Minimal API Workshop
ASP.NET 10 · Minimal APIs
Building Secure & Scalable Minimal APIs
A full-day, hands-on workshop
9:00 AM – 5:00 PM
What you'll build
Roastery — an ordering API for a small coffee roaster
- Browse a public menu — anyone
- Place orders — signed-in customers
- Run fulfillment — staff (baristas)
- By 5 PM: persisted, secured, cached, resilient, tested, and containerized
The day
| Time | Module |
|---|---|
| 9:20 | 1 · Fundamentals & the endpoint pipeline |
| 10:45 | 2 · Data, validation & the shape of a good API |
| 1:00 | 3 · Identity, tokens & authorization |
| 2:30 | 4 · Performance, resilience & testing |
| 3:45 | 5 · Aspire, containers & shipping |
Morning break 10:30 · Lunch 12:00 · Afternoon break 2:15 · Wrap-up 4:40
How each module works
- ~25 min concept demo — follow along or just watch
- ~45 min lab — you build it at your own pace
- Every lab ends at a git checkpoint tag
- Behind?
git checkout checkpoint-Nand rejoin the group
Two kinds of users
Customer
- Browse the menu
- Place orders
- View their own orders
Staff (barista)
- Everything a customer can
- Manage products
- Advance any order
The order lifecycle
Pending -> Roasting -> Ready -> PickedUp
|
+-------> Cancelled
The API enforces every transition. Illegal moves return 409.
Ground rules
- Ask questions any time — interrupt me
- Pair up if you like
- The
.httpfiles have every request ready to send - Fall back to a checkpoint rather than fall behind
Lab
Environment check
cd src/00-startthendotnet run- Open
https://localhost:7181/health→ Healthy - If it works, you're ready. If not, raise a hand now.
Ends at let's build