Skip to content
FrontHeaven
Light mode

HTTP & APIs

Intermediate

How the web communicates. Master networking protocols, REST architecture, HTTP/2 & HTTP/3 QUIC, OAuth 2.0 PKCE, WebSockets, OpenAPI contracts, and enterprise API resilience.

Requires:JavaScript
0 / 48 lessons
Lessons

48

Complete to finish this stage

Est. time

38h

At a comfortable pace

Difficulty

Intermediate

For complete beginners

Why HTTP & APIs Matter

Hypertext Transfer Protocol (HTTP) and Application Programming Interfaces (APIs) form the universal communication substrate of the World Wide Web. Modern frontend engineering requires far more than issuing a simple fetch() request—it demands an end-to-end understanding of DNS resolution, TCP/TLS handshakes, HTTP/2 multiplexing, HTTP/3 QUIC transport, cryptographic authentication, resilient error recovery, rate limiting, and contract-first schema design.

Curriculum Overview

This master curriculum spans 3 difficulty tiers across 48 comprehensive lessons:

  1. Level 1 — Beginner (Lessons 1–12): Web & Networking Fundamentals, HTTP Request/Response Architecture, HTTP Methods & Idempotency, Status Code Taxonomy (2xx, 3xx, 4xx, 5xx), HTTP Headers & Content Negotiation, URLs & Query Encoding, Web Data Formats (JSON, Multipart FormData), REST Architectural Principles, JavaScript Data Fetching (Fetch API, Axios, AbortController), CORS & Same-Origin Policy, API Developer Tooling (DevTools, Postman, cURL), and 6 Beginner Integration Labs.
  2. Level 2 — Intermediate (Lessons 13–30): RFC 9110 HTTP Semantics, HTTP Protocol Evolution (HTTP/1.1, HTTP/2, HTTP/3 QUIC), Authentication Architectures (Sessions vs Tokens, Token Rotation), Hardened HTTP Cookies (HttpOnly, Secure, SameSite), JSON Web Tokens (JWT / RFC 7519), OAuth 2.0 with PKCE, OpenID Connect (OIDC), REST API Design & RFC 7807 Error Standards, Advanced Pagination (Offset vs Cursor Keyset), Filtering, Sorting & Sparse Fieldsets, Correlation IDs, Reliability Engineering (Exponential Backoff, Jitter, Circuit Breakers), HTTP Caching & ETag Validation, Full-Duplex WebSockets, Server-Sent Events (SSE), GraphQL & SDL Schemas, OpenAPI 3.1 & Swagger Documentation, and 6 Intermediate Labs.
  3. Level 3 — Advanced (Lessons 31–48): Deep HTTP Binary Framing & Flow Control, Transport Layer Engineering (TCP BBR/CUBIC, TLS 1.3 0-RTT, ALPN), Browser Networking & Critical Resource Prioritization, Advanced API & Web Security (CSRF, CSP, HMAC Request Signing, Replay Defense), Passwordless WebAuthn & Passkeys, Rate Limiting Algorithms (Token Bucket, Sliding Window), High-Performance Edge Computing & Brotli Compression, Distributed Microservice APIs & BFF Patterns, API Gateway Architecture, Multi-Protocol Selection (gRPC vs GraphQL vs REST), Webhook Delivery & Idempotency Keys, Zero-Downtime API Versioning & Sunset Standards, Contract-First OpenAPI & Code Generation, Automated API Testing (MSW, Pact, Grafana k6), OpenTelemetry Distributed Tracing & SLOs, Enterprise API Governance (Spectral, Backstage), and 3 Senior Architect Capstones.
Start learning
Stage progress0%

HTTP & APIs lessons

48 lessons · follow them in order for best results.

