Node.js built an HTTP server out of Node's http module: one listener, a hand-parsed URL, a chain of if statements, and a body assembled from stream chunks. Everything here still runs on that, but nobody ships a real API that way. The routing table grows, two endpoints need the same authentication check and a third needs a different one, and the listener stops being maintainable.
Express 24,430 is the answer the Node community settled on in 2010 and has not seriously revisited since. It is small — 28 direct dependencies, about 75 kB unpacked — and deliberately unopinionated. You get a router, a middleware stack that composes small functions into a request pipeline, and convenience methods on the request and response objects. You do not get an ORM, a dependency injection container, or a project structure, which is why two Express codebases can look nothing alike.
The version here is Express 5.2.1, published on 1 December 2025. Express 5 matters more than the version number suggests: body parsing, static serving and the router now ship inside the framework, and a rejected promise from an async handler reaches your error middleware instead of vanishing. Express 4 tutorials mostly still work, and this chapter marks where they no longer do. Everything converges on one project, the Bookshelf API of The Bookshelf API, kept behind a data interface so MongoDB can swap in MongoDB 1,815 without touching a route and Next.js can consume it from Next.js 10,514 .
What you will learn
What Express adds to Node's http module, and what Express 5 changed.
How the router matches methods, paths and parameters, and how to modularize routes.
How request and response objects parse bodies, negotiate types and stream files.
How the middleware stack works, and how to write and audit your own.
How to serve static assets, render templates and accept uploads.
How to authenticate with sessions, passwords, JWTs, Passport and OpenID Connect.
How to validate input, raise typed errors and return consistent payloads.
How to log, test, document, secure, rate-limit, cache and deploy the API.
How Express compares with Koa 304,877 , Fastify 314,116 , NestJS 79,377 and Hono 383,227 .
Sections
- Express in the MERN Stack
- Routing
- Request and Response
- Middleware
- Static Files and Uploads
- Cookies and Auth
- Validation and Error Handling
- Observability and Testing
- REST Design and Docs
- Security and Rate Limits
- GraphQL and Real-Time APIs
- Performance and Deploy
- The Bookshelf API
- Express Alternatives
- NestJS Version
- Test Yourself!