HTTP fundamentals
Almost every backend speaks HTTP. It is a request–response protocol: a client sends a request, a server sends back exactly one response.
Anatomy of a request and a response
POST /orders HTTP/1.1
Host: api.example.com
Content-Type: application/json
Authorization: Bearer eyJhbGciOi...
{"sku": "book-42", "quantity": 1}
HTTP/1.1 201 Created
Location: /orders/9001
Content-Type: application/json
{"id": 9001, "status": "pending"}
A request has a method, a path, headers and an optional body. A response has a status code, headers and an optional body.
Methods: safe and idempotent
- A safe method does not change server state:
GET,HEAD,OPTIONS. - An idempotent method has the same effect whether you send it once or ten times.
| Method | Safe | Idempotent | Typical use |
|---|---|---|---|
| GET | yes | yes | Read a resource |
| PUT | no | yes | Replace a resource at a known URL |
| DELETE | no | yes | Remove a resource |
| POST | no | no | Create or trigger an action |
| PATCH | no | not guaranteed | Partial update |
Idempotency matters because networks fail. If a PUT times out, the client can safely retry it. Retrying a POST might create two orders, which is why payment APIs accept an idempotency key header: the server remembers the key and returns the first result for repeats.
Status codes
- 2xx success:
200 OK,201 Created,204 No Content. - 3xx redirection:
301 Moved Permanently,302 Found,304 Not Modified. - 4xx client error:
400 Bad Request(malformed),401 Unauthorized(not authenticated),403 Forbidden(authenticated but not allowed),404 Not Found,409 Conflict,422 Unprocessable Content,429 Too Many Requests. - 5xx server error:
500 Internal Server Error,502 Bad Gateway,503 Service Unavailable.
The line between 4xx and 5xx tells clients whether a retry could help: repeating a 4xx request unchanged will fail again.
Caching headers
Cache-Control: max-age=3600lets clients and CDNs reuse a response for an hour.Cache-Control: no-storeforbids storing it at all. Use it for sensitive data.- Validators allow cheap revalidation. The server sends an
ETag(a version fingerprint) orLast-Modified. The client later sendsIf-None-MatchorIf-Modified-Since, and the server replies304 Not Modifiedwith no body if nothing changed.
Content negotiation
The client says what it accepts (Accept: application/json, Accept-Encoding: gzip, br). The server picks a representation and says what it chose in Content-Type and Content-Encoding.
Statelessness and cookies
HTTP is stateless: each request carries everything the server needs, and no request depends on the previous one. Sessions are layered on top. The server sets a cookie:
Set-Cookie: sid=abc123; HttpOnly; Secure; SameSite=Lax; Path=/; Max-Age=2592000
The browser sends Cookie: sid=abc123 on later requests. HttpOnly hides the cookie from JavaScript, Secure restricts it to HTTPS, and SameSite=Lax stops it from being sent on most cross-site requests, which blocks common CSRF attacks.
Statelessness is what lets you run many identical server instances behind a load balancer: any instance can handle any request.