Web & Networking FundamentalsMaster core internet networking: client vs server architecture, DNS resolution, IP addressing, TCP vs UDP transport protocols, HTTP vs HTTPS, and URL anatomy.Beginner 35 min Level 1 — BeginnerHTTP Fundamentals: Request & Response ModelMaster fundamental HTTP architecture: the stateless request/response model, message framing, request line, status line, HTTP headers, request body, and response body.Beginner 35 min Level 1 — BeginnerHTTP Methods: GET, POST, PUT, PATCH & DELETEMaster HTTP request methods: GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS, Safe vs Unsafe methods, and Idempotency guarantees.Beginner 35 min Level 1 — BeginnerHTTP Status Codes: 2xx, 3xx, 4xx & 5xxMaster HTTP status codes: Success (200, 201, 204), Redirection (301, 302, 304), Client Errors (400, 401, 403, 404, 409, 422, 429), and Server Errors (500, 502, 503, 504).Beginner 40 min Level 1 — BeginnerHTTP Headers: Negotiation, Auth & CachingMaster HTTP headers: Content-Type, Accept, Authorization, Cache-Control, Cookie/Set-Cookie, Origin, Referer, User-Agent, and CORS control headers.Beginner 35 min Level 1 — BeginnerURLs, Query Strings & Percent EncodingMaster Uniform Resource Locators (URLs): protocol, domain, port, path, path parameters vs query parameters, fragment identifiers, and percent-encoding (encodeURIComponent).Beginner 35 min Level 1 — BeginnerData Formats: JSON, Multipart & Content NegotiationMaster web data representation formats: JSON serialization, XML, URL-encoded forms, Multipart form data for binary file uploads, and Content Negotiation.Beginner 35 min Level 1 — BeginnerREST APIs & Resource-Oriented ArchitectureMaster REST architecture: what an API is, Roy FieldingBeginner 40 min Level 1 — BeginnerJavaScript Data Fetching: Fetch API & AxiosMaster data fetching in JavaScript: Fetch API, request configuration, headers, JSON deserialization, HTTP error handling, async/await, Axios, and AbortController cancellation.Beginner 45 min Level 1 — BeginnerCORS & Same-Origin Policy in DepthMaster web security boundaries: Same-Origin Policy (scheme, host, port), Cross-Origin Resource Sharing (CORS), simple requests, preflight OPTIONS checks, and resolving CORS errors.Beginner 40 min Level 1 — BeginnerAPI Tools: DevTools, Postman, Insomnia & cURLMaster essential API testing and inspection tools: Browser DevTools Network tab, Postman, Insomnia, cURL CLI commands, and HTTPie for API debugging.Beginner 35 min Level 1 — BeginnerBeginner Projects & API Integration LabsConsolidate Level 1 HTTP & API skills with 6 practical labs: Live Weather Client, Movie Database Browser, GitHub User API Client, News Reader, and a full CRUD Product Catalog.Beginner 50 min Level 1 — BeginnerHTTP Semantics: Idempotency, Safety & RepresentationMaster advanced HTTP semantics: RFC 9110 standard, safe vs unsafe methods, idempotency guarantees, conditional requests (If-Match, If-Unmodified-Since), and resource representations.Intermediate 45 min Level 2 — IntermediateHTTP Evolution: HTTP/1.1, HTTP/2 & HTTP/3 (QUIC)Master the evolution of HTTP: HTTP/1.1 keep-alive and head-of-line blocking, HTTP/2 binary framing and multiplexing, HPACK compression, and HTTP/3 with UDP-based QUIC.Intermediate 50 min Level 2 — IntermediateAPI Authentication: Sessions, Tokens & RotationMaster API authentication architectures: Session-based auth vs Token-based auth, API keys, HTTP Basic auth, Bearer tokens, Access vs Refresh tokens, and Token Rotation strategies.Intermediate 45 min Level 2 — IntermediateHTTP Cookies: Security, SameSite & AttributesMaster HTTP cookies: Session vs Persistent cookies, Set-Cookie attributes (Secure, HttpOnly, SameSite: Strict/Lax/None), cookie scoping (domain, path), and preventing CSRF attacks.Intermediate 45 min Level 2 — IntermediateJSON Web Tokens (JWT) & Cryptographic ClaimsMaster JSON Web Tokens (JWT / RFC 7519): Header, Payload, Signature, standard claims (iss, sub, exp, aud), asymmetric signing (RS256 vs HS256), and security vulnerabilities.Intermediate 45 min Level 2 — IntermediateOAuth 2.0 & The PKCE Authorization FlowMaster OAuth 2.0 (RFC 6749): Roles (Client, Auth Server, Resource Server), Scopes, Authorization Code Flow, and Proof Key for Code Exchange (PKCE) for Single-Page Applications.Intermediate 50 min Level 2 — IntermediateOpenID Connect (OIDC) & Identity FederationMaster OpenID Connect (OIDC): OIDC vs OAuth 2.0, ID Tokens vs Access Tokens, UserInfo endpoint, Discovery document (.well-known/openid-configuration), and Identity Federation.Intermediate 45 min Level 2 — IntermediateREST API Design: Resources, Versioning & DeprecationMaster enterprise REST API design: resource naming, URI conventions, HTTP status code strategy, RFC 7807 problem details, API versioning strategies, and deprecation headers.Intermediate 45 min Level 2 — IntermediateAPI Pagination: Offset, Cursor & Keyset StrategiesMaster API pagination architectures: Offset-based pagination (limit/offset), Cursor-based pagination (keyset), infinite scroll synchronization, and handling massive datasets.Intermediate 45 min Level 2 — IntermediateAPI Filtering, Sorting & Sparse FieldsetsMaster advanced API querying: filtering operators (eq, gte, in), multi-column sorting, full-text search parameters, and sparse fieldsets (?fields=id,name).Intermediate 45 min Level 2 — IntermediateAPI Error Handling & Correlation IDsMaster resilient API error handling: RFC 7807 Problem Details, domain error codes, retryable vs non-retryable errors, Correlation IDs (X-Correlation-ID), and global error handlers.Intermediate 45 min Level 2 — IntermediateAPI Reliability: Retries, Backoff & Circuit BreakersMaster API reliability engineering: timeouts, automated retries, exponential backoff with full jitter, Circuit Breaker pattern, and graceful degradation.Intermediate 50 min Level 2 — IntermediateHTTP Caching: Cache-Control, ETags & 304 ValidationMaster HTTP caching architecture: Cache-Control directives (max-age, no-cache, no-store, stale-while-revalidate), ETags, Last-Modified validation, and 304 Not Modified.Intermediate 45 min Level 2 — IntermediateWebSockets: Full-Duplex Real-Time CommunicationMaster WebSockets (RFC 6455): HTTP 101 Switching Protocols upgrade handshake, persistent full-duplex TCP connections, ping/pong heartbeats, reconnection logic, and authentication.Intermediate 50 min Level 2 — IntermediateServer-Sent Events (SSE) & Stream ProcessingMaster Server-Sent Events (SSE): text/event-stream format, EventSource API, unidirectional real-time data streaming, automatic reconnection, and SSE vs WebSockets comparison.Intermediate 45 min Level 2 — IntermediateGraphQL: Declarative API Query LanguageMaster GraphQL: REST vs GraphQL, Schema Definition Language (SDL), Types, Queries, Mutations, Variables, Fragments, Resolvers, and Apollo Client integration.Intermediate 50 min Level 2 — IntermediateAPI Documentation: OpenAPI 3.1 & SwaggerMaster API documentation: OpenAPI Specification 3.1, Swagger UI, JSON Schema definitions, request/response examples, authentication schemes, and automated client generation.Intermediate 45 min Level 2 — IntermediateIntermediate Projects & Real-Time LabsConsolidate Level 2 HTTP & API skills with 6 intermediate projects: OAuth2 PKCE Auth Flow, Real-Time Chat with WebSockets, GraphQL Dashboard, Paginated Feed, and Resilient API Client.Intermediate 60 min Level 2 — IntermediateHTTP Internals: Binary Framing, Streams & Flow ControlMaster deep HTTP internals: message framing, persistent connections, HTTP/2 binary framing layer (HEADERS, DATA, SETTINGS frames), stream states, flow control windows, HPACK vs QPACK.Advanced 55 min Level 3 — AdvancedTransport & Cryptography: TCP, TLS 1.3 & QUICMaster deep transport networking: DNS recursive resolution, TCP 3-way handshake and congestion control (BBR, CUBIC), TLS 1.3 0-RTT handshakes, ALPN, PKI certificates, and QUIC connection migration.Advanced 55 min Level 3 — AdvancedBrowser Networking & Critical Resource SchedulingMaster browser networking internals: connection pooling, resource prioritization (Highest to