An API (application programming interface) is a published set of rules that lets one program read or change data in another without anyone copying it across. When you buy software, it decides whether the tool can connect to your other systems, automations and AI later. Ask: is there a public API, on which plan, and what can it change?
Most owners never need to see an API, but they live with the consequences of choosing software without one: staff retyping orders, spreadsheets exported every Monday, and AI tools that can't reach the data they'd need. You don't need to become technical to avoid that. You need to read a vendor's API page for six things, know where API access hides in pricing, and send a handful of questions that expose a weak answer before you sign.
An API in plain English: the trade counter
Think of a wholesaler with a trade counter. You can't walk into the warehouse and take things off the shelves. You go to the counter, show your account card, fill in their order form, and ask only for items on their published list. The counter staff fetch what you asked for or take your order. An API is that counter, for software.
- Endpoint: one window at the counter for one kind of request, such as "orders", "customers" or "products".
- API key or token: your account card. It proves who's asking, and anyone holding it can make requests as you, so it's treated like a password.
- Read and write: asking what's in stock is a read; placing an order or changing an address is a write. Some APIs only allow reads.
- Rate limit: how many requests the counter will serve per second or per month before it asks you to wait.
- Documentation: the published list of windows, forms and rules. If it isn't published, you're relying on the vendor's word.
You'll never have to type one, but seeing a request once makes the idea concrete. Here is roughly what an automation sends to a booking system's API to ask for tomorrow's appointments, and what comes back (illustrative; every vendor's field names differ):
Request: GET /v1/bookings?date=2026-10-14&status=confirmed
Authorization: Bearer [your API key]
Response: [
{ "id": "bk_4821",
"customer_id": "cl_2290",
"service": "Full colour and cut",
"start": "2026-10-14T09:30",
"staff_id": "st_03",
"deposit_paid": true },
...
]
Everything a buyer needs to know is visible in that small exchange. "bookings" is the endpoint. The key proves who's asking. The fields that come back are the only facts another tool can ever get from this system: if "deposit_paid" weren't in the list, no automation or AI assistant could chase unpaid deposits, however clever it was. That's why the documentation check below asks whether your records, and the fields you care about, are actually there.
There's also a reverse arrangement, where the counter rings you the moment your order is ready instead of you asking repeatedly. That's a webhook, and it's why some automations run instantly while others lag; how webhooks make automations instant explains it.
Why the API decides what your software can do in two years
When you buy software, you're buying what it does today and what it can connect to later. The API governs the second part.
- Automations run on APIs. Every Zapier "Zap" or Make scenario that moves an order into your accounts is using the APIs of both apps. No API, no connector.
- AI tools reach your data through APIs. When an assistant connects to your calendar, CRM or shop, it's using an API. Whether AI can work with the tools you already use comes down, most of the time, to whether those tools expose the right data.
- Leaving depends on it. A good API lets you pull all your data out in a usable form when you switch vendors. Without one, you may be limited to exports the vendor chooses. Avoiding vendor lock-in starts with this check.
- Custom tools are built on it. If you ever pay someone to build a small tool, such as a stock alert or a quoting helper, it will talk to your systems through their APIs.
Software without an API isn't necessarily bad software. It's software where every connection to anything else is a person copying data, forever.
"Integrates with" vs "works with Zapier" vs "open API"
Sales pages use these phrases loosely. They mean very different things for you.
| What the vendor says | What it usually means | What you can do | Watch out for |
|---|---|---|---|
| "Integrates with [named app]" | The vendor built one fixed link to that app | Use that link as designed | It may sync only some fields, one way, or on a paid add-on |
| "Works with Zapier" or "on Make" | A connector exists, built on the API | Build your own automations from its triggers and actions | The connector may expose only a few actions; Zapier bills per task |
| "Open API" or "public API" | Documented access you or a developer can use directly | Anything the documentation allows | The plan it's on, rate limits, and whether writes are allowed |
| "You can export your data" | A CSV or spreadsheet download | Move data by hand | Exports may leave out history, attachments or custom fields |
A native integration and an automation connector each have their place; native integrations versus Zapier compares them for everyday connections.
