Skip to content
Module
Tech

API

An API (application programming interface) is a defined way for one piece of software to request data or actions from another. On the web, most APIs work over HTTP: a client sends a request to an endpoint (a URL) with a method such as GET or POST, and receives a response with a status code and usually JSON data. The documentation, often an OpenAPI specification, is the contract both sides rely on.

Why it matters for a PM

Integrations with payment providers, CRMs, AI models and partners all go through APIs, and their limits shape the product: rate limits, pagination, authentication, the errors they return and how old versions are retired. A PM who can read API documentation and send a test request scopes an integration accurately and writes a spec that covers the failure cases.

Example

A PM scoping a CRM integration reads the API documentation and notices that contacts can only be fetched 100 at a time, with a limit of 10 requests per second. Syncing 200,000 contacts will take time, so the spec plans an initial import in the background and incremental updates afterward.

Key points

  • The frontend calls the backend through an API; the backend in turn calls third-party APIs.
  • Status codes signal the outcome: 2xx for success, 4xx for a problem with the request, 5xx for a server failure.
  • Authentication relies on API keys or tokens, such as OAuth 2.0 access tokens, with scopes that limit access.
  • Versioning and deprecation policies tell you how long an integration will keep working.

Common mistakes

  • Specifying only the success path and leaving error handling to chance.
  • Ignoring rate limits until a data sync fails in production.
  • Putting API keys in frontend code or in shared documents.

Go further with Module

The courses and lessons that cover this concept: