Skip to content
7 articles

API

7 technical articles and tutorials in the API category

API2026-10-11

Incomplete HTTPS Certificate Chain: Browser Distrusts a “Valid” Leaf

Leaf dates and SAN look fine, but clients still reject the cert? Usually a missing intermediate or misordered fullchain. Verify Issuer→Subject with openssl s_client and a local decoder.

Read more
API2026-10-10

Complete Guide to HTTP API Testing: From Basics to Advanced Debugging Techniques

Master the core skills of HTTP API testing, including GET/POST/PUT/DELETE requests, header configuration, request body formats, authentication methods, and debugging techniques. Boost your development efficiency with an online API testing tool.

Read more
API2026-09-13

HTTP GET vs POST: When to Use Each? Semantics, Safety, and Best Practices

GET vs POST semantics, idempotency, caching, URL length limits, security tradeoffs, REST conventions, and common mistakes. Includes curl examples and a decision table for picking the right method.

Read more
API2026-09-08

Unexpected token '<' is not valid JSON — 5 Reasons Your API Returned HTML Instead

fetch throws SyntaxError: Unexpected token '<' when the response body is HTML, not JSON. Covers the 5 root causes: SPA history fallback returning index.html, auth 302 redirects, gateway 502 error pages, wrong baseURL, and missing res.ok checks — with curl diagnostics.

Read more
API2026-07-14

Online JWT Generator/Decoder: JSON Web Token Tool

Learn JWT (JSON Web Token) structure, how it works, and use cases. Understand how to use an online tool to generate and decode JWTs, plus security best practices.

Read more
API2026-07-10

Online Certificate Decoder: Parse SSL/TLS Certificate Information

Decode PEM certificates locally: Subject, Issuer, SAN, validity, and chain context. Pair with OpenSSL for hostname mismatch, missing intermediates, and clock skew — nothing is uploaded.

Read more
API2026-06-16

What Is a CORS Preflight Request (OPTIONS)? A Cross-Origin Mechanism Every Frontend Developer Must Know

What is a CORS preflight request? Why does the browser send an OPTIONS request? This article explains preflight trigger conditions, response headers like Access-Control-Allow-Origin, common CORS error troubleshooting, and how to bypass CORS restrictions in API testing.

Read more