Routing, middleware and error handling give you the machinery to answer a request; design decides what the request looks like — whether a client asks for /api/v1/books?genre=fantasy or /api/v1/getBooksByGenre/fantasy, whether page two arrives as ?page=2 or ?after=YmtfMDAz, and what a client that cached a book yesterday must send to avoid downloading it again today. A route handler can be rewritten in an afternoon; a URL that mobile apps have shipped against is close to permanent.
REST is not a protocol and has no conformance suite — it is the set of constraints Roy Fielding described in his 2000 dissertation, of which the industry uses three: a uniform interface over addressable resources, stateless requests, and responses that say whether they can be cached. Follow them and your API can be cached by a proxy it has never met and described in one file that generates documentation and a typed client. What follows traces GET /api/v1/books from naming to a documentation page, with every response taken from an Express 5.2.1 24,430 server holding 42 books in memory.