API
An API (application programming interface) is a defined way for one piece of software to request data or actions from another. On the web, most APIs work over HTTP: a client sends a request to an endpoint (a URL) with a method such as GET or POST, and receives a response with a status code and usually JSON data. The documentation, often an OpenAPI specification, is the contract both sides rely on.
Why it matters for a PM
Integrations with payment providers, CRMs, AI models and partners all go through APIs, and their limits shape the product: rate limits, pagination, authentication, the errors they return and how old versions are retired. A PM who can read API documentation and send a test request scopes an integration accurately and writes a spec that covers the failure cases.
Example
A PM scoping a CRM integration reads the API documentation and notices that contacts can only be fetched 100 at a time, with a limit of 10 requests per second. Syncing 200,000 contacts will take time, so the spec plans an initial import in the background and incremental updates afterward.
Key points
- The frontend calls the backend through an API; the backend in turn calls third-party APIs.
- Status codes signal the outcome: 2xx for success, 4xx for a problem with the request, 5xx for a server failure.
- Authentication relies on API keys or tokens, such as OAuth 2.0 access tokens, with scopes that limit access.
- Versioning and deprecation policies tell you how long an integration will keep working.
Common mistakes
- Specifying only the success path and leaving error handling to chance.
- Ignoring rate limits until a data sync fails in production.
- Putting API keys in frontend code or in shared documents.
Go further with Module
The courses and lessons that cover this concept: