# API Resources & Authentication (Laravel) > API routes, resource controllers, API resources, pagination, rate limiting, CORS, Sanctum (SPA/tokens), Passport/OAuth2, scopes - 26 interview questions - Mid-Level - [Interview Questions: Laravel](https://sharpskill.dev/en/technologies/laravel/interview-questions.md) ## 1. In Laravel, where to define API routes by default? **Answer** API routes are defined in the routes/api.php file. These routes are automatically prefixed with /api and have the api middleware applied by default. Unlike web routes defined in routes/web.php, API routes don't use sessions and are designed for stateless calls (REST, GraphQL, etc.). ## 2. Which Artisan command generates a resource controller for an API? **Answer** The php artisan make:controller PostController --api command generates a resource controller optimized for APIs. This controller contains the index, store, show, update and destroy methods, but WITHOUT the create and edit methods (which serve to display forms in web context, useless for a REST API). This --api option avoids superfluous code in an API-only context. ## 3. What is an API Resource in Laravel? **Answer** An API Resource is a transformation class that converts an Eloquent model into a JSON array for API responses. It allows precise control over which attributes are exposed, adding computed fields, hiding sensitive data (passwords), and managing relationships. This decouples the database structure from the API response and ensures consistency in output formats. ## 23 more questions available - How to create an API Resource for a User model? - How to return a paginated collection with an API Resource? Sign up for free: https://sharpskill.dev/en/login ## Other Laravel interview topics - [PHP Basics](https://sharpskill.dev/en/technologies/laravel/interview-questions/php-basics.md): 25 questions, Junior - [PHP OOP Essentials](https://sharpskill.dev/en/technologies/laravel/interview-questions/php-oop-essentials.md): 20 questions, Junior - [Composer & Autoloading](https://sharpskill.dev/en/technologies/laravel/interview-questions/composer-autoloading.md): 18 questions, Junior - [Laravel Fundamentals](https://sharpskill.dev/en/technologies/laravel/interview-questions/laravel-fundamentals.md): 20 questions, Junior - [Laravel Routing](https://sharpskill.dev/en/technologies/laravel/interview-questions/laravel-routing.md): 20 questions, Junior - [Blade Templates](https://sharpskill.dev/en/technologies/laravel/interview-questions/blade-templates.md): 18 questions, Junior - [Request & Response](https://sharpskill.dev/en/technologies/laravel/interview-questions/request-response.md): 20 questions, Junior - [Eloquent ORM Basics](https://sharpskill.dev/en/technologies/laravel/interview-questions/eloquent-orm-basics.md): 22 questions, Junior - [Eloquent Relationships](https://sharpskill.dev/en/technologies/laravel/interview-questions/eloquent-relationships.md): 25 questions, Mid-Level - [Migrations & Schema Builder](https://sharpskill.dev/en/technologies/laravel/interview-questions/database-migrations.md): 20 questions, Mid-Level - [Validation & Forms](https://sharpskill.dev/en/technologies/laravel/interview-questions/validation-forms.md): 22 questions, Mid-Level - [Authentication](https://sharpskill.dev/en/technologies/laravel/interview-questions/authentication.md): 20 questions, Mid-Level - [Authorization & Policies](https://sharpskill.dev/en/technologies/laravel/interview-questions/authorization-policies.md): 18 questions, Mid-Level - [Middleware](https://sharpskill.dev/en/technologies/laravel/interview-questions/middleware.md): 18 questions, Mid-Level - [Service Container & DI](https://sharpskill.dev/en/technologies/laravel/interview-questions/service-container-di.md): 20 questions, Mid-Level - [Queues & Jobs](https://sharpskill.dev/en/technologies/laravel/interview-questions/queues-jobs.md): 22 questions, Mid-Level - [Events & Listeners](https://sharpskill.dev/en/technologies/laravel/interview-questions/events-listeners.md): 18 questions, Mid-Level - [Notifications & Mail](https://sharpskill.dev/en/technologies/laravel/interview-questions/notifications-mail.md): 20 questions, Mid-Level - [File Storage](https://sharpskill.dev/en/technologies/laravel/interview-questions/file-storage.md): 18 questions, Mid-Level - [Testing & PHPUnit](https://sharpskill.dev/en/technologies/laravel/interview-questions/testing-phpunit.md): 24 questions, Mid-Level - [Caching](https://sharpskill.dev/en/technologies/laravel/interview-questions/caching.md): 18 questions, Mid-Level - [Livewire & Inertia](https://sharpskill.dev/en/technologies/laravel/interview-questions/livewire-inertia.md): 20 questions, Mid-Level - [Eloquent Advanced](https://sharpskill.dev/en/technologies/laravel/interview-questions/eloquent-advanced.md): 24 questions, Senior - [Repository Pattern](https://sharpskill.dev/en/technologies/laravel/interview-questions/repository-pattern.md): 20 questions, Senior - [Laravel Packages](https://sharpskill.dev/en/technologies/laravel/interview-questions/laravel-packages.md): 20 questions, Senior - [Performance Optimization](https://sharpskill.dev/en/technologies/laravel/interview-questions/performance-optimization.md): 22 questions, Senior - [Security Best Practices](https://sharpskill.dev/en/technologies/laravel/interview-questions/security-best-practices.md): 22 questions, Senior - [Laravel Octane](https://sharpskill.dev/en/technologies/laravel/interview-questions/laravel-octane.md): 18 questions, Senior - [Laravel Distributed Systems](https://sharpskill.dev/en/technologies/laravel/interview-questions/laravel-distributed-systems.md): 22 questions, Senior - [Observability & Monitoring](https://sharpskill.dev/en/technologies/laravel/interview-questions/observability-monitoring.md): 20 questions, Senior - [Deployment & DevOps](https://sharpskill.dev/en/technologies/laravel/interview-questions/deployment-devops.md): 20 questions, Senior --- Source: SharpSkill (https://sharpskill.dev), tech interview preparation for your real stack. HTML version of this page: https://sharpskill.dev/en/technologies/laravel/interview-questions/api-resources-authentication