codexier.

Integrations & CRM

APIs Explained for Business Owners

By CodexierPublished 7 min read

Every integration quote you will ever receive depends on one thing: whether the systems involved have an API, and what that API allows. Vendors say "we have an API" the way estate agents say "close to transport". This guide explains what an API actually is, why some connections take a day and others take a month, and the five questions that tell you which case you are in before you sign anything.

What an API is, in plain terms

Think of a system such as Fortnox, HubSpot or your booking tool as a building. The web interface is the front door for people. The API is a service entrance for other programs: a set of clearly labelled doors, each of which does one thing, such as "give me the invoices from March" or "create this customer". A program knocks on a door with a request in an agreed format, and the system answers in an agreed format. Because both sides follow the same rules, a developer can write a program that moves data between your webshop and your accounting system without anyone retyping it. That is all an integration is: a program that uses two APIs and applies your business rules in between.

Why some systems connect easily

The difference between an afternoon and a month is almost entirely in the API's design and documentation. Modern SaaS products built for integration expose a REST or GraphQL API with public documentation, sandbox accounts and webhooks. Older or more closed systems offer a partial API, an export file on a schedule, or nothing but a screen. Swedish systems vary widely: Fortnox and Visma eAccounting have documented, widely used APIs; many industry-specific tools, from booking systems to workshop software, have APIs that exist on paper but are thin, undocumented or reserved for certified partners.

What the vendor offersWhat it means for youTypical integration effort
Public REST API, documentation, sandbox, webhooksAnything the API covers can be automated in near real timeDays
Public API, but read-only or missing key objectsYou can report on data but not create or update itDays, but with a manual step remaining
Partner-only APIA certified integrator must build and host it; you depend on themWeeks, plus partner fees
Scheduled file export or import (CSV, SIE)Batch sync, hours or days behind, fragile to format changesDays to build, ongoing babysitting
No API, screen onlyOnly screen automation or manual entry; brittle and often against terms of useAvoid, or change the system

Webhooks matter more than they sound: without them, your integration must keep asking "anything new?" on a timer, which is slower and eats rate limits.

Limits, keys and permissions

Three technical details shape what an integration can do and how safe it is. An API key or token is the credential a program uses to prove it is allowed in; treat it like a password for the whole system, store it in a secrets manager, and give each integration its own key so one can be revoked without breaking the others. Permissions, or scopes, define what a key may do: read invoices but not create them, see contacts but not delete them. Ask for the minimum. Rate limits cap how many requests a key may make per second, minute or day; an integration that syncs a large webshop's stock every minute may hit them, and the design has to account for it.

  • One key per integration, named, with an owner, revoked when the integration is retired.
  • Minimum scopes: an invoice sync does not need permission to delete customers.
  • Rate limits documented and respected in the design; batch and back off instead of hammering.
  • Logs of what each key did, so an error or a leak can be traced to one system.

Questions to ask a vendor

Before buying any system you intend to connect to another, ask these five questions in writing and keep the answers. They take a vendor ten minutes to answer honestly and separate real integration capability from a checkbox on a feature list.

1. Is there a public API and where is the documentation?

You want a link you can open today. "Available on request" or "for partners" is a different, more expensive answer.

2. Which objects can we read and which can we write?

Ask specifically about the ones you need: customers, orders, invoices, bookings, stock. Read-only on the one you need to write is a dealbreaker.

3. Does it send events (webhooks) when something changes?

Without events, everything is polling on a schedule and real-time flows are off the table.

4. What does API access cost and what are the limits?

Some vendors charge for the API tier, cap calls per day, or require a higher plan. Get the numbers.

5. Can we get a sandbox account?

A test environment means your integration can be built and tested without touching live data.

When there is no API

Sometimes the system you depend on has no usable API and switching is not an option this year. The honest alternatives, in order of preference: a scheduled export and import if the system can produce files; an email-parsing flow if it sends notifications with the data you need; or screen automation, where a program clicks through the interface as a person would. Screen automation works until the vendor changes a button, and some terms of service forbid it. Whichever route you take, keep a person in the loop for anything that writes money-related data, and put the cost of the workaround into the case for replacing the system.

When you do not need any of this: if two systems are used by one person who moves a handful of records a week, copying by hand is cheaper than any integration and has no maintenance cost. Integrations pay when the volume is real, the delay hurts, or errors in retyping cost money. That is the work in our automation and integration optimisation service, and a messy CRM is often the first symptom; see the CRM health checklist. Whether your systems can be connected at all is usually clear within a 15-minute call.

Frequently asked questions

Is an API the same as an integration?

No. An API is the door a system offers; an integration is the program that walks through two of them and applies your rules in between. A vendor having an API means an integration is possible, not that it exists or is included.

Do we need a developer to use an API?

For anything beyond simple flows, yes. Tools like Zapier, Make and n8n let non-developers connect common systems through prebuilt connectors, which works for straightforward triggers and actions. Once you need mapping logic, error handling or Swedish systems the tools do not support, a developer builds and maintains it.

Is it safe to give a supplier our API keys?

Give each supplier a separate key with the minimum permissions, keep a register of who holds what, and revoke keys when the work ends. Never send keys by email; use a password manager share or the system's own key management. Under GDPR, an integrator handling personal data through your API also needs a processor agreement.

Does Fortnox have an API?

Yes, a documented one that covers customers, invoices, articles, orders and accounting data, with an app registration process. It is one of the more integration-friendly Swedish systems, which is why so many webshop and CRM connections to Fortnox exist.

Wondering whether two of your systems can talk to each other?

Fifteen minutes with an engineer: name the systems and what should flow between them, and we tell you whether the APIs allow it, what it would take and where the workaround would sit if they do not.

Book a free 15-minute call