Search Topics
Search across all FastAPI topics
What is an API?
FundamentalsYour frontend is talking to your backend. But how? And what happens when the conversation breaks down?
You build a frontend, deploy it, and try to fetch data from your backend. The browser console shows a CORS error. Your frontend can see the backend, but the browser blocks every request.
Access to fetch at 'http://localhost:8000/api' from origin 'http://localhost:3000' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present.
Question
Why would the browser block a request that clearly works when you test it with curl or Postman? The answer is baked into how the web works — and understanding it starts with understanding what an API actually is.
The Big Picture: How APIs Work
Every API interaction follows the same pattern. Your client sends a request, the server processes it, and sends back a response. That's it. Everything else is details.
Client
Your browser or app
HTTP Request
GET, POST, etc.
Server
Your FastAPI app
HTTP Response
Data + status code
Client
Renders the data
So What Does "API" Actually Mean?
API stands for Application Programming Interface. Think of it as a contract: "Send me data in this shape, and I'll send you data back in that shape."
You never touch the server's database directly. You never see its internal code. You just talk to the API, and it handles everything behind the scenes.
Real-world
It's like ordering at a restaurant. You tell the waiter what you want (the API), and the kitchen (the server) makes it. You never walk into the kitchen yourself — the waiter handles the back-and-forth.
APIs 101
What you just learned
An API is a contract between software systems — it defines how they talk to each other
Clients send requests, servers send responses — that's the whole cycle
You never access the server's internals directly — the API is the go-between
HTTP: The Language Your API Speaks
HTTP is how clients and servers communicate. Every time you hit an API, you're sending an HTTP request. Every response you get back? Also HTTP. A request has a method (GET, POST, etc.), a URL, headers, and optionally a body. A response has a status code, headers, and the data.
# Here's a full HTTP conversation
# Your client sends this:
GET /api/items/42 HTTP/1.1
Host: example.com
Accept: application/json
# The server responds with this:
HTTP/1.1 200 OK
Content-Type: application/json
{"id": 42, "name": "Widget", "price": 9.99}JSON: How Your Data Travels
JSON (JavaScript Object Notation) is the standard data format for APIs. If you know Python dictionaries, you basically already know JSON. There are just a couple of quirks.
# Python dictionary — looks familiar, right?
item = {
"name": "Widget",
"price": 9.99,
"tags": ["electronics", "sale"],
"in_stock": True, # Python uses True (capital T)
}
# Same data as JSON (spot the difference!)
# {"name": "Widget", "price": 9.99, "tags": ["electronics", "sale"], "in_stock": true}
# JSON uses true (lowercase t) — that's basically the only gotchaHTTP & JSON
What you just learned
HTTP is the protocol — it carries requests and responses between client and server
Methods (GET, POST, etc.) tell the server what you want to do
JSON is how data travels — it's almost identical to Python dicts
Status Codes: What the Server Is Telling You
Ever seen a 404? That's a status code. Every HTTP response includes one, and it tells you what happened. Here are the ones you'll run into constantly when building APIs.
Insight
Think of status codes as the server's one-word answer before the details. 200 = "Sure, here you go." 404 = "Never heard of it." 500 = "Something broke and it's not your fault."
200
OK
Request succeeded
201
Created
Resource was created
204
No Content
Success, no body returned
400
Bad Request
Malformed request syntax
401
Unauthorized
Missing or invalid auth
404
Not Found
Resource does not exist
422
Validation Error
Data failed validation
500
Internal Server Error
Something broke on the server
Status codes
What you just learned
2xx means success — the server did what you asked
4xx means you messed up — bad request, missing auth, wrong URL
5xx means the server messed up — something crashed on their end
422 is FastAPI's favorite — it means your data didn't pass validation
Try It: Build a Request
Pick a scenario, hit Send, and watch the full HTTP conversation play out — from request to response.
Think about it...
If you send a POST request with no body to an endpoint that expects JSON, what status code do you get back?
Hint: Think about what FastAPI does with Pydantic models...
Key Points
APIs Are Contracts
They define how software systems communicate without exposing internals
HTTP Is the Protocol
Requests and responses flow over HTTP with methods, URLs, headers, and bodies
JSON Is the Format
Structured data travels as JSON — nearly identical to Python dicts
Status Codes Communicate Results
2xx for success, 4xx for client errors, 5xx for server errors