From 7d44e71db7a664d596d6810f358cc8d8d5760547 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Tue, 21 Jul 2026 18:47:41 +0200 Subject: [PATCH] chore: sync content to repo (#10167) Co-authored-by: nilbuild <4921183+nilbuild@users.noreply.github.com> --- .../content/api-gateways@MJeUD4fOHaJu1oxk4uQ-x.md | 1 + .../api-integration-patterns@R3aRhqCslwhegMfHtxg5z.md | 3 +-- .../api-keys--management@tzUJwXu_scwQHnPPT0oY-.md | 3 ++- .../content/api-security@qIJ6dUppjAjOTA8eQbp0n.md | 3 +-- .../content/bff-pattern@v8iYctF_k40ES0_hHXS9N.md | 8 ++++++++ .../content/crud-operations@zXxEiM5HeOn7W-Vue0tQf.md | 11 +++++++++++ ...filtering-sorting--search@dL3YellfAszBeJnm8KEYE.md | 8 ++++++++ .../content/grpc-apis@1DrqtOwxCuFtWQXQ6ZALp.md | 4 +--- .../api-design/content/http@2HdKzAIQi15pr3YHHrbPp.md | 1 - .../key-generation--rotation@0fSfFtskcJ0HNUZPf998l.md | 8 ++++++++ .../content/load-balancing@p5wsniYnOS7cbHd92RxGk.md | 3 +-- .../naming-conventions@0yY_lWzWVOC_WmPoyHw8W.md | 8 ++++++++ .../content/observability@oIZimEuBHCBGsK6b-s57f.md | 8 ++++++++ .../api-design/content/oidc@jWekRGRa1131w92oS1HeW.md | 7 +++++++ .../content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md | 1 - .../resource-modeling@8IDks2DNFZ5nER7wK2Bu4.md | 9 +++++++++ .../scopes--permissions@qjawwRcMl2-IDwk8ExpPL.md | 7 +++++++ .../streaming-responses@zeYJPEduAmLQHqq4kNBdx.md | 8 ++++++++ 18 files changed, 89 insertions(+), 12 deletions(-) create mode 100644 src/data/roadmaps/api-design/content/bff-pattern@v8iYctF_k40ES0_hHXS9N.md create mode 100644 src/data/roadmaps/api-design/content/crud-operations@zXxEiM5HeOn7W-Vue0tQf.md create mode 100644 src/data/roadmaps/api-design/content/filtering-sorting--search@dL3YellfAszBeJnm8KEYE.md create mode 100644 src/data/roadmaps/api-design/content/key-generation--rotation@0fSfFtskcJ0HNUZPf998l.md create mode 100644 src/data/roadmaps/api-design/content/naming-conventions@0yY_lWzWVOC_WmPoyHw8W.md create mode 100644 src/data/roadmaps/api-design/content/observability@oIZimEuBHCBGsK6b-s57f.md create mode 100644 src/data/roadmaps/api-design/content/oidc@jWekRGRa1131w92oS1HeW.md create mode 100644 src/data/roadmaps/api-design/content/resource-modeling@8IDks2DNFZ5nER7wK2Bu4.md create mode 100644 src/data/roadmaps/api-design/content/scopes--permissions@qjawwRcMl2-IDwk8ExpPL.md create mode 100644 src/data/roadmaps/api-design/content/streaming-responses@zeYJPEduAmLQHqq4kNBdx.md diff --git a/src/data/roadmaps/api-design/content/api-gateways@MJeUD4fOHaJu1oxk4uQ-x.md b/src/data/roadmaps/api-design/content/api-gateways@MJeUD4fOHaJu1oxk4uQ-x.md index 8a6bc3122..42f83c185 100644 --- a/src/data/roadmaps/api-design/content/api-gateways@MJeUD4fOHaJu1oxk4uQ-x.md +++ b/src/data/roadmaps/api-design/content/api-gateways@MJeUD4fOHaJu1oxk4uQ-x.md @@ -5,4 +5,5 @@ API Gateways act as the main point of entry in a microservices architecture, oft Visit the following resources to learn more: - [@article@What does an API Gateway do?](https://www.redhat.com/en/topics/api/what-does-an-api-gateway-do) +- [@article@API gateway vs. Load balancer: Do you need one or both?](https://roadmap.sh/network-engineer/api-gateway-vs-load-balancer) - [@article@What are API Gateways?](https://www.ibm.com/blog/api-gateway/) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/api-integration-patterns@R3aRhqCslwhegMfHtxg5z.md b/src/data/roadmaps/api-design/content/api-integration-patterns@R3aRhqCslwhegMfHtxg5z.md index 7035d737b..b3d6a2fa6 100644 --- a/src/data/roadmaps/api-design/content/api-integration-patterns@R3aRhqCslwhegMfHtxg5z.md +++ b/src/data/roadmaps/api-design/content/api-integration-patterns@R3aRhqCslwhegMfHtxg5z.md @@ -4,5 +4,4 @@ API Integration Patterns, in the context of API Design, refers to the common par Visit the following resources to learn more: -- [@article@API Integration Patterns - Dzone](https://dzone.com/refcardz/api-integration-patterns) -- [@article@API Integration Patterns - Devoteam](https://uk.devoteam.com/expert-view/api-integration-patterns/) \ No newline at end of file +- [@article@API Integration Patterns - Dzone](https://dzone.com/refcardz/api-integration-patterns) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/api-keys--management@tzUJwXu_scwQHnPPT0oY-.md b/src/data/roadmaps/api-design/content/api-keys--management@tzUJwXu_scwQHnPPT0oY-.md index 46ca84dfa..41676ce3b 100644 --- a/src/data/roadmaps/api-design/content/api-keys--management@tzUJwXu_scwQHnPPT0oY-.md +++ b/src/data/roadmaps/api-design/content/api-keys--management@tzUJwXu_scwQHnPPT0oY-.md @@ -1,7 +1,8 @@ # API Keys & Management + API keys and management are an integral part of API design. An API key is a unique identifier used to authenticate a user, developer, or calling program to an API. This ensures security and control over API endpoints, as only those with a valid API key can make requests. API Management, on the other hand, refers to the practices and tools that enable an organization to govern and monitor its API usage. It involves all the aspects of managing APIs including design, deployment, documentation, security, versioning, and analytics. Both elements play crucial roles in securing and organizing API access for efficient and controlled data sharing and communication. Visit the following resources to learn more: - [@article@What is API Key Management?](https://www.akeyless.io/secrets-management-glossary/api-key-management/) -- [@article@API Key Management - Definition and Best Practices](https://infisical.com/blog/api-key-management) +- [@article@API Key Management - Definition and Best Practices](https://infisical.com/blog/api-key-management) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/api-security@qIJ6dUppjAjOTA8eQbp0n.md b/src/data/roadmaps/api-design/content/api-security@qIJ6dUppjAjOTA8eQbp0n.md index 16d34f8dc..e1843ff7f 100644 --- a/src/data/roadmaps/api-design/content/api-security@qIJ6dUppjAjOTA8eQbp0n.md +++ b/src/data/roadmaps/api-design/content/api-security@qIJ6dUppjAjOTA8eQbp0n.md @@ -4,5 +4,4 @@ API Security refers to the practices and products that are used to secure applic Visit the following resources to learn more: -- [@article@OWASP Project API Security](https://owasp.org/API-Security/editions/2023/en/0x00-toc/) -- [@feed@Explore top posts about Security](https://app.daily.dev/tags/security?ref=roadmapsh) \ No newline at end of file +- [@article@OWASP Project API Security](https://owasp.org/API-Security/editions/2023/en/0x00-toc/) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/bff-pattern@v8iYctF_k40ES0_hHXS9N.md b/src/data/roadmaps/api-design/content/bff-pattern@v8iYctF_k40ES0_hHXS9N.md new file mode 100644 index 000000000..21c214ba1 --- /dev/null +++ b/src/data/roadmaps/api-design/content/bff-pattern@v8iYctF_k40ES0_hHXS9N.md @@ -0,0 +1,8 @@ +# BFF Pattern + +The Backend for Frontend (BFF) pattern involves creating a dedicated API layer for each type of client, typically one BFF for web, one for mobile, and possibly one for third-party consumers. Rather than forcing all clients to use a single general-purpose API, each BFF is tailored to the exact data shape and interaction patterns its client needs. This reduces over-fetching, simplifies client logic, and allows each frontend team to evolve their API contract independently without affecting other clients. + +Visit the following resources to learn more: + +- [@article@Backend for Frontend](https://bff-patterns.com/) +- [@video@"Backends for Frontends": what is it?](https://www.youtube.com/watch?v=tmGnpU8xOGE) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/crud-operations@zXxEiM5HeOn7W-Vue0tQf.md b/src/data/roadmaps/api-design/content/crud-operations@zXxEiM5HeOn7W-Vue0tQf.md new file mode 100644 index 000000000..80ba8ac67 --- /dev/null +++ b/src/data/roadmaps/api-design/content/crud-operations@zXxEiM5HeOn7W-Vue0tQf.md @@ -0,0 +1,11 @@ +# Handling CRUD Operations in API Design + +When designing APIs, one needs to account for various types of interactions with data - these typically revolve around the CRUD operations; Create, Read, Update, and Delete. Whether the API is designed for a banking app or a social media platform, the need to create new data, read or retrieve existing data, update or modify that data, and delete unnecessary data is universal. + +Therefore, mastering CRUD operations in API design is a fundamental skill. Effective handling of CRUD operations facilitates seamless interaction between the front-end and back-end systems, and ensures proper data management, thereby improving user experience. + +Visit the following resources to learn more: + +- [@article@Introduction to Building a CRUD API with Node.js and Express](https://www.split.io/blog/introduction-to-building-a-crud-api-with-node-js-and-express/) +- [@article@An expert's guide to CRUD APIs](https://www.forestadmin.com/blog/an-experts-guide-to-crud-apis-designing-a-robust-one/) +- [@article@Rethinking CRUD For REST API Designs - Palentir](https://blog.palantir.com/rethinking-crud-for-rest-api-designs-a2a8287dc2af) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/filtering-sorting--search@dL3YellfAszBeJnm8KEYE.md b/src/data/roadmaps/api-design/content/filtering-sorting--search@dL3YellfAszBeJnm8KEYE.md new file mode 100644 index 000000000..17ac2a7a2 --- /dev/null +++ b/src/data/roadmaps/api-design/content/filtering-sorting--search@dL3YellfAszBeJnm8KEYE.md @@ -0,0 +1,8 @@ +# Filtering, Sorting & Search + +Filtering, sorting, and search are query capabilities that let API consumers retrieve exactly the data they need rather than fetching everything and processing it client-side. Filtering narrows results by field values (?status=active), sorting orders them (?sort=created_at&order=desc), and search allows freetext or fuzzy matching across fields. Designing these using predictable query parameter names and clearly documenting supported combinations is a significant part of API usability. + +Visit the following resources to learn more: + +- [@article@How to Implement Filtering and Sorting in REST APIs](https://oneuptime.com/blog/post/2026-01-26-rest-api-filtering-sorting/view) +- [@article@Implement Search, Sort, Filter and Pagination Rest API With Node JS](https://www.youtube.com/watch?v=0T4GsMYnVN4) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/grpc-apis@1DrqtOwxCuFtWQXQ6ZALp.md b/src/data/roadmaps/api-design/content/grpc-apis@1DrqtOwxCuFtWQXQ6ZALp.md index 03a71535b..ae5fef8bb 100644 --- a/src/data/roadmaps/api-design/content/grpc-apis@1DrqtOwxCuFtWQXQ6ZALp.md +++ b/src/data/roadmaps/api-design/content/grpc-apis@1DrqtOwxCuFtWQXQ6ZALp.md @@ -4,8 +4,6 @@ gRPC is a platform agnostic serialization protocol that is used to communicate b Visit the following resources to learn more: -- [@official@gRPC Website](https://grpc.io/) - [@official@gRPC Introduction](https://grpc.io/docs/what-is-grpc/introduction/) - [@official@gRPC Core Concepts](https://grpc.io/docs/what-is-grpc/core-concepts/) -- [@video@Stephane