A production API platform has seven components beyond the endpoints themselves.
API Design (OpenAPI-first)
OpenAPI 3.1 specification written before implementation — resource naming, HTTP verb selection, request/response schema, error codes, pagination design (cursor vs offset), filtering patterns and hypermedia (HATEOAS where appropriate).
REST API Engineering
RESTful API with correct HTTP semantics, idempotency enforcement on mutation endpoints, consistent error responses (RFC 7807 Problem Details), ETag-based caching, conditional requests and content negotiation.
GraphQL API Engineering
GraphQL schema design, resolver optimisation with DataLoader (N+1 prevention), pagination (Relay cursor spec), subscriptions for real-time data, persisted queries, complexity limiting and depth limiting.
Authentication & Authorisation
OAuth 2.0 / OIDC for third-party access, API key management with scopes and expiry, JWT validation with correct algorithm enforcement, per-endpoint authorisation and audit logging for all API access.
Rate Limiting & Quotas
Per-API-key rate limiting (requests per second, requests per day), quota management with overage handling, burst allowances, rate limit headers (X-RateLimit-Remaining, Retry-After) and graceful degradation under load.
Developer Experience
Auto-generated OpenAPI documentation with Stoplight or Redoc, interactive API playground, code samples in 5+ languages, SDK generation (openapi-generator), changelog, webhook documentation and sandbox environment.