API guide

API and microservices questions, answered

Short answers to the questions we hear most often about APIs, integration and microservices.

REST, GraphQL or gRPC?

REST for most public and partner APIs: widely understood and easy to cache. GraphQL when many different front-ends need different shapes of data. gRPC for fast internal service-to-service calls.

Do we need an API gateway?

If you expose APIs to partners or the internet, yes. It gives you one place for authentication, rate limits, routing and monitoring.

Do we need a service mesh?

Not usually at first. Libraries and the gateway cover most needs. A mesh such as Istio or Linkerd helps when you have many services and need consistent encryption and traffic control between them.

How do we version APIs?

Avoid breaking changes. When one is unavoidable, publish a new version, run both for an agreed period, tell callers early, and track who still uses the old one.

Can our legacy systems take part?

Yes. Wrap them with small adapters or put the gateway in front, then modernise behind that front over time.

Should we rewrite our application as microservices?

Rarely in one go. See monolith or microservices.

Untangling integrations, or opening APIs to partners?

Tell us which systems need to talk, who will call your APIs, and what breaks today. We will come back with a plain view of the right structure, what to change first, and what to leave alone.