  Web Services
 Applying the REST Architectural Style
This presentation will discuss how the Representational State
Transfer (REST) architectural style can be applied to the design
of your web services.

You will learn how to use HTTP methods and status codes
properly and we will discuss how to use Hypermedia As The
Engine Of Application State (HATEOAS).

The principles of REST and HATEOAS will be demonstrated
through the Atom Publishing Protocol (AtomPub) using the
Google Data APIs and other AtomPub implementations as
"Hypertext Transfer Protocol (HTTP) is an
application-level protocol for distributed,
collaborative, hypermedia information systems. Its
use for retrieving inter-linked resources led to the
establishment of the World Wide Web."[1]
Methods and Resources
HTTP methods are the actions
that can be performed on resources.
Uniform Resource Identi ers (URIs)
Resources are identi ed by a URI.
Example URIs:

Examples of resources could include:
  • documents
  • people
  • places
  • things
  • abstract concepts (e.g. processes, transactions)
Limited Vocabulary
There are only 8 methods: HEAD, GET, POST, PUT,
going to talk about 4 of them); but you get to de ne
your own resources.[2]
REST Architecture
  • HTTP is just one (very popular) instance of the REST
  •   You can use HTTP correctly and not be RESTful and you
      can use REST without HTTP.
  •   REST is about de ning a uniform interface.

Example of a non-RESTful standard based on HTTP:
  • WebDAV
What Makes a Service RESTful?
If the HTTP method doesn’t match the method
information, the service isn’t RESTful. If the scoping
information isn’t in the URI, the service isn’t
resource-oriented. These aren’t the only
requirements, but they’re good rules of thumb.
                                    From RESTful Web Services[3]
HTTP Methods
How are you manipulating a resource?
We’ll cover four of the eight methods...
  • GET a representation of a resources.
  • Safe: Can't hold the user responsible for side-effects.
  • Idempotent: N > 0 identical requests are each the same
      as a single request.
  •   Cacheable.

GET /people HTTP/1.1

Note that the HTTP request and response examples in this
presentation are meant to be illustrative and are not
always complete. Some HTTP headers may be missing.
More on Safety
A hit counter is generally "safe". Yes, it changes state
but the user is not held accountable for that state
Deleting something is not safe: you've held the user
accountable. For example, Google Web Accelerator
(cache pre-fetching) broke 37signals' Backpack web
application because they were using GET to delete
  •   POST a new representation of a resource.
  •   New resource is subordinate to the requested resource.
  •   Not safe.
  •   Not idempotent.
  •   Can be cached only through the Cache-Control or
      Expires header elds.

POST /people HTTP/1.1
Content-Type: application/x-www-form-urlencoded
  • PUT a modi ed representation of a resource.
  • Not safe.
  • Idempotent: PUTting the same thing multiple times is
      the same as doing it once.
  •   Responses are not cacheable.

PUT /people/bradley-holt HTTP/1.1
Content-Type: application/x-www-form-urlencoded
  • DELETE a resource.
  • Not safe.
  • Idempotent. Deleting something multiple times is the
      same as doing it once.
  •   Responses are not cacheable.

DELETE /people/bradley-holt HTTP/1.1
HTTP Status Codes
What was the result of your request?
A few examples...[5]
200 OK
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 200 OK
Content-Type: text/html
<!DOCTYPE html>
  <title>Bradley Holt</title>
<div class="vcard">
  <a class="url fn" href="">Bradley Holt</a>
201 Created
POST /people HTTP/1.1
Content-Type: application/x-www-form-urlencoded

HTTP/1.1 201 Created
Location: /people/bradley-holt
202 Accepted
POST /people HTTP/1.1
Content-Type: application/x-www-form-urlencoded

HTTP/1.1 202 Accepted
Location: /queue/4jn6rk
301 Moved Permanently
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 301 Moved Permanently
Location: /people/BradleyHolt
302 Found
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 302 Found
Location: /people/BradleyHolt
400 Bad Request
POST /people HTTP/1.1
Content-Type: application/x-www-form-urlencoded

HTTP/1.1 400 Bad Request
Content-Type: text/html
<!DOCTYPE html>
  <title>Bradley Holt</title>
<p>URL is not valid.</p>
401 Unauthorized
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 401 Unauthorized
WWW-Authenticate: BASIC realm="Area 51"
403 Forbidden
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 403 Forbidden
404 Not Found
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 404 Not Found
405 Method Not Allowed
POST /people/bradley-holt HTTP/1.1

HTTP/1.1 405 Method Not Allowed
409 Con ict
PUT /people/bradley-holt HTTP/1.1
Content-Type: application/x-www-form-urlencoded

HTTP/1.1 409 Conflict
Content-Type: text/html
<!DOCTYPE html>
<p>You are editing revision 5 and the latest revision number is 6.</p>
418 I’m A Teapot
According to the Hyper Text Coffee Pot
Control Protocol (HTCPCP/1.0)[6]:
Any attempt to brew coffee with a teapot should result
in the error code "418 I'm a teapot". The resulting entity
body MAY be short and stout.

