REST API Design Principles: Best Practices with Examples
What is REST
REST (Representational state Transfer) is an architectural style for designing networked applications. Uses standard HTTP Methods.
Why Rest Matters?
It provides a simple and standard way for applications to communicate with each other over the internet.
- Scalability : REST APIs are usually stateless, which means each request contains all the information required by the server to process it. The server does not rely on information from previous requests.
- Interoperability: Works across different platform.
- Efficiency: Uses Caching, Statelessness for performance.
- Easy Integration: REST makes it easier to connect different systems.

Real time communication protocols
Real-time communication helps overcome these limitations by enabling faster and continuous data exchange.
- Polling
- WebSocket’s
- Server-sent Events(SSE)
- Long Polling
WebSocket’s: Persistent Full-Duplex Communication
- Definition: WebSocket’s provides a persistent, Full duplex Connection between the client and server over a single TCP connection.
- How they work:
- WebSocket handshake using HTTP upgrade request.
- Step-1: client request an upgrade to WebSocket’s.
- WebSocket handshake using HTTP upgrade request.
- Step-2: Server accepts and keeps the connection open.
- Either client or server can send messages at any time.
- Step-3: Data is exchanged in real-time using frame.
- Step-4: Either party can close the connection when done.

Advantage of use cases of WebSocket’s
- Advantages:
- Persistent connection = lower latency
- Reduces overhead compared to HTTP polling.
- Efficient for real-time applications.
- Use Cases:
- Live chat Applications.
- Stock Market price updates.
- Multiplayer online Games.
- Collaborative Tools.(Google Docs, Figma)
3. Long Polling: Simulating Real-Time With HTTP.
- Long polling is a technique in which the client sends a request to the server and waits until new data is available. Once the server has new information, it sends a response back to the client.
- How it differs from regular polling.
- Instead of sending an immediate response, the server keeps the request open until new data becomes available.
- How Long Polling Works
- Client makes an HTTP requests.
- Server holds the request until data is available.
- Server responds with new data.
- Client immediately sends another request.

2. Session Management
What is web Session
A wed session is a mechanism used to maintain the state of a users interaction Across multiple Http requests. Since Http is a state less protocol every request sent from a browser to a server is independent. the server does not inherently know wheteher two requests came from the same user, a session solve the problem.
Session lifecycle
1. User Authentication: user Submit request.
{
"userName" : "rakesh",
"password" : "pass,123@123"
}
Server Validates Credentials.
2. Session Creation : Server creates
{
"sessionId":"ABC123",
"userId" : "1001",
"role" : "Admin"
}
Sore in session repository.
3. SessionId sent to browser
Response header:
setCookiejSESSIONID=xyz123
Browser store the cookie.
Why web session matter
- web applications often need to track user state (login status, shopping cart, user prefrences).
- Http is state less memory each request independent.
- goal to understand how to maintain state in web applications.
Understanding Statelessness in Http
- Http does not retain memory of previous requests.
- Each request must contain all necessary information.
- This is a challenges for user sessions.

Techniques for maintaining State
- Session-Based Authentication(server-side session storage + cookies for session Ids).
- Server maintains session state.
- Client holds only a sessionId.
- Token Based Authentication(JWT, OAuth, token)
- Session state is Embedded within the token itself.
- Server does not need to track user session.

1. Session Based Authentication
- Server-side session storage
- Cookies for session IDS.
- Once user logs in server creates a session & assigns a sessionID.
- Session data is stored server-side , while sessionID to sent to the client.
- Client store the sessionId in the cookie.
2. Token-based Authentication
- Encodes session data in a self contained token.
- No need for server-side session storage.
- Used in modern state less Authentication.
