From designing RESTful endpoints to securing them with JWT, running on Kestrel behind middleware, and reverse-engineering a database with EF Core — everything in one page.
Every topic you need — from design principles to the embedded HTTP server and the middleware pipeline.
Client sends an HTTP request, the API talks to a service, the service talks to the database — and the response travels back.
Basic architecture: Controller → Service / Business Logic → Repository / EF Core → SQL Server.
Follow REST principles: resources, statelessness, proper HTTP verbs, and meaningful URLs.
| HTTP Method | Purpose | Example |
|---|---|---|
| GET | Read | Get products |
| POST | Create | Add product |
| PUT | Full update / replace | Replace product |
| PATCH | Partial update | Change only price |
| DELETE | Delete | Delete product |
GET /api/products GET /api/products/10 POST /api/products PUT /api/products/10 PATCH /api/products/10 DELETE /api/products/10
Good REST URL: use nouns for resources (/api/products), never verbs (/api/getProducts). Let the HTTP method express the action.
Authentication asks who are you? Authorization asks what are you allowed to do?
Who are you?
What are you allowed to do?
Login ↓ Authentication ↓ JWT Token ↓ Authorization ↓ Role / Policy ↓ API Access
The runtime executes your code; the host manages its lifetime, configuration, and infrastructure.
Executes the application and provides the services required to run it.
The Host handles:
if (app.Environment.IsDevelopment()) { // Development configuration } app.Environment.IsProduction(); app.Environment.IsStaging(); app.Environment.EnvironmentName;
ASPNETCORE_ENVIRONMENT=Development
Kestrel is ASP.NET Core's cross-platform web server. It receives HTTP requests and can listen for HTTP/HTTPS directly.
Production tip: Kestrel can run directly, but for production it often works behind a reverse proxy such as IIS, Nginx, or Apache — which handles TLS termination, load balancing, and static files while Kestrel focuses on app requests.
Middleware is software in the HTTP request/response pipeline. Each component can process the request, call the next middleware, and then process the response on the way back.
Search any term, abbreviation, or meaning. 25+ entries covering the full Web API vocabulary.
Every API response tells the client what happened. These are the ones you'll use most.
| Code | Meaning |
|---|---|
| 200 | OK / Success |
| 201 | Created |
| 204 | No Content |
| 400 | Bad Request |
| 401 | Unauthorized / Authentication required |
| 403 | Forbidden / Not permitted |
| 404 | Not Found |
| 409 | Conflict |
| 500 | Internal Server Error |
Reverse Engineering means creating .NET entity classes and a DbContext from an existing database.
# Common command dotnet ef dbcontext scaffold "Connection_String" Microsoft.EntityFrameworkCore.SqlServer # Example dotnet ef dbcontext scaffold "Server=.;Database=CollegeDB;Trusted_Connection=True;TrustServerCertificate=True" Microsoft.EntityFrameworkCore.SqlServer
Models/ Student.cs Course.cs Teacher.cs CollegeDbContext.cs
| Approach | Direction |
|---|---|
| Code First | C# Classes → Database |
| Database First / Reverse Engineering | Database → C# Classes |
The full request path — from the client's browser all the way down to SQL Server and back.
The fastest possible recap — one line per concept.
The golden rule: Authentication happens before Authorization, both live in the middleware pipeline, and everything runs on Kestrel — managed by the Host from Program.cs.