APIs: reading API docs, authentication and HTTP status codes
For support technicians, service desk L2 staff and MSP technicians who are starting to handle tickets about integrations between systems and need to read an API reference and an HTTP log with confidence. No coding is required; being comfortable with a web browser and basic networking is enough. Covers the parts of an API reference entry, which HTTP methods are safe or idempotent and why that matters for retries, how requests authenticate (Basic, bearer tokens) and how to handle credentials, what the common status codes mean (based on RFC 9110, RFC 6750 and MDN), and how to decide the next step and owner from a request/response exhibit. Rate limits, pagination and webhooks are covered in more depth in 'Supporting integrations and APIs'.
- Level
- Beginner
- Length
- About 80 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify the method, path and path parameters, query parameters, headers and body in an API reference entry
- Identify whether an HTTP method is safe or idempotent and what that means for retrying a failed request
- Identify how a request authenticates and handle API credentials without exposing them
- Interpret HTTP status codes in a request/response log, including 400, 401, 403, 404, 405, 415, 422, 429 and 5xx
- Choose the next troubleshooting step and the owner from an HTTP request/response exhibit
Course outline
- 1.Reading an API reference entry: method, path, parameters, headers and bodyLesson · 14 min
- 2.Safe and idempotent methods, and what they mean for retriesLesson · 12 min
- 3.Identifying how a request authenticates and handling credentialsLesson · 14 min
- 4.Interpreting status codes in a request/response logLesson · 16 min
- 5.Choosing the next step and the owner from an HTTP exchangeLesson · 10 min
- 6.APIs: reading API docs, authentication and HTTP status codes: knowledge checkKnowledge check · 14 questions
- 7.APIs: reading API docs, authentication and HTTP status codes: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- IETF RFC 9110: HTTP Semantics (June 2022)
- IETF RFC 6750: The OAuth 2.0 Authorization Framework: Bearer Token Usage
- MDN Web Docs: HTTP response status codes
- MDN Web Docs: 429 Too Many Requests
- MDN Web Docs: HTTP authentication
- GitHub Docs: Getting started with the REST API
- GitHub Docs: Troubleshooting the REST API
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.