Design, build (or fully spec) and test a small secured API
The capstone project for API Development for Beginners — a free Data & Tech course. Pass it and you earn a certificate anyone can verify.
- Free
- 6 steps
- Pass mark 65%
- Graded within minutes
- Beginner-friendly
The project unlocks once you complete the lessons. The workbook is free to download now so you can see exactly what is expected.
What you will submit
A single link to a public GitHub repo OR shared doc that contains: (1) your API design with at least 4 endpoints under a /v1 version prefix using correct REST methods, including at least one query parameter and clearly marked authenticated endpoints; (2) per-endpoint specs with body fields/types, validation rules with their 400 messages, success status codes and one consistent error shape; (3) a README documenting every endpoint with example request and response; and (4) a link to (or export of) your Postman collection with one tested request per endpoint. If you deployed a live API, include its base URL; otherwise the spec plus Postman collection is fully accepted.
What to do, step by step
- Choose one simple Nigerian app idea you understand (e.g. a bookshop, a food-vendor order system, a class attendance tracker, a small e-commerce store, or a mini payments-style ledger). In one or two sentences, name the app and the resources (the nouns) your API will manage.
- Design at least FOUR endpoints across your resource(s), following REST: use plural-noun paths under a version prefix (e.g. /v1/products and /v1/products/{id}) and the correct HTTP methods so you cover at least Create (POST), Read (GET list and/or single), Update (PUT/PATCH) and Delete (DELETE). Include at least one useful query parameter (a filter, search or pagination with page & limit) on a GET endpoint.
- Add AUTHENTICATION: mark which endpoints are public and which require a key/token, and show where the secret goes (an Authorization header). State which endpoints return 401 when the key is missing or wrong.
- Specify request and response detail for each endpoint: the JSON body fields with their types and which are required, your validation rules (e.g. 'name is required', 'price must be a positive number') with the exact 400 error they return, the success status code (200/201), and a single consistent error JSON shape used across the whole API.
- Build a Postman collection that tests your API: one saved, clearly named request per endpoint, each with its method, URL, headers (including auth) and example JSON body, plus at least one automated test (e.g. 'status is 200/201'). If you deployed a real coded API, point the requests at your live URL; if you specified it on paper, you may point the same requests at a public practice API (e.g. JSONPlaceholder) to prove the shapes work — either is accepted.
- Document everything in a README (in a public GitHub repo or a shared doc): the app idea, each endpoint (method, path, auth, params/body fields, example request, example success response with status code, and common errors), and a short note on how you'd earn from this skill (a role or freelance gig you'd target, the platform, and rough pay in ₦ and/or $). Share the repo/doc link plus your exported Postman collection link.
Files to work with
Project workbook (fill in, then submit)The whole brief, an evidence checklist, the grading rubric as a self-check and the link-sharing steps in one file. Opens in Word, Google Docs or WPS.Word · 7 KBHow it is graded
| Criterion | Weight |
|---|---|
| REST design — at least 4 endpoints using plural-noun paths, a /v1 version prefix, correct HTTP methods covering create/read/update/delete, and at least one useful query parameter | 25% |
| Requests, JSON & status codes — well-formed JSON bodies and responses, correct success codes (200/201), and sensible field names/types throughout | 20% |
| Authentication & error handling — endpoints correctly marked public vs protected with the key/token in an Authorization header, 401 on missing/bad auth, plus validation rules with 400 messages and one consistent error shape | 25% |
| Postman testing — a clearly organised collection with one named request per endpoint (method, URL, headers, body) and at least one passing automated test | 20% |
| Documentation & earning note — a clear README documenting each endpoint (method, path, auth, fields, example request/response, errors) plus a realistic note on how to earn from the skill | 10% |
You need 65% overall to pass. A failed submission comes back with feedback and can be revised and resubmitted.
Before you submit: make your link public
If your work lives in Google Drive or Google Docs, open Share → General access and change “Restricted” to “Anyone with the link” (Viewer). Then paste the link into a private browser window: if it opens without sign-in, you are ready. A private link cannot be graded — it is the single most common reason a good project fails.
Frequently asked questions
Do I have to finish API Development for Beginners before submitting the project?
Yes. The submission screen opens once every lesson in API Development for Beginners is marked complete. The lessons are where the methods, the Nigerian context and the worked examples the project depends on are taught.
How is the project graded?
An examiner scores each rubric criterion from 0 to 100 and weights them as shown on this page; you need 65% overall to pass. Most submissions are graded within minutes and you get written feedback on what was strong and what to improve.
Can I resubmit if I fail?
Yes. A failed project comes back with feedback; revise the weak parts and resubmit. A passed project is final — the certificate is issued and cannot be re-rolled.
What do I actually submit?
A write-up of what you did (under 5,000 characters) plus a public link to your work — a Google Drive folder, Google Doc, spreadsheet, GitHub repository or video. The link must open without sign-in; a private link cannot be graded. The free project workbook on this page walks you through all 6 steps.
Is the certificate real?
Yes. Passing this project issues a certificate with a unique verification code. Anyone — an employer, a client, a school — can open the verification page and see that the certificate is genuine and which project earned it.
More Data & Tech projects
- Sales Dashboard for a Local Business
Data Analysis Foundations
- My Skillnaija Frontend Portfolio
Frontend Web Development
- My First Python Program: 'Kudi Tracker'
Coding Foundations
- Your Junior Technician Field Pack
Data Centre Technician: Racks, Power, Cooling, Cabling and Remote Hands
Ready to earn this certificate?
API Development for Beginners is free and self-paced. Finish the lessons, complete this project, and the certificate is yours to share.
Start learning free