Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

An API (application programming interface) is a documented contract that lets one software component request data or functionality from another through a defined interface. The caller uses specified operations, inputs and formats; the provider returns a defined result or error while keeping its internal implementation behind the interface. APIs can be local library functions, browser capabilities or remote web services—not just internet endpoints.

That contract is the key idea. A human interface is designed for clicking, tapping and typing. An API is designed for structured calls made by software. IBM, MDN and NIST describe the term in closely related ways: a set of rules, features and a well-defined syntax that programs can use to access functionality. See IBM’s API explanation, the MDN API glossary and the NIST definition.

What does API stand for?

API stands for application programming interface. “Application” means a software program or component, “programming” means the interface is used by code, and “interface” means the defined boundary through which that code interacts with another component.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST calls an API “a system access point or library function that has a well-defined syntax” and is accessible from application programs or user code. MDN describes it as features and rules inside a program that enable interaction through software rather than a human user interface. Those definitions include interfaces that never use a network.

How an API works

Every API interaction follows the provider’s contract, although the details differ by API:

  1. Discover the operation. The developer reads documentation to find an available method, endpoint or library function.
  2. Build the call. Code supplies required arguments, parameters, headers and, where applicable, a request body.
  3. Send the request. A local call runs in the same process; a web API commonly sends an HTTP request to an endpoint.
  4. Process the response. The provider returns data or an error in the format defined by its contract.
  5. Handle failure. Production code checks status, validates returned fields, observes limits and applies an appropriate retry or user-facing error policy.

For a web API, an HTTP request normally contains a method such as GET or POST, a URL, query parameters, headers and sometimes a body. The response includes a status and data or an error. An endpoint is the digital location where an API receives calls for a resource or operation.

A simple example

Imagine a service that exposes a customer-record endpoint. Your application sends the documented HTTP method, customer identifier and authentication details. The service returns a structured record or an error such as “not found.” Your application does not need to know how the provider stores the record internally; it only needs the contract.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Types of APIs

Library and operating-system APIs

A programming-language library can expose functions for strings, files, dates or encryption. Calling one of those functions is an API interaction, but it can happen entirely on the same computer with no HTTP request. This local meaning follows the NIST definition.

Browser APIs

Web browsers expose capabilities such as Geolocation, media capture and Web Animations to JavaScript. A page calls the browser’s documented interface, and the browser mediates access to the device or rendering engine. MDN’s API glossary uses these browser examples.

Web APIs

A web API is a remote interface exposed over a network, commonly through HTTP. It may serve data, trigger an action or transform an input. Responses often use JSON or XML, but the representation is part of the individual API’s contract rather than a universal rule.

What is a REST API?

REST (representational state transfer) is an architectural style for web APIs, not a synonym for every API. A REST API generally models resources and uses HTTP methods such as GET, POST, PUT and DELETE according to the service’s documented semantics. IBM’s REST API overview describes the style and its design principles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

REST does not mandate JSON, a particular authentication scheme, pagination format or status-code policy. Two APIs can both be described as RESTful while differing in resource names, error objects, versioning and authorization. Evaluate the actual contract rather than assuming a convention is guaranteed.

REST compared with other web approaches

Question What to check in the specific API
What is modeled? Resources, actions, queries or operations
How is it called? HTTP methods, URLs, headers and request bodies
What comes back? JSON, XML or another representation; schema and status codes
How is access controlled? Authentication and authorization requirements
How does it evolve? Versioning, compatibility and deprecation policy
How is failure reported? Error fields, retry guidance and validation rules

API endpoint, request and response

An endpoint is the address at which a web API receives a request. It is usually a URL, often combined with an HTTP method: for example, a documented GET endpoint might retrieve a resource while a POST endpoint creates or starts an operation. The URL alone is not the full contract; method, parameters, headers, authentication and body rules matter too.

Query parameters commonly control filtering, pagination or output options. Headers can carry content types, credentials, conditional requests or client metadata. A request body carries structured input for methods that accept one. The response should be treated as an interface: check its status, content type and required fields before using the data.

