GraphQL and Real-Time APIs

The API you have built so far answers questions the server decided in advance: a client asks for /books/42 and gets whatever fields REST Design and Docs put in the payload, one round trip per resource. This section covers the two places where that breaks down — when clients need to choose the shape of the response themselves, and when the server must push data to clients that did not ask for it. Both answers mount inside the same Express 24,430 app. A GraphQL server is one POST route with an unusual body, so it shares your helmet 10,736 , CORS and rate-limit middleware; a Socket.IO 24,482 server is not a route at all, attaching to the http.Server and taking its requests before Express sees them.

One Node process, three entry points: REST routes, a GraphQL endpoint, an upgraded socket
One Node process, three entry points: REST routes, a GraphQL endpoint, an upgraded socket

Everything printed below ran on Node.js 25.8.0 2,131 with Express 5.2.1, graphql 17.0.2, graphql-yoga 5.24.1 8,529 , dataloader 2.2.3 and socket.io 4.8.3. Socket.IO introduced Socket.IO at the Node level and Front-End Web Development covers the browser WebSocket API, so the real-time subsections concentrate on what changes once a socket server shares a process and a deployment with your Express API.

Subsections