Resta saysHTTP methods express intent: GET reads, POST creates, PUT/PATCH update, DELETE removes.
The method is the verb. GET retrieves (no side effects, safe to repeat); POST creates or triggers an action; PUT replaces a whole resource; PATCH partially updates; DELETE removes. GET and PUT/DELETE are idempotent (repeating is safe); POST usually isn't. Matching method to intent makes an API predictable.
Power-ups you unlock
GET read · POST create · PUT replace
PATCH partial update · DELETE remove
GET/PUT/DELETE idempotent; POST usually not
Method = intent
The 401 Bandit attacks — common mistakes
Using GET to change data (caches/crawlers will break it)
POST for everything regardless of intent
Assuming POST is idempotent
Boss battleAssign the right method to: fetch a user, create one, rename one, remove one.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>GET /users/42 read
POST /users create
PATCH /users/42 update name
DELETE /users/42 remove</pre></body></html>