Maarek - gRPC Introduction](https://youtu.be/XRXTsQwyZSU) -- [@feed@Explore top posts about gRPC](https://app.daily.dev/tags/grpc?ref=roadmapsh) \ No newline at end of file +- [@video@Stephane Maarek - gRPC Introduction](https://youtu.be/XRXTsQwyZSU) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/http@2HdKzAIQi15pr3YHHrbPp.md b/src/data/roadmaps/api-design/content/http@2HdKzAIQi15pr3YHHrbPp.md index 8d9728cca..d949178c6 100644 --- a/src/data/roadmaps/api-design/content/http@2HdKzAIQi15pr3YHHrbPp.md +++ b/src/data/roadmaps/api-design/content/http@2HdKzAIQi15pr3YHHrbPp.md @@ -4,7 +4,6 @@ HTTP, or Hypertext Transfer Protocol, is a fundamental piece of any API design. Visit the following resources to learn more: -- [@article@Everything you need to know about HTTP](https://cs.fyi/guide/http-in-depth) - [@article@What is HTTP?](https://www.cloudflare.com/en-gb/learning/ddos/glossary/hypertext-transfer-protocol-http/) - [@article@An overview of HTTP](https://developer.mozilla.org/en-US/docs/Web/HTTP/Overview) - [@article@HTTP/3 From A To Z: Core Concepts](https://www.smashingmagazine.com/2021/08/http3-core-concepts-part1/) diff --git a/src/data/roadmaps/api-design/content/key-generation--rotation@0fSfFtskcJ0HNUZPf998l.md b/src/data/roadmaps/api-design/content/key-generation--rotation@0fSfFtskcJ0HNUZPf998l.md new file mode 100644 index 000000000..021afd939 --- /dev/null +++ b/src/data/roadmaps/api-design/content/key-generation--rotation@0fSfFtskcJ0HNUZPf998l.md @@ -0,0 +1,8 @@ +# Key Generation & Rotation + +Key generation and rotation covers the practices around creating, distributing, and periodically replacing API keys. Generation involves producing keys that are sufficiently random and long to resist brute force. Rotation is the process of replacing an existing key with a new one, either on a schedule or after a suspected compromise, without causing downtime for the consumer. Good key management also includes hashing keys at rest, scoping them to minimum required permissions, and providing consumers with a safe way to rotate without service interruption. + +Visit the following resources to learn more: + +- [@article@Introduction And Lesson Overview](https://codesignal.com/learn/courses/api-key-authentication-security/lessons/api-key-generation-basics) +- [@video@What Are API Keys, And Why Are They So Important?](https://www.youtube.com/watch?v=sNn23dPRUS8&t=103s) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/load-balancing@p5wsniYnOS7cbHd92RxGk.md b/src/data/roadmaps/api-design/content/load-balancing@p5wsniYnOS7cbHd92RxGk.md index 9ae774d30..2a8ac025f 100644 --- a/src/data/roadmaps/api-design/content/load-balancing@p5wsniYnOS7cbHd92RxGk.md +++ b/src/data/roadmaps/api-design/content/load-balancing@p5wsniYnOS7cbHd92RxGk.md @@ -5,6 +5,5 @@ Load Balancing plays a crucial role in the domain of API Design. It primarily re Visit the following resources to learn more: - [@article@What is Load Balancing?](https://www.cloudflare.com/en-gb/learning/performance/what-is-load-balancing/) -- [@article@Load Balancers in API](https://learn.microsoft.com/en-us/rest/api/load-balancer/) -- [@article@API Gateway vs Load Balancer: Which is Right for Your Application?](https://konghq.com/blog/engineering/api-gateway-vs-load-balancer) +- [@article@API gateway vs. Load balancer: Do you need one or both?](https://roadmap.sh/network-engineer/api-gateway-vs-load-balancer) - [@video@What is a Load Balancer?](https://www.youtube.com/watch?v=sCR3SAVdyCc) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/naming-conventions@0yY_lWzWVOC_WmPoyHw8W.md