Engineering write-ups, product decisions, and the occasional opinion on how to ship developer infrastructure. Long enough to be useful, short enough that you'll finish it.

Playwright vs Puppeteer vs Selenium compared: browsers, languages, speed, auto-waiting, and scraping. Plus when an API replaces a headless browser for screenshots and PDFs.

What supply chain attacks and third-party data breaches are, why they now drive nearly half of all breaches, and how developers can reduce the risk from dependencies, vendors, and…

Looking for a Firecrawl alternative? Compare Jina Reader, Crawl4AI, Apify, and ApyHub for turning web pages into clean Markdown and text for LLMs and AI agents.

What is MCP in AI? A plain-English guide to the Model Context Protocol: MCP servers, tools, MCP vs APIs and RAG, and security basics.

How AI agents discover, choose, and call APIs, why function calling and MCP matter, what agents need from an API, and how to keep agent access safe.

Technically yes, practically no. What RFC 9110 says about GET request bodies, why servers and proxies drop them, and what to do instead.

CORS is the browser refusing to let your JavaScript read a response from another origin. Why it exists, what a preflight is, and how to fix it properly.

A 502 means one server got a bad answer from another. A 503 means the server cannot handle the request right now. Different causes, different fixes.

A bearer token is a credential where possession is proof. How it works, how it differs from API keys, Basic auth and OAuth, and why it must never leave secure storage.

A 429 means you are calling faster than the server allows. How to read Retry-After, how to back off correctly, and how to avoid hitting it.

PUT replaces the whole resource. PATCH updates part of it. Why that difference matters for idempotency, and which to pick.

An idempotent request produces the same result whether it runs once or ten times. Which HTTP methods are idempotent, and why retries depend on it.