What Is an API? A Plain-English Guide
An API is a defined way for software to request data or functionality from other software. Learn how requests, endpoints, HTTP, and REST fit together.
An API (Application Programming Interface) is a defined way for one piece of software to ask another for data or functionality. The API specifies what the caller can request and what it can expect in return, without requiring the caller to know how the other software is built.
For example, a weather app can ask a weather service for current conditions in a location. The app sends a request to an endpoint; the service returns data the app can display. That is software asking software.
1. What the term API means
An API is an interface: a boundary between software components with rules for interacting across it. The rules can define available operations, required inputs, output formats, errors, permissions, and other behavior. The implementation behind the interface can change while callers continue to use the documented interface.
MDN describes an API as features and rules that let software interact with a program, rather than interacting through a human user interface. NIST similarly defines it as a system access point or library function with defined syntax and functionality. MDN’s API definition and NIST’s glossary provide formal descriptions.
A menu or electrical socket can help explain the idea: you use a defined interface without controlling the machinery behind it. The analogy has limits. An actual API can specify data formats, authentication, authorization, error responses, and operational behavior.
2. A concrete example: a weather request
Imagine a weather app that shows the current conditions for a city. The app is the client, and the weather service provides an API. The client sends a request asking for weather data for a location. The service processes it and sends a response, which the app uses to update its screen.
| Part | In the weather example |
|---|---|
| Client | The weather app making the request |
| API | The documented interface and its rules |
| Endpoint | A particular address at which the service exposes an operation or resource |
| Request | The method, address, headers, and any other required inputs |
| Response | The result or error returned to the client |
The weather service might require a location and credentials. Its documentation tells the developer what endpoint to call, which inputs are accepted, how to authenticate, and what response to handle. The exact details differ by service; there is no single request format used by every API.
3. How a web API request works
- Choose a documented endpoint. An endpoint identifies a particular API operation or resource.
- Build the request. A request commonly includes an HTTP method and URL. Headers carry metadata, such as an authorization token or a requested response format. Some requests also include a body, often when submitting data.
- The service checks the request. It may check the caller’s identity, permissions, inputs, and rate or usage limits.
- Read the response. The server returns a result or an error. In HTTP, the response includes a status code; the body may contain data, an error description, or no content.
- Handle success and failure. The client should use successful results and handle errors, retries, and invalid or missing data deliberately.
HTTP is a common way to access network APIs. In this exchange, the client sends an HTTP request and receives an HTTP response. HTTP is a protocol; API is the broader idea of a software interface. See MDN’s HTTP overview.
4. API, web API, HTTP, and REST: what is the difference?
| Term | Meaning |
|---|---|
| API | A software interface with defined operations and rules. It may be local or remote, and it does not have to use HTTP. |
| Web API | An API accessed through web technologies or a network service. A browser can also expose APIs to pages without calling a third-party server. |
| HTTP | A client-server protocol used to send requests and receive responses. It is commonly used by web APIs. |
| REST | An architectural style for networked APIs, built around resources and constraints such as stateless interactions. |
A REST API is one kind of network API; it is not a synonym for every API or every HTTP API. REST describes an architectural style, while HTTP describes a protocol. People sometimes use “RESTful” loosely for an HTTP service that does not meet every REST constraint. For more, see Google Cloud’s REST API basics and MDN’s REST glossary.
APIs also exist inside a programming language or operating system, and in browser features. For instance, a program can call a library function, or a web page can use a browser API such as Web Audio. These interfaces need not be remote web services. MDN explains the distinction in its introduction to web APIs.
5. Methods, headers, bodies, and responses
HTTP methods
The method indicates the kind of operation requested. GET commonly retrieves data, and POST commonly submits data. REST-style APIs also often use PUT and DELETE. Do not infer an endpoint’s full behavior from the method alone: follow the API’s documentation.
Headers and request bodies
Headers carry metadata about a request or response. An API may use a header for authentication, content negotiation, or other service-specific settings. A request body carries submitted data when the operation requires it. Not every request has a body, and not every API uses JSON.
Status codes and response data
HTTP status codes give a broad indication of the result. A successful status does not guarantee that every field in a response is useful to your application, so validate inputs and handle missing or unexpected data. An error response can indicate a bad request, missing credentials, insufficient permissions, a missing resource, or a temporary service problem. The API documentation defines the details.
6. Authentication and authorization
Authentication establishes who or what is making a request. Authorization determines what that caller is allowed to do. They are related but different checks.
An API may be public, require an API key, use an OAuth access token, or require another access method. Some APIs expose different permissions to different callers. Never assume an endpoint is public or that every API uses keys. Consult its documentation and keep credentials out of source code intended for public distribution, browser code, and logs.
