API (Application Programming Interface)
Last updated:
What an API is
An API is a contract between two systems. It lists what you can ask for, how to phrase the request and what comes back. The system offering the API decides what it exposes: an online shop might let partners read products and prices but not change them. The program on the other side never sees the internal code or database, only the answers the API returns.
Most APIs on the web follow the REST style. Each kind of resource, such as products or orders, has its own address, called an endpoint, and standard HTTP methods describe the action: GET reads data, POST creates something, PUT or PATCH changes it and DELETE removes it.
How it works
A typical API call has these parts:
- Endpoint: the URL that identifies the resource, for example the address of a product search.
- Method: the HTTP verb, such as GET to read or POST to send data.
- Authentication: proof that the caller is allowed in, such as an API key, a bearer token or an OAuth access token, usually sent in a header.
- Body and response: the data sent with the request and the data returned, most often in JSON, plus a status code such as 200 for success or 404 for not found.
- Limits: most providers cap the number of requests per minute or per day. These caps are called rate limits.
Example
A customer asks a furniture store's chatbot whether a sofa is in stock in gray. The chatbot sends a GET request to the store's inventory API with the product name and color. The API answers in JSON with the stock level and delivery time, and the chatbot replies with that live information instead of quoting an outdated product page.
Why it matters for business chatbots
A chatbot trained on documents knows what was true when the content was added. APIs give it access to data that changes: stock, prices, open appointment slots or account details. Language models reach APIs through tool calling: the model asks for a call, and the application runs it.
Because the application holds the credentials, it decides which endpoints the chatbot can use and which data the model sees. Read-only access, narrow permissions and server-side credentials keep the risk low, including the risk that a manipulated message triggers a call it should not, known as prompt injection.
APIs and intoCHAT
intoCHAT does not offer a public API of its own, so there are no intoCHAT API keys for reading conversations or managing agents from your code. It works with APIs in the other direction: your agent can call yours.
- Custom API actions let the agent call your HTTP API during a chat, with any method and authentication by bearer token, basic auth, an API key in a header or query string, or custom headers.
- You can import a request from a cURL command, define inputs the agent fills from the conversation, send JSON request bodies, choose which response fields the model sees and test each action before going live. Up to 25 actions per agent.
- Connect your store creates live product-search actions from a shop's public data, with no API keys or app install.
- To get leads out, use the email alert for each new lead, sent to the owner and up to 5 more addresses, and the CSV export in the leads table.