Urgent.News

What's breaking now, across thousands of outlets.

Tech

A rant about APIs

Over the past few weeks, I've integrated with multiple APIs for Vori's onboarding flow, including contract rendering, e-signature collection, invoicing/billing, CRMs, card processors, and gateways. These APIs have their own unique annoyances, but they're especially frustrating given that many have been around for a decade. It's disappointing that developers can't simply copy existing, better APIs and practices to improve their offerings.

I shouldn't need to log in to read API documentation, yet many require this step, disrupting my workflow and forcing me to wait for support responses to access crucial information.

One team acknowledged that gated documentation is not ideal, yet executives continue to push for it. This is especially problematic for agentic development, where providing links to documentation disrupts the flow of building a client and integrating. I'd prefer to share documentation links with agents so they can explore the schema, build a client, and integrate without unnecessary barriers.

The lack of authentication requirements for documentation is a waste of time and resources, and it's disrespectful to developers who have been publishing APIs for over a decade without providing OpenAPI specifications. I'm not asking for a Postman collection; I need an OpenAPI spec to generate a typed client and focus on building my business. Why settle for inferior formats when good ones are available?

Issuing credentials can be necessary, but waiting weeks for IT to generate them is frustrating. Rotate credentials quickly, and don't make me file support tickets for potential security incidents. Self-serve credential issuance is better, but the fact that credentials are tied to the identity of the person who created them creates issues with log association and credential rotation.

I'm considering migrating away from e-sign providers that tie credentials to user identities, as it hinders incident resolution and accountability.

Webhooks are great for building real-time workflows, but I dislike providers that verify webhook endpoints before saving them. Sending a payload to the endpoint and only saving the configuration if the response is successful is an unnecessary hurdle. It's hard to validate without a shared secret, and the provider won't provide one until the endpoint is verified. Writing a support ticket about this issue wasn't helpful, as the team didn't understand the problem, and their response only served to prolong the issue.

Despite the frustrations, progress is being made. Building APIs is better than nothing, even if the developer experience is horrible. I'm thankful for the strides being taken, but we need to do better to avoid wasting time and resources on subpar solutions.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.clintonblackburn.com →

More in Tech

Fetching Instagram profiles concurrently in Go with HikerAPI

HikerAPI has official clients for Python and Node, but not for Go. I wanted to pull public Instagram profile data (followers, post count, bio) from a Go program, so I wrote a small client using only…

  • HikerAPI lacks a Go client for Instagram profiles.
  • CLI fetches profiles concurrently with worker pool.
  • Access key required for API endpoint GET request.

Splitting a dinner bill by who ate what, with the whole bill in the URL

A table of three splits a $96 dinner equally. One of them skipped the cocktails and still pays $32. I wanted a way to split one dinner by who ate what, shared plates included, and to send the result…

  • Three friends used Dollopify to split a $96 dinner bill fairly
  • One friend paid $32 after skipping cocktails, others paid equally
  • Bill was shared via a single HTML file with minified JSON

Openreach's optical upgrade: what 800G means for AI data center buyers

Openreach is deploying Ciena Waveserver equipment with WaveLogic 6 coherent technology in its Optical Spectrum Extended Access portfolio.

  • Openreach expands optical network with 800G capacity
  • Deployment includes Ciena's Waveserver and WaveLogic 6 technology
  • Key for AI data center buyers to understand performance specifics

GraphQL resolvers often check the top-level object and skip the nested ones

A common GraphQL setup puts the permission check in the root resolver. project(id: 7) checks that you're a member of project 7 and returns it. Every nested field resolves on its own after that.

  • GraphQL resolvers often check top-level object, skip nested ones
  • Authorization bypass possible in nested field resolvers
  • Place authorization check in each type's resolver or data loader

More from Thursday 8 October →