7. Using an API safely as a beginner
- Find the service’s official documentation and identify the operation that fits your task.
- Check its endpoint, method, required parameters, accepted formats, authentication rules, limits, and response examples.
- Make a small request with test data and credentials that have only the permissions needed.
- Inspect the response status and body. Handle errors and validate the data before relying on it.
- Keep secrets in a server-side secret store or environment configuration appropriate to your deployment; do not commit them to a repository.
- Plan for timeouts, temporary failures, and service limits. Retry only when appropriate for the operation, with a bounded strategy.
Documentation is part of the interface: it tells callers what they can request and what responses to expect. Google Cloud’s API design guidance discusses API definitions and design; individual API documentation remains authoritative for that service’s behavior.
8. What developers use APIs for
APIs let programs use capabilities or data exposed by other software. A mobile app may request data from its own backend, a browser page may use a browser feature, or a service may integrate with another provider. The common thread is a defined software interface, not a particular programming language, vendor, or network protocol.
For example, a developer building a reporting tool might need screenshots of web pages. A screenshot API provides a defined request interface for that task. ScreenshotNeo is a website screenshot API and MCP server: a GET request with a URL can return a PNG, JPEG, WebP, or PDF. Its API documentation is at ScreenshotNeo docs.
9. Or skip the browser setup
If your API task is capturing a website, ScreenshotNeo lets you request the result without setting up a browser yourself. This runnable cURL example saves a WebP screenshot:
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://stripe.com \
-o shot.webp
Get an API key and see the available options in the ScreenshotNeo API documentation. The same request can be made with Python:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Or with Node.js:
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://stripe.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);
ScreenshotNeo accepts cookie or consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. Responses report the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots. Every feature is on every plan. Sign up for ScreenshotNeo and get 1,000 free screenshots a month, with no card.
10. Troubleshooting API requests
| Symptom | Common cause | What to check |
|---|---|---|
| Unauthorized response | Missing, expired, malformed, or incorrectly placed credentials | Check the documented authentication scheme, credential scope, and whether the credential is being sent in the expected header or parameter. |
| Forbidden response | The caller is authenticated but lacks permission for the operation or resource | Check account permissions, token scopes, and resource access. |
| Bad request or validation error | A required parameter is missing, a value has the wrong type, or the body does not match the documented format | Compare the request with the endpoint schema and inspect the error response. |
| Not found | The endpoint path or resource identifier is wrong, or the resource is unavailable to this caller | Check the base URL, API version, path, and identifier. |
| Rate limit response | Too many requests in the service’s allowed interval | Follow the service’s limit and retry guidance; reduce request volume or use supported batching. |
| Timeout or connection failure | Network trouble, a slow service, or a client timeout that is too short | Check connectivity and service guidance; use a suitable timeout and bounded retries where safe. |
| Unexpected response format | The client assumes a format or schema not guaranteed by the endpoint | Check response headers and docs, parse defensively, and handle absent or new fields. |
Status codes and error formats vary by API. Read the response body and the service’s own documentation rather than relying on a generic assumption about a particular code.
11. Reliability, performance, and cost
An API call adds a dependency to your software. Network calls can fail or take longer than expected, and external services can enforce quotas or charge based on usage. Set timeouts, handle errors, and use retries only when they are safe and bounded. For operations that create or change data, check whether repeating a request could duplicate an action.
For performance, avoid requesting fields or records you do not need when the API supports filtering or pagination. Reuse results where the API’s caching rules allow it, and avoid unnecessary repeated calls. Do not assume a particular response time or quota: those depend on the service, endpoint, account, and current terms.
Before adopting an API, check its pricing, limits, data handling, and authentication requirements. A public API is not necessarily free, unrestricted, or suitable for sensitive data. Estimate cost from the provider’s current pricing and your expected request volume.
12. Frequently asked questions
Does an API always return JSON?
No. The response format is defined by the specific API. JSON is common in web APIs, but an API can use other formats.
Can I use an API without knowing how the service is implemented?
Yes. That is one purpose of an interface: callers use the documented operations and behavior without depending on internal implementation details.
Is an API the same thing as an SDK?
No. An API defines the interface. An SDK is a set of tools or code that can help developers use an API or platform; whether one is available depends on the provider.
Does every API need an internet connection?
No. Some APIs are local interfaces, such as library functions or operating-system and browser features. Remote web APIs require communication with a service.
Where should I start learning?
Start with the official documentation for an API you want to use, then make a small request and inspect its response. MDN’s web API introduction is a useful guide to browser and web APIs.