Where API access hides in the price list
API access is often the difference between two plans, and it's rarely on the headline comparison. Two real examples show the patterns to look for.
- Monthly call limits by plan. Airtable's documentation lists 1,000 API calls a month on its Free plan, 100,000 on Team, and no monthly cap on Business and Enterprise Scale, with a rate limit of 5 requests per second per base on every plan (see Airtable's API call limits). A thousand calls is about 33 a day: fine for a nightly sync, nowhere near enough to update stock every time something sells. Run the sum for an illustrative candle maker that logs each online order in an Airtable base through an automation: find the product record, update its stock, add the order row. That's three calls an order, so 350 orders a month uses about 1,050 calls, and the sync would stop working in the last few days of the month on the Free plan, usually during the busiest week. On Team, the same workload uses about 1% of the allowance.
- Features gated to paid tiers. Calendly allows basic API requests on all plans, but its webhooks need a paid subscription, and a few data-deletion and activity-log endpoints are Enterprise only (see Calendly's API overview). If your automation depends on hearing about new bookings instantly, the free plan won't do.
Other patterns to look for: API access "available on request" (often meaning a sales conversation and a higher plan), per-call charges above a threshold, and AI features whose API is billed separately from the subscription. AI model APIs are the clearest case: a ChatGPT or Claude chat subscription doesn't include API use, which is billed per token on the developer platform. When you add up what a connection really costs, the four ways to connect two business apps sets the options side by side.
Connector billing can also turn a one-off job into an expensive one. Say an illustrative homeware shop moving to new stock software wants to copy its 2,000 products across, and builds a Zap that creates one product per run. Each successful action step is a task on Zapier, so that's at least 2,000 tasks, against 750 a month on the Professional plan. The import stalls a third of the way through, or needs a bigger plan for one month. For bulk moves, ask the new vendor whether it offers a spreadsheet import or will run the migration through its API directly; many do, and an import like that uses no Zapier tasks at all. Keep the automation for the ongoing trickle of new products.
Reading API documentation in 15 minutes, without being a developer
You don't need to understand code to learn a lot from a vendor's API pages. Search "[product name] API documentation" and check six things.
- Is it public? If you can read it without logging in or signing an agreement, that's a good sign. Hidden documentation often means limited or partner-only access.
- Are your records there? Look for a list of objects or resources in the menu: orders, customers, products, invoices, bookings. Check that the ones your business runs on appear.
- Can it write, or only read? Look for words like "create", "update" and "delete" next to each object, or the terms POST, PUT and PATCH, which are the technical names for writing. Read-only APIs can report but can't act.
- What are the limits? Find the "rate limits" or "usage limits" page and check whether limits differ by plan.
- Is there a webhooks section? If there is, automations can react instantly. If there isn't, anything connected will check on a timer.
- Is there a changelog? A dated list of changes and advance notice before old versions are switched off tells you the vendor takes the API seriously.
Filled in, the six checks make a short note you can file with the quote. For an illustrative roofing contractor looking at a job-management app, fifteen minutes on the documentation produced this:
| Check | What the pages showed | Verdict |
|---|---|---|
| 1. Public? | Yes, readable without logging in | Good |
| 2. Our records? | Jobs, customers, quotes and invoices listed; no "materials" or "purchase orders" | Supplier orders will stay manual |
| 3. Write access? | Create and update on jobs and customers; quotes read-only | An automation can't mark a quote as accepted |
| 4. Limits? | 120 requests a minute on every plan | Far more than a firm this size needs |
| 5. Webhooks? | "Job completed" and "invoice paid" only | No instant alert when a customer accepts a quote |
| 6. Changelog? | Last entry three years old | Ask the vendor whether the API is still maintained |
Two of those rows became questions for the sales call, and the sixth turned out to matter most: the vendor admitted a new API was "planned", which means the current one may be switched off with limited notice.
