Network Stack, HTTP vs HTTPS, Core API Styles, Lifecycle Management & Key Principles
1 API Fundamentals & Client-Server Contract
API (Application Programming Interface) defines how software components interact and communicate with each other.
π API Contract Defines:
Hides internal implementation details (DB schema, business logic) while safely exposing necessary functionality to external consumers.
Establishes clear, isolated boundaries between distinct system components, enabling decoupled client-server apps and distributed microservices.
2 API Protocols in the Network Stack
βChoosing wrong protocols can lead to performance bottlenecks and limitations in functionality.β
Application-level communication protocols operate at the topmost layer of the standardized network stack:
3 HTTP (Hypertext Transfer Protocol) Deep Dive
HTTP is the foundational stateless request-response protocol of the World Wide Web and modern web APIs.
β‘ 5 Core HTTP Methods (CRUD Operations)
| HTTP Method | Action / Intent | Description & Idempotence |
|---|---|---|
| GET | Retrieve Data | Fetches resource data without modifying server state (Safe & Idempotent). |
| POST | Create Data | Creates a new subordinate resource on the server (Non-idempotent). |
| PUT | Update Data (Full) | Replaces the target resource entirely with new payload (Idempotent). |
| DELETE | Remove Data | Deletes the specified resource permanently (Idempotent). |
| PATCH | Partial Update | Modifies specific fields of an existing resource without full overwrite. |
200 OK, 201 Created).301 Moved, 304 Not Modified).400 Bad Request, 401 Unauthorized, 404 Not Found).500 Internal Error, 502 Bad Gateway, 503 Service Unavailable).Content-Type: Tells client/server MIME type of data (e.g. application/json).Authorization: Carries credentials/tokens for authentication (e.g. Bearer <token>).Accept: Specifies media types acceptable for the response.Cache-Control: Directives for caching mechanisms in browsers/CDNs (e.g. max-age=3600).User-Agent: Identifies the requesting browser, OS, and client software.4 HTTPS (HTTP + TLS/SSL Encryption)
HTTPS = HTTP + TLS/SSL Encryption
Protects data in transit from eavesdropping, interception, and tampering across public networks.
5 Core API Architectural Styles: REST, GraphQL, & gRPC
The universal industry-standard API architectural style for web, cloud, and mobile clients.
/api/v1/users, /api/v1/orders) using standard HTTP methods.A client-driven query language for APIs that eliminates over-fetching and under-fetching.
/graphql).Query β Read and retrieve exact required fieldsMutation β Create, update, or delete server dataSubscription β Real-time WebSocket event streamingπ‘ Recommended Choice for: Complex frontend UIs, mobile apps with bandwidth constraints, and aggregating multi-service dashboards into a single request.
A high-throughput, low-latency Remote Procedure Call framework created by Google for microservices.
.proto files with auto-generated client/server SDKs in multiple languages.1οΈβ£ Unary
Single Req β Single Resp
2οΈβ£ Server Streaming
Single Req β Stream Resp
3οΈβ£ Client Streaming
Stream Req β Single Resp
4οΈβ£ Bidirectional
Two-way continuous stream
π‘ Best Suited For: Internal backend-to-backend microservices, high-frequency trading, and IoT telemetry pipelines.
6 API Design Process, Approaches & Lifecycle Management
π 4 Requirements Discovery Steps
Map out end-user stories, workflows, and developer interaction patterns.
Establish bounded domains, clear responsibilities, and external dependencies.
Specify latency budgets, throughput limits (QPS), and payload size targets.
Define authentication protocols, RBAC authorization, and data privacy regulations.
π 3 Core API Design Approaches
Start with high-level user requirements and client workflows, then design API contracts and database models downward.
Begin with existing databases, domain models, and internal system capabilities, then expose API endpoints upward.
(Industry Best Practice) Formally define and approve the API contract (OpenAPI/Swagger, Proto) before writing any implementation code.
π API Lifecycle Management Flow
7 Key API Design Principles
/users, /orders), predictable casing.Cache-Control headers, ETags, and Redis edge layers.