Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsYou can create a small PHP web service with one PHP file: accept an HTTP request, validate its input, set a JSON content type and return a JSON response with an appropriate status code. This example assumes PHP is installed locally and you have an HTTP server for testing. It does not need a database; persistence is optional.
What this endpoint does
A web service endpoint is a URL that accepts an HTTP request and returns data or performs an action. PHP runs on the server and can produce JSON or XML as well as HTML. For this tutorial, the endpoint accepts a name in a query parameter and returns a JSON greeting. A missing or invalid name produces a client-error response.
As an Amazon Associate I earn from qualifying purchases.
The example uses plain PHP rather than a framework, and keeps data in the request instead of storing it. That makes the request, validation, status code and response easy to see in one place.
What you need
- A local PHP parser/runtime.
- A web server. For local learning and testing, PHP includes a built-in development server.
- A browser or HTTP client, such as
curl, to send a request and inspect the response.
The PHP documentation describes the runtime and web server as core components for server-side PHP use. See What is PHP and what can it do?.
#1 Best Overall
Create the PHP endpoint
Create a file named index.php in a new project directory, then add this code:
<?php
declare(strict_types=1);
header('Content-Type: application/json; charset=utf-8');
$name = $_GET['name'] ?? '';
if (!is_string($name)) {
http_response_code(400);
echo json_encode(['error' => 'Name must be a single text value.']);
exit;
}
$name = trim($name);
if ($name === '') {
http_response_code(400);
echo json_encode(['error' => 'The name parameter is required.']);
exit;
}
http_response_code(200);
echo json_encode(['message' => 'Hello, ' . $name . '!']);
How the response is formed
header()tells the client that the response body is JSON encoded as UTF-8.http_response_code()sets the HTTP status:200for success and400when the request is invalid.json_encode()converts PHP arrays into valid JSON.exitstops execution after an error response so the success response is not also sent.
For a request with ?name=Ada, the response body is {"message":"Hello, Ada!"}. A request with no name returns {"error":"The name parameter is required."} and status 400. In a larger service, handle encoding failures explicitly and keep response shapes consistent.
Rank #2
Run it locally and send a request
- Open a terminal in the directory containing
index.php. - Start PHP’s built-in server with
php -S 127.0.0.1:8000. - In a browser, visit
http://127.0.0.1:8000/?name=Ada, or runcurl -i "http://127.0.0.1:8000/?name=Ada"in another terminal. - Check that the response includes a successful HTTP status, a JSON content type and the greeting object. Try
curl -i "http://127.0.0.1:8000/"to check the missing-input error and its400status. - Stop the server with
Ctrl+Cwhen you finish.
The built-in server is intended for development, testing or controlled demonstrations—not public networks or production. PHP documents that it is not a full-featured web server; by default it is single-threaded, so a blocked request can stall the application. Use a production web server and deployment setup for a public service. See PHP: Built-in web server.
Validate input and protect errors
Treat every value from a client as untrusted. This example checks that name is a single string, trims whitespace and rejects an empty value. Real endpoints should also decide which characters and maximum length are acceptable for their specific data, and reject malformed or out-of-range values before using them.
Return useful client-facing errors without disclosing filesystem paths, credentials, stack traces or raw exception messages. Configure PHP appropriately for the deployment environment and log diagnostic details privately. The PHP manuals cover security fundamentals and security.
When to add a database
This greeting endpoint has no state to preserve, so it does not need a database. Add persistence only when the service must store or retrieve data across requests. PHP’s PDO extension offers a consistent interface for database access, but you still need the PDO driver matching the database you choose. PDO does not rewrite SQL or emulate missing database features; it is not a complete database abstraction layer. See PHP Data Objects.
Rank #4
For a database-backed endpoint, use prepared statements with bound values for client-supplied data instead of building SQL by concatenating input. Keep database credentials outside the public document root, install the required PDO driver, and avoid returning database exceptions to callers.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBe cautious with older examples that use a PDO DSN beginning with uri:: the PHP manual marks this DSN form deprecated as of PHP 8.5.0 because remote URI-based DSNs raise security concerns. Check the applicable guidance for your PHP version in PDO::__construct.
Prepare the service for production
Local success only confirms that the endpoint works in a development setup. Before making a service public, choose and configure a production web server, confirm the PHP version and required extensions, and deploy the code with an appropriate document root. Review error display and logging, validate all request data, and add authentication or authorization if the endpoint exposes private data or actions. A database is not a default requirement; if you add one, secure credentials and use safe query patterns.
A framework can help when an application needs routing, structured validation, middleware or shared conventions. Plain PHP is enough for a small endpoint, but you must implement those concerns yourself as the service grows. There is no single framework, API design, authentication method or hosting vendor required by the term “web service.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →




