APIs, explained
What's actually happening when your code talks to a service.
An API is a way for one program to ask another program for something. On the web that's almost always HTTP: you send a request to a URL, you get a response back.
The four parts of a request
Method — what kind of operation. GET to read, POST to create, PUT/PATCH to update, DELETE to remove. The method carries meaning, and services rely on it.
URL — what you're operating on, plus any query parameters.
Headers — metadata about the request. Authentication, what format you're sending, what format you want back.
Body — the data, for methods that carry one. Usually JSON.
Reading the response
Status code first. 2xx succeeded, 3xx redirected, 4xx you did something wrong, 5xx they did.
Learn to distinguish 401 (I don't know who you are) from 403 (I know, and no) — they point at completely different fixes.
Body second, usually JSON. Note that error responses have a different shape from success responses, which is why code that assumes the success shape crashes on errors.
The rules for calling one
Always handle failure. The network fails, services go down, rate limits trigger. Code with no error path will break, and when it does it'll break silently.
Set a timeout. Without one, a hanging request hangs forever.
Retry only what's retryable. 429 and 5xx, with exponential backoff. Never retry a 400 — that's your bug, and retrying it forever gets you banned.
Check the status before parsing. Parsing an error page as JSON produces a confusing error a long way from the real cause.
Never put the key in browser code. If it must be secret, the call goes through your own server.
I need to call <API> to <do what>. Here are the relevant docs: <paste> Write the integration with: - Authentication as the docs specify, key from an environment variable. - Timeout, and retry with backoff on 429 and 5xx only. - Status checked before parsing; error responses handled separately. - Errors that tell me what happened, without leaking the key. Then tell me: what does this cost per call, what's the rate limit, and what happens to my app when this service is down?
Read the API's error documentation before writing the happy path. It tells you what your code actually has to handle, which is usually more than you assumed.