API development services and integration work compared

Building an API and integrating with one are different jobs. Building means committing to a contract other people depend on, which makes versioning and documentation the product. Integrating means depending on somebody else's decisions, which makes failure handling the product.

If you are building it rather than hiring API integration companies, the contract is the deliverable

Once external parties depend on your API you cannot casually change it, so design for versioning from the first release, decide what constitutes a breaking change, and write the deprecation policy before anyone needs it. Documentation is part of the product rather than an afterthought: an API that needs a phone call to use has failed. Ask a bidder how it versions and how it would remove a field two years after launch.

What an API integration company is really for: failure handling

Somebody else's service will be slow, unavailable, or will change without telling you. The code that matters is what happens then: timeouts that do not hang your system, retries with backoff, idempotency so a retry does not duplicate an effect, a queue so work is not lost, and alerting when a partner stops behaving. Ask a bidder to describe its behaviour when a third party returns errors for an hour, because that is a normal Tuesday.

Payment integration services have stricter rules than the rest

Payment work carries the PCI Data Security Standard, and the architecture that keeps it manageable is to keep cardholder data out of your systems entirely using hosted fields or tokenisation. Beyond that, payment integrations need idempotency so a retried charge does not become two, webhook handling that tolerates duplicates and out of order delivery, and reconciliation against the provider's records. Require a reconciliation report from the first release.

Own the credentials and know what they can do

Integration credentials should be held in your own accounts, scoped to the minimum permissions required and rotatable without downtime. A surprising number of integrations run on an administrative key created by someone who has left. The elements at 16 CFR 314.4 are a practical reference here: access limited by need, encryption, logging of authorised activity and an incident response plan that names who acts.

Questions people ask about api development services

What is different about building an API versus integrating with one?

Building commits you to a contract others depend on, so versioning, deprecation policy and documentation are the product. Integrating means depending on someone else's decisions, so timeouts, retries, idempotency and alerting are the product.

What should an integration do when a third party fails?

Time out without hanging your system, retry with backoff, stay idempotent so retries do not duplicate effects, queue work so nothing is lost, and alert a human. Ask a bidder to describe an hour of third party errors.

What is specific to payment integrations?

PCI DSS applies, so keep card data out of your systems with hosted fields or tokenisation. Then idempotency so a retried charge is not two charges, webhook handling tolerant of duplicates and out of order delivery, and reconciliation from release one.

Sources

Related answers

Get your agency shortlistDescribe your project