Plenty of APIs use JSON over HTTP and call themselves RESTful without following the actual constraints that make REST useful — a stateless design, resource names that are nouns instead of verbs, a response structure a client can predict. This is the reference Taliferro actually uses: the headers worth knowing, the questions worth asking before you ship, and the specific rules that separate a REST API from an API that just resembles one.
Co-Founder Taliferro
| Content-Length | Length of the message (without headers) |
| Content-Type | Media type of the entity-body sent to the recipient |
| Connection | Allows sender to specify options for a particular connection |
| Date | Current date and time according to the responder |
| ETag | Current value of the entity. Reflects changes only to object, not the metadata |
| Host | Specifies the Internet host and port number of response |
| Server | Information about the software used by the origin server |
| Accept | Type of content adequate for the response |
| Authorization | Information required for request authentication |
| Cache-Control | Directives that MUST be obeyed by all caching mechanisms |
| Content-Length | Length of the message (without headers) |
| Content-Type | Media type of the entity-body sent to the recipient |
| Date | Current date and time according to the requester |
| If-Match | Use with a method to make request conditional |
| If-None-Match | Use with a method to make request conditional |
| Host | Specifies the Internet host and port number of the resource requested |
| Server | Information about the software used by the origin server to handle the request |
Caching lets an application reference a resource or composite resource later instead of re-fetching it, which reduces network traffic and latency and speeds up the user's response. If a resource is cacheable, give it an expiration.
This is the part most "REST APIs" quietly get wrong. Grouped by what they're actually checking, not as one undifferentiated list.
/plural-noun/ID/plural-noun/ID
None of these rules are exotic — most of them are things every REST tutorial mentions once, in passing, and most real APIs still violate at least a few of them by the time they ship. The fastest way to check yours: pick one endpoint and run it through the four rule groups above, in order. If it survives all four, it's actually REST — not just an API that happens to speak JSON.
Tyrone ShowersStart with API design and integration services, or see the API security certification.
Want this fixed on your site?
Tell us your URL and what feels slow. We’ll point to the first thing to fix.
Explore Taliferro's free tools: Ask TODD · Find · Email Signature Builder · SayIt · Lead Vault · Meet Maya — or become an affiliate.
More from the blog