Build a todo API
The tutorial teaches one idea per chapter. This builds one thing, end to end: a todo API where people sign up, log in, and can only ever see their own todos.
By the end you will have:
POST /auth/signup,/auth/login, and five more auth endpoints you did not writeGET,POST,PATCHandDELETEfor todos, each scoped to the signed-in user- validation that rejects bad input before your code runs, and documents itself at
/docs - a test suite that proves one user cannot touch another’s data
- something you can deploy
The chapters
Section titled “The chapters”-
Set it up — one command, and a tour of what you get.
-
The first endpoint — a route, a schema, and why the filesystem is the router.
-
Storing todos — a table, a migration, and real persistence.
-
Locking it down — signup, login, and scoping every query to its owner.
-
Testing it — including the tests that matter most.
-
Shipping it — what production refuses to boot with, and why.
What you need
Section titled “What you need”Bun 1.4 or newer. Nothing else — no database server, no Redis, no S3 account. The default stack is SQLite on disk and mail printed to your terminal, so the whole thing runs on a laptop on a plane.
bun --version # 1.2.0 or higherThe finished thing
Section titled “The finished thing”If you would rather read the code than build it, here is the whole app — six files you write, on
top of what bun create gives you:
src/ app.ts configured by the scaffold; you add nothing route.ts binds ctx to your bricks — three lines schema.ts your table, plus auth's routes/todos/ index.get.ts list index.post.ts create [id].patch.ts update [id].delete.ts delete app.test.ts the suiteFour route files, a schema, and a test. Everything else — auth endpoints, request parsing, error shapes, OpenAPI, graceful shutdown — you get without writing it.