# Statelessness — REST API Design: Resources, Status Codes and Security

Source: https://www.skillbyai.com/en/restapi/api-statelessness

> Understand why REST servers stay stateless, how each request carries its own context and how that helps horizontal scaling.

## Every request stands alone

In a stateless API, the server keeps no session data about the client between calls. Each request carries everything needed to understand it — an auth token, the resource id, any filters — so no request depends on server memory of a previous one.

## A drive-through, not a waiter

A waiter remembers your table's order across the meal — stateful. A drive-through window has no memory of you; every car states its full order at the speaker. Stateless servers work the same way: any server instance can handle any request.

## Why it matters at scale

Statelessness lets you add or remove servers behind a load balancer freely — no server holds client-specific data that would be lost on failover. It trades a little repeated data (like a token) for much simpler horizontal scaling.

**Quiz:** In a stateless REST API, where should the client's identity/auth info live?

- [ ] In server-side session memory
- [ ] Stored in the database and looked up by IP
- [x] Sent with every request (e.g. a token in headers)
- [ ] Hard-coded in the client source code

*Answer:* Sent with every request (e.g. a token in headers). Statelessness means the server holds no per-client session; the request itself must carry the credentials needed to authenticate it.
