Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A web API is a software interface that lets one program use data or capabilities provided by another program. In web development, the phrase usually means either an API built into a browser, such as the DOM or Fetch API, or an API exposed by an online service, such as a weather or payments service. It is a contract describing what software can request, how it must ask, and what response it will receive.

That definition is broader than “a URL” and broader than “REST.” A web API can contain objects, methods, events, permissions and rules. HTTP URLs are common for service APIs, but the interface—not the transport alone—is the API.

What “web API” means

MDN Web Docs defines an API as “a set of features and rules that exist inside a software program … enabling interaction with it through software—as opposed to a human user interface.” In practical terms, an API is the software-facing contract between a provider and a caller.

The provider documents operations, inputs, outputs, errors, authentication and limits. Your code follows that contract instead of manipulating the provider’s internal implementation. The provider can change its internals while preserving the documented interface.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two meanings you will see most often

  • Browser API: functionality supplied by the browser and exposed to page code. The DOM lets JavaScript read and change document content; Web Audio provides audio-processing functions; storage APIs retain data in a browser. These are interfaces layered on JavaScript, not part of the JavaScript language itself.
  • Third-party or web-service API: operations or data exposed by an external service. A page can call a mapping, payment, search or weather service and use the returned result in its own interface.

MDN’s introduction to web APIs explains this distinction and the security rules around it.

How an HTTP-backed API call works

For an online service, a client sends an HTTP request and a server sends an HTTP response. HTTP is client-server and stateless at its core; cookies can add session state.

  1. Choose an operation. The API documentation identifies an endpoint and an HTTP method such as GET, POST, PUT or DELETE.
  2. Build the request. Include the URL path, query parameters, headers and, where applicable, a body. An authorization header or API key commonly identifies the caller.
  3. Send it. A browser, server program, mobile app, command-line client or another service can be the client.
  4. Read the response. The response contains an HTTP status code, headers and optionally a body, often JSON. Your code must handle success and failure statuses explicitly.

The MDN HTTP overview describes request and response messages in detail. An API may use HTTP without being REST, and REST is only one architectural style for HTTP services.

Request parts

Part Purpose Example
Method States the intended operation GET to retrieve data
URL and path Identifies the service and resource https://api.example.com/v1/forecast
Query parameters Filters or options encoded in the URL ?city=Paris
Headers Metadata, credentials and content negotiation Authorization, Accept
Body Input data for methods such as POST JSON describing a new record

Using a browser API with Fetch

Fetch is itself a browser API for making network requests. It returns a Promise that resolves to a Response when response headers arrive. A resolved Promise does not mean the HTTP operation succeeded; inspect response.ok or response.status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
async function loadForecast() {
  const response = await fetch('/api/forecast?city=Paris');

  if (!response.ok) {
    throw new Error(`Request failed: ${response.status}`);
  }

  const forecast = await response.json();
  document.querySelector('#forecast').textContent = forecast.summary;
}

loadForecast().catch(error => {
  document.querySelector('#forecast').textContent = error.message;
});

The Fetch API documentation covers fetch(), Request and Response.

What the browser may block

Browser APIs can require HTTPS, a secure context or explicit user permission. Cross-origin requests are also governed by browser security policy, including CORS. Support differs by feature and browser. For example, MDN labels the Network Information API “Limited availability,” and it does not work in some widely used browsers.

These constraints apply to the particular API, not to the word “API” generally. Check current browser documentation before relying on a feature.

Web-service APIs: authentication, data and limits

An external API has provider-specific rules. Before integrating one, verify:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Authentication: API key, OAuth token, signed request or another credential. Keep secret credentials on your server, not in publicly delivered JavaScript.
  • Format: JSON, XML, binary data, images, files or a streaming response.
  • Limits and billing: quotas, rate limits, per-request charges, monthly allowances and overage behavior.
  • Errors: status codes, error-body format, retry guidance and idempotency rules.
  • Reliability: timeouts, maintenance behavior, pagination, versioning and fallback options.
  • Data handling: what information is collected, retained or shared and whether regional requirements apply.

There is no universal “best web API.” Compare the capability, compatibility, permissions, authentication, response format, limits, reliability and terms for your actual workload. The provider’s current documentation is authoritative for those values.

