All capabilities · Programming foundations

Build and consume REST APIs

Design and ship HTTP APIs (FastAPI/Flask/Express), call third-party APIs, handle auth, errors and rate limits.

~20 focused hoursbeginner
Explore 3 tools for this project
Market relevance

Which roles ask for this — and how often

Share of job postings in India, per role, that name this capability.

What employers mean

You should be able to…

  1. Design REST endpoints (routes, status codes, pagination) for a resource like documents or chat sessions
  2. Validate request/response bodies with Pydantic models instead of raw dicts
  3. Call a third-party API (payment gateway, LLM provider) and handle timeouts, retries and rate limits
  4. Add authentication (API key or OAuth2/JWT) to protect endpoints
  5. Auto-generate and read OpenAPI/Swagger docs for an API you built or consumed
  6. Version an API (v1/v2) without breaking existing clients
  7. Write integration tests against a running API using a test client

Needs first: Write production-quality Python for AI work

Learn — free, link-checked

The few resources that matter

Tools for practice

Choose a tool for the job

Start with one tool for each part of your project. You don’t need to learn them all.

Go to the practice brief

3 tools to explore

Pydantic

Build · Test

Define typed schemas and validate the structured data entering your application.

Practice

Hinglish conversation summarizer API with validated payloads and key auth

Build a FastAPI service with three endpoints: submit a Hinglish support thread, fetch its auto-generated English summary and priority, and list threads with pagination. Every payload is modelled and validated with Pydantic, write endpoints sit behind an API key, and the OpenAPI docs carry worked examples. Run it locally with Uvicorn and back it with an httpx integration suite that covers the auth, validation and pagination paths.

Start from

CMU Hinglish DoG dataset on Hugging Face — code-mixed Hindi-English conversation threads with English references, used as the incoming tickets

Milestones
  1. Model request/response schemas in Pydantic and stub the three endpoints · ~3h
  2. Wire the summarise-and-prioritise call and persist threads with limit/offset paging · ~4.5h
  3. Add API-key auth on writes and turn validation errors into useful 422 bodies · ~3h
  4. Write the httpx integration suite over auth, paging and validation · ~3h
  5. Fill the OpenAPI examples and write the README quickstart · ~1.5h
Done when
  • GET /docs renders working OpenAPI documentation with example requests
  • POST /tickets rejects malformed payloads with a 422 and a clear error message
  • GET /tickets supports limit/offset pagination and returns correct total counts
  • Protected endpoints return 401 without a valid API key, verified by an automated test
Prove it

Evidence a recruiter can check

  • The rendered `/docs` page with real example request and response bodies on all three endpoints
  • An httpx test file asserting 422 on a malformed payload, 401 without a key, and correct total counts across two pages
  • A curl transcript in the README taking one Hinglish thread from POST through to its summarised GET
  • A note on the one endpoint you redesigned mid-build — what the first shape got wrong, and the commit that changed it
Signal it

Built a FastAPI service that summarises code-mixed Hinglish support threads into English with a priority score — Pydantic-validated payloads, API-key auth on writes, and an httpx suite covering auth, paging and validation.

Interview

Questions you'll get asked

  1. How would you design an endpoint to upload and process a large PDF asynchronously?
  2. What's the difference between PUT and PATCH, and when do you use each?
  3. How do you validate that a request body matches an expected schema in FastAPI?
  4. How would you handle a third-party API that rate-limits you at 60 requests/minute?
  5. Walk me through how you'd add pagination to a `/documents` list endpoint with 100k rows.
  6. How do you version an API without breaking mobile clients still on v1?
  7. What status code would you return if an LLM call times out, and why?