self": "/users/123",
    "orders": "/users/123/orders",
    "edit": "/users/123",
    "delete": "/users/123"
  }
}

Benefits include improved API discoverability, reduced documentation needs, and easier API evolution.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

24

When would you use PATCH vs PUT?

Intermediate ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

PUT: Replaces the entire resource with the provided data. If you omit fields, they should be set to default/null values.

PATCH: Partial update of a resource. Only updates the fields provided in the request body.

Example:

PUT /users/123
{
  "name": "John Doe",
  "email": "john@example.com"
}
# Replaces entire user object

PATCH /users/123
{
  "email": "newemail@example.com"
}
# Only updates email field
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

25

Explain idempotency in API design.

Part of Pro
26

Compare different API authentication methods.

Part of Pro
27

How would you implement role-based access control (RBAC) in an API?

Part of Pro
28

What are the different API versioning strategies?

Part of Pro
29

When should you introduce a new API version?

Part of Pro
30

How should you structure error responses in APIs?

Part of Pro Visual
31

How do you implement pagination in APIs?

Part of Pro
32

What caching strategies can you apply to APIs?

Part of Pro
33

How do you implement rate limiting in APIs?

Part of Pro
34

What are common API security vulnerabilities?

Part of Pro
35

How do you secure API endpoints?

Part of Pro
36

How do you implement API key management?

Part of Pro
37

What is an API Gateway and when would you use one?

Part of Pro
38

Explain the difference between synchronous and asynchronous APIs.

Part of Pro
39

How do you design APIs for mobile applications?

Part of Pro
40

What are webhooks and how do you implement them?

Part of Pro
41

How do you handle file uploads in APIs?

Part of Pro
42

Compare REST vs GraphQL APIs.

Part of Pro
43

How do you handle API documentation and ensure it stays up-to-date?

Part of Pro
44

How do you implement API analytics and usage tracking?

Part of Pro
45

What are API design anti-patterns to avoid?

Part of Pro Visual
46

How do you implement API testing strategies?

Part of Pro
47

How do you design filtering, sorting, and search on a collection endpoint?

Part of Pro
48

How should an API client retry a failed request without making the outage worse?

Part of Pro Visual
49

How would you push real-time updates to API clients? Compare polling, long polling, Server-Sent Events, and WebSockets.

Part of Pro
50

What is idempotency in REST APIs and which HTTP methods are idempotent?

Part of Pro
51

What are the different types of API authentication methods?

Part of Pro
52

What is content negotiation in REST APIs?

Part of Pro
53

How do you handle errors in REST APIs?

Part of Pro
54

What are HTTP response headers commonly used in REST APIs?

Part of Pro
55

What is rate limiting and how is it implemented?

Part of Pro
56

What is pagination and what are different pagination techniques?

Part of Pro
57

What is CORS and how does it affect REST APIs?

Part of Pro
58

What are the considerations for API deprecation?

Part of Pro
59

How do you implement search functionality in REST APIs?

Part of Pro
60

What are the differences between API-first and code-first approaches?

Part of Pro
61

How do you implement real-time features with REST APIs?

Part of Pro
62

What are the security headers important for REST APIs?

Part of Pro
63

How do you handle errors in gRPC?

Part of Pro
64

What is gRPC metadata and how is it used?

Part of Pro
65

What are gRPC interceptors and what are they used for?

Part of Pro
66

How do timeouts and deadlines work in gRPC?

Part of Pro
67

What is connection pooling in gRPC and how does it work?

Part of Pro
68

How do you implement authentication in gRPC?

Part of Pro
69

What are the different load balancing strategies in gRPC?

Part of Pro
70

How do you handle streaming in gRPC?

Part of Pro
71

What is gRPC health checking and how do you implement it?

Part of Pro
72

How do you model a non-CRUD action, like cancelling an order, in a REST API?

Part of Pro
73

How do retries work in gRPC, and which calls are safe to retry?

Part of Pro Visual
Expert 37
74

What is gRPC and when would you use it?

Part of Pro
75

What are microservices and how do REST APIs fit into microservices architecture?

Part of Pro
76

How do you handle backward compatibility in APIs?

Part of Pro
77

How do you optimize API response times?

Expert ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Database Optimization:

  • Use appropriate indexes
  • Implement query optimization
  • Consider read replicas
  • Use connection pooling

Response Optimization:

  • Implement field selection: GET /users?fields=id,name,email
  • Use compression (gzip)
  • Minimize payload size
  • Implement lazy loading

Architecture Patterns:

  • Async processing for heavy operations
  • Background job queues
  • Microservices for scalability
  • API gateways for routing and caching

Monitoring:

  • Track response times
  • Monitor error rates
  • Implement distributed tracing
  • Use APM tools
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

78

How do you implement API monitoring and observability?

