Phase 6 · Applied & ProfessionalModule 36~44 min read

Web Development: HTTP, APIs & Frameworks

Consume and build web APIs with requests, Flask, and FastAPI.

What you'll learn

The web runs on a simple request/response protocol — and Python is superb at both using web APIs and building them. This lesson takes you from raw HTTP to a working REST API.

By the end of this lesson you'll be able to:

  • Describe an HTTP request and response and what status codes mean
  • Consume any web API with the requests library
  • Explain REST and how HTTP verbs map to actions
  • Build a small JSON API with FastAPI
  • Choose between Flask, FastAPI, and Django

How the web works: HTTP

Every web interaction is a request from a client and a response from a server. A request has a method (GET, POST…), a path, headers, and sometimes a body; the response has a status code, headers, and a body.

http-exchange.txt
GET /users/1 HTTP/1.1
Host: api.example.com
Accept: application/json

--- the server responds ---

HTTP/1.1 200 OK
Content-Type: application/json

{"id": 1, "name": "Ada"}

Note

Status codes come in families: 2xx success (200 OK, 201 Created), 3xx redirect, 4xx your mistake (400 Bad Request, 401 Unauthorized, 404 Not Found), 5xx the server's fault (500 Internal Server Error). Learn these — they tell you instantly who's to blame.

Consuming APIs with requests

The requests library makes calling APIs trivial. Each verb has a function; responses expose .status_code, .json(), .text, and more. Always set a timeout.

client.py
import requests

# GET and parse a JSON response
resp = requests.get("https://api.example.com/users/1", timeout=10)
print(resp.status_code)          # 200
data = resp.json()               # JSON body -> Python dict
print(data["name"])              # Ada

# POST a JSON body to create something
resp = requests.post(
    "https://api.example.com/users",
    json={"name": "Grace"},
    timeout=10,
)
print(resp.status_code)          # 201  (Created)

Watch out

Never hard-code API keys or tokens in your source. Read them from environment variables (os.environ) or a secrets manager, and keep them out of version control — a leaked key in a public repo is one of the most common security incidents.

REST fundamentals

REST is a convention for API design: model your data as resources (nouns) at clear URLs, and use HTTP verbs for actions.

  • GET /users — list; GET /users/1 — read one
  • POST /users — create
  • PUT/PATCH /users/1 — update
  • DELETE /users/1 — delete

Responses are usually JSON, and the status code communicates the outcome.

Building an API with FastAPI

FastAPI turns typed Python functions into a JSON API. It uses your type hints to validate input and to generate interactive documentation automatically — a lot of power for very little code.

app.py
# app.py
from fastapi import FastAPI

app = FastAPI()

@app.get("/health")
def health():
    return {"status": "ok"}          # a dict is returned as JSON automatically

@app.get("/users/{user_id}")
def get_user(user_id: int):          # the type hint validates the path param
    return {"id": user_id, "name": "Ada"}
terminal
$ pip install "fastapi[standard]"
$ fastapi dev app.py
INFO   Uvicorn running on http://127.0.0.1:8000
# Interactive, auto-generated docs live at /docs

Key idea

Returning a dict becomes a JSON response; the user_id: int hint means a request to /users/abc is rejected with a clear 422 error before your code even runs. Those same hints power the auto-generated /docs page.

Frameworks & deployment

  • Flask — tiny and flexible; great for small apps and learning.
  • FastAPI — modern, async, typed; ideal for APIs.
  • Django — "batteries included" (ORM, admin, auth) for large full-stack sites.

In production you run these behind an ASGI/WSGI server (Uvicorn, Gunicorn) and a reverse proxy, usually in a container. You'll meet packaging and deployment in the next modules.

Recap & quick check

Key takeaways

  • HTTP is a request/response protocol: method + path + headers + body, answered with a status code + body.
  • Status families: 2xx success, 3xx redirect, 4xx client error, 5xx server error.
  • requests consumes APIs: resp.status_code, resp.json(); always set a timeout and keep keys in env vars.
  • REST models data as resource URLs (nouns) and uses verbs: GET read, POST create, PUT/PATCH update, DELETE delete.
  • FastAPI turns typed functions into a JSON API, validating input and generating docs from type hints.
  • Flask = minimal, FastAPI = modern APIs, Django = full-stack batteries-included.

Quick check

1. What does a 404 status code mean?

2. How do you turn a JSON response body into a Python dict with requests?

3. In REST, which verb creates a new resource?

4. How does FastAPI validate a path parameter like user_id?

5. Where should API keys and tokens live?

APIs need somewhere to keep their data. Next: talking to databases from Python. Next up: Module 37 — Databases with Python.