Learning Hub
← Web Development

What a backend does

6 min readΒ·Updated 2026-09-09

A backend enforces business rules, coordinates data and external services, authenticates requests, and returns results through an interface such as an API. It protects invariants that cannot be trusted to browser code.

A backend enforces business rules, coordinates data and external services, authenticates requests, and returns results through an interface such as an API. It protects invariants that cannot be trusted to browser code.

At a glance

Question Practical answer
When is it useful? When a learner completes a lesson, the backend verifies identity, validates the lesson, records progress transactionally, updates an achievement if eligible, and returns the new state.
What should you do? Write the request-to-response steps for creating an order, including validation, authorization, database change, external payment, error handling, and audit evidence.
How do you know it worked? Invalid or unauthorized requests cannot change data, retries do not create duplicates, and logs can trace the operation without exposing secrets.
Common failure A backend is not merely a database wrapper; put rules at the boundary that owns consistency and security.
flowchart LR
  A[Question] --> B[What a backend does]
  B --> C[Small example]
  C --> D[Evidence]

The important idea is not to stop at a definition: connect the concept to a small example and observable evidence.

Worked example

When a learner completes a lesson, the backend verifies identity, validates the lesson, records progress transactionally, updates an achievement if eligible, and returns the new state.

Before acting, write the success signal. Change one condition at a time, observe the result, and record assumptions. For What a backend does, this separates what you know from what you are merely guessing.

Practice in 20–30 minutes

Goal: Write the request-to-response steps for creating an order, including validation, authorization, database change, external payment, error handling, and audit evidence.

  1. Record the starting state and your prediction.
  2. Implement the smallest version without adding unnecessary tools.
  3. Change exactly one input or constraint and repeat.
  4. Save a command, screenshot, output, or checklist as evidence.

Expected result: Invalid or unauthorized requests cannot change data, retries do not create duplicates, and logs can trace the operation without exposing secrets.

What can go wrong

A backend is not merely a database wrapper; put rules at the boundary that owns consistency and security.

When the result differs from your prediction, do not change many things at once. Check inputs, versions, environment, permissions, and logs, then repeat from the smallest example.

Definition of done

  • I can explain the concept in my own words.
  • I completed the small example and kept evidence.
  • I know one failure mode and how to check it.
  • Someone else can repeat the work without guessing missing steps.

Go deeper

Use the linked resource or repository at the end of the page when you need a full implementation. Check current versions before applying commands to a real project.