← Back to courses

Course

GraphQL

69 lessons across 8 modules

Intermediate to advanced, assuming JavaScript or TypeScript, REST basics and some Node.js. Fundamentals and the comparison with REST, schema and types, queries and mutations, resolvers, a real server, the React client, then the advanced and production concerns GraphQL creates that REST does not. The road is laid out in full; lessons are being written one at a time.

Course8 modules69 lessonsEach heading below is a module (one topic). Each card under it is a lesson. Start with Module 1.
Solid: ready (0)Dashed: coming soon (69)
Module 1 of 87 lessonsComing soon

GraphQL Fundamentals

What it is, and what it costs you

Building REST APIs, for the comparison →

What is GraphQL?

1

A query language and a type system - not a database, not a framework.

One request returning exactly the fields asked for

Lesson 1planned

Why GraphQL?

2

Over-fetching, under-fetching, and the round trips REST forces.

Three REST calls collapsing into one query

Lesson 2planned

GraphQL vs REST

3

An honest comparison, including where REST is still the better answer.

Caching, status codes, and what you give up

Lesson 3planned

GraphQL Architecture

4

Schema, resolvers, and the single endpoint everything goes through.

Drawing the pieces before writing any of them

Lesson 4planned

Request and Response Flow

5

Parse, validate, execute, respond - and where each can fail.

Following one query through all four stages

Lesson 5planned

GraphQL Operations

6

Query, mutation, and subscription - the three things you can send.

The same data read, changed, and watched

Lesson 6planned

When to Use GraphQL

7

The conditions that justify it, and the ones that do not.

A single client and one team, better served by REST

Lesson 7planned
Module 2 of 89 lessonsComing soon

Schema and Types

The contract everything else is checked against

Schema

8

SDL, the root types, and the schema as the actual API.

A schema file read as documentation

Lesson 8planned

Object Types

9

Types and their fields - the nouns of your domain.

Modelling a Course and its Lessons

Lesson 9planned

Scalar Types

10

The five built-ins, and writing a custom scalar.

A DateTime scalar that validates on the way in

Lesson 10planned

Lists

11

List types, and the four ways nullability combines with them.

[Course], [Course!], [Course]! and [Course!]! compared

Lesson 11planned

Non-Null Types

12

The exclamation mark, and why it is harder to remove than to add.

A non-null field that makes one error blank a whole list

Lesson 12planned

Enums

13

A closed set of values, checked before a resolver runs.

A status field that cannot be misspelled

Lesson 13planned

Interfaces

14

Shared fields across types, and querying them.

A Node interface with an id on everything

Lesson 14planned

Unions

15

One field returning several unrelated types.

A search result that is a Course or a Lesson or a User

Lesson 15planned

Input Types

16

Why arguments need their own types, and how to shape them.

One input object instead of nine arguments

Lesson 16planned
Module 3 of 88 lessonsComing soon

Queries and Mutations

Writing the operations a client sends

Queries

17

Asking for a shape, and getting that shape back.

The response mirroring the request, field for field

Lesson 17planned

Fields

18

Selection sets, nesting, and the depth you are allowed.

Walking from a course to its lessons to their authors

Lesson 18planned

Arguments

19

Filtering and parameterising at any level, not just the root.

Arguments on a nested field, not only the top one

Lesson 19planned

Aliases

20

Requesting the same field twice under different names.

Two courses fetched in one query

Lesson 20planned

Fragments

21

Reusing a selection set, and colocating it with a component.

A fragment per component, composed at the page

Lesson 21planned

Variables

22

Parameterising an operation instead of building strings.

Why string interpolation into a query is a bug

Lesson 22planned

Mutations

23

Writes, their return values, and why they resolve in series.

A mutation returning the record it just changed

Lesson 23planned

Multiple Operations

24

Several operations in one document, and naming them.

Choosing which operation to run by name

Lesson 24planned
Module 4 of 89 lessonsComing soon

Resolvers

The functions that actually produce the data

What is a Resolver?

25

One function per field, and the default you usually get free.

The resolver you did not write, and what it does

Lesson 25planned

Resolver Structure

26

The map from types to fields to functions.

A resolver map beside the schema it implements

Lesson 26planned

Parent

27

The first argument - what the level above returned.

A lesson resolver reading its course id from parent

Lesson 27planned

Arguments

28

The second argument, already validated against the schema.

Trusting args for shape, never for authorization

Lesson 28planned

Context

29

Per-request state - the user, the database, the loaders.

Building context once per request, not per field

Lesson 29planned

ResolveInfo

30

The fourth argument, and the one advanced use it has.

Reading the selection set to avoid over-fetching

Lesson 30planned

Nested Resolvers

31

How a tree of fields resolves, and in what order.

A query three levels deep, traced

Lesson 31planned

Resolver Composition

32

Wrapping resolvers for auth, logging, and validation.

One authenticated() wrapper used across a schema

Lesson 32planned

Error Handling

33

Throwing from a resolver, and what the client receives.

