Skip to content

Build a todo API

The tutorial teaches one idea per chapter. This builds one thing, end to end: a todo API where people sign up, log in, and can only ever see their own todos.

By the end you will have:

  • POST /auth/signup, /auth/login, and five more auth endpoints you did not write
  • GET, POST, PATCH and DELETE for todos, each scoped to the signed-in user
  • validation that rejects bad input before your code runs, and documents itself at /docs
  • a test suite that proves one user cannot touch another’s data
  • something you can deploy
  1. Set it up — one command, and a tour of what you get.

  2. The first endpoint — a route, a schema, and why the filesystem is the router.

  3. Storing todos — a table, a migration, and real persistence.

  4. Locking it down — signup, login, and scoping every query to its owner.

  5. Testing it — including the tests that matter most.

  6. Shipping it — what production refuses to boot with, and why.

Bun 1.4 or newer. Nothing else — no database server, no Redis, no S3 account. The default stack is SQLite on disk and mail printed to your terminal, so the whole thing runs on a laptop on a plane.

Terminal window
bun --version # 1.2.0 or higher

If you would rather read the code than build it, here is the whole app — six files you write, on top of what bun create gives you:

src/
app.ts configured by the scaffold; you add nothing
route.ts binds ctx to your bricks — three lines
schema.ts your table, plus auth's
routes/todos/
index.get.ts list
index.post.ts create
[id].patch.ts update
[id].delete.ts delete
app.test.ts the suite

Four route files, a schema, and a test. Everything else — auth endpoints, request parsing, error shapes, OpenAPI, graceful shutdown — you get without writing it.

Start with the setup →