One habit that makes debugging APIs much harder is returning HTTP 200 OK for every request.
An HTTP status code tells the client what happened before it even reads the response body.
Examples:
200 → Success
201 → Resource created
400 → Client sent invalid data
401 → Authentication required
403 → Authenticated, but not allowed
404 → Resource doesn't exist
500 → Server failed unexpectedly
If every response is
200, frontend developers have to inspect every response body just to know whether something failed.Let HTTP do its job. That's what it was designed for.