API documentation and OpenAPI

Documentation is the practical instruction set for callers. It should identify operations, parameters, authentication requirements, request and response schemas, examples, limits and errors. The API is the callable behavior; documentation describes how to call it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenAPI is a specification for describing an HTTP API’s interface. An OpenAPI document can let developers and tools discover endpoints, parameters and capabilities and generate clients or interactive reference pages. It is not the API service itself.

Authentication, errors and reliability

Authentication proves who is making a request; authorization determines what that caller may do. Common mechanisms include an API key, bearer token or signed request, but the correct mechanism is implementation-specific. Keep secrets out of browser code and source-control repositories, use the provider’s required transport security and grant only necessary permissions.

Handle failures deliberately:

  • Validate required inputs before sending.
  • Distinguish authentication and authorization failures from missing resources and invalid data.
  • Use bounded retries only for failures the documentation identifies as transient, preferably with exponential backoff and jitter.
  • Respect rate limits and quotas; do not turn a retry loop into a traffic spike.
  • Log request identifiers and safe diagnostic details without recording credentials or sensitive payloads.

Latency and availability depend on the particular service and network path. Measure the API you depend on, set client timeouts, and provide a fallback or clear degraded experience when the dependency is unavailable. Never assume that a REST label guarantees a particular reliability level.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Concrete API example: taking a website screenshot

ScreenshotNeo is a website screenshot API and MCP server for developers. A GET request to ScreenshotNeo returns a PNG, JPEG, WebP or PDF. The endpoint, parameter name and response behavior illustrate an API contract: your code supplies an access key and URL, and the service returns the requested artifact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));

See the ScreenshotNeo documentation for the complete contract. Its 63 options include full-page capture with lazy images loaded, CSS-selector element capture, dark mode, 12 device presets and custom viewports, retina scale, PDF paper and page controls, custom CSS and JavaScript, pre-capture clicks, hidden selectors, selector/delay/network-idle waits, request and resource blocking, custom headers, cookies, user agents and Authorization, timezone and geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Parameters used by other screenshot APIs also work, easing migration.

Before capture, ScreenshotNeo can accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Only clean shots are billed. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and responses identify the result with X-Page-Verdict and X-Billed headers.

Plans

Plan Allowance and price
Free 1,000 shots/month, no card
Starter $5 for 3,000 shots
Growth $15 for 15,000 shots
Pro $39 for 60,000 shots
Scale $99 for 250,000 shots
Business $249 for 1,000,000 shots

Yearly billing gives two months free, and every feature is on every plan. An MCP server provides take_screenshot, get_page_info and capture_pdf tools to Claude, Cursor and other MCP clients, allowing AI agents to call the interface.

“API” versus “web service”

An API is the broader concept: any documented software interface, including a local library or browser capability. A web service is a network-accessible service, typically consumed over HTTP. Therefore, every web service exposes some API, but not every API is a web service. The distinction is about scope and transport, not quality.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to choose or integrate an API

  1. Define the operation your application needs and the data or side effect it requires.
  2. Read the authoritative reference for authentication, schemas, limits, status codes and errors.
  3. Try a minimal request in a non-production environment and inspect the complete response.
  4. Wrap the call in a small client with timeouts, validation, safe logging and bounded retries.
  5. Pin a documented version where available and monitor deprecation notices.
  6. Test malformed input, expired credentials, missing resources, throttling, timeouts and provider errors.

Or skip the browser setup

For website screenshots, the one-call ScreenshotNeo API avoids installing and maintaining a browser. Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed. Its MCP server lets AI agents take screenshots. You get 1,000 screenshots a month free with no card, and paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Frequently Asked Questions

Is an API always a URL?

No. A library function and a browser Geolocation interface are APIs too. URLs are typical for remote web APIs.

Does REST mean JSON?

No. REST is an architectural style. JSON, XML and other representations are choices made by the individual API contract.

Is API documentation the API?

No. The API is the callable behavior; documentation explains operations, inputs, outputs, authentication and errors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is an endpoint?

It is the digital location where a web API receives calls for a resource or operation, together with the method and rules defined by that API.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.