Part of Pro
79

How do you design APIs for high availability?

Part of Pro
80

What is API contract testing and how do you implement it?

Part of Pro Visual
81

What are the challenges of API deprecation and how do you manage them?

Part of Pro Visual
82

How do you design APIs for third-party integrations?

Expert ·

Answer it yourself first - out loud, or typed below.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Last attempt -

Your answer

Re-explain

Design Considerations:

  1. Developer Experience:

    • Clear documentation
    • Interactive API explorer
    • SDKs in popular languages
    • Sandbox environment
  2. Partnership Models:

    • Public APIs: Open to all developers
    • Partner APIs: Restricted access
    • Private APIs: Internal use only
  3. Onboarding Process:

    • Self-service registration
    • API key management
    • Usage tiers and billing
    • Support channels

Example Partner API Structure:

POST /partners/webhooks
Authorization: Bearer partner_token
{
  "url": "https://partner.com/webhook",
  "events": ["order.created", "order.updated"],
  "secret": "webhook_secret"
}

Integration Patterns:

  • Webhook notifications
  • Polling endpoints
  • Real-time APIs (WebSockets)
  • Batch processing APIs
Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

Related concept

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

83

How do you handle data consistency in distributed API systems?

Part of Pro
84

What strategies do you use for API performance testing?

Part of Pro
85

How do you implement microservices communication patterns?

Part of Pro Visual
86

How do you design APIs for scalability?

Part of Pro
87

How do you design a multi-tenant API so one tenant can never read another tenant's data?

Part of Pro
88

Walk through the OAuth 2.0 authorization code flow with PKCE, and explain when you would use it.

Part of Pro
89

How would you design a REST API for a complex domain with relationships?

Part of Pro
90

What are the security considerations for REST APIs?

Part of Pro
91

What are webhooks and how do they differ from polling?

Part of Pro
92

How do you implement API documentation and what are the best practices?

Part of Pro
93

What is API orchestration vs choreography?

Part of Pro
94

What are API gateways and service mesh, and how do they differ?

Part of Pro
95

What are the best practices for API error handling and debugging?

Part of Pro
96

How do you optimize gRPC performance for high-throughput scenarios?

Part of Pro
97

How do you implement custom load balancing in gRPC?

Part of Pro
98

What is gRPC reflection and when would you use it?

Part of Pro
99

How do you handle gRPC streaming backpressure?

Part of Pro
100

How do you implement circuit breakers with gRPC?

Part of Pro
101

How do you implement distributed tracing in gRPC?

Part of Pro
102

What are the security best practices for gRPC in production?

Part of Pro
103

How do you handle gRPC service discovery in a microservices architecture?

Part of Pro
104

How do you implement graceful shutdown for gRPC servers?

Part of Pro
105

How do you implement request validation in gRPC?

Part of Pro
106

How do you debug and troubleshoot gRPC issues?

Part of Pro
107

What is gRPC-Web and when would you use it?

Part of Pro
108

How do you implement caching strategies with gRPC?

Part of Pro
109

How do you handle versioning in gRPC services?

Part of Pro
110

How do you implement comprehensive monitoring for gRPC services?

Part of Pro

No matches

Try a different filter or search term.

Know someone prepping for API Design? Send them this set.
Learn · Concepts

The core concepts of API Design.

21 concepts in teaching order, one step-by-step diagram each. Go through one, then see every question it answers.

