‹ Start From Zero Lesson 9 of 21
Contents Lesson 9 of 21

3 min read · foundations

What a URL actually is

You have typed thousands. Here is what the parts do, because from unit 3 onwards you build them rather than click them.

The parts

https://eodhd.com/api/eod/AAPL.US?from=2026-01-01&fmt=json
\___/   \_______/\______________/\_______________________/
scheme    host         path                query

Scheme — https means encrypted in transit. Everything here uses it.

Host — which machine on the internet answers.

Path — which thing on that machine you are asking for.

Query — the options, after ?, joined by &, each a name=value.

The query is where your parameters go

from=2026-01-01 and fmt=json are two options on one request. Course 1 builds these in code rather than typing them, and course 2 spends a lesson on the fact that anything in a query string is visible — to the browser, to logs, to anyone watching. That is why an API key in a URL is a problem, and it is the single most important thing this track teaches.

Special characters have to be escaped

A space, an & or a ? inside a value would be read as structure. encodeURIComponent converts them safely. It looks like pedantry until a ticker with an unusual character silently breaks a request.

What comes back

A status code and a body. The code is the summary:

  • 200 — fine.
  • 404 — no such thing. Usually a typo in the path.
  • 401 / 403 — who are you, or you may not.
  • 429 — too many requests. You will meet this one properly in course 1.
  • 5xx — the server broke, not you.

The body is usually JSON, which unit 2 already showed you how to read. Usually — course 3 meets a 404 whose body is plain text, which breaks code that assumes otherwise.

Try it now

Open https://eodhd.com/api/eod/AAPL.US?api_token=demo&fmt=json in a browser and look at the raw JSON. Then change the ticker to something that does not exist and look at what comes back instead. Two requests, and you have seen both halves of what your code will handle.

Live API response: apple one daily bar

The second half will surprise you, so here it is as measured on 28 September 2026:

Request Status Body
NOTREAL.US with api_token=demo 403 Forbidden (plain text, not JSON)
NOTREAL.US with your own key, from course 1 404 Ticker Not Found. (plain text, not JSON)

Not the 404 the list above promised. The demo key only covers a handful of symbols, so the server refuses before it checks whether the ticker exists, and the status answers "you may not" rather than "no such thing". The same typo means two different codes depending on the key, which is why you read the body as well as the status.