Ship Your Own Full-Stack App
The capstone project for Full-Stack Web Development — a free Data & Tech course. Pass it and you earn a certificate anyone can verify.
- Free
- 7 steps
- Pass mark 65%
- Graded within minutes
- Beginner-friendly
The project unlocks once you complete the lessons. The workbook is free to download now so you can see exactly what is expected.
What you will submit
One submission with the live URL, the public GitHub repository URL, and a link to (or upload of) the README as a PDF or Word file with the screenshots embedded. The reviewer will open the live app, read the code, and check the commit history.
What to do, step by step
- Build your own app with the same bones as BukkaBook. It can be BukkaBook itself with your own twist (a different food business, a laundry, a barber's bookings) or another idea that needs the same parts. It must have: a frontend page that lists items and lets a signed-in user create something (an order, a booking, a request); an Express API under /api with at least GET, POST and PATCH routes; a database (SQLite in development is fine, Postgres or SQLite in production) with at least three related tables and parameterised queries throughout; register and login with hashed passwords and a JWT in an httpOnly cookie; and at least one owner-only action protected on the server.
- Part 1. Deploy it: put the app live on a host of your choice with the database hosted too, environment variables set in the host (never committed), and HTTPS. Paste the live URL. If a free host sleeps, say so in the README so a reviewer waits for it to wake.
- Part 2. The repo: push the code to a public GitHub repository with a .gitignore that excludes node_modules, .env and local database files, an .env.example, and at least 10 commits with meaningful messages that show the app being built up over time, not one giant commit.
- Part 3. README: in the repo, a README that says what the app does, how to run it locally (commands), the API routes in a table, how sign-in and roles work, and three things you would improve next. Include two screenshots (phone width and desktop width).
- Part 4. Security check: in the README, a short section listing how your app handles SQL injection, XSS, secrets, password storage and missing auth checks, pointing to the file and line where each is handled.
- Part 5. AI note: state honestly which parts an AI assistant helped with, one mistake it made that you caught, and how you verified its output. Using an assistant is allowed and expected; hiding it or shipping its bugs is not.
- Part 6. One test: include at least one automated test run with node --test (for example, a test that a POST with a missing field returns 400) and show its output in the README.
Files to work with
Project workbook (fill in, then submit)The whole brief, an evidence checklist, the grading rubric as a self-check and the link-sharing steps in one file. Opens in Word, Google Docs or WPS.Word · 7 KBHow it is graded
| Criterion | Weight |
|---|---|
| The live app works end to end: list, sign in, create, and an owner-only action | 22% |
| The API uses correct status codes, validates input, and returns a consistent error shape | 14% |
| Database design is sound and every query is parameterised | 14% |
| Authentication is done safely: hashed passwords, httpOnly cookie, server-side role checks | 16% |
| Deployment is real: hosted database, environment variables, HTTPS, honest README notes | 12% |
| The repo and README show the work is theirs: meaningful commits, setup instructions, security and AI notes, a test | 22% |
You need 65% overall to pass. A failed submission comes back with feedback and can be revised and resubmitted.
Before you submit: make your link public
If your work lives in Google Drive or Google Docs, open Share → General access and change “Restricted” to “Anyone with the link” (Viewer). Then paste the link into a private browser window: if it opens without sign-in, you are ready. A private link cannot be graded — it is the single most common reason a good project fails.
Frequently asked questions
Do I have to finish Full-Stack Web Development before submitting the project?
Yes. The submission screen opens once every lesson in Full-Stack Web Development is marked complete. The lessons are where the methods, the Nigerian context and the worked examples the project depends on are taught.
How is the project graded?
An examiner scores each rubric criterion from 0 to 100 and weights them as shown on this page; you need 65% overall to pass. Most submissions are graded within minutes and you get written feedback on what was strong and what to improve.
Can I resubmit if I fail?
Yes. A failed project comes back with feedback; revise the weak parts and resubmit. A passed project is final — the certificate is issued and cannot be re-rolled.
What do I actually submit?
A write-up of what you did (under 5,000 characters) plus a public link to your work — a Google Drive folder, Google Doc, spreadsheet, GitHub repository or video. The link must open without sign-in; a private link cannot be graded. The free project workbook on this page walks you through all 7 steps.
Is the certificate real?
Yes. Passing this project issues a certificate with a unique verification code. Anyone — an employer, a client, a school — can open the verification page and see that the certificate is genuine and which project earned it.
More Data & Tech projects
- Sales Dashboard for a Local Business
Data Analysis Foundations
- My Skillnaija Frontend Portfolio
Frontend Web Development
- My First Python Program: 'Kudi Tracker'
Coding Foundations
- Your Junior Technician Field Pack
Data Centre Technician: Racks, Power, Cooling, Cabling and Remote Hands
Ready to earn this certificate?
Full-Stack Web Development is free and self-paced. Finish the lessons, complete this project, and the certificate is yours to share.
Start learning free