What is an API? The 2026 Explainer
An API is a contract between two pieces of software. Here is what that means in plain English, what a real API call looks like, and the five types you will run into in 2026.
On this page3 sections
Every app you use today is held together by APIs. Most people who write code can give you a fuzzy answer for what one is. Here's a sharper one.
An API (Application Programming Interface) is a contract between two pieces of software. One side promises to accept certain requests in a specific shape. The other side gets to make those requests and rely on the response shape. That's it.
When you open Instagram, the app is making API calls to Meta's servers. When your accountant's software pulls your bank transactions, that's an API call. When ChatGPT books you a flight, it's calling a flight API behind the scenes.
The shape of a typical API call
Most APIs you'll touch today are HTTP-based. A request looks like this:
GET https://api.stripe.com/v1/customers/cus_123
Authorization: Bearer sk_test_...
Stripe's server reads that, looks up customer cus_123, and sends back JSON:
{ "id": "cus_123", "email": "alice@example.com", "created": 1715200000 }
Four things to notice:
- Verb (
GET): what you want to do - URL: where to send it
- Headers: auth and metadata
- Body: the data you're sending (omitted on
GET)
Types of APIs you'll run into
| Type | What it is | When to use |
|---|---|---|
| REST | The default. URLs map to resources, verbs map to actions. | Almost anything public-facing. |
| GraphQL | One endpoint, you describe exactly the fields you want. | Complex front-ends with nested data. |
| gRPC | Binary, fast, type-safe. | Internal service-to-service calls. |
| Webhooks | Reverse direction. The server calls you when something happens. | Notifications, event streams. |
| MCP | An API designed specifically for AI models to discover and call. | Giving an LLM access to your system. |
What "calling an API" actually involves
Three skills:
- Reading the docs to find the right endpoint
- Authenticating (usually a token in the
Authorizationheader) - Sending the request and parsing the response
You can do all three with curl, with a library in your language, or with a tool like PreMan that lets you paste a URL and click Run. For a beginner, the last option means you can learn the request/response loop without fighting your terminal.
Bring the loop to your API
Catch the regression. Open a verified fix.
Join the waitlist to see which users a release may affect, monitor endpoints in production, and prepare a reviewable fix PR when something breaks.