What is API?
Definition
An API (Application Programming Interface) is a defined set of rules that lets one piece of software use the functions or data of another. It acts as a contract: it specifies which operations can be called, what parameters they take, what responses and errors come back, and in which format. Because only the interface is shared, systems such as a web shop and a payment provider can work together without knowing each other's internals.
Also known as: Application Programming Interface, web API

An interface is a contract
An API describes how two programs talk to each other without either one knowing how the other is built: which operations exist, what input they expect, what they return and how failures are reported. That makes it more useful to think of an API as a contract than as a piece of code. Everything behind the contract can be rewritten, the database swapped out, the server moved, and as long as the interface stays the same, the applications using it keep working.
Most everyday integrations rely on this separation. An online store can create shipments in a carrier's system without access to its internals; accounting software can pull bank transactions without ever seeing the bank's database. The only thing the two sides share is a documented, versioned interface.
Kinds of APIs
In everyday conversation “API” usually means a web service, but the term covers much more:
- Library and framework APIs: the functions, classes and methods a language's standard library or a package exposes. Calls happen inside the same program, with no network involved.
- Operating system APIs: the calls applications make to read files, open network connections or allocate memory.
- Browser APIs: interfaces such as
fetch,localStorageor Geolocation that the browser makes available to JavaScript. - Web APIs: services reached over a network, usually via HTTP. Payment gateways, mapping services, CRMs and ERPs mostly expose their functionality this way.
Common styles of web API
| Style | Core idea | Typical use |
|---|---|---|
| REST | Resources are addressed by URLs and manipulated with HTTP methods | General-purpose and public web APIs |
| GraphQL | The client sends one endpoint a query describing exactly the fields it needs | Front ends where different screens need differently shaped data |
| gRPC | Remote procedure calls defined with Protocol Buffers, running over HTTP/2 | Low-latency internal traffic between services |
| SOAP | Strict XML message format described by WSDL | Older enterprise integrations, e.g. in banking and government |
The rules of the most widespread of these, the REST API, have their own entry. All of the styles above follow a request-response pattern in which the client asks and waits for an answer. When the other system instead notifies you on its own as soon as something happens, that pattern is called a webhook.
What makes an API good
- Documentation: every endpoint, field and error code is written down. For web APIs, the OpenAPI Specification provides a machine-readable description format from which docs, tests and client code can be generated.
- Versioning: removing a field or changing what it means breaks every consumer. Breaking changes belong in a new version (e.g.
/v2/), with the old one kept alive for a migration period. - Security: access is controlled with API keys, OAuth or token-based schemes. The moment an interface is reachable over a network, it is part of your attack surface.
- Predictable errors: error responses share one structure and give the client enough information to fix the problem, without leaking internal details.
- Limits: rate limiting and pagination stop a single client from slowing the whole system down.
Common misconceptions
“An API is a server.” An API is the description of the doors a server opens to other software. The same server can host a website and serve an API at the same time.
“If a system has an API, integration is easy.” Having an API does not mean it exposes the data or actions you need. Before planning an integration, check that the required endpoints actually exist, what the usage limits are and how fresh the data is.
“APIs are public.” Most APIs are private: they connect a company's own mobile app to its backend, or the services inside a microservices architecture, and outsiders never see them.

