Level 2 · Intermediate Building APIs¶
Goal: build a backend service the way working teams do. You'll move from the raw
node:http server of Level 1 to Express 5, and then add, one lesson at a time, the parts
every production API needs: consistent resource design, validated input, a single error
path, a real database, password and token authentication, an automated test suite, and
structured logs.
Each lesson contributes a file to the level project, a multi-user tasks API. By module 10 you will assemble them and run a nine-test integration suite against a real Postgres engine.
Modules¶
- Express Fundamentals — what Express adds to
node:http,req/reshelpers, and the app factory - Routing & Middleware — route syntax in Express 5, routers per resource, and how the middleware stack runs
- REST API Design — URLs, methods, status codes, error bodies, cursor pagination, versioning, idempotency keys
- Validating Input with Zod — schemas for body, params, and query, and a reusable validation middleware
- Error Handling — operational vs programmer errors, one error middleware, and crash-safe processes
- PostgreSQL with Kysely — pools, parameterized queries, transactions, migrations, and alternatives
- Authentication: Sessions, JWT & Password Hashing — scrypt, cookie sessions, bearer JWTs, and choosing between them
- Testing with node:test & Supertest — unit tests with mocks and HTTP integration tests against a database
- Structured Logging with Pino — JSON logs, levels, request ids, and redacting secrets
- Project — A REST API with Auth — the complete tasks API with tests
What you need before starting¶
- Level 1, especially the raw HTTP server (lesson 08) and configuration (lesson 09).
- Basic SQL:
SELECT,INSERT,UPDATE,DELETE,JOIN, and what a primary key and foreign key are. The SQL Mastery Path covers these. - For running the API outside tests: a PostgreSQL server (local install or a container). The test suite itself runs without one, using an in-process Postgres build.
Package versions used while writing this level: Express 5, Zod 4, Kysely 0.29, pg 8, Pino 10, Supertest 7. Minor versions move quickly; if an API looks different in your installed version, check that package's changelog.