b/src/data/roadmaps/api-design/content/naming-conventions@0yY_lWzWVOC_WmPoyHw8W.md new file mode 100644 index 000000000..e4a20c509 --- /dev/null +++ b/src/data/roadmaps/api-design/content/naming-conventions@0yY_lWzWVOC_WmPoyHw8W.md @@ -0,0 +1,8 @@ +# Naming Conventions + +Naming conventions are the rules you follow to keep your API's URLs, parameters, and field names consistent and predictable. This includes decisions like using plural nouns for collections (/users not /user), lowercase kebab-case for URLs, camelCase or snake_case for JSON fields, and avoiding verbs in resource paths. Consistent naming reduces friction for developers consuming your API and signals that the API was designed deliberately rather than assembled ad hoc. + +Visit the following resources to learn more: + +- [@article@REST API URI Naming Conventions and Best Practices](https://restfulapi.net/resource-naming/) +- [@video@Good APIs Vs Bad APIs: 7 Tips for API Design](https://www.youtube.com/watch?v=_gQaygjm_hg) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/observability@oIZimEuBHCBGsK6b-s57f.md b/src/data/roadmaps/api-design/content/observability@oIZimEuBHCBGsK6b-s57f.md new file mode 100644 index 000000000..d48744040 --- /dev/null +++ b/src/data/roadmaps/api-design/content/observability@oIZimEuBHCBGsK6b-s57f.md @@ -0,0 +1,8 @@ +# Observability + +Observability is the ability to understand what is happening inside a running API by examining the data it produces, such as logs, metrics, and traces. A highly observable API lets you answer questions like "why did this request fail", "where is the latency coming from", and "is this service degrading" without needing to reproduce the problem locally. + +Visit the following resources to learn more: + +- [@article@Understanding API Observability](https://medium.com/@shubhadeepchat/understanding-api-observability-cd0c61392dec) +- [@video@Observability for APIs | Postman Intergalactic](https://www.youtube.com/watch?v=Wkng1VXQAaU&list=PLM-7VG-sgbtB5XIrXIWWaLPqPpjn7IoVC) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/oidc@jWekRGRa1131w92oS1HeW.md b/src/data/roadmaps/api-design/content/oidc@jWekRGRa1131w92oS1HeW.md new file mode 100644 index 000000000..99c84c6d2 --- /dev/null +++ b/src/data/roadmaps/api-design/content/oidc@jWekRGRa1131w92oS1HeW.md @@ -0,0 +1,7 @@ +OIDC +OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. While OAuth 2.0 handles authorization (what you can do), OIDC handles authentication (who you are). It introduces the concept of an ID token, a signed JWT that contains claims about the authenticated user, such as their name, email, and user ID. OIDC is the standard behind "Sign in with Google / GitHub / Apple" flows and is the correct choice when your API needs to verify a user's identity, not just their permissions. + +Visit the following resources to learn more: + +- [@article@OIDC: Simplifying Secure Authentication With OpenID Connect](https://www.fortinet.com/resources/cyberglossary/oidc) +- [@video@OAuth 2.0 and OpenID Connect (in plain English)](https://www.youtube.com/watch?v=996OiexHze0) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md b/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md index b150e2ca1..78908d4c9 100644 --- a/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md +++ b/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md @@ -7,5 +7,4 @@ Visit the following resources to learn more: - [@article@Rate limit](https://developer.mozilla.org/en-US/docs/Glossary/Rate_limit) - [@article@Throttle](https://developer.mozilla.org/en-US/docs/Glossary/Throttle) - [@article@Debounce](https://developer.mozilla.org/en-US/docs/Glossary/Debounce) -- [@article@What