← All topics

5 articles & lessons

Backend & APIs

Articles and learning notes on backend & apis.

  1. AuthN & AuthZ — OAuth 2.0, OIDC, JWT

    The two things you can't afford to get wrong. Authentication vs authorization untangled, OAuth 2.0's actual flows, OIDC's identity layer, and JWTs — including the specific parts of ‘just use JWTs’ that get people breached. With a working OAuth code flow you can trace end to end.

    55 min read
  2. gRPC & Protobuf — When RPC Wins

    Binary framing + strict schemas + streaming = the internal-service default at Google, Netflix, Uber, Cloudflare. What Protobuf actually is, how gRPC uses HTTP/2, when RPC is the right shape, and a working polyglot client-server in Python.

    55 min read
  3. GraphQL — Schema, Resolvers, N+1, When to Pick It

    GraphQL isn't ‘REST but better’ — it's a different set of tradeoffs. Schema-first design, resolver mechanics, the N+1 disaster and DataLoader fix, and a defensible checklist for when GraphQL beats REST (and when it emphatically does not).

    55 min read
  4. REST API Design — Resources, Versioning, Idempotency

    The design decisions that separate an API you can still maintain at v4 from one you have to burn down. Resources vs actions, versioning strategies that actually work, and idempotency keys as a first-class citizen. With a full working design for a real ‘orders’ API.

    55 min read
  5. HTTP Fundamentals — Verbs, Status Codes, Headers, Caching

    The protocol every web system speaks, unpacked line by line. Verbs, status codes, headers, and the cache directives that decide whether your API costs $50 or $50,000 a month. With a curl-only walkthrough of a real request.

    55 min read