Difficulty: Beginner
Explain the main HTTP methods, what safe and idempotent mean, and the important status code families with examples. What is the difference between PUT and PATCH, and between 401 and 403?
HTTP is the language browsers and servers speak: a client sends a request with a method, a path, headers and an optional body, and the server answers with a status code, headers and an optional body. It is stateless, so each request must carry everything needed to process it. Let's cover the methods, then the two properties that interviewers dig into, and then status codes.
GET retrieves a resource and must not change server state. POST submits data to be processed, typically creating a new resource or triggering an action. PUT replaces the entire resource at a given URL, or creates it if it does not exist. PATCH applies a partial update, sending only the fields to change. DELETE removes a resource. HEAD is like GET but returns only headers, useful to check size or existence. OPTIONS asks which methods are allowed, and browsers use it for CORS preflight requests.
Two vocabulary words matter. A method is safe if it does not modify server state: GET, HEAD and OPTIONS. A method is idempotent if calling it many times has the same effect as calling it once: GET, HEAD, PUT, DELETE and OPTIONS are idempotent, while POST is not (submitting twice can create two orders) and PATCH is not guaranteed to be. This is why a payment endpoint needs an idempotency key: if the network times out and the client retries a POST, you do not want to charge twice. PUT versus PATCH: PUT sends the complete representation and repeating it gives the same result; PATCH like increment the balance by 100 would not be idempotent.
Status codes come in five families. 1xx are informational, such as 101 Switching Protocols used when upgrading to WebSocket. 2xx means success: 200 OK, 201 Created (with a Location header), 202 Accepted (queued for later processing), 204 No Content (success with empty body, common for DELETE). 3xx are redirections: 301 Moved Permanently, 302 Found (temporary), 304 Not Modified (use your cached copy, response to a conditional request with ETag or If-Modified-Since), 307 and 308 which preserve the method on redirect. 4xx are client errors: 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 405 Method Not Allowed, 409 Conflict, 422 Unprocessable Entity (validation failed), 429 Too Many Requests. 5xx are server errors: 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable, 504 Gateway Timeout.
The favourite trick question is 401 versus 403. Despite its name, 401 means unauthenticated: the server does not know who you are, you have no valid credentials, so log in. 403 means authenticated but not authorised: the server knows who you are and you are not allowed to do this. Some APIs return 404 instead of 403 to avoid revealing that a resource exists. Another pair: 502 means a gateway or proxy received an invalid response from the upstream server (the app crashed), while 504 means the upstream did not respond in time.
Also worth knowing: 301 versus 302 matters for SEO, since search engines transfer ranking to the target of a 301 but not necessarily a 302. Never use GET for actions that change state, because crawlers, prefetchers and link previews issue GETs freely. And 200 with an error message inside the body is an anti-pattern that breaks monitoring and client libraries. Finally, HTTP headers like Content-Type, Authorization, Cache-Control, ETag and Accept carry the metadata that make all of this work.
$ curl -i -X POST https://api.example.com/orders -H 'Content-Type: application/json' -d '{"item":"book"}'
HTTP/1.1 201 Created
Location: /orders/981
$ curl -i https://api.example.com/orders/981 -H 'If-None-Match: "v3"'
HTTP/1.1 304 Not Modified
$ curl -i https://api.example.com/admin
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer
201 returns the new resource location, 304 lets the client reuse its cache, 401 says authenticate first.
HTTP Methods, Idempotency, Status Codes, REST, Safe Methods