Name Content-Type, Accept, and Authorization, use each on a blog API, then catch the token-in-the-URL mistake.
In this article
Name GET, POST, PUT, DELETE, and PATCH, use each on a blog API, then catch the /delete path mistake.