Skip to content

API

An API is a way for one program to ask another for data or an action under agreed rules, with no clicking, such as a shop passing orders to accounting software.

Also called: application programming interface

Filip Kostecki

Published

With APIs, a company’s programs exchange data on their own: an order from the web shop reaches the accounting software and the warehouse without anyone retyping it. When you choose a contractor or a software supplier, ask about keys, limits and version changes.

How does it work?

  1. The provider publishes the address of the service and its documentation. You usually call it over the internet: your program sends a request to that address with a command (fetch, add, change), and the data travels as JSON, a text format with a simple, fixed structure.
  2. The program proves who it is with an API key from the account settings, or with an access token it receives after signing in, which stays valid only briefly.
  3. The server replies with a status code (success, an error on your side, an error on the server’s side) and the data.
  4. If there are too many requests, the server returns code 429. The program waits as long as the Retry-After header says, then tries again.
  5. Providers change their APIs from time to time and announce it through version numbers and a change log. The integration has to follow them.

API key or token?

An API key is a long-lived secret that works until it is revoked, so whoever gets hold of it can use it. An access token is short-lived and often limited in scope, for example read-only.

Example from practice

An online shop passes each paid order to its accounting software through the software’s API. You set up the connection once, with a key that is allowed only to add invoices. After that, the shop sends the order data, the software creates the invoice and replies that it is done, and nobody types anything in by hand. If the accounting software is down for a moment, the shop waits and sends the order again instead of losing it.

When does it make sense, and when not?

An API makes sense when two programs should exchange data regularly without a person, or when you need the data at once, on request. To react to an event such as a paid order, a webhook uses fewer requests: the provider notifies you by itself. If the exchange is rare, say once a month, exporting and importing a file is enough.

The same logic works inside Microsoft 365: Power Automate connectors call APIs for you, and a client portal usually pulls its data from other systems through them.

We build integrations through APIs, including with Microsoft 365 tools, as part of our Microsoft 365 automation service. Tell us which programs should exchange data, and after a short call you get a plan of work and a quote.

Describe your integration

What to watch out for

Request limits

Every provider sets its own limits. The Google Sheets API allows 300 read requests per minute per project. Limits change, so ask your contractor how the program counts requests and what it does after a 429 error.

Keys are passwords

A key does not belong in code, a repository, a spreadsheet or an email. Keep it in a secrets store or in environment variables, and replace it if it leaks. Use a separate key for each integration, so that you can cut one off without breaking the others. Google advises against putting a key in the URL, because it is then easy to leak.

Versions and changes

A provider can change its API. Microsoft says it announces a version as deprecated at least 24 months before retiring it, but not every provider gives that much notice. Ask your contractor who follows these changes and who fixes the integration when a provider withdraws something.

Questions and answers

What is an API key?

It is a long-lived secret issued in your account settings, which a program sends with every request. A standard key does not prove who is asking: it ties the request to a project, which is where limits and billing are counted (Google Cloud).

What does a 429 error mean?

The program sent too many requests in a short time and the server has stopped it (RFC 6585). The response often includes a Retry-After header with the number of seconds to wait. The program should wait, not retry at once.

Do you have to pay to use an API?

It depends on the provider. Some APIs are free or included in the licence, others are billed by use. Microsoft, for example, includes its standard Graph APIs in the user licence and bills metered ones by usage. Ask the provider about pricing and limits before anyone builds on it.

See also

Articles that use this term

Filip Kostecki

Founder of FKDRIVE. Designs, builds and maintains web systems, automation and websites.

Let us talk about your project.

Thirty minutes online about one or two processes that eat the most time. If you would rather write, the contact form is just as good a route.

Book 30 minutes

COOKIES

Without cookies we are working in the dark

We have no way of telling which parts of this site help somebody and which ought to go. Consent switches on visit statistics, session recordings with form content masked automatically, and measurement of how our advertising performs. We do not trade in your data and we do not sell it to anyone.

You can change this at any time with the “Cookie settings” link in the footer. What exactly we collect →