The constraints that make an API "RESTful": stateless (each request self-contained), uniform interface (consistent resource URLs + standard methods), cacheable (responses declare cacheability), client–server separation, and layered (proxies/gateways can sit between). Following them yields scalable, predictable APIs that play well with web infrastructure.
Power-ups you unlock
Stateless: each request self-contained
Uniform interface: consistent URLs + methods
Cacheable responses
Client–server, layered architecture
The 401 Bandit attacks — common mistakes
Server-side session state breaking statelessness
Inconsistent URL/method conventions
Marking everything non-cacheable
Boss battleExplain how statelessness helps an API scale horizontally.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>stateless → any server can handle any request
→ add servers behind a load balancer freely
→ horizontal scale</pre></body></html>