What web APIs are used for

  • A browser API can update a page with the DOM, store a preference, request a user’s location or process audio.
  • A website can call a weather API, then render the returned forecast.
  • A backend can use payment, shipping, identity, search or messaging APIs without exposing provider secrets to the browser.
  • An automation service can submit jobs, poll their status and download generated files through an API.

In each case, the API defines the allowed interaction. The human interface may be a webpage, but the API is the machine-readable path behind it.

A concrete web API: ScreenshotNeo

ScreenshotNeo is a website screenshot API and MCP server. A GET request to https://api.screenshotneo.com/v1/shot returns a PNG, JPEG, WebP or PDF for a supplied URL. Before capture it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and whether the request was billed.

Call it with cURL

curl -G "https://api.screenshotneo.com/v1/shot" 
  -d access_key=YOUR_API_KEY 
  --data-urlencode url=https://stripe.com 
  -o shot.webp

Call it with Python

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Call it with Node.js

const q = new URLSearchParams({
  access_key: 'YOUR_API_KEY',
  url: 'https://stripe.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const bytes = Buffer.from(await res.arrayBuffer());
await require('node:fs').promises.writeFile('shot.webp', bytes);

See the ScreenshotNeo API documentation for parameters and response headers. It supports full-page captures with lazy images, CSS-element capture, dark mode, 12 device presets plus custom viewports, retina scale, PDF paper and page options, custom CSS and JavaScript, clicks, waits, blocked resources, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, asynchronous jobs with signed webhooks, bulk capture for up to 100 URLs per call, usage information and an OpenAPI specification. Parameter names used by other screenshot APIs also work, easing migration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plans and billing

Plan Allowance Price
Free 1,000 shots/month Free, no card
Starter 3,000 shots $5
Growth 15,000 shots $15
Pro 60,000 shots $39
Scale 250,000 shots $99
Business 1,000,000 shots $249

Yearly billing gives two months free, and every feature is included on every plan. ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

Or skip the browser setup

Use the one-call example above when you need a clean capture without configuring a browser. Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed. The MCP server lets AI agents take screenshots. You get 1,000 screenshots a month free with no card, and paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common misconceptions

“An API is just a URL”

A URL identifies a network resource, but an API also includes methods, parameters, headers, response formats, errors and rules. Browser APIs may not use URLs at all.

“Every API is REST”

REST is one design style. Other HTTP interfaces use different conventions, and browser APIs consist of objects, methods, events and permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“A successful fetch Promise means success”

Fetch resolves when it receives response headers, including for many HTTP errors. Check the status before parsing or using the body.

“Browser and service APIs have the same constraints”

Browser APIs are subject to secure-context, permission, compatibility and cross-origin rules. Service APIs have provider-specific authentication, quotas, terms and availability.

How to choose an API for a project

  1. Define the exact capability or data you need.
  2. Decide whether a browser API can provide it or whether a server-side service is required.
  3. Read the current documentation for authentication, supported environments, request and response schemas, limits and pricing.
  4. Test normal responses, malformed input, unauthorized requests, rate limits, timeouts and provider errors.
  5. Plan retries, caching, logging, monitoring and a fallback where failure would affect users.
  6. Review privacy, permission and data-retention implications before production use.

Learning the DOM, events, asynchronous JavaScript and Fetch gives a foundation for browser APIs. For external services, add HTTP, JSON, authentication, versioning and error handling. MDN’s client-side web APIs guide provides a structured starting point.

Frequently Asked Questions

Is an API a programming language?

No. An API is an interface and contract. JavaScript, Python and other languages can call the same API when they can follow its documented rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a web API return something other than JSON?

Yes. APIs can return HTML, XML, images, PDFs, binary files or streams as well as JSON. The response headers and documentation specify the format.

Do I always need a backend to use an API?

No. Browser-safe APIs can be called from frontend code. A backend is needed when credentials must remain secret, browser security blocks the request, or server-side processing is more appropriate.

What should I do when an API call times out?

Set a sensible client timeout, record the request and response context, follow the provider’s retry guidance, and avoid blindly repeating non-idempotent operations.

The Bottom Line

A web API is the documented software contract that lets programs interact. Browser APIs provide capabilities inside the browser; web-service APIs expose operations or data over a network. Learn the specific API’s methods, security requirements, response format, limits and failure behavior rather than assuming every API works the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.