The complete request lifecycle
Read the contract before sending data.
- POST
Create the session
POST /api/lesson-sessionsreturns the only copy of the bearer token. Later requests send it asAuthorization: Bearer …. - POST
Create a lesson
POST /api/lessonsvalidates the JSON body, inserts a session-scoped row, and returns201 Created. - GET
Read collection or resource
GET /api/lessonslists your rows.GET /api/lessons/{id}returns one or a useful404. - PATCH
Change only supplied fields
A partial update allowlists
title,summary, andpublished. Unsent fields remain intact. - DELETE
Remove and verify absence
DELETE /api/lessons/{id}returns204 No Content. A later GET proves the resource is gone.