# What Is an API? A Plain-English Guide for Business

Source: https://dijituldevelopments.co.uk/guides/what-is-an-api/
Updated: 2026-10-10

> An API (application programming interface) is a defined way for one piece of software to ask another for data or to do something, such as creating an invoice in Xero or taking a payment through Stripe. dijitul builds API integrations and custom APIs for UK businesses, with a fixed-price quote after a free chat.

## Key facts

- An API is a contract: send a request in an agreed format, get a predictable response
- Most business APIs are REST over HTTPS and exchange JSON
- GraphQL APIs, such as Shopify's Admin API, let you ask for exactly the fields you need
- Access is controlled with API keys or OAuth 2.0 tokens
- APIs have rate limits, versions and change over time
- Webhooks are the reverse: the other system calls you when something happens

## An API in one paragraph

Think of an API as a counter in a shop. You cannot walk into the stockroom, but you can ask at the counter for a specific thing, in a specific way, and get it back in a predictable form. Software works the same way. Your website cannot reach into Xero's database, but it can send Xero's API a request like "create this invoice for this customer" and receive a reply saying it worked, with the invoice number. That is how ecommerce shops post sales to accounts, how booking systems take card payments and how dashboards pull data from several systems at once.

## How an API request works

Most business APIs follow the REST style over HTTPS:

- **An endpoint**, which is a URL for a type of thing, such as invoices or customers.
- **A method**: GET to read, POST to create, PUT or PATCH to update, DELETE to remove.
- **A body**, usually JSON, containing the data you are sending.
- **Authentication**, proving who is asking.
- **A response** with a status code (200 means fine, 401 means not authorised, 429 means slow down) and JSON data.

Some APIs use **GraphQL** instead, where one endpoint accepts a query describing exactly which fields you want. Shopify's Admin API is the best-known UK ecommerce example.

## Keys, OAuth and why security matters

Simple APIs use an **API key**, a long secret string sent with each request. It must live on the server, never in a web page or a public code repository. Accounting and Microsoft 365 APIs use **OAuth 2.0**: a person approves access once, and the integration receives short-lived access tokens plus refresh tokens. The Xero API, QuickBooks Online API, HMRC's MTD APIs and Microsoft Graph all work this way. Tokens expire, so integrations must refresh them reliably and store them encrypted.

## What can go wrong with APIs

- **Rate limits.** Most APIs cap how many calls you can make per minute or day. Integrations should queue and batch work.
- **Timeouts and duplicates.** If a request times out, did it succeed? Good integrations use idempotency keys (Stripe supports them directly) or check before retrying.
- **Version changes.** Providers retire old versions. Shopify, for example, releases dated API versions and retires old ones on a schedule.
- **Silent failures.** Without logging and alerts, a broken integration can go unnoticed for weeks.

For changes that should reach you instantly, APIs often provide webhooks.

## A real example, step by step

Here is what happens, in API terms, when an online shop sells something and the sale reaches the accounts:

- The customer pays on the website. The site calls the **Stripe API** to create a Payment Intent, a record of the payment being attempted. Stripe returns an ID and handles the card details itself, so they never touch your server.
- When the payment succeeds, Stripe sends your site a **webhook** saying so. Your site checks the signature to confirm it really came from Stripe.
- Your site sends a POST request to the **Xero API** with JSON describing the invoice: contact, line items, account codes, VAT. It includes an OAuth 2.0 access token proving it has permission.
- Xero replies with a status of 200 and the new invoice's ID. Your site saves that ID against the order.
- Your site sends another request to record the payment against the invoice.
- If Xero replies with 429 (too many requests), your site waits and tries again later from a queue, rather than giving up.

Nobody retyped anything, and the accounts are up to date within seconds. Every step is logged, so if something goes wrong, someone can see exactly which request failed and why.

The same pattern, with different APIs, powers stock syncs between Shopify and a warehouse, new leads flowing from a website form into a CRM, and calendar bookings appearing in Outlook through Microsoft Graph. Once you see a business process as a series of requests and responses, it becomes much easier to spot where an API could remove manual work.

## Using APIs in your business, and when to talk to us

If staff copy data from one system to another, an API can probably do it for them. Common projects include website orders into accounts, CRM contacts into email tools, stock levels between a warehouse system and Shopify, and giving your own customers or partners an API into your system. dijitul handles both sides: API integration with other people's systems and API development for your own. We start with a free chat and give a fixed-price quote.

## FAQs

### What does API stand for?

Application programming interface. It is the set of rules that lets one piece of software request data or actions from another, such as a website asking Xero to create an invoice or asking Stripe to take a payment.

### What is the difference between an API and an integration?

The API is the door another system provides. The integration is the software you build that uses that door: it decides what data to send, when, how to map fields and what to do when something fails. dijitul builds integrations on top of APIs.

### What is the difference between REST and GraphQL?

REST APIs expose many URLs, one per type of thing, each returning a fixed shape of data. GraphQL uses one endpoint where you describe exactly the fields you need. GraphQL can reduce the number of calls; REST is simpler and more widespread.

### Are APIs secure?

They can be, when built properly: HTTPS everywhere, secrets stored on the server, OAuth 2.0 for user access, least-privilege scopes, input validation, rate limiting and logging. Most API breaches come from leaked keys or missing permission checks, not the API idea itself.

### Can dijitul build an API for our own software?

Yes. dijitul builds REST and GraphQL APIs for business systems so customers, partners or your own apps can connect, with authentication, rate limits, versioning and documentation. It starts with a free chat and a fixed-price quote.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
