Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Serving Other Systems From a Django Application
Python & Django

Serving Other Systems From a Django Application

Building a Django API for mobile apps and integrations: share business logic rather than views, apply identical permissions, version early and rate limit.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Reuse the business logic, not the views. Apply the same permission rules, version from the start, and document it well enough that nobody needs to ask you questions.

Share the logic, not the views

The temptation is to duplicate business rules between web views and API endpoints. That duplication drifts, and the two paths eventually behave differently.

Put the business logic in a service layer that both the web views and the API call. Then a rule change applies everywhere by construction.

Permissions must apply identically

  • The same record-level filtering as the web interface
  • The same action permissions
  • Tested adversarially, with tokens from different users
  • Applied to list endpoints, not just detail ones

An API that bypasses your permission model is a hole in it, and it is frequently discovered by someone exploring rather than by a test.

Design for the consumer

  1. Consistent structure across every endpoint
  2. Meaningful status codes, not 200 with an error in the body
  3. Pagination on every collection, from the start
  4. Filtering and ordering where consumers will need it
  5. Expose business concepts, not your table structure

Version it from the beginning

Adding versioning after the first consumer means either breaking them or maintaining an unversioned path forever. A path prefix costs nothing at the start.

Then be explicit about what constitutes a breaking change and announce deprecations with real dates.

Rate limit, including internally

LimitApplies to
Per tokenExternal consumers
Per endpointExpensive operations
Internal servicesYes — loops cause outages
Unauthenticated endpointsStrictly

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Should we use a REST framework?

For anything beyond a couple of endpoints, yes. Serialisation, permissions and pagination are solved problems.

How do we handle authentication?

Tokens for services, session or token for a first-party front end. Do not invent a scheme.

Can the API and web app share models?

Yes, and they should share the service layer too. Duplicating business rules between them is the failure to avoid.

What about documentation?

Generated from your serialisers and schemas, so it cannot drift from the implementation.

Keep reading

More on Python & Django

Python & Django

An API Other Systems Can Depend On

Designing a Python API service others can depend on: validation at the boundary, consistent errors and status codes, early versioning and documentation.

Python & Django

Moving and Transforming Data Reliably

Building data pipelines in Python that cope with malformed input: restartable stages, quarantining failures, reconciling counts and alerting on absence.

Start here

Adding an API to an existing application?

The permission and logic sharing decisions matter most. Happy to review a design.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →