THE SHORT ANSWER
An API lets one system request data or an action from another. A webhook lets one system notify another when an event occurs. An integration combines these mechanisms, mappings, authentication and business rules into a working connection.
API asks; webhook announces
| Concept | Plain-English role | Example |
|---|---|---|
| API | Request information or an action | CRM asks an email platform to add a contact |
| Webhook | Notify another system that something happened | Payment gateway announces a captured payment |
| Integration | The complete connected flow | Form validates, stores, confirms and routes a registration |
Define the contract between systems
- Which event starts the flow?
- Which fields move, and how are they mapped?
- How is identity matched?
- How is access authenticated?
- What happens on retry or duplicate delivery?
- Where are failures logged and resolved?
Protect the connection
Use least privilege, keep API keys and signing secrets out of client code, validate incoming events and restrict sensitive data. A convenient connector does not remove these responsibilities.
For deeper technical literacy, read APIs Explained and Authentication & Permissions.
Evidence & context: OWASP Foundation
Apply the idea to one real workflow
Choose one current workflow. Record the present outcome, the proposed change, the accountable owner, the most important exception or failure, and one before-and-after measure. Test the smallest safe version before expanding it.
Sources & further reading
- Introduction to web APIs
MDN Web Docs. Standards-oriented introduction to interfaces that expose capabilities. Product APIs vary in transport, authentication, limits and guarantees.
- Function calling
OpenAI Developers. Official documentation for model-selected function calls. The application, not the model, executes custom functions and must validate arguments, permissions and results.
- Secrets Management Cheat Sheet
OWASP Foundation. Security guidance on secret creation, storage, distribution, rotation and revocation. It supports the principle that private credentials do not belong in public client code.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