Low), preload/prefetch/preconnect hints, network waterfall optimization, and streaming fetch responses.Advanced 50 min Level 3 — AdvancedAPI & Web Security: CSRF, CSP, Replay & SignaturesMaster enterprise API security: Cross-Site Request Forgery (CSRF), Content Security Policy (CSP), Cross-Site Scripting (XSS), Clickjacking, HMAC Request Signing, and Replay Attack defense.Advanced 55 min Level 3 — AdvancedAdvanced Authentication: Passkeys, WebAuthn & MFAMaster next-generation authentication: FIDO2 / WebAuthn, Passkeys, biometric public-key cryptography, Multi-Factor Authentication (TOTP / RFC 6238), and Enterprise Single Sign-On (SSO / SAML).Advanced 50 min Level 3 — AdvancedRate Limiting: Token Bucket, Sliding Window & 429Master API rate-limiting algorithms: Fixed Window, Sliding Window Log, Token Bucket, Leaky Bucket, Distributed Rate Limiting with Redis, HTTP 429 Too Many Requests, and Retry-After.Advanced 50 min Level 3 — AdvancedAPI Performance: Compression, Edge & Payload OptimizationMaster API performance engineering: Brotli vs Gzip compression, request batching, Edge caching, CDN stale-while-revalidate, and database payload serialization optimization.Advanced 50 min Level 3 — AdvancedDistributed APIs, Microservices & The BFF PatternMaster distributed API architectures: Microservices vs Monoliths, Reverse Proxies, Load Balancers, Service Discovery, Backend-for-Frontend (BFF) pattern, and API Aggregation.Advanced 55 min Level 3 — AdvancedAPI Gateway Architecture: Routing, Auth & Rate LimitingMaster API Gateway architecture: central routing, authentication offloading, rate limiting, request/response transformation, SSL termination, load balancing, and health checks.Advanced 50 min Level 3 — AdvancedAdvanced API Patterns: REST, GraphQL, gRPC & WebhooksMaster advanced API paradigm selection: REST vs GraphQL vs gRPC vs WebSockets vs Server-Sent Events vs Webhooks, Long Polling, Bidirectional Streaming, and Event-Driven Architecture (EDA).Advanced 55 min Level 3 — AdvancedWebhooks: Delivery, Signatures & IdempotencyMaster enterprise webhooks: event delivery pipelines, HMAC SHA-256 signature verification, replay attack prevention, exponential backoff retries, and consumer idempotency.Advanced 50 min Level 3 — AdvancedAPI Reliability: Idempotency Keys & Fault ToleranceMaster advanced API reliability: Idempotency-Key headers, request deduplication, Bulkhead isolation, distributed locks, graceful degradation, and disaster recovery.Advanced 55 min Level 3 — AdvancedAPI Versioning & Zero-Downtime Migration StrategiesMaster enterprise API evolution: URI versioning (/v1/), Header versioning, Media-Type negotiation, breaking vs non-breaking changes, Sunset headers, and zero-downtime migration.Advanced 50 min Level 3 — AdvancedAPI Contracts: OpenAPI, JSON Schema & Code GenMaster Contract-First API development: OpenAPI 3.1, JSON Schema, Protocol Buffers, runtime validation with Zod / TypeBox, and automated end-to-end type-safe client generation.Advanced 50 min Level 3 — AdvancedAPI Testing: MSW, Contract Testing & Load Testing (k6)Master comprehensive API testing: Mock Service Worker (MSW) network mocking, Consumer-Driven Contract Testing with Pact, and performance/load testing with Grafana k6.Advanced 55 min Level 3 — AdvancedAPI Observability: OpenTelemetry, Metrics & SLOsMaster enterprise API observability: OpenTelemetry distributed tracing, Trace IDs & Span IDs, P95/P99 latency metrics, Error Budgets, and Service Level Objectives (SLIs / SLOs).Advanced 55 min Level 3 — AdvancedEnterprise API Governance & Lifecycle ArchitectureMaster enterprise API strategy: API governance councils, enterprise style guides, API catalogs (Backstage), security compliance baselines, and full API lifecycle management.Advanced 55 min Level 3 — AdvancedAdvanced Projects & Senior API Architect BlueprintMaster senior-level API engineering with 3 enterprise capstones: Multi-Tier Production REST Platform, Real-Time WebSocket Infrastructure, and the Complete Senior Learning Path.Advanced 75 min Level 3 — Advanced