-
Architecture
API gateway vs reverse proxy vs CORS proxy: what each one does
API gateway vs reverse proxy vs CORS proxy compared: who each serves, what it does, where they overlap, and how to choose the right one for your architecture.
6 min read Read -
Performance
Batching API requests from the browser to cut round trips
When batching API requests helps, how to express dependencies between calls, how to handle partial failures, and the limits that keep a batch from hurting you.
5 min read Read -
API keys
Publishable API keys: designing keys that are safe in a browser
What makes a publishable API key safe to ship in a browser bundle: scoped capabilities, origin allowlists and their limits, quotas, test keys and rotation.
7 min read Read -
Testing
Record and replay: deterministic API mocks for tests and demos
Use the record and replay pattern to turn real API responses into fixtures: how matching works, how to keep secrets out of recordings, and when to re-record.
5 min read Read -
Security
SSRF explained: why every proxy needs a guard against internal IPs
What server-side request forgery is, how attackers reach internal services and cloud metadata through URL fetchers, and the defenses that actually hold up.
6 min read Read -
Edge
WebAssembly at the edge: transform API traffic without a server
How WebAssembly modules can rewrite API requests and responses inline: sandboxing, a minimal ABI, time and memory budgets, and choosing fail-open or fail-closed.
5 min read Read -
API keys
You can't hide an API key in frontend code. Do this instead
Why environment variables, bundlers and obfuscation can't hide an API key in frontend code, and the three patterns that actually keep secrets off the client.
6 min read Read