Development
What is an API? A plain-English guide for business owners
APIs quietly connect the software your business relies on. Here is what they are, how they work and how to use them without the jargon.
Rapid Action Team · · 10 min read

Key takeaways
- An API is a set of agreed rules that lets one piece of software ask another for data or to carry out a task.
- Most small businesses already rely on APIs every day through payments, maps, booking tools and accounting software.
- The best first API project is usually a repetitive manual task, such as copying orders or leads between systems.
- API keys are like passwords for your systems, so they should be kept private, limited in scope and changed if exposed.
- Off-the-shelf connectors suit simple jobs, while custom integrations make sense when data is complex or business-critical.
If you run a business, you have probably heard a developer or software salesperson say "we can do that through the API". It is one of those terms that gets used constantly and explained rarely, which makes it hard to judge whether a project is simple, expensive or worth doing at all.
This guide explains what an API is in plain English, shows where you are already using them, and walks through how to decide whether connecting your systems is worth the effort. No coding knowledge needed.
What is an API, in simple terms?
API stands for application programming interface. Strip away the jargon and it means this: a published set of rules that lets one piece of software talk to another.
When your website shows a map of your shop, it is not storing the whole world's geography. It sends a short message to a mapping service asking for a map centred on your postcode, and the mapping service sends one back. The API is the agreed format for that conversation: what you can ask for, how to ask, and what the answer will look like.
The counter-service analogy
Think of a busy trade counter at a builders' merchant. You do not walk into the warehouse and hunt for timber yourself. You go to the counter, ask for a specific item in a specific way, and the person behind the counter fetches it, checks you have an account, and hands it over.
- You are the software making the request (your website, your CRM, your app).
- The counter is the API.
- The warehouse is the other company's system and data, which you never see directly.
The counter protects the warehouse, keeps requests orderly and means you do not need to know how the shelves are arranged. That is exactly what an API does for software.
Why APIs exist at all
Without APIs, every pair of systems would need someone to copy information between them by hand, or a developer to build a fragile one-off connection. APIs give software companies a stable, documented doorway so that thousands of other businesses can connect safely without being given access to everything.
How does an API actually work?
Almost every API conversation follows the same pattern: a request goes out, and a response comes back. Most modern web APIs do this over the same technology your browser uses to load web pages.
A request usually contains four things:
- An address (endpoint). The specific location you are talking to, such as the "orders" section of an online shop's system.
- An action. Whether you want to read something, create something new, update it or delete it.
- Credentials. A key or token that proves you are allowed to ask.
- Details. Any information needed, such as a customer email or an order number.
The response then comes back with a status code and, usually, some data. Here is a simplified example of what a response describing an order might look like:
{
"order_id": "10452",
"status": "paid",
"total": 84.50,
"currency": "GBP",
"customer_email": "sam@example.co.uk"
}
You will never need to read this yourself, but it helps to see that the data is structured and predictable. That predictability is what lets one system reliably understand another.
Status codes worth recognising
When something goes wrong, developers often quote a number. These are standard web status codes, documented in detail on MDN's HTTP status reference. The common ones are:
| Code | What it means | What usually happened |
|---|---|---|
| 200 | OK | The request worked |
| 201 | Created | A new record was successfully added |
| 401 | Unauthorised | The key is missing, wrong or expired |
| 403 | Forbidden | The key is valid but lacks permission for this action |
| 404 | Not found | The record or address does not exist |
| 429 | Too many requests | You have hit the provider's usage limit |
| 500 | Server error | Something broke on the provider's side |
Knowing these helps you have a sensible conversation with a developer or support team, even if you never touch the code.
Examples of APIs you already rely on
Most small businesses use dozens of APIs without realising. A few everyday examples:
- Card payments. When a customer pays on your website, the checkout sends the payment details to your payment provider through an API and receives a "paid" or "declined" answer within seconds.
- Online booking. A booking widget checks your calendar through an API before offering a time slot, so you do not get double-booked.
- Accounting. Many bookkeeping tools pull bank transactions through Open Banking APIs, which the largest UK banks were required to provide following an order by the Competition and Markets Authority.
- Delivery and tracking. Courier systems create labels and return tracking numbers through APIs, which your shop can then email to customers automatically.
- Email marketing. When someone signs up on your website, an API call adds them to your mailing list.
- Address lookup. The "find address" button on a UK checkout uses a postcode lookup API.
Each of these replaces a step that someone would otherwise do by hand.

API, integration or webhook: what is the difference?
These terms get mixed up, and the difference matters when you are reading a quote.
- API. The doorway itself. Your system asks a question and gets an answer.
- Webhook. A reverse arrangement. Instead of your system repeatedly asking "anything new?", the other system sends a message to you the moment something happens, such as "a new order has just been placed".