                                                                       Clipped photo by revolution cycle / CC BY 2.0
500 Internal Server Error
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
<!DOCTYPE html>
  <title>Internal Server Error</title>
<p>Oops, someone broke the application.</p>
503 Service Unavailable
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 503 Service Unavailable
Retry-After: 120
Content-Type: text/html
<!DOCTYPE html>
  <title>Service Unavailable</title>
<p>Try again in two minutes.</p>
Uniform Interface
Loose coupling and self-described messages
versus ne-grained functionality.
Uniform Interface
• URI identi es the resource.
• HTTP method says how we're manipulating the
•   Entity-header elds and entity-body[7] represent the
•   Requests and responses are self-descriptive and
Hypermedia As The Engine Of
Application State (HATEOAS)
From Chapter 5 of the Fielding Dissertation[8]:
In order to obtain a uniform interface, multiple architectural constraints are
needed to guide the behavior of components. REST is de ned by four interface
constraints: identi cation of resources; manipulation of resources through
representations; self-descriptive messages; and, hypermedia as the engine of
application state.
State of What?
Wait, you just said requests and responses
are "stateless" and now you're talking about
application state?
Requests and Responses
• Each request and each response is, itself stateless
    (forget about cookies for a minute).
•   All relevant state information is included in the request
    or response.
•   Not just state, but state transitions can be part of a
    request: POST, PUT and DELETE can change state on
    the server.
•   HTML 5
•   microformats
•   RDFa
•   URI Templates
•   WADL
•   Atom
Follow the Hyperlinks
• Link from current resource to another resource
• Form to nd resources (i.e. a "search" form)
• Form to manipulate resource's state
 (via POST, PUT or DELETE)
RESTful Implementations
REST is just an architectural style.
Implementations can vary in how RESTful they are.
• An actual protocol that is RESTful
• Uses XML document hypermedia formats to represent
•   Originally designed for publishing blogs
•   Used as the base for many RESTful web services
     • Google Data APIs (GData)
     • Amazon Simple Storage Service (Amazon S3)
     • Windows Azure Platform
GET Atom Service
GET / HTTP/1.1

HTTP/1.1 200 OK
Content-Type: application/atomsvc+xml
<?xml version="1.0" encoding="utf-8"?>
<service xmlns=""
    <collection href="">
      <atom:title>Blog Entries</atom:title>
    <collection href="">
Note: Service Document tells us everything we need to know to get started (loose coupling). For example, it
tells us the URIs of the collections to GET or POST to. URIs are up to the server to decide and should be opaque
to the client.
GET Atom Collection
GET /blog HTTP/1.1

HTTP/1.1 200 OK
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="">
  <title>Blog Entries</title>
  <link rel="self" href=""/>
POST Entry to Atom
       Collection Document
POST /blog HTTP/1.1
Slug: =?utf-8?q?blog-entry?=
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>A Blog Entry</title>
  <summary>Summary of my blog entry...</summary>

HTTP/1.1 201 Created
Location: /blog/blog-entry
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>A Blog Entry</title>
  <link rel="edit" href=""/>
  <summary>Summary of my blog entry...</summary>
GET Atom Collection
         Document (again)
GET /blog HTTP/1.1

HTTP/1.1 200 OK
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="">
  <title>Blog Entries</title>
  <link rel="self" href=""/>
    <title>A Blog Entry</title>
    <link rel="edit" href=""/>
    <summary>Summary of my blog entry...</summary>
GET Atom Entry
GET /blog/blog-entry HTTP/1.1

HTTP/1.1 200 OK
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>A Blog Entry</title>
  <link rel="edit" href=""/>
  <summary>Summary of my blog entry...</summary>
PUT Atom Entry
PUT /blog/blog-entry HTTP/1.1
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>A Blog Entry</title>
  <summary>Updated summary...</summary>

HTTP/1.1 200 OK
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>A Blog Entry</title>
  <link rel="edit" href=""/>
  <summary>Updated summary...</summary>
POST Atom Media Entry
POST /media HTTP/1.1
Slug: =?utf-8?q?vacation-photo?=
Content-Type: image/png
...binary data...

HTTP/1.1 201 Created
Location: /media/vacation-photo.png
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <link rel="edit-media" href=""/>
  <link rel="edit" href=""/>
   • edit-media URI represents the actual media
   • edit URI represents the media entry (Atom Entry)
DELETE Atom Entry
DELETE /blog/blog-entry HTTP/1.1

HTTP/1.1 200 OK
Google Calendar API
The Google Calendar Data API allows client
applications to view and update calendar events in
the form of Google Data API feeds.
Your client application can use the Calendar Data
API to create new events, edit or delete existing
events, and query for events that match particular
                                 From the Developer's Guide[9]
GET Calendar Feed
GET /calendar/feeds/default/owncalendars/full HTTP/1.1

Response (truncated):
HTTP/1.1 200 OK
Content-Type: application/atom+xml
<feed xmlns=''
  <title type='text'>'s Calendar List</title>
    <title type='text'>Bradley Holt (personal)</title>
    <link rel=''
    <gCal:timezone value='America/New_York'/>
GET Event Feed
GET /calendar/feeds/ HTTP/1.1

