REST APIs with Express

Build real REST APIs with Express 5: routing, middleware, validation, errors, security and tests, running in every lesson.

31 lessons across 8 units: routing, middleware, REST design, validation, error handling, app structure, security and testing with Express 5, with 38 runnable examples, quizzes and 31 coding problems that build real APIs.

Units
8
Lessons
31
Coding problems
31
Examples
38

Free: units 1 to 2 (8 lessons). Units 3 to 8 with DevArcade Pro.

See pricing

What you'll learn

  • Hello, ExpressWhat Express adds to node:http, routes and methods, parameters and query strings, and every kind of response.
  • MiddlewareThe middleware chain and next(), reading request bodies, routers and mounting, static files and SPAs.
  • Designing REST APIsResources and status codes, a complete CRUD API, pagination, filtering and sorting, ETags and lost updates.
  • ValidationValidating at the boundary, a schema validator, and validation middleware for body, query and params.
  • Error HandlingError-handling middleware, async errors in Express 5 and 4, error classes and Problem Details.
  • Structuring an AppApp factories and injected dependencies, routes, services and repositories, a JSON file store, response caching.
  • Security and Production MiddlewareCORS and preflight, rate limiting, security headers and limits, API keys and bearer tokens.
  • Testing and ShippingTesting apps over HTTP, request logging, health checks and shutdown, then the bookmarks API boss.

Course outline

8 units and 31 lessons. Each lesson has a short read with examples you run, a quiz, and coding problems tested in your browser; most have a step-through visualizer.

  1. Unit 1:Hello, Express

    What Express adds to node:http, routes and methods, parameters and query strings, and every kind of response.

    Free
    1. What Express Adds Express is a thin layer over node:http: routing, middleware and response helpers. An app is just a request handler.
      1 problem
    2. Routes and HTTP Methods app.get, post, put, patch, delete and all; app.route for one path with several methods; first match wins; why Express does not send 405 for you.
      1 problem
    3. Route Parameters and Query Strings req.params from :name segments, Express 5's path syntax ({optional}, *splat), and req.query: strings, arrays and validation.
      1 problem
    4. Sending Responses res.send for strings, Buffers and objects, res.json, status and sendStatus, headers, redirects, downloads, cookies, and the automatic ETag.
      1 problem
  2. Unit 2:Middleware

    The middleware chain and next(), reading request bodies, routers and mounting, static files and SPAs.

    Free
    1. Middleware and next() Functions that run in order for every request: app.use, calling next(), ending early, path-scoped middleware and res.locals.
      1 problem
    2. Reading Request Bodies express.json, urlencoded and text, why req.body is undefined without them, size limits, and the 400 and 413 errors parsers produce.
      1 problem
    3. Routers and Mounting express.Router as a mini app, mounting it under a path, req.baseUrl, mergeParams, router-level middleware and next('router').
      1 problem
    4. Static Files and a SPA Fallback express.static: index files, dotfiles, directory redirects, caching headers, and serving a single-page app with a fallback to index.html.
      1 problem
  3. Unit 3:Designing REST APIs

    Resources and status codes, a complete CRUD API, pagination, filtering and sorting, ETags and lost updates.

    Pro
    1. Resources, URLs and Status Codes Design an API around resources: plural nouns in URLs, methods as verbs, nesting, the status codes clients rely on, and the Location header.
      1 problem
    2. A Complete CRUD API Create, read, update and delete over HTTP: ids, 201 with Location, PUT versus PATCH, 204 on delete, 404s, and ignoring fields clients must not set.
      1 problem
    3. Pagination Never return everything: page and limit parameters with caps, a response envelope with totals, Link headers, and when cursors beat page numbers.
      1 problem
    4. Filtering and Sorting Query parameters for filters, a sort syntax like ?sort=-year,title, allowlists for fields, and 400s for anything you do not support.
      1 problem
    5. ETags and Lost Updates Two clients editing the same resource: the lost update problem, versions as ETags, If-Match with 412 Precondition Failed, and 428 when the header is missing.
      1 problem
  4. Unit 4:Validation

    Validating at the boundary, a schema validator, and validation middleware for body, query and params.

