// Topics / APIs

APIs

    LLM Structured Output in Go: JSON Schema, Validation, Retries How to get reliable JSON from LLMs in Go with schemas, validation, repair loops, and typed contracts. llm api go Rate Limiting: The Boring Feature That Saves You at 3 AM Token bucket, sliding windows, identity keys, response headers, and fail-open rules: how to pick and run rate limiting for high-traffic multi-tenant APIs. api backend go API Versioning: Pick One and Stop Overthinking It Put the version in the URL for public APIs and in a header for internal ones. The real work of API versioning is deprecation and avoiding breaking changes. api architecture backend GraphQL Federation in 2021: Most Teams Still Don't Need It A year after my last federation post, Apollo is pushing it hard. Most teams I see have under 30 engineers and don't need a federated graph. api microservices opinion API Gateway Patterns: Edge, BFF, and Service Mesh Ingress Edge gateways, BFFs, and mesh ingress: what belongs in an API gateway, what doesn't, and what I learned running them at my infrastructure startup and a large telecom. api microservices architecture API Gateway Build vs Buy: Kong, Envoy, or Custom Go I've built a custom Go gateway, run Kong in prod, evaluated Envoy, and used managed cloud gateways. What I recommend after doing each wrong at least once. api go kubernetes GraphQL Federation: Why Most Teams Don't Need It Most teams adopting GraphQL federation don't need it. When it makes sense, when REST is fine, and why conference talks are a bad basis for architecture. api architecture opinion gRPC in Production with Go: Protos, Deadlines, Errors gRPC patterns from moving a startup's internal APIs off REST: proto design, Go servers and clients, status codes, testing, and mistakes that cost weekends. api go microservices API Versioning Strategies: Why I Use URL Path Versioning After versioning messes at multiple companies, I landed on URL path versioning for anything public. The alternatives didn't survive contact with reality. api architecture API Design Lessons: Every Field Is a Contract HTTP API design lessons from fintech and mobility platforms: stable resource shapes, error formats, versioning, pagination, timestamps, and rate limits. api engineering backend API Rate Limiting: Token Buckets, Redis, and Headers Rate limiting APIs at a fintech startup: choosing the limit key, token bucket vs other algorithms, Redis Lua scripts, headers, and fail-open. api backend architecture GraphQL in Production: N+1 Queries, Caching, and Tracing GraphQL in production at a fintech startup: N+1 queries, query cost limits, caching, field-level tracing, and what the conference talks leave out. api backend production API Versioning Strategies: What Works and What Doesn't URL path, query, header, or no API versioning? What worked for a fintech partner API, what counts as breaking, and how to deprecate cleanly. api architecture GraphQL vs REST: Pick the Boring One GraphQL vs REST, from a fintech and a mobility startup: GraphQL for varied clients and connected data, REST for CRUD and HTTP caching, often both. api architecture Securing APIs: Authentication and Authorization Patterns How we secured a tiered data API: short-lived RS256 JWTs, OAuth2 scopes mapped to tiers, fail-closed authorization middleware, safe token storage. security api REST API Design Principles That Stand the Test of Time Lessons from building a high-volume data API: the REST conventions that actually matter, the ones that don't, and why consistency beats cleverness. api engineering architecture