An API (application programming interface) is how one piece of software asks another for data or for an action: your website asking a payment gateway to take a payment, a shipping service for a tracking status, or an SMS provider to send an OTP. This handbook covers the basics every business owner and beginner developer needs, shows a first API call, and points to our in-depth guides for each topic.
This page is the starting point. For choosing between REST, GraphQL, gRPC and webhooks, read Mastering API architectures. For keys, OAuth 2.0 and tokens, read The evolution of API authentication. For testing, read API testing with Postman.
An API call is an HTTPS request to an endpoint URL, with a method (GET, POST, PUT, PATCH, DELETE), headers such as an API key, and usually a JSON body; the reply is a status code plus JSON. Most business APIs are REST over HTTPS. Keep API keys on the server, never in browser code, handle errors and rate limits, and verify webhook signatures. On Domain India cPanel hosting, PHP's cURL works for calling APIs; requests that run longer than about 90 seconds are cut off.
1. What an API is, in one example
Think of a restaurant. You (the client) don't walk into the kitchen (the other system's database). You give an order to the waiter (the API) in an agreed format, and the waiter brings back what you asked for, or an explanation of why not.
Every modern integration works this way: UPI and card payment gateways, GST and e-invoicing services, courier tracking, WhatsApp Business messaging, maps, AI models. Each provider publishes documentation describing its endpoints, the data it expects and what it returns.
2. The parts of an API call
| Part | What it is | Example |
|---|---|---|
| Endpoint | The URL you call | https://api.example.com/v1/orders |
| Method | What you want to do | GET reads, POST creates, PUT or PATCH updates, DELETE removes |
| Headers | Metadata such as credentials and format | Authorization: Bearer YOUR_KEY and Content-Type: application/json |
| Query parameters | Filters in the URL | ?status=paid&page=2 |
| Body | The data you send, usually JSON | {"amount": 49900, "currency": "INR"} |
| Response | A status code plus data | 201 Created with the new order as JSON |
The status code tells you what happened before you read the body:
3. Make your first API call
You can try an API from any terminal with curl. This reads data (GET) and then creates something (POST) on a typical REST API:
# Read
curl -s https://api.example.com/v1/orders/1234 \
-H "Authorization: Bearer YOUR_API_KEY"
# Create
curl -s -X POST https://api.example.com/v1/orders \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"amount": 49900, "currency": "INR"}'The same POST from PHP, with a timeout and proper error handling:
<?php
// Keys live in a file outside public_html, e.g. /home/youruser/config/secrets.php
$secrets = require dirname(__DIR__) . '/config/secrets.php';
$ch = curl_init('https://api.example.com/v1/orders');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 20,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer ' . $secrets['orders_api_key'],
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => json_encode(['amount' => 49900, 'currency' => 'INR']),
]);
$body = curl_exec($ch);
$status = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
if ($body === false) {
error_log('API call failed: ' . curl_error($ch));
} elseif ($status >= 400) {
error_log("API returned $status: $body");
} else {
$order = json_decode($body, true, 512, JSON_THROW_ON_ERROR);
}And from JavaScript on a server (Node.js 18 or later has fetch built in):
const res = await fetch("https://api.example.com/v1/orders/1234", {
headers: { Authorization: `Bearer ${process.env.ORDERS_API_KEY}` },
signal: AbortSignal.timeout(20000),
});
if (!res.ok) throw new Error(`API returned ${res.status}`);
const order = await res.json();For a fuller PHP walk-through, see how to integrate third-party APIs with PHP.
4. The main kinds of API
- REST uses URLs for things and HTTP methods for actions, with JSON data. It is what most payment, SMS and business APIs offer.
- GraphQL has one endpoint where the client asks for exactly the fields it needs. See building GraphQL APIs.
- Webhooks reverse the direction: the provider calls your URL when something happens, such as "payment captured".
- SOAP is an older XML style still found in some banking and government integrations.
- WebSockets and streaming keep a connection open for live updates such as chat.
When and why to choose each is covered in Mastering API architectures.
5. Keep your API keys safe
Anything in JavaScript that runs in the visitor's browser, or in a mobile app, can be read by anyone. Call the API from your server and keep the key there. If a key has ever been committed to a public repository, revoke it in the provider's dashboard and create a new one.
- Store keys outside your web root, in a config file above
public_htmlor in environment variables, never in a file a browser can download. - Use test keys while building; most payment gateways give separate sandbox credentials.
- Give each integration its own key with the narrowest permissions the provider allows, so you can revoke one without breaking the rest.
- Verify webhooks. Check the signature header the provider sends, using its documented method, before you trust a "payment successful" message.
- Validate everything that comes back before you save it to your database.
The full picture, including OAuth 2.0 and JWT, is in The evolution of API authentication.
6. Handle errors and rate limits
- Set a timeout on every call, as in the examples above, so a slow provider does not freeze your page.
- Retry only what is safe to retry, such as 429, 502, 503 and 504, and wait longer each time. If the response has a
Retry-Afterheader, respect it. - Don't retry a payment blindly. Use the provider's idempotency key, if it offers one, so a repeated request cannot charge twice.
- Log the status code and the provider's error message, never the API key.
7. Test before you build
Try each endpoint in a tool such as Postman or with curl before you write application code, so you know exactly what the API returns for success and for each error. Our Postman guide covers collections, environments and automated tests.
8. Running API integrations on Domain India
- cPanel shared hosting. PHP's cURL functions work for calling external APIs. Socket and process functions such as
fsockopen,stream_socket_clientandproc_openare disabled, so a library that relies on them fails; see PHP disabled functions on shared hosting. A request that takes longer than about 90 seconds returns a 504, so move slow work to a cron job. - DirectAdmin shared hosting.
curl_execis disabled on most DirectAdmin sites, so test an integration on your plan before you rely on it. - App Platform. Node.js apps are detected automatically and other languages run from a Dockerfile. Keep keys in the app's environment variables. WebSockets are not supported. See getting started with the App Platform.
- VPS. A self-managed server with root access runs any API client or server, including WebSocket and gRPC services.
Frequently asked questions
What is an API in simple terms?
An API is an agreed way for one program to ask another for data or an action over the internet. Your program sends a request to an endpoint URL and gets back a status code and data, usually as JSON.
What is the difference between an API key and OAuth?
An API key is a single secret that identifies your application and is sent with every request. OAuth 2.0 issues short-lived, scoped tokens, and is used when a user grants an app access to their account or when an API requires stronger security.
Where should I store API keys for my website?
On the server, in a config file outside public_html or in environment variables. Never put a secret key in browser JavaScript, a mobile app or a public code repository.
What does HTTP error 429 mean?
429 Too Many Requests means you have hit the API's rate limit. Wait before retrying, respect any Retry-After header, and slow down or batch your requests.
Can I call external APIs from PHP on Domain India cPanel hosting?
Yes. PHP's cURL functions work on Domain India cPanel servers. Socket and process functions are disabled, and a request running longer than about 90 seconds returns a 504, so keep calls short and move slow work to a cron job.
What is a webhook?
A webhook is an API call in the other direction: the provider sends a request to a URL on your site when an event happens, such as a payment being captured. Always verify the webhook's signature before acting on it.
Ready to build an integration? Read Mastering API architectures, deploy an API service on the App Platform, or open a support ticket if a call fails on your hosting. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.
Deploy Node.js apps automatically, or any language from a Dockerfile, with environment variables for your API keys.
See the App Platform