    Pro
    1. Validate at the Boundary Everything from a request is untrusted: check types, presence, lengths and ranges once, at the edge, and answer with errors clients can act on.
      1 problem
    2. Describe Shapes with a Schema Write the rules down once as data: types, required fields, lengths, ranges, enums and patterns, with nested objects and a cleaned value out.
      1 problem
    3. Validation Middleware One reusable middleware per route: validate body, query and params, convert query strings to numbers, store the clean values, and send consistent 400s.
      1 problem
  5. Unit 5:Error Handling

    Error-handling middleware, async errors in Express 5 and 4, error classes and Problem Details.

    Pro
    1. Error-handling Middleware Four parameters make an error handler: how next(err) and thrown errors reach it, where to put it, a JSON 404, and handing off when headers are sent.
      1 problem
    2. Async Errors: Express 5 and 4 Express 5 forwards rejected promises from async handlers to your error handler; Express 4 did not, which is why asyncHandler wrappers exist.
      1 problem
    3. Error Classes and Problem Details An HttpError class with status, expose and details, small helpers to throw it, and RFC 9457 Problem Details as a standard JSON error format.
      1 problem
  6. Unit 6:Structuring an App

    App factories and injected dependencies, routes, services and repositories, a JSON file store, response caching.

    Pro
    1. The App Factory Build the app in createApp(deps) and start it elsewhere: tests get a fresh app with fake dependencies, and nothing listens on import.
      1 problem
    2. Routes, Services and Repositories Keep HTTP in the routes, business rules in services and storage in repositories, so each part can change and be tested on its own.
      1 problem
    3. A Repository on a JSON File Persist to a JSON file behind a repository interface, and serialize writes so concurrent requests cannot overwrite each other.
      1 problem
    4. Caching Responses Cache-Control for clients and CDNs, an in-memory TTL cache for expensive GETs, cache keys, and invalidating on writes.
      1 problem
  7. Unit 7:Security and Production Middleware

    CORS and preflight, rate limiting, security headers and limits, API keys and bearer tokens.

    Pro
    1. CORS and Preflight Requests Why browsers block cross-origin calls, the Access-Control headers that allow them, preflight OPTIONS requests, credentials and an origin allowlist.
      1 problem
    2. Rate Limiting Protect the API from floods and brute force: a fixed-window counter per client, 429 with Retry-After, RateLimit headers, and choosing the key.
      1 problem
    3. Security Headers and Limits The headers helmet sets and why, dropping X-Powered-By, small body limits, and the defaults that make an API harder to abuse.
      1 problem
    4. API Keys and Bearer Tokens Authenticate API clients with the Authorization header: 401 versus 403, WWW-Authenticate, scopes, and comparing secrets in constant time.
      1 problem
  8. Unit 8:Testing and Shipping

    Testing apps over HTTP, request logging, health checks and shutdown, then the bookmarks API boss.

    Pro
    1. Testing an Express App Start the real app on port 0 and call it with fetch, from node:test with assert; what to cover; and how to know your tests catch bugs.
      1 problem
    2. Request Logging One structured log line per request when it finishes: method, path, status, duration and request id, with the level chosen by status.
      1 problem
    3. Health Checks and Shutdown Liveness versus readiness endpoints, checking dependencies with a timeout, and draining traffic before a graceful shutdown.
      1 problem
    4. Boss: A Bookmarks API Everything together: an Express API with auth for writes, validation, conflicts, pagination and filtering, 405s, JSON errors and a file that survives restarts.
      1 problem

Start REST APIs with Express for free

Enroll for free and units 1 and 2 are yours. DevArcade Pro opens every unit of every course, including new ones as they launch, monthly or yearly.

All courses