TM
Blog

3 Things You Must Do When Calling Third-Party APIs

Hoss@Hossapp /

3 Things You Must Do When Calling Third-Party APIs

Leveraging third party APIs is a great way to add features and functionality to your software products, but each one introduces new risks that need to be managed. Unexpected problems can lead to feature breakage, or even total outage - which means serious consequences for users and loss of revenue for your business. But with enough preparation, you can anticipate and solve these issues. Here are three things your software team needs to do when calling third-party APIs:

  1. Comprehensive Logging

When calling a third-party API it is important to have basic visibility into:

  • How many calls are being made
  • How long those calls are taking
  • How many errors are being returned from a call
  • Headers and and bodies for requests and responses

Most API providers don’t give you this kind of visibility, but having the above records is critical for maintaining a robust and available service.

Many APIs enforce rate limits or quotas, which often go unnoticed while call volumes are low in development, but appear unexpectedly after going into production. Having visibility into the number of calls is also important to keep an eye on the health of the system. If calls drop to zero or suddenly spike, it could be an indication of a problem elsewhere that needs to be addressed.

Once a problem is noticed, an engineer will often need to inspect the call log to get to the root cause. If the problem has never been encountered before (for example a rate limit, expired credential or internal server error), an engineer will learn about this by inspecting the response body. If the body is not already recorded, they will need to add logging and do an emergency production deployment before being able to further diagnose the issue. Having comprehensive logging in place from the start will reduce the time to resolution and eliminate emergency build deployments.

  1. Monitoring and Alerting

Frequently, API providers will encounter service degradation resulting in increased call response times or intermittent errors. Once comprehensive logging is in place, it is important to create alerts so that issues are identified before they are reported by users. Without monitoring, many teams assume they are not having issues and are surprised to find that problems were simply going unnoticed.

At a minimum, alerts should be put in place for:

  • 95th percentile latency above threshold
  • rors increased above threshold

Latency thresholds can be determined on a per-API basis, but a good default for most providers is one second. Errors are determined by the status code or a connection failure. Once these are logged, an alert should be created so you know as soon as one of your integrations is failing.

  1. Automatic Retries

Automatic retries are often overlooked when an integration is first being developed. The calls work in development, but once they are deployed to production, intermittent failures are seen in application logs. API calls fail for many reasons, and can often be immediately retried successfully. Implementing an automatic retry around API calls that checks for retriable conditions can significantly reduce the impact of intermittent issues with API integrations.

Each API call should be wrapped in logic that:

  • Makes the API call
  • Checks for a retriable error
  • Repeats the call up to a set number of times after a delay

It is important to think about the maximum number of retries and delay between each call. While a fixed delay between retries can be used, it is often preferable to use an exponential backoff, increasing the delay between calls. If exponential backoff is used, it is important to set a maximum delay as exponential functions grow very quickly.

Subscribe to Hoss ModeA weekly newsletter with curated articles, community discussions, news and trends.

A Guide to GDPR Compliance When Using Third-Party APIs

Hoss
Read more
The average small-to-medium-sized team uses 18 APIs to power their applications - and 50% of all B2B collaboration occurs using an API. But did you know that there are unique data privacy and compliance challenges associated with using these third-party APIs? As an engineering or IT leader, it’s important to be familiar with those challenges and implement proactive strategies to protect your customers’ privacy and stay compliant.
Any company that comes in contact with a person’s protected health information – like a health plan, healthcare provider or healthcare clearinghouse - is required to develop HIPAA-compliant policies to protect that data. Further, protected health information can only be shared between parties that are HIPAA compliant - this includes third parties like APIs that might store or transmit protected health information on a company’s behalf.
TM

Copyright © Hoss Technologies, Inc. 2020 - All rights reserved. Terms of Service & Privacy Policy