What an endpoint actually is
A URL, a verb, and a promise about what comes back.
An endpoint is a specific address on a server that does one thing. It is defined by two pieces together: the path and the method. The same path with a different verb is a different endpoint entirely, doing something completely different.
- GET /courses: give me the list. Changes nothing.
- POST /courses: create a new one. Changes something.
- GET /courses/42: give me this specific one.
- DELETE /courses/42: remove it. Changes something, irreversibly.
The body of a response is almost always JSON, a text format of keys and values that every language can read. It is a shape you and the caller agree on. Nothing enforces that agreement at runtime, which is why typed clients and schema validation exist, and why this app validates every server function input.
Does calling this twice do something different than calling it once?
If yes, it is unsafe, and you need to think about retries, double-clicks, and flaky networks. That is a whole lesson in the Infrastructure track.
What to remember
- An endpoint is a path plus a method, and both matter.
- GET must not change anything, because things will repeat it without asking.
- JSON is a shared shape, not an enforced one.
Terms in this lesson
Field notes
Loaded from a deliberately slow source. The lesson above was already readable while this was still travelling. That is streaming, and it is the same trick a chat interface uses.
The URL that read everyone’s invoices
An invoice page checked that you were logged in and then loaded whatever id was in the address. Changing the number showed somebody else’s invoice. It was found by a customer who mistyped, not by a review.
Classic IDOR, still extremely common
The key in the client bundle
An API key was placed behind the public environment prefix so it would be readable from the frontend. It worked. It was also visible to every visitor, and was being used by strangers within a week.
Scraped from a public bundle
resolved in 901ms · region iad1
Hide field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.