is rate limiting? | Rate limiting and bots](https://www.cloudflare.com/en-gb/learning/bots/what-is-rate-limiting/) - [@video@Rate Limiting techniques visualization](https://smudge.ai/blog/ratelimit-algorithms) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/resource-modeling@8IDks2DNFZ5nER7wK2Bu4.md b/src/data/roadmaps/api-design/content/resource-modeling@8IDks2DNFZ5nER7wK2Bu4.md new file mode 100644 index 000000000..a8a6bd3fc --- /dev/null +++ b/src/data/roadmaps/api-design/content/resource-modeling@8IDks2DNFZ5nER7wK2Bu4.md @@ -0,0 +1,9 @@ +#Resource Modeling + +Resource modeling is the process of deciding what "things" your API exposes and how they map to URLs. A resource is any noun your API manages, like a user, an order, or a product. Modeling it means defining its boundaries, its relationships to other resources, and what data it carries. Good resource modeling done upfront prevents awkward URL structures and inconsistent data shapes that are painful to fix once consumers are depending on your API. + +Visit the following resources to learn more: + +- [@article@Practical Guide to REST API Resource Modeling](https://www.advancedcustomfields.com/blog/rest-api-resource/) +- [@article@Resource modelling: think before you start coding](https://medium.com/abn-amro-developer/resource-modelling-think-before-you-start-coding-a421357e9756) +- [@video@Modeling RESTful API Resources](https://www.youtube.com/watch?v=E7WSBLHEvbI) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/scopes--permissions@qjawwRcMl2-IDwk8ExpPL.md b/src/data/roadmaps/api-design/content/scopes--permissions@qjawwRcMl2-IDwk8ExpPL.md new file mode 100644 index 000000000..8b5b9a326 --- /dev/null +++ b/src/data/roadmaps/api-design/content/scopes--permissions@qjawwRcMl2-IDwk8ExpPL.md @@ -0,0 +1,7 @@ +# Scopes & Permissions + +Scopes are labels attached to an API key or access token that declare what actions it is allowed to perform. Rather than a single all-or-nothing key, scopes let you issue credentials with fine-grained access. For example, a key with orders:read can fetch orders but not create or delete them. This follows the principle of least privilege and limits the blast radius if a key is leaked. Scopes are a core concept in OAuth 2.0 and are equally applicable to plain API key systems. + +Visit the following resources to learn more: + +- [@article@What are REST API Scopes?](https://auth0.com/blog/permissions-privileges-and-scopes/) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/streaming-responses@zeYJPEduAmLQHqq4kNBdx.md b/src/data/roadmaps/api-design/content/streaming-responses@zeYJPEduAmLQHqq4kNBdx.md new file mode 100644 index 000000000..69a2eba53 --- /dev/null +++ b/src/data/roadmaps/api-design/content/streaming-responses@zeYJPEduAmLQHqq4kNBdx.md @@ -0,0 +1,8 @@ +# Streaming Responses + +Streaming responses allow a server to send data to the client incrementally as it becomes available, rather than buffering the entire response and sending it at once. This is useful for large datasets, file downloads, log tailing, or AI-generated text where the first tokens can be delivered to the user before the full response is ready. HTTP chunked transfer encoding and SSE are common mechanisms for streaming, and it meaningfully improves perceived performance for slow or large responses. + +Visit the following resources to learn more: + +- [@article@Streaming Data with REST APIs](https://apisyouwonthate.com/blog/streaming-data-with-rest-apis/) +- [@video@https://www.youtube.com/watch?v=xTTtqwGWemw](https://www.youtube.com/watch?v=xTTtqwGWemw&t=210s) \ No newline at end of file