Foundation · 04 · Connect your stackLesson 2 of 4
APIs without fear
- Call a real API from Claude Code (keys, requests, responses)
- Store secrets properly - never in chat, never in the repo
- Build your first API-powered workflow
What an API actually is
The finish line for this lesson is a shipped integration: a script Claude wrote against a live API, keys stored properly, output verified against the vendor's own UI. An API is how programs use a product instead of humans clicking it. Every SaaS tool you pay for has a web interface for people and, almost always, an API for machines: send a structured request to a URL, get structured data back. That is the whole concept.
Why you care when MCP exists: not every tool has an MCP server, and APIs give you full, precise control for pipelines - exports, bulk updates, scheduled pulls. The sales track's enrichment waterfall and the ops track's reporting are API work. And here is the fear-killer: Claude writes all the API code. Your job is knowing what to ask for and how to handle the keys.
Keys, and the .env discipline
An API key is a password for programs. Anyone holding it can act as your account - which is why key handling is the one part of this lesson where discipline is non-negotiable. The rules:
- Keys live in a file named .env in the project - one KEY=value per line. Nowhere else.
- .env is listed in .gitignore, so it can never reach the repo. Claude sets this up correctly if you ask.
- Never paste a key into the chat. Say "use the APOLLO_API_KEY from .env" - code reads keys from the environment by name; Claude never needs the value itself.
- Each teammate gets their own key where the vendor allows it - revocation stays surgical.
# .env (gitignored, never committed)
APOLLO_API_KEY=your-key-here
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...
# .gitignore must contain:
.envNow stack the defenses you already built: add Read(./.env*) to your deny rules so Claude itself cannot read the file (week two), and you saw ${VAR} expansion keep keys out of .mcp.json (last lesson). One more for completeness: an environment setting exists that scrubs credentials from subprocesses Claude spawns - your admin can enforce it org-wide in the rollout track.
Your first API call, end to end
Twenty minutes, one real integration. The point is not the script - it is feeling the loop where Claude writes, runs, hits an error, and fixes it while you steer.
- Pick a tool you use that has an API - your email platform, CRM, or enrichment provider all work.
- Get a key from its dashboard - usually under Settings, then API or Developers. Put it straight into .env.
- Open Claude Code in a fresh project folder and ask: "Write a script that calls the [tool] API using the key from .env, fetches [something real - this week's campaign stats], and saves the result as a CSV. Then run it and show me the output."
- Claude writes the script, runs it, and likely hits a real-world error - a wrong field name, a rate limit. Watch it read the error and fix itself. This loop is why you do not need to know the API's documentation by heart.
- Verify the output file against what the tool's web interface shows. Same numbers? You just shipped your first integration.
- Then the test almost nobody runs: change one filter value and confirm the count moves. Three vendors in our own stack return HTTP 200 and the unfiltered set when they get a filter key they do not recognize. One sizing sweep returned an identical 66,502 for every one of 17 countries and looked like a finding. An implausibly clean number (100%, 0%, identical across segments) is evidence of an ignored filter until proven otherwise.
From one call to a workflow
A single call proves the connection. A workflow chains calls into something your team would actually use: fetch from system A, transform, deliver to system B. Build one today - small but real.
- Fetch this week's stats from your email platform, compute the changes vs last week, write a summary markdown report.
- Pull new CRM contacts, check them against your ICP notes from the brain, flag the mismatches in a CSV.
- Read a list of domains, call one enrichment API for each, merge results into your master sheet - with a before-and-after row count.
Then apply the law: you will run this workflow again, so it becomes a skill now - "Turn this into a skill called campaign-report." Script, key handling, and verification get encoded, and a skill wrapping an API workflow is exactly what the capstone pushes up the Ladder onto a schedule.
Do this now
Sources and further reading
Want us to set it up with you, end to end?
Three one-on-one sessions. We train you on your real stack and build your first agents together, until you can run it yourself. You keep everything.