Gateway Gus saysContent negotiation lets one endpoint serve multiple formats based on the Accept header.
A client states what it wants via Accept: application/json (or XML, CSV…); the server returns that format and echoes Content-Type. The server should add Vary: Accept so caches store each format separately. Most JSON APIs only speak JSON, but negotiation matters for APIs serving multiple representations of the same resource.
Power-ups you unlock
Client sends Accept; server picks the format
Server echoes Content-Type
Add Vary: Accept for correct caching
One resource, multiple representations
Timeout Titan attacks — common mistakes
Ignoring Accept and always returning one format
Forgetting Vary: Accept (cache serves wrong type)
406 vs silently defaulting confusion
Boss battleShow requests for the same resource as JSON and as CSV.