Two terms you'll meet on the way. OAuth is the "sign in and approve access" screen you've seen when connecting apps, a safer alternative to pasting a key. Scopes are the permissions a connection asks for, such as "read orders" but not "delete customers". Good APIs let you grant narrow scopes.
The approval screen is where scopes bite. Picture an illustrative estate agency trying an AI meeting-notes tool that only needs to see the calendar to know which meetings to join. The sign-in screen asks to "read, compose, send and permanently delete all your email" and "see, edit and delete all your calendars". Clicking Allow would give a trial app full control of the office inbox. The right move is to cancel, check the tool's settings or help pages for a calendar-only option, and if none exists, try it on a spare account with no client email in it. A vendor that asks for far more access than the job needs is telling you something about how carefully it builds.
Worked example: a farm shop choosing a till system
Here's an illustration. Say a farm shop sells in store, runs a café, and takes orders for a weekly veg box online. It's replacing its till system and has two finalists. The prices below are hypothetical, to show the reasoning.
- Till A, $69 a month. Integrates with one accounting package. No public API; exports sales as a spreadsheet.
- Till B, $99 a month. Public API on its standard plan, including stock levels and sales, plus webhooks for each sale and a Zapier connector.
The shop wants three things over the next year: stock levels in the till to update the online veg-box page, so it stops selling boxes it can't fill; sales data flowing into a spreadsheet for forecasting; and, later, an AI assistant that drafts the weekly veg-box email from what's actually in stock.
With Till A, a staff member copies stock counts to the website twice a week and exports sales on Mondays: say three hours a week at $16 an hour, about $2,500 a year, plus the orders the shop has to refund when the website is out of date. With Till B, the stock sync runs on a webhook, sales feed the spreadsheet automatically, and the AI email becomes possible because the stock data is reachable. The extra $30 a month costs $360 a year.
On price alone, Till A wins. On the job the shop actually needs done, Till B wins clearly, and the deciding factor was a line on its API documentation that the sales page never mentioned.
Questions to send the vendor before you sign
Ask in writing, so the answers become part of what you were sold. This takes five minutes to send and is worth doing even for inexpensive software.
Subject: API questions before we sign up
1. Do you have a public API? Please send the documentation link.
2. Which plan includes API access, and are there monthly call
limits or rate limits on that plan?
3. Which records can the API create or update (not just read)?
We particularly need: [orders / stock / customers / bookings].
4. Do you support webhooks? For which events?
5. Is there a connector for Zapier or Make, and which triggers
and actions does it include?
6. Can we export all our data, including history, through the
API or another route if we leave?
7. Are there any per-call or usage charges for the API or for
AI features used through it?
8. How much notice do you give before changing or retiring
an API version?
This sits well alongside the general checks in what to do before you buy any AI tool.
The answers are where the value is, so read them line by line. Suppose an illustrative hair salon sends the list to a booking-software vendor and gets this back:
| Question | Vendor's answer | What it means for the salon |
|---|---|---|
| 2. Which plan? | "API on Pro, $49 a month, 10,000 calls a month" | Budget for Pro, not the $29 plan on the comparison page. 10,000 calls is plenty for one salon |
| 3. What can it write? | "Clients can be created and updated. Bookings are read-only via API" | An automation can add new clients but can't move or cancel appointments. Rebooking still happens by hand |
| 4. Webhooks? | "Yes: booking created" | No "booking cancelled" event, so a waiting-list text can't fire when a slot frees up |
| 5. Zapier? | "Two triggers, one action" | Enough for "new booking, add to mailing list"; not enough for much else |
| 6. Full export? | "CSV of clients on request" | Booking history and notes may stay behind if the salon leaves. Ask whether the API can read past bookings |
None of those answers is a scandal, and the software may still be the right choice. But the salon now knows the waiting-list automation it wanted isn't possible, before it has moved three years of clients across rather than after.
