API Design
Designing interfaces that are clear, consistent and hard to misuse.
Backend Engineer
Junior
Write correct code, ship small changes safely, ask good questions.
Core: start here
- API TestingCalling endpoints and checking status codes, bodies and side effects.
- Double SubmissionA user clicking twice and creating two orders, and how to prevent it.
- PaginationReturning large result sets one page at a time.
6 more junior concepts
- API KeyA long random secret identifying a calling application rather than a user.
- API Naming ConventionsConsistent casing, plurals and verbs across endpoints.
- Filtering and SortingLetting clients narrow down and order results.
- Breaking ChangeA change that forces clients to update.
- 429 Too Many RequestsThe status returned when a client goes over a rate limit.
- WebhookAn HTTP callback: a service calls your URL when something happens.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- API DesignDesigning interfaces that are clear, consistent and hard to misuse.
- Error Response FormatA consistent shape for API errors, like RFC 9457 Problem Details.
- API VersioningEvolving an API without breaking existing clients.
- Idempotency KeyA client-supplied ID that makes retried requests safe.
- Offset vs Cursor PaginationSimple page numbers vs stable, scalable cursors.
- Rate LimitingLimiting how many requests a client can make.
9 more mid-level concepts
- API ContractThe agreed shape and behavior of an API.
- API GatewayA single entry point handling routing, auth and rate limits for many services.
- ETagA version identifier used for conditional requests and caching.
- HMACA keyed hash proving a message came from someone holding the secret.
- IdempotenceDoing something twice has the same effect as doing it once.
- OAuth Scopes and PermissionsLimiting what a token can do, e.g. read-only access.
- Opaque Resource IdentifiersNot leaking database IDs or internal structure in URLs.
- Backward CompatibilityNew versions that still work with old clients.
- DeprecationMarking something for removal and giving users time to migrate.
Senior
Own a system, its failure modes, and its trade-offs.
- Bulk OperationsEndpoints that act on many items in one request.
- API-First DesignDesigning the API contract before implementing it.
- Contract TestingVerifying that services agree on the API contract between them.
- Designing WebhooksSignatures, retries, ordering and idempotency for outgoing webhooks.
- HATEOASResponses that include links to the possible next actions.
- Long-Running OperationsReturning 202 Accepted and a status URL for slow work.
- Public vs Internal APIsWhy public APIs need much more care about stability.
- Sparse FieldsetsLetting clients choose which fields they receive.
- Backend for Frontend (BFF)A backend tailored to one frontend's needs.
- Rate Limiting AlgorithmsToken bucket, leaky bucket, fixed window and sliding window.
Staff
Shape how many teams build, across systems.
- API Lifecycle ManagementDesigning, publishing, versioning and retiring APIs across an organization.
Data Analyst
Mid-level
Own an analysis end to end, from vague question to recommendation.
- PaginationReturning large result sets one page at a time.
- 429 Too Many RequestsThe status returned when a client goes over a rate limit.
- Rate LimitingLimiting how many requests a client can make.
- Bulk OperationsEndpoints that act on many items in one request.
Data Engineer
Junior
Build and fix pipelines from clear specs; write correct SQL.
Core: start here
- API TestingCalling endpoints and checking status codes, bodies and side effects.
3 more junior concepts
- Breaking ChangeA change that forces clients to update.
- PaginationReturning large result sets one page at a time.
- WebhookAn HTTP callback: a service calls your URL when something happens.
Mid-level
Own pipelines and models end to end, including their quality.
- ETagA version identifier used for conditional requests and caching.
- HMACA keyed hash proving a message came from someone holding the secret.
- IdempotenceDoing something twice has the same effect as doing it once.
- API VersioningEvolving an API without breaking existing clients.
- Idempotency KeyA client-supplied ID that makes retried requests safe.
- Offset vs Cursor PaginationSimple page numbers vs stable, scalable cursors.
- Rate LimitingLimiting how many requests a client can make.
- Backward CompatibilityNew versions that still work with old clients.
- DeprecationMarking something for removal and giving users time to migrate.
Senior
Design the platform's storage, processing and modeling choices.
- Contract TestingVerifying that services agree on the API contract between them.
Frontend Engineer
Junior
Build UI that works, ship small changes safely, ask good questions.
Core: start here
- Double SubmissionA user clicking twice and creating two orders, and how to prevent it.
7 more junior concepts
- API KeyA long random secret identifying a calling application rather than a user.
- API Naming ConventionsConsistent casing, plurals and verbs across endpoints.
- API TestingCalling endpoints and checking status codes, bodies and side effects.
- Filtering and SortingLetting clients narrow down and order results.
- Breaking ChangeA change that forces clients to update.
- PaginationReturning large result sets one page at a time.
- 429 Too Many RequestsThe status returned when a client goes over a rate limit.
Mid-level
Own a feature end to end without hand-holding.
- API DesignDesigning interfaces that are clear, consistent and hard to misuse.
- WebhookAn HTTP callback: a service calls your URL when something happens.
- API ContractThe agreed shape and behavior of an API.
- API GatewayA single entry point handling routing, auth and rate limits for many services.
- Error Response FormatA consistent shape for API errors, like RFC 9457 Problem Details.
- ETagA version identifier used for conditional requests and caching.
- IdempotenceDoing something twice has the same effect as doing it once.
- OAuth Scopes and PermissionsLimiting what a token can do, e.g. read-only access.
- API VersioningEvolving an API without breaking existing clients.
- Idempotency KeyA client-supplied ID that makes retried requests safe.
- Offset vs Cursor PaginationSimple page numbers vs stable, scalable cursors.
- Rate LimitingLimiting how many requests a client can make.
- Backward CompatibilityNew versions that still work with old clients.
- DeprecationMarking something for removal and giving users time to migrate.
Senior
Own an app's architecture, performance, and failure modes.
Core: start here
- Contract TestingVerifying that services agree on the API contract between them.
7 more senior concepts
- Bulk OperationsEndpoints that act on many items in one request.
- API-First DesignDesigning the API contract before implementing it.
- HATEOASResponses that include links to the possible next actions.
- Long-Running OperationsReturning 202 Accepted and a status URL for slow work.
- Public vs Internal APIsWhy public APIs need much more care about stability.
- Sparse FieldsetsLetting clients choose which fields they receive.
- Backend for Frontend (BFF)A backend tailored to one frontend's needs.