Response (truncated):
HTTP/1.1 200 OK
Content-Type: application/atom+xml

<feed xmlns=''
  <title type='text'>Bradley Holt (personal)</title>
  <gCal:timezone value='America/New_York'/>
    <title type='text'>Biking</title>
    <link rel='self' type='application/atom+xml'
    <gd:eventStatus value=''/>
    <gd:when startTime='2009-08-15T10:00:00.000-04:00'
    <gd:who rel=''
    <gd:where valueString=''/>
POST an Event to the
POST /calendar/feeds/ HTTP/1.1
Content-Type: application/atom+xml

<entry xmlns=''
  <title type='text'>Haircut</title>
  <gd:eventStatus value=''/>
  <gd:when startTime='2009-09-17T18:00:00.000-04:00'
  <gd:who rel=''
  <gd:where valueString='Barber Shop'/>

Response (truncated):
HTTP/1.1 201 Created
Content-Type: application/atom+xml

<entry xmlns=''
  <title type='text'>Haircut</title>
  <link rel='self' type='application/atom+xml'
  <gd:eventStatus value=''/>
  <gd:eventStatus value=''/>
  <gd:when startTime='2009-09-17T18:00:00.000-04:00'
  <gd:who rel=''
  <gd:where valueString='Barber Shop'/>
  • Allows client and server to control caching of resource.
  • An example of why URIs are important (cache only applies
      to a given URI).
  •   Reduces latency.
  •   Reduces network traffic.
  •   Cached by: browser, proxy, gateway.

GET /people/bradley-holt HTTP/1.1
Cache-Control: max-age=1800

HTTP/1.1 200 OK
Content-Type: text/html
Cache-Control: max-age=3600
...HTML data...
Conditional GET
• An entity tag (ETag) allows for a conditional GET.
• An example of why URIs are important (conditional GET
    only applies to a given URI).
•   Reduces latency.
•   Reduces network traffic.
Conditional GET (continued)
GET /people/bradley-holt HTTP/1.1

HTTP/1.1 200 OK
Content-Type: text/html
ETag: 6f6327696a7c8c6e7e
...HTML data...

GET /people/bradley-holt HTTP/1.1
If-None-Match: 6f6327696a7c8c6e7e

HTTP/1.1 304 Not Modified
Content Negotiation
   • Different representations of a resource served by the same

Request HTML:
GET /people/bradley-holt HTTP/1.1
Accept: text/html

HTTP/1.1 200 OK
Content-Type: text/html
<!DOCTYPE html>
  <title>Bradley Holt</title>
<div class="vcard">
  <a class="url fn" href="">Bradley Holt</a>
Content Negotiation
Request Atom:
GET /people/bradley-holt HTTP/1.1
Accept: application/atom+xml

HTTP/1.1 200 OK
Content-Type: application/atom+xml
<?xml version="1.0" encoding="utf-8"?>
<entry xmlns="">
  <title>Bradley Holt</title>
  <link rel="edit" href=""/>
  <summary>Bradley Holt</summary>
• Accept-Charset
  • utf-8
  • iso-8859-1
• Accept-Encoding
  • compress
  • gzip
• 406 Not Acceptable
REST is Not...
•   XML/JSON over HTTP
•   Flickr API
•   Twitter API
•   If it says, "REST API" there's a good chance it isn't RESTful.
• No ne-grained function/method calling: course-grained
    representation exchange instead.
•   Uniform interface and loose coupling over efficiency.
Author: Bradley Holt
Technical Review: Josh Sled
Layout & Design: Jason Pelletier
Photo: Revolution Cycle, Solar Powered Tea Pot, http://www.           

This presentation licensed under Creative Commons -- Attribution 3.0 United States License.
[1]: Hypertext Transfer Protocol. (2009, August 25). In Wikipedia, The Free Encyclopedia. Retrieved August 25, 2009, from
[2]: HTTP/1.1: Method De nitions. (n.d.). Retrieved August 26, 2009, from World Wide Web Consortium - Web Standards:
[3]: Richardson, L., & Ruby, S. (2007). RESTful Web Services. Sebastopol, CA: O’Reilly Media, Inc.
[4]: Google Web Accelerator: Hey, not so fast - an alert for web app designers. (2005, May 6). Retrieved September 8, 2009, from Signal
vs. Noise:
[5]: HTTP/1.1: Status Code De nitions. (n.d.). Retrieved August 27, 2009, from World Wide Web Consortium - Web Standards:
[6]: Hyper Text Coffee Pot Control Protocol (HTCPCP/1.0) (1998, April 1). Retrieved August 31, 2009, from The Internet Engineering Task
Force (IETF):
[7]: HTTP/1.1: Entity (n.d.). Retrieved September 1, 2009, from World Wide Web Consortium - Web Standards:
[8]: Fielding Dissertation: CHAPTER 5: Representational State Transfer (REST) (2000). Retrieved September 1, 2009, from Architectural
Styles and the Design of Network-based Software Architectures: elding/pubs/dissertation/
[9]: Developer's Guide - Google Calendar APIs and Tools (n.d.). Retrieved September 1, 2009, from Google Data APIs:

