API search allows a mobile application to request only the records that match a particular search term. Instead of downloading every record, the React Native application sends a search value to the REST API and the server returns matching data.
?search=rahul. The API receives the
search value, validates it, safely queries the database, and returns
JSON data.
API search means finding records from a server according to a value provided by the client.
Mobile App
↓
Search Keyword
↓
REST API
↓
Database
↓
Matching Records
↓
JSON Response
↓
Mobile App
Suppose a student management application contains 10,000 students. Downloading all students just to find one student is inefficient.
Instead, the mobile application can send:
search=rahul
The server returns only the matching students.
A common REST API search URL looks like:
GET /api/students.php?search=rahul
Here:
User enters:
"rahul"
↓
React Native
↓
GET /api/students.php?search=rahul
↓
PHP REST API
↓
MySQL Database
↓
Matching Students
↓
JSON Response
PHP can read the search value from the $_GET array.
$search = $_GET['search'] ?? '';
$search = trim($search);
The null coalescing operator prevents an undefined index notice when the parameter is not supplied.
$search = trim(
$_GET['search'] ?? ''
);
if ($search === '') {
echo json_encode([
"success" => false,
"message" =>
"Search keyword is required"
]);
exit;
}
The API can require a search value before executing the database query.
Suppose the database contains a students table with a
name column.
SELECT *
FROM students
WHERE name LIKE ?
The SQL LIKE operator can be used for partial matching.
The percent symbol % represents zero or more characters.
SELECT *
FROM students
WHERE name LIKE '%rahul%'
This can match names containing rahul.
Use prepared statements instead of directly inserting user input into SQL queries.
$sql = "
SELECT *
FROM students
WHERE name LIKE ?
";
$stmt = $pdo->prepare($sql);
$keyword = "%{$search}%";
$stmt->execute([$keyword]);
$students =
$stmt->fetchAll(
PDO::FETCH_ASSOC
);
Sometimes users should be able to search by more than one field. For example, name, email, or mobile number.
SELECT *
FROM students
WHERE name LIKE ?
OR email LIKE ?
OR mobile LIKE ?
The same search keyword can be supplied to all three parameters.
Search can also be implemented for a student ID.
SELECT *
FROM students
WHERE student_id LIKE ?
For a partial student ID search:
$keyword = "%{$search}%";
SELECT *
FROM students
WHERE name LIKE ?
OR student_id LIKE ?
This is useful in a student management mobile application where the user may search using either a student's name or ID.
header(
"Content-Type: application/json"
);
echo json_encode([
"success" => true,
"data" => $students
]);
The React Native application can read the JSON response and display the records.
The API should handle the case where no record matches the search.
if (count($students) === 0) {
echo json_encode([
"success" => true,
"message" =>
"No students found",
"data" => []
]);
exit;
}
Returning an empty array makes it easy for the mobile application to handle the result.
<?php
header(
"Content-Type: application/json"
);
require_once '../db.php';
$search = trim(
$_GET['search'] ?? ''
);
if ($search === '') {
http_response_code(400);
echo json_encode([
"success" => false,
"message" =>
"Search keyword is required"
]);
exit;
}
try {
$sql = "
SELECT id,
student_id,
name,
email,
mobile
FROM students
WHERE name LIKE ?
OR student_id LIKE ?
ORDER BY name ASC
";
$stmt = $pdo->prepare($sql);
$keyword = "%{$search}%";
$stmt->execute([
$keyword,
$keyword
]);
$students =
$stmt->fetchAll(
PDO::FETCH_ASSOC
);
echo json_encode([
"success" => true,
"data" => $students
]);
} catch (PDOException $e) {
http_response_code(500);
echo json_encode([
"success" => false,
"message" =>
"Server error"
]);
}
?>
Suppose your API is running at:
http://localhost/api/students.php
To search for Rahul:
http://localhost/api/students.php?search=rahul
The server receives rahul as the search parameter.
