APIs Explained for Business Owners
By CodexierPublished 7 min read
Every integration quote you will ever receive depends on one thing: whether the systems involved have an API, and what that API allows. Vendors say "we have an API" the way estate agents say "close to transport". This guide explains what an API actually is, why some connections take a day and others take a month, and the five questions that tell you which case you are in before you sign anything.
What an API is, in plain terms
Think of a system such as Fortnox, HubSpot or your booking tool as a building. The web interface is the front door for people. The API is a service entrance for other programs: a set of clearly labelled doors, each of which does one thing, such as "give me the invoices from March" or "create this customer". A program knocks on a door with a request in an agreed format, and the system answers in an agreed format. Because both sides follow the same rules, a developer can write a program that moves data between your webshop and your accounting system without anyone retyping it. That is all an integration is: a program that uses two APIs and applies your business rules in between.
Why some systems connect easily
The difference between an afternoon and a month is almost entirely in the API's design and documentation. Modern SaaS products built for integration expose a REST or GraphQL API with public documentation, sandbox accounts and webhooks. Older or more closed systems offer a partial API, an export file on a schedule, or nothing but a screen. Swedish systems vary widely: Fortnox and Visma eAccounting have documented, widely used APIs; many industry-specific tools, from booking systems to workshop software, have APIs that exist on paper but are thin, undocumented or reserved for certified partners.
| What the vendor offers | What it means for you | Typical integration effort |
|---|---|---|
| Public REST API, documentation, sandbox, webhooks | Anything the API covers can be automated in near real time | Days |
| Public API, but read-only or missing key objects | You can report on data but not create or update it | Days, but with a manual step remaining |
| Partner-only API | A certified integrator must build and host it; you depend on them | Weeks, plus partner fees |
| Scheduled file export or import (CSV, SIE) | Batch sync, hours or days behind, fragile to format changes | Days to build, ongoing babysitting |
| No API, screen only | Only screen automation or manual entry; brittle and often against terms of use | Avoid, or change the system |
Webhooks matter more than they sound: without them, your integration must keep asking "anything new?" on a timer, which is slower and eats rate limits.
Limits, keys and permissions
Three technical details shape what an integration can do and how safe it is. An API key or token is the credential a program uses to prove it is allowed in; treat it like a password for the whole system, store it in a secrets manager, and give each integration its own key so one can be revoked without breaking the others. Permissions, or scopes, define what a key may do: read invoices but not create them, see contacts but not delete them. Ask for the minimum. Rate limits cap how many requests a key may make per second, minute or day; an integration that syncs a large webshop's stock every minute may hit them, and the design has to account for it.
- One key per integration, named, with an owner, revoked when the integration is retired.
- Minimum scopes: an invoice sync does not need permission to delete customers.
- Rate limits documented and respected in the design; batch and back off instead of hammering.
- Logs of what each key did, so an error or a leak can be traced to one system.
Questions to ask a vendor
Before buying any system you intend to connect to another, ask these five questions in writing and keep the answers. They take a vendor ten minutes to answer honestly and separate real integration capability from a checkbox on a feature list.
1. Is there a public API and where is the documentation?
You want a link you can open today. "Available on request" or "for partners" is a different, more expensive answer.
2. Which objects can we read and which can we write?
Ask specifically about the ones you need: customers, orders, invoices, bookings, stock. Read-only on the one you need to write is a dealbreaker.
3. Does it send events (webhooks) when something changes?
Without events, everything is polling on a schedule and real-time flows are off the table.
4. What does API access cost and what are the limits?
Some vendors charge for the API tier, cap calls per day, or require a higher plan. Get the numbers.
5. Can we get a sandbox account?
A test environment means your integration can be built and tested without touching live data.
When there is no API
Sometimes the system you depend on has no usable API and switching is not an option this year. The honest alternatives, in order of preference: a scheduled export and import if the system can produce files; an email-parsing flow if it sends notifications with the data you need; or screen automation, where a program clicks through the interface as a person would. Screen automation works until the vendor changes a button, and some terms of service forbid it. Whichever route you take, keep a person in the loop for anything that writes money-related data, and put the cost of the workaround into the case for replacing the system.
When you do not need any of this: if two systems are used by one person who moves a handful of records a week, copying by hand is cheaper than any integration and has no maintenance cost. Integrations pay when the volume is real, the delay hurts, or errors in retyping cost money. That is the work in our automation and integration optimisation service, and a messy CRM is often the first symptom; see the CRM health checklist. Whether your systems can be connected at all is usually clear within a 15-minute call.
- Automation and integration optimisationWe connect the systems you already run, with keys, scopes and error handling done properly.
- CRM health checklistIf integrations are creating duplicates and stale data, start here.
- Book a free 15-minute callName the two systems; we tell you whether the connection is a day, a month or a workaround.
Frequently asked questions
Is an API the same as an integration?
No. An API is the door a system offers; an integration is the program that walks through two of them and applies your rules in between. A vendor having an API means an integration is possible, not that it exists or is included.
Do we need a developer to use an API?
For anything beyond simple flows, yes. Tools like Zapier, Make and n8n let non-developers connect common systems through prebuilt connectors, which works for straightforward triggers and actions. Once you need mapping logic, error handling or Swedish systems the tools do not support, a developer builds and maintains it.
Is it safe to give a supplier our API keys?
Give each supplier a separate key with the minimum permissions, keep a register of who holds what, and revoke keys when the work ends. Never send keys by email; use a password manager share or the system's own key management. Under GDPR, an integrator handling personal data through your API also needs a processor agreement.
Does Fortnox have an API?
Yes, a documented one that covers customers, invoices, articles, orders and accounting data, with an app registration process. It is one of the more integration-friendly Swedish systems, which is why so many webshop and CRM connections to Fortnox exist.
Wondering whether two of your systems can talk to each other?
Fifteen minutes with an engineer: name the systems and what should flow between them, and we tell you whether the APIs allow it, what it would take and where the workaround would sit if they do not.
Book a free 15-minute call