anfloy.AcademyBook a call

Foundation · 04 · Connect your stackLesson 2 of 4

APIs without fear

75 min working time · Week 4

By the end of this lesson you can
  • Call a real API from Claude Code (keys, requests, responses)
  • Store secrets properly - never in chat, never in the repo
  • Build your first API-powered workflow

What an API actually is

The finish line for this lesson is a shipped integration: a script Claude wrote against a live API, keys stored properly, output verified against the vendor's own UI. An API is how programs use a product instead of humans clicking it. Every SaaS tool you pay for has a web interface for people and, almost always, an API for machines: send a structured request to a URL, get structured data back. That is the whole concept.

Why you care when MCP exists: not every tool has an MCP server, and APIs give you full, precise control for pipelines - exports, bulk updates, scheduled pulls. The sales track's enrichment waterfall and the ops track's reporting are API work. And here is the fear-killer: Claude writes all the API code. Your job is knowing what to ask for and how to handle the keys.

Keys, and the .env discipline

An API key is a password for programs. Anyone holding it can act as your account - which is why key handling is the one part of this lesson where discipline is non-negotiable. The rules:

  • Keys live in a file named .env in the project - one KEY=value per line. Nowhere else.
  • .env is listed in .gitignore, so it can never reach the repo. Claude sets this up correctly if you ask.
  • Never paste a key into the chat. Say "use the APOLLO_API_KEY from .env" - code reads keys from the environment by name; Claude never needs the value itself.
  • Each teammate gets their own key where the vendor allows it - revocation stays surgical.
.env - and the .gitignore line that protects it
# .env (gitignored, never committed)
APOLLO_API_KEY=your-key-here
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

# .gitignore must contain:
.env

Now stack the defenses you already built: add Read(./.env*) to your deny rules so Claude itself cannot read the file (week two), and you saw ${VAR} expansion keep keys out of .mcp.json (last lesson). One more for completeness: an environment setting exists that scrubs credentials from subprocesses Claude spawns - your admin can enforce it org-wide in the rollout track.

Your first API call, end to end

Twenty minutes, one real integration. The point is not the script - it is feeling the loop where Claude writes, runs, hits an error, and fixes it while you steer.

  1. Pick a tool you use that has an API - your email platform, CRM, or enrichment provider all work.
  2. Get a key from its dashboard - usually under Settings, then API or Developers. Put it straight into .env.
  3. Open Claude Code in a fresh project folder and ask: "Write a script that calls the [tool] API using the key from .env, fetches [something real - this week's campaign stats], and saves the result as a CSV. Then run it and show me the output."
  4. Claude writes the script, runs it, and likely hits a real-world error - a wrong field name, a rate limit. Watch it read the error and fix itself. This loop is why you do not need to know the API's documentation by heart.
  5. Verify the output file against what the tool's web interface shows. Same numbers? You just shipped your first integration.
  6. Then the test almost nobody runs: change one filter value and confirm the count moves. Three vendors in our own stack return HTTP 200 and the unfiltered set when they get a filter key they do not recognize. One sizing sweep returned an identical 66,502 for every one of 17 countries and looked like a finding. An implausibly clean number (100%, 0%, identical across segments) is evidence of an ignored filter until proven otherwise.

From one call to a workflow

A single call proves the connection. A workflow chains calls into something your team would actually use: fetch from system A, transform, deliver to system B. Build one today - small but real.

  • Fetch this week's stats from your email platform, compute the changes vs last week, write a summary markdown report.
  • Pull new CRM contacts, check them against your ICP notes from the brain, flag the mismatches in a CSV.
  • Read a list of domains, call one enrichment API for each, merge results into your master sheet - with a before-and-after row count.

Then apply the law: you will run this workflow again, so it becomes a skill now - "Turn this into a skill called campaign-report." Script, key handling, and verification get encoded, and a skill wrapping an API workflow is exactly what the capstone pushes up the Ladder onto a schedule.

Do this now

Sources and further reading

We set it up with you

Want us to set it up with you, end to end?

Three one-on-one sessions. We train you on your real stack and build your first agents together, until you can run it yourself. You keep everything.