Websites and Tech

Application Programming Interface (API)

Also called API

A defined way for one piece of software to request data from another, or ask it to do something, without a person clicking through screens.

Quick facts: Application Programming Interface (API)

Category
Websites and Tech
Also called
API
Level
Intermediate
Affects
Conversion tracking accuracy, automation, reporting, data protection compliance
Where to see it
Platform developer documentation, Zapier or Make, Postman, CRM integration settings, Google Ads and Meta Events Manager diagnostics
In this article4
  1. How an API works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

An application programming interface (API) is a defined way for one piece of software to request data from another, or ask it to do something, without a person clicking through a screen. When your booking system sends a new lead into your CRM, or your online shop reports a sale to Meta, an API is usually doing the work.

How an API works

The software that offers the API publishes rules: which addresses (endpoints) you can call, what you must send, and what you get back. A request usually names an endpoint, says what action to take (read some data, create a record, update one), and includes a key or token proving who is asking. The reply typically comes back as structured data in JSON format, which another program can read straight away.

Most marketing APIs follow the REST style, which uses ordinary web addresses and methods. A webhook works the other way round: instead of you asking for data, the other system sends it to you the moment something happens, such as a new form submission. Tools such as Zapier and Make sit between hundreds of APIs, so you can connect them without writing code.

APIs come with limits. Most cap how many requests you can make in a period, require you to re-authorise access from time to time, and retire old versions on a published schedule.

Why it matters

Marketing now depends on systems talking to each other. A few common examples:

  • The Meta Conversions API sends purchases and leads from your server to Meta, so tracking holds up better when browsers block cookies.
  • The Google Ads API lets software upload offline conversions, such as deals marked as won in your CRM, so bidding learns which leads turn into customers.
  • The Search Console API exports far more search query data than the download button in the interface.
  • CRMs, email platforms and booking systems pass contacts and events between each other through their APIs.

There is a UK GDPR angle too. Sending customer data to an ad platform through an API is still a transfer of personal data, even when emails are hashed first. You need a lawful basis, the right consent where PECR applies, and the transfer should appear in your privacy policy and records.

Common mistakes

  • Exposing keys. Pasting an API key into website code that anyone can read, or into a shared spreadsheet.
  • One all-powerful key for everything, rather than separate, limited access for each tool.
  • No monitoring. Integrations break silently when a token expires or a version is retired, and nobody notices until a report looks wrong weeks later.
  • Double counting. Sending the same conversion through a pixel and an API without a shared event ID to de-duplicate them.
  • Sending data before consent has been given.

How to act on it

List the places your data needs to flow, such as form to CRM, CRM to ad platforms and shop to analytics, and check whether each one is working today. Prefer the built-in integrations your platforms already offer before building anything custom. Store keys in the tool’s secure settings, give each connection only the access it needs, and set an alert or a weekly check on anything that sends conversions.

Write down what each integration does and who owns it, so it survives a change of staff or agency. Connecting conversion data to the ad platforms properly is a core part of how I run performance marketing.

Do and do not

Do

  • List and check every data flow between your systems
  • Give each key only the access it needs
  • Set alerts on integrations that send conversions

Do not

  • Put API keys in public website code
  • Send the same conversion twice without de-duplication
  • Pass personal data to platforms before consent

Questions people ask about this

Do I need a developer to use an API?

Not always. Many platforms connect to each other through built-in integrations, and tools such as Zapier and Make let you link APIs with no code. You need a developer when there is no ready-made connection, when the volume of data is large, or when the integration handles sensitive data and needs careful security.

Is an API key the same as a password?

In effect, yes. Anyone who has your API key can do whatever that key is allowed to do, often without any further check. Keep keys out of public website code and shared documents, give each one the narrowest access it needs, and revoke any key that may have been exposed.

Why does my API integration keep breaking?

The usual causes are expired tokens that need re-authorising, an API version that the provider has retired, a changed field name in one of the connected systems, or hitting a rate limit. Check the error log in whichever tool runs the connection, and set up an alert so failures are noticed the same day.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.