Partial data alongside an errors array

Lesson 33planned
Module 5 of 88 lessonsComing soon

GraphQL with Node.js

Standing up a real server

The Node.js course →

Setting Up a GraphQL Server

34

The pieces you need, and the smallest server that runs.

Hello world over a single endpoint

Lesson 34planned

Apollo Server

35

Setup, plugins, and the context function.

A server with auth context and a logger plugin

Lesson 35planned

Schema Definition

36

Organising SDL across files as the schema grows.

A schema split by domain rather than by type kind

Lesson 36planned

Resolvers

37

Wiring resolvers to the schema, and keeping them thin.

A resolver that calls a service and nothing else

Lesson 37planned

PostgreSQL Integration

38

Relational data behind a graph, and the joins it implies.

A nested query and the SQL it really runs

Lesson 38planned

MongoDB Integration

39

Document data behind a graph, and where it fits better.

The same schema served from documents

Lesson 39planned

Service Layer

40

Business logic outside resolvers, so it stays testable.

Swapping the database without touching a resolver

Lesson 40planned

Building a Complete API

41

Schema, resolvers, services, and a database, end to end.

A courses API with full CRUD

Lesson 41planned
Module 6 of 88 lessonsComing soon

GraphQL with React

Consuming a graph from the client

The React course →

Apollo Client

42

Setup, the link chain, and where the cache sits.

A client with auth headers and an error link

Lesson 42planned

Queries from React

43

useQuery, and the hook result read properly.

A course list with no fetch written by hand

Lesson 43planned

Mutations

44

useMutation, and what to do once it resolves.

Creating a course and refreshing what should change

Lesson 44planned

Variables

45

Passing arguments from component state into an operation.

A search box driving a parameterised query

Lesson 45planned

Loading and Error States

46

First load, refetch, and partial data with errors.

A response that is both successful and failed

Lesson 46planned

Caching

47

The normalized cache, and why ids matter so much.

One record updating everywhere it appears

Lesson 47planned

Cache Updates

48

Refetching against writing to the cache directly.

An insert that updates a list without a round trip

Lesson 48planned

Optimistic UI

49

Rendering the expected result, and rolling it back.

A toggle that reverts when the server refuses

Lesson 49planned
Module 7 of 810 lessonsComing soon

Advanced GraphQL

Auth, pagination, subscriptions, and N+1

Authentication

50

Identifying the caller once, in context, per request.

A token verified before any resolver runs

Lesson 50planned

Authorization

51

Field-level and resolver-level checks - and never in the client.

A field one role may read and another may not

Lesson 51planned

Pagination

52

Offset against cursor, and the Relay connection shape.

edges, nodes, and pageInfo explained once

Lesson 52planned

Filtering

53

Filter inputs that stay expressive without becoming SQL.

A filter input that the database can actually use

Lesson 53planned

Sorting

54

Sort arguments, defaults, and stable ordering.

Pagination breaking without a tiebreaker

Lesson 54planned

File Uploads

55

Multipart uploads, and why signed URLs are usually better.

Uploading beside the graph rather than through it

Lesson 55planned

Subscriptions

56

Live data over WebSockets, and what it costs to run.

A notification pushed to one connected client

Lesson 56planned

DataLoader

57

Batching and per-request caching, and where to construct it.

A loader shared across one request and no longer

Lesson 57planned

The N+1 Problem

58

Why a graph invites it, and how to see it happening.

One query producing 101 database calls

Lesson 58planned

Performance Optimization

59

Measuring per-resolver cost before changing anything.

A trace showing which field is actually slow

Lesson 59planned
Module 8 of 810 lessonsComing soon

Production GraphQL

The problems GraphQL creates that REST does not

Error Handling

60

Error codes, partial success, and not leaking internals.

A stack trace that reached a client

Lesson 60planned

Security

61

Introspection, batching abuse, and the single-endpoint surface.

What an attacker learns from introspection alone

Lesson 61planned

Query Complexity

62

Depth and cost limits, because any client can ask for anything.

A deeply nested query that would never return

Lesson 62planned

Rate Limiting

63

Limiting by cost rather than by request count.

Why one endpoint breaks per-route rate limits

Lesson 63planned

Caching

64

Response, field, and persisted-query caching - and HTTP caching lost.

Getting a CDN back in front of a graph

Lesson 64planned

Monitoring

65

Per-field metrics, and which operations actually run.

Finding the resolver behind a latency spike

Lesson 65planned

Logging

66

Logging operations without recording variables you must not keep.

An operation log that redacts a password variable

Lesson 66planned

Testing

67

Schema, resolvers, and integration through real operations.

A test that runs a query against a test server

Lesson 67planned

Versioning and Schema Evolution

68

Additive change, deprecation, and never shipping v2.

Removing a field only after nobody queries it

Lesson 68planned

Production Best Practices

69

The decisions worth making before launch, not after.

A pre-launch review of a real schema

Lesson 69planned