Answers that should worry you
- "Yes, we have an API" with no documentation link. Ask again. If it still doesn't arrive, assume it's limited or private.
- "API access is available on Enterprise." Price the Enterprise plan now, not after you're dependent on the tool.
- "Our partners can build anything you need." Usually means paid professional services rather than access you control.
- "It's read-only for now." Fine for reports; useless if you need to update stock or create orders from elsewhere.
- "We're building one." Buy for what exists today. Roadmaps slip.
- API keys tied to one person's login. When that person leaves, every connection breaks. Look for keys you can create under a business or service account. This one usually shows up quietly. In an illustrative bookkeeping practice, the automations linking the client portal to the practice's email tool were connected through the practice manager's own login. She left, her account was switched off on her last day, and the welcome emails for new clients simply stopped. Nobody noticed for nine days, until a new client rang to ask whether their documents had arrived. The fix was a shared admin account that owns every connection, with its password in the practice's password manager.
More questions about APIs and software buying
Do I need a developer to use an API?
Usually not. Automation tools such as Zapier and Make have ready-made connectors built on thousands of apps' APIs, and you set them up by choosing options from menus. You need a developer when no connector exists for the app, when you need an action the connector doesn't offer, or when the volume of data is large enough that a small custom script is cheaper than per-task automation fees.
Is giving another tool access to my software's API a security risk?
It can be, because an API key works like a password to your data. Keep the risk small: give each connection only the permissions it needs, use keys tied to a business account rather than one person's login, store keys in a password manager, and revoke them when a tool is dropped or someone leaves. Review the list of connected apps in each system every quarter.
Does using an API cost extra?
Sometimes. Some software includes API access on every plan with usage limits, some reserves it for higher tiers, and AI models charge per token for API use. A ChatGPT or Claude chat subscription doesn't include API use; that's billed separately on the developer platform. Ask the vendor for the plan, the limits and any per-call charges in writing before you commit.
Further reads
- Questions to Ask an AI Vendor Before You Sign Anything — The wider vendor question list, beyond APIs.
- Zapier vs Make vs n8n for AI Automation: Which Fits Your Business? — Choose the automation tool that will sit on top of your APIs.
- How to Prepare Your Small Business for AI Agents — AI agents need APIs to act; see what to get ready.
- How to Brief a Developer on a Custom AI Workflow You Need — When a connector isn't enough, how to brief someone to build it.
- Per-Seat SaaS Fees vs One Custom Tool: Five-Year Costs Compared — Compare subscription costs with building one tool on an API.
- What Does the ChatGPT API Cost for a Business Automation? — What AI model APIs cost once you start connecting them.
- Is AI Too Complicated for Non-Technical Business Owners? — Four levels of AI use, from typing into a chat box to custom builds, with honest learning times and five tests for when to bring in help.
- AI Glossary for Business Owners: 50 Terms in Plain English — Fifty AI terms in plain English, grouped by where you'll meet them, each with what it means for your decisions, plus five words vendors like to stretch.
- Open-Source vs Paid AI Models: What Small Businesses Should Know — How to choose between open-weight and paid AI models: what the licences allow, how prices compare, and a tested way to decide for your own documents.
- iPaaS, Middleware or Custom Code: How Should Your Apps Connect? — iPaaS, middleware and custom code explained in plain English, with one real-shaped integration costed three ways over three years.
- What Does It Cost to Integrate AI Into Your Existing Software? — Four ways to add AI to software you already run, what each costs to build and run, and a letting agency's three quotes compared per request.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Airtable support documentation on API call limits; Calendly help pages on API and webhook plan requirements; Zapier and Make help documentation; OpenAI and Anthropic pricing pages. Checked September 2026.