5 articles & lessons
Backend & APIs
Articles and learning notes on backend & apis.
AuthN & AuthZ — OAuth 2.0, OIDC, JWT
The two things you can't afford to get wrong. Authentication vs authorization untangled, OAuth 2.0's actual flows, OIDC's identity layer, and JWTs — including the specific parts of ‘just use JWTs’ that get people breached. With a working OAuth code flow you can trace end to end.
55 min readgRPC & Protobuf — When RPC Wins
Binary framing + strict schemas + streaming = the internal-service default at Google, Netflix, Uber, Cloudflare. What Protobuf actually is, how gRPC uses HTTP/2, when RPC is the right shape, and a working polyglot client-server in Python.
55 min readGraphQL — Schema, Resolvers, N+1, When to Pick It
GraphQL isn't ‘REST but better’ — it's a different set of tradeoffs. Schema-first design, resolver mechanics, the N+1 disaster and DataLoader fix, and a defensible checklist for when GraphQL beats REST (and when it emphatically does not).
55 min readREST API Design — Resources, Versioning, Idempotency
The design decisions that separate an API you can still maintain at v4 from one you have to burn down. Resources vs actions, versioning strategies that actually work, and idempotency keys as a first-class citizen. With a full working design for a real ‘orders’ API.
55 min readHTTP Fundamentals — Verbs, Status Codes, Headers, Caching
The protocol every web system speaks, unpacked line by line. Verbs, status codes, headers, and the cache directives that decide whether your API costs $50 or $50,000 a month. With a curl-only walkthrough of a real request.
55 min read