Method: GET
GET
http://localhost/api/students.php?search=rahul
Click Send.
A successful response may look like:
{
"success": true,
"data": [
{
"id": 1,
"student_id": "ST001",
"name": "Rahul Kumar",
"email": "rahul@example.com",
"mobile": "9876543210"
}
]
}
React Native can send the search keyword using Fetch.
const searchStudents = async (keyword) => {
const response = await fetch(
"https://example.com/api/students.php?search="
+ encodeURIComponent(keyword)
);
const result =
await response.json();
console.log(result);
};
Search values can contain spaces and special characters.
encodeURIComponent() safely encodes the value before adding
it to a URL.
const keyword =
encodeURIComponent(
"Rahul Kumar"
);
const url =
"/api/students.php?search="
+ keyword;
This prevents spaces and special characters from creating an invalid query string.
<TextInput
placeholder="Search student"
value={search}
onChangeText={setSearch}
/>
<Button
title="Search"
onPress={() =>
searchStudents(search)
}
/>
The TextInput collects the keyword and the button starts the API request.
const [students, setStudents] =
useState([]);
const searchStudents = async (
keyword
) => {
const response = await fetch(
"https://example.com/api/students.php?search="
+ encodeURIComponent(keyword)
);
const result =
await response.json();
setStudents(result.data || []);
};
The returned array can then be displayed using a FlatList.
<FlatList
data={students}
keyExtractor={(item) =>
item.id.toString()
}
renderItem={({ item }) => (
<Text>
{item.name}
</Text>
)}
/>
FlatList is useful when the API returns many search results.
A loading indicator provides feedback while the API request is running.
const [loading, setLoading] =
useState(false);
const searchStudents = async (
keyword
) => {
setLoading(true);
try {
// API request
} finally {
setLoading(false);
}
};
try {
const response = await fetch(url);
if (!response.ok) {
throw new Error(
"Search request failed"
);
}
const result =
await response.json();
setStudents(result.data || []);
} catch (error) {
console.log(
error.message
);
}
The application should handle network failures and API errors instead of assuming every request succeeds.
import axios from "axios";
const searchStudents = async (
keyword
) => {
const response = await axios.get(
"https://example.com/api/students.php",
{
params: {
search: keyword
}
}
);
setStudents(
response.data.data || []
);
};
Axios can automatically build the query string from the
params object.
Search can be combined with other query parameters such as course, status, or page.
GET /api/students.php
?search=rahul
&course=php
&status=active
&page=1
This allows the API to provide more specific results.
Search input comes from the user and must be treated as untrusted input. Never directly concatenate it into SQL.
Unsafe:
$sql =
"SELECT * FROM students
WHERE name LIKE '%$search%'";
Safer:
$sql = "
SELECT *
FROM students
WHERE name LIKE ?
";
$stmt = $pdo->prepare($sql);
$stmt->execute([
"%{$search}%"
]);
Prepared statements help protect the database from SQL injection.
If student data is private, the search endpoint can be protected using JWT authentication.
Authorization:
Bearer YOUR_JWT_TOKEN
The server should verify the JWT before returning protected student data.
Search Input
↓
React Native
↓
encodeURIComponent()
↓
GET Search API
↓
PHP REST API
↓
Validate Search
↓
Prepared SQL Query
↓
MySQL
↓
JSON Response
↓
React Native
↓
FlatList
API search allows a React Native application to request matching records from a PHP/MySQL REST API. Query parameters can carry the search keyword, PHP can process the value, and prepared statements can safely search the database. The API then returns the matching records as JSON.
GET /api/students.php?search=rahul
This approach is useful for student lists, user lists, products, customers, courses, and many other mobile application features.
$_GET.LIKE operator can perform partial matching.encodeURIComponent() helps safely encode search values in URLs.Question: Which query parameter could be used to search for a student named Rahul?