Start →
  1. 1 Thinking in resources: what REST actually is REST is constraints, not JSON over HTTP: address resources, let methods decide the action, send hypermedia links to what's next and more. Answers 4 questions 20 steps Start →
  2. 2 HTTP methods: what each verb promises A method's promise about safety and idempotency decides when a retry is safe, when a cache is legal, and PUT versus POST. Answers 3 questions 23 steps Start →
  3. 3 Status codes and error design: how an API says NO The status code tells machines whose fault the failure was and whether to retry. The error body tells a developer what to fix, and it is never an apology. Answers 3 questions 21 steps Start →
  4. 4 Authentication: proving who is calling Authentication asks who you are and authorization asks what you may do. Authentication methods differ mainly in where the identity state lives. Answers 4 questions 23 steps Start →
  5. 5 Authorization: a route check is not an object check A role check at the route is needed but not enough. The most common API breach is never asking whether this user owns object 123. Pro Answers 3 questions 13 steps Unlock →
  6. 6 The browser enforces CORS, not your server The browser runs the same-origin policy to protect its users. And CORS headers tell the browser which origins may read the reply, but requests from curl, POSTMAN don't go through that check. Answers 3 questions 15 steps Start →
  7. 7 API security: three families of mistakes, not a top ten list Real breaches come from missing checks, leaked fields and trusted input. Answers 4 questions 20 steps Start →
  8. 8 Designing a list endpoint is designing a small query language Pagination, filtering, sorting and field selection are one problem. Offset paging drifts and slows down. A cursor pins your position to a stable key. Pro Answers 2 questions 20 steps Unlock →
  9. 9 HTTP caching: infrastructure you do not own, working for you Declare freshness with Cache-Control and identity with ETag, and caches serve your traffic. The hard part is invalidation. Answers 3 questions 21 steps Start →
  10. 10 Conditional requests: the lost update and the fix HTTP already has Two clients read one row and both write it back, and the slower write silently erases the faster one. If-Match makes that loss a loud 412. Pro Answers 1 question Unlock →
  11. 11 Rate limiting shares capacity fairly, and the algorithm decides how A limiter protects a shared resource from any one caller, malicious or just retrying badly. The algorithm decides which bursts get through. Answers 5 questions 19 steps Start →
  12. 12 Versioning an API: changing the contract you already published Only a breaking change needs a new version, and most changes are additive. The deprecation lifecycle matters far more than where the version number goes. Answers 7 questions 20 steps Start →
  13. 13 Async APIs and webhooks: when the work takes longer than the request Do not keep the connection open. Return 202 with a job the client can poll, or send a webhook to whoever needs to know and handle every delivery problem. Answers 6 questions 19 steps Start →
  14. 14 Real-time APIs: step up from polling only for a clear reason Poll while the delay is acceptable. Push with SSE when only the server has new data, and open a WebSocket only when the client sends messages back. Pro Answers 2 questions 20 steps Unlock →
  15. 15 File uploads: do the bytes go through your API or skip it? Every upload design makes one choice: the bytes go through your API or skip it. A signed URL gives permission to upload, but your API still keeps control. Pro Answers 2 questions 18 steps Unlock →
  16. 16 Who controls the response shape In REST the server decides the response shape, in GraphQL the client builds it, and in gRPC a compiled contract sets it. The trade-offs come from who decides the shape. Answers 4 questions 19 steps Start →
  17. 17 The API gateway: what belongs at the edge A gateway exists so auth, rate limiting, routing and TLS are implemented once at the edge rather than copied into every service. Pro Answers 3 questions 17 steps Unlock →
  18. 18 Scale and availability: what statelessness makes possible, and what still fails Holding no session is what lets the servers scale out. For availability, the other half, assume parts fail and stop one failure from spreading. Answers 4 questions 22 steps Start →
  19. 19 Service boundaries: chains, events, and sagas Every call you add multiplies the risk. Events decouple services but data agrees later, and a saga replaces a transaction with compensations that undo earlier steps. Pro Answers 4 questions 21 steps Unlock →
  20. 20 Testing APIs: three different questions Three suites, three questions: behaviour, compatibility, capacity. The contract test is the one only an API needs. Answers 4 questions 19 steps Start →
  21. 21 Documentation: the docs come from the spec, not a hand-written copy Hand-written docs are a second copy of what the code does, and copies go out of date. A spec that generates the reference, clients and checks cannot go out of date. Answers 3 questions 19 steps Start →

More topics in System Design Concepts →

Pro · $10/mo

90 of 110 API Design answers are in Pro.

Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.

  • Full answers + code
  • AI explanations, simpler or deeper
  • 1,000 AI credits / month
  • Cancel anytime

Change topic

Pick a different technology or stack. Your current topic stays put until you choose a new one.

Technologies
No technologies match “”.
Cross-cutting topics
No topics match “”.
By role
Stacks & frameworks

MEAN

MongoDB, Express, Angular, Node.js

MERN

MongoDB, Express, React, Node.js

LAMP

Linux, Apache, MySQL, PHP

Django

Python Full-Stack Development

Ruby on Rails

Convention over Configuration

Serverless on AWS

Serverless Architecture on AWS

Flutter Mobile

Flutter Cross-Platform Mobile Development

Spring Boot

Enterprise Java Development

.NET

Microsoft Ecosystem

Vue

Vue.js, Vite, TypeScript, Tailwind, Node.js

Go Backend

Golang, gRPC, PostgreSQL, Redis, RabbitMQ

FastAPI

Python, FastAPI, SQLAlchemy, PostgreSQL

React Native

React, TypeScript, Redux, Firebase

iOS Native

Swift, SwiftUI, UIKit, Firebase

Android Native

Java, Jetpack Compose, Firebase

DevOps / Platform

Docker, Kubernetes, Terraform, CI/CD

AI Engineer

LLMs, RAG, Agents, Evals

AI-Powered Developer

Claude Code, Copilot, Agentic Workflows

Core SWE Interview Prep

Data structures, algorithms, OS, concurrency, networking, git