- Integration. The finished connection that uses APIs and often webhooks to move data between two systems according to your business rules.
| API | Webhook | Integration | |
|---|---|---|---|
| Who starts the conversation | Your system asks | The other system tells you | Both, depending on design |
| Best for | Looking things up, creating records | Reacting to events quickly | Ongoing, automated workflows |
| Example | Check stock level for a product | Notify you when a payment succeeds | Sync every new web order into your accounts |
A good integration usually combines both: a webhook alerts your system that something happened, and an API call fetches the full details.
What can APIs do for a small business?
The benefits are practical rather than glamorous.
Less manual data entry
If a member of staff spends part of each day copying orders, leads or invoices from one screen to another, that is the clearest sign an API could help. Automated transfers are faster and do not make typing mistakes.
Faster service for customers
When systems talk to each other, a customer can get a confirmation, a tracking link or a booking reminder instantly instead of waiting for someone to send it manually.
One version of the truth
Disconnected systems drift apart. Your website says something is in stock while your stock spreadsheet says it is not. Connecting them through APIs keeps information consistent.
Room to grow
A business that relies on manual processes needs more people as it grows. A business whose systems are connected can handle more orders with the same team.
Do your systems have an API? How to check
Before planning anything, find out what is possible.
- Search the vendor's website for "API", "developers" or "integrations". Most established software has a developer section.
- Check your plan level. Some providers only include API access on higher-priced plans.
- Look for ready-made connections. Many tools already connect to popular accounting, CRM or email software with a few clicks.
- Read the limits. Providers often cap how many requests you can make per minute or per day.
- Ask your account manager directly if the documentation is unclear. A vague answer is useful information in itself.
If one of your key systems has no API at all, that is worth knowing before you commit to it for another few years.
Keeping API connections secure
An API key is effectively a password for your business systems. Anyone who has it can often read your customer data or create records in your name. Some basic rules:
- Keep keys on the server. Keys should never be placed in website code that visitors' browsers can see.
- Grant the minimum access. If a connection only needs to read orders, do not give it permission to issue refunds.
- Use separate keys for different tools and people, so you can switch one off without breaking everything.
- Change keys immediately if you suspect one has leaked, for example after a former contractor leaves.
- Think about personal data. If customer information moves between systems, it falls under UK GDPR, so you should know where it goes and why.
Off-the-shelf connectors or a custom integration?
There are broadly two ways to connect your systems.
No-code automation tools let you link popular apps through a visual interface. They are quick to set up and suit simple, low-volume tasks like adding new form submissions to a spreadsheet. The downsides are monthly costs that rise with usage, limited control over error handling, and workflows that can become hard to manage as they multiply.
Custom integrations are built by a developer to fit your exact process. They take longer and cost more upfront, but they handle complex logic, large volumes and important data more reliably, and you are not paying per task.
| Consideration | No-code connector | Custom integration |
|---|---|---|
| Setup time | Hours to days | Days to weeks |
| Upfront cost | Low | Higher |
| Ongoing cost | Subscription that grows with usage | Hosting and maintenance |
| Complex rules | Limited | Fully flexible |
| Error handling | Basic | Designed to your needs |
| Best for | Simple, low-risk tasks | Business-critical or high-volume data |
A sensible approach is often to prove the value with a simple connector, then move to a custom build once the process is clearly worth investing in. Our backend development team regularly helps businesses make that step.
What to ask before starting an API project
Whether you are briefing an agency or a freelancer, these questions help avoid surprises:
- What happens if one system is down when the other tries to send data?
- How will we know if the connection fails, and who gets alerted?
- Which data moves, in which direction, and how often?
- What are the provider's usage limits and costs at our expected volume?
- Who will maintain the integration when a provider updates its API?
- Where will the keys be stored, and who has access to them?
Good answers to these questions are usually a better sign of quality than a low quote.
FAQs
What does API stand for?
API stands for application programming interface. In practice, it is a set of rules that allows two software systems to exchange information or trigger actions.
Do I need to know how to code to use an API?
No. Many tools offer ready-made connections you can switch on yourself. For anything more tailored, a developer handles the technical work while you define what should happen and when.
Are APIs free?
Some are free, some are included in your software subscription, and others charge per request or require a higher plan. Always check the pricing and usage limits before building anything that depends on them.
Is using an API safe?
APIs are generally secure when set up properly, using private keys, limited permissions and encrypted connections. Most problems come from keys being shared carelessly or given more access than needed.
What happens if an API stops working?
A well-built integration should retry failed requests, log what went wrong and alert someone. If a provider changes or retires its API, the integration may need updating, which is why ongoing maintenance matters.
If you have a manual process you suspect could be automated, or you want a second opinion on connecting your website to other systems, book a call and we will talk it through in plain English.


