API filtering allows a mobile application to request only the records that match specific conditions. Instead of returning every record, the REST API applies one or more filters and returns the required data.
API filtering means selecting only the records that satisfy a particular condition.
Mobile App
↓
Filter Parameters
↓
REST API
↓
Database
↓
Filtered Records
↓
JSON Response
Suppose a student database contains 5,000 students. A mobile application may need only active students.
Instead of downloading all 5,000 students, the application can request:
?status=active
The server returns only active students.
A common filtering URL is:
GET /api/students.php?status=active
Here status is the filter parameter and
active is its value.
| Search | Filtering |
|---|---|
| Looks for a keyword | Selects records using conditions |
| Example: search=rahul | Example: status=active |
| Usually text based | Can use text, numbers, dates, categories, etc. |
$status = trim(
$_GET['status'] ?? ''
);
The API can read the filter value from the query string using
$_GET.
Suppose the students table contains a
status column.
SELECT *
FROM students
WHERE status = ?
The value can be supplied safely using a prepared statement.
$sql = "
SELECT *
FROM students
WHERE status = ?
";
$stmt = $pdo->prepare($sql);
$stmt->execute([
$status
]);
$students =
$stmt->fetchAll(
PDO::FETCH_ASSOC
);
Prepared statements help keep user-provided filter values separate from SQL commands.
Suppose students have a course column.
GET /api/students.php?course=PHP
The SQL condition can be:
SELECT *
FROM students
WHERE course = ?
Filtering can also be used for a class or category.
GET /api/students.php?class=12
PHP can read the value:
$class = $_GET['class'] ?? '';
$stmt = $pdo->prepare(
"SELECT *
FROM students
WHERE class = ?"
);
$stmt->execute([$class]);
An API can return records belonging to a specific user.
GET /api/orders.php?user_id=15
The SQL query could be:
SELECT *
FROM orders
WHERE user_id = ?
Filtering can also be performed using numeric values.
For example, find products below a particular price:
GET /api/products.php?max_price=1000
SELECT *
FROM products
WHERE price <= ?
You can also filter records using a minimum value.
GET /api/products.php?min_price=500
SELECT *
FROM products
WHERE price >= ?
Date filters are useful for payments, orders, attendance, reports, and other time-based records.
GET /api/payments.php?date=2026-10-04
Example SQL:
SELECT *
FROM payments
WHERE payment_date = ?
An API can receive more than one filter at the same time.
GET /api/students.php
?course=PHP
&status=active
The SQL query can use AND:
SELECT *
FROM students
WHERE course = ?
AND status = ?
<?php
header(
"Content-Type: application/json"
);
require_once '../db.php';
$status =
trim($_GET['status'] ?? '');
$course =
trim($_GET['course'] ?? '');
if (
$status === '' &&
$course === ''
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"At least one filter is required"
]);
exit;
}
try {
$conditions = [];
$params = [];
if ($status !== '') {
$conditions[] =
"status = ?";
$params[] = $status;
}
if ($course !== '') {
$conditions[] =
"course = ?";
$params[] = $course;
}
$sql = "
SELECT id,
student_id,
name,
course,
status
FROM students
WHERE "
. implode(
" AND ",
$conditions
)
. "
ORDER BY name ASC
";
$stmt = $pdo->prepare($sql);
$stmt->execute($params);
$students =
$stmt->fetchAll(
PDO::FETCH_ASSOC
);
echo json_encode([
"success" => true,
"data" => $students
]);
} catch (PDOException $e) {
http_response_code(500);
echo json_encode([
"success" => false,
"message" =>
"Server error"
]);
}
?>
Suppose we want active PHP students:
http://localhost/api/students.php
?course=PHP&status=active
The API applies both conditions and returns students satisfying both filters.
Sometimes an API needs records matching either of two conditions.
SELECT *
FROM students
WHERE course = ?
OR course = ?
For example, the API could return students from either PHP or Java.
The SQL IN operator can be useful when selecting from
multiple known values.
SELECT *
FROM students
WHERE course IN ('PHP', 'Java', 'Python')
For dynamic values, generate placeholders and bind them safely instead of directly inserting user input.
Some tables contain boolean-like values such as active/inactive or published/unpublished.
GET /api/courses.php?published=1
Example query:
SELECT *
FROM courses
WHERE published = ?
The API should validate the expected values before executing the query.
React Native can send filter values as query parameters.
const response = await fetch(
"https://example.com/api/students.php"
+ "?course=PHP"
+ "&status=active"
);
const result =
await response.json();
console.log(result.data);
import axios from "axios";
const response = await axios.get(
"https://example.com/api/students.php",
{
params: {
course: "PHP",
status: "active"
}
}
);
console.log(
response.data.data
);
Axios creates the query string from the params object.
A mobile application can provide controls such as dropdowns or buttons for selecting filters.
const [course, setCourse] =
useState("PHP");
const [status, setStatus] =
useState("active");
The selected values can then be sent to the filtering API.
const [students, setStudents] =
useState([]);
const loadStudents = async () => {
const response = await axios.get(
"https://example.com/api/students.php",
{
params: {
course,
status
}
}
);
setStudents(
response.data.data || []
);
};
The returned records can be displayed using a FlatList.
Search and filtering can be combined.
GET /api/students.php
?search=rahul
&course=PHP
&status=active
The API can apply the keyword search together with the selected filters.
WHERE
(
name LIKE ?
OR student_id LIKE ?
)
AND course = ?
AND status = ?
Never assume that a filter value supplied by a user is valid.
$allowedStatus = [
'active',
'inactive'
];
if (
$status !== '' &&
!in_array(
$status,
$allowedStatus,
true
)
) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Invalid status"
]);
exit;
}
Filter values come from the client and should be treated as untrusted input.
Unsafe:
$sql =
"SELECT * FROM students
WHERE status = '$status'";
Safer:
$stmt = $pdo->prepare(
"SELECT *
FROM students
WHERE status = ?"
);
$stmt->execute([
$status
]);
Prepared statements should be used for dynamic values.
If the API returns private data, filtering should be performed only after authentication and authorization checks where required.
Authorization:
Bearer YOUR_JWT_TOKEN
For example, a student should normally receive only data they are authorized to access.
Method: GET
http://localhost/api/students.php
?course=PHP&status=active
Click Send.
Example response:
{
"success": true,
"data": [
{
"id": 1,
"student_id": "ST001",
"name": "Rahul Kumar",
"course": "PHP",
"status": "active"
}
]
}
React Native
↓
Select Filters
↓
Query Parameters
↓
GET Request
↓
PHP REST API
↓
Validate Filters
↓
Build Conditions
↓
Prepared SQL Query
↓
MySQL
↓
Filtered JSON Data
↓
React Native FlatList
API filtering allows a React Native application to request only the records that satisfy selected conditions. PHP receives the filter parameters, validates them, creates the required SQL conditions, and uses prepared statements to safely retrieve the matching records.
GET /api/students.php
?course=PHP&status=active
Filtering is an important REST API feature for student management, e-commerce, attendance, payment, product, and many other mobile applications.
AND.OR can be used when either condition should match.Question: Which URL correctly filters students by active status?