THE SHORT ANSWER

An application programming interface defines how software can request a capability and receive a response. A product might call APIs for payments, maps, email, CRM, AI models, identity or analytics. The API contract describes allowed operations and data; authentication, authorization and validation control whether a request should succeed.

Think REQUEST → SYSTEM → RESPONSE

Illustrative API exchange
StepExampleProduct concern
RequestCreate an email deliveryValid recipient, template and permission
SystemEmail service processes the operationAvailability, limits and provider behavior
ResponseAccepted, rejected or failedWhat the product records and shows next
Later eventDelivery or bounce notificationReconciliation and duplicate handling

APIs connect product capabilities

A checkout may request a payment order, a booking flow may fetch maps, a product may add a contact to a CRM, and an AI feature may send approved context to a model service. Each connection creates a dependency with its own data, permissions, cost and failure modes.

An API can read from or write to a database behind another system, but the interface and the database are separate layers.

Evidence & context: MDN Web Docs

Record the integration contract

  1. Operation and business purpose
  2. Required request fields
  3. Expected response and error states
  4. Authentication method and permission scope
  5. Rate or usage limits
  6. Timeout and retry behavior
  7. Duplicate or idempotency handling
  8. Data sensitivity and retention
  9. Owner and fallback

Keep private credentials and sensitive validation on the server

A browser is controlled by the user and its code can be inspected. Do not expose private API secrets there. The server should validate consequential requests, confirm authorization and treat external responses and webhooks as untrusted until verified.

For agent-specific integration layers, read Agents, Tools, APIs and MCP. For identity and permissions, continue to authentication and authorization.

Evidence & context: OWASP Foundation · OWASP Foundation

Sources & further reading

  1. Introduction to web APIs

    MDN Web Docs. Standards-oriented introduction to interfaces that expose capabilities. Product APIs vary in transport, authentication, limits and guarantees.

  2. How the web works

    MDN Web Docs. Standards-oriented learning material on clients, servers, DNS, HTTP and browser rendering. It is a simplified conceptual introduction rather than a complete architecture guide.

  3. Authorization Cheat Sheet

    OWASP Foundation. Security guidance emphasizing least privilege, deny-by-default behavior and authorization checks on every request. Implementation details depend on the application's threat model.

  4. Secrets Management Cheat Sheet

    OWASP Foundation. Security guidance on secret creation, storage, distribution, rotation and revocation. It supports the principle that private credentials do not belong in public client code.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