WEBVTT

0:00:03.240000 --> 0:00:06.500000
 Hello everyone and welcome to this video.


0:00:06.500000 --> 0:00:11.060000
 In this video, we're going to be exploring
 the differences between web

0:00:11.060000 --> 0:00:13.620000
 services and APIs.

0:00:13.620000 --> 0:00:17.160000
 Now, you might be thinking to yourself,
 yes, that is a very, very good

0:00:17.160000 --> 0:00:21.180000
 point, a very good set of questions
 to ask because as a student or learn

0:00:21.180000 --> 0:00:26.660000
 or someone getting into this space,
 it can be a little bit difficult or

0:00:26.660000 --> 0:00:31.640000
 confusing to essentially tell what the
 differences are between web services

0:00:31.640000 --> 0:00:36.420000
 and APIs. And the reason for that is
 primarily because not a lot of people

0:00:36.420000 --> 0:00:38.020000
 understand the differences.

0:00:38.020000 --> 0:00:42.980000
 So during random discussions or general
 discussions, I shouldn't say random,

0:00:42.980000 --> 0:00:48.840000
 but general discussions, you may hear these
 two terms being used interchangeably

0:00:48.840000 --> 0:00:53.240000
 to describe maybe the same thing
 or two different types of things.

0:00:53.240000 --> 0:00:59.560000
 But widely speaking, the reason why
 there is no clear cut definition as

0:00:59.560000 --> 0:01:04.120000
 to what the difference is, and I'm
 speaking again at a very at a very

0:01:04.120000 --> 0:01:09.980000
 high level, the reason for that all comes
 down to when each of these technologies

0:01:09.980000 --> 0:01:11.660000
 became prominent.

0:01:11.660000 --> 0:01:17.120000
 So in the modern world, as of me recording
 this video, you would typically

0:01:17.120000 --> 0:01:23.200000
 consider an endpoint, an API, right,
 just based on the technologies being

0:01:23.200000 --> 0:01:25.680000
 used, so on and so forth.

0:01:25.680000 --> 0:01:31.640000
 However, you know, you may also be
 asking us another question, what to

0:01:31.640000 --> 0:01:36.540000
 what extent our web services used
 over APIs and vice versa.

0:01:36.540000 --> 0:01:39.700000
 And that all, all of that comes
 down to the definition.

0:01:39.700000 --> 0:01:44.340000
 Now, in the previous video, I provided
 you with a definition of web services

0:01:44.340000 --> 0:01:50.320000
 and APIs, but we didn't dive deeper into
 actually extrapolating or identifying

0:01:50.320000 --> 0:01:55.140000
 the differences between the two, and
 essentially finding where that line

0:01:55.140000 --> 0:01:59.240000
 is drawn. And that's what we're going
 to be exploring in this video.

0:01:59.240000 --> 0:02:05.460000
 So to start off with, I'm going to
 utilize a general description or a

0:02:05.460000 --> 0:02:10.720000
 summary, and then we'll actually take
 a look at the complete definitions.

0:02:10.720000 --> 0:02:16.500000
 So first and foremost, web services
 and APIs, by the way, API stands for

0:02:16.500000 --> 0:02:22.320000
 application programming interface, are
 related concepts in web development,

0:02:22.320000 --> 0:02:25.120000
 but they have distinct differences.

0:02:25.120000 --> 0:02:30.340000
 So these distinct differences are what
 make it difficult to sort of separate.

0:02:30.340000 --> 0:02:35.100000
 And I'm speaking generally, I know
 that many professional developers,

0:02:35.100000 --> 0:02:38.840000
 pen testers understand the difference
 now, but they only understand the

0:02:38.840000 --> 0:02:41.440000
 difference once they've
 interacted with both.

0:02:41.440000 --> 0:02:45.780000
 And they understand, you know, why
 one was used over the other.

0:02:45.780000 --> 0:02:51.820000
 So to begin to actually start, web
 services are a broader category of

0:02:51.820000 --> 0:02:57.160000
 technologies that are used to enable
 machine to machine communication

0:02:57.160000 --> 0:03:00.660000
 and data exchange over the internet.

0:03:00.660000 --> 0:03:05.920000
 Okay, so I've underlined the key word
 or set of words there, machine to

0:03:05.920000 --> 0:03:08.180000
 machine web services.

0:03:08.180000 --> 0:03:13.840000
 Okay, now they encompass various
 protocols and data formats.

0:03:13.840000 --> 0:03:16.260000
 We can keep that to the site for now.

0:03:16.260000 --> 0:03:20.400000
 The key thing is, I want you to understand
 what type of communication

0:03:20.400000 --> 0:03:22.100000
 they facilitate.

0:03:22.100000 --> 0:03:36.400000
 In the case of APIs, APIs are a set
 of rules and service application or

0:03:36.400000 --> 0:03:42.600000
 platform. Okay, so just think about
 that for a second, let it settle in.

0:03:42.600000 --> 0:03:46.160000
 The key differences are
 already listed here.

0:03:46.160000 --> 0:03:52.200000
 Okay, so web services, machine to machine,
 APIs, not really, you can't

0:03:52.200000 --> 0:03:57.100000
 really think of it as a service, but
 more so a set of rules that allow,

0:03:57.100000 --> 0:04:02.280000
 which means they provide or facilitate
 communication or the ability for

0:04:02.280000 --> 0:04:07.060000
 developers to access the functionality
 of data over service application

0:04:07.060000 --> 0:04:13.380000
 or platform. So an API is in essence,
 it works similarly to a web service

0:04:13.380000 --> 0:04:18.080000
 in that they are an endpoint that, you
 know, another system can interact

0:04:18.080000 --> 0:04:21.780000
 with or even a human can interact with.

0:04:21.780000 --> 0:04:25.280000
 But the reason as to why they
 are set up is different.

0:04:25.280000 --> 0:04:27.620000
 And that's where the differences lie.

0:04:27.620000 --> 0:04:32.380000
 So with a web service, generally speaking,
 based on my experience, you

0:04:32.380000 --> 0:04:37.520000
 are configuring web services for one
 or two or more systems to communicate

0:04:37.520000 --> 0:04:39.580000
 with one another.

0:04:39.580000 --> 0:04:43.800000
 All right, and when you're setting
 this up, you're strictly looking at

0:04:43.800000 --> 0:04:48.540000
 it from that perspective in that you're
 not looking for this or for a

0:04:48.540000 --> 0:04:54.180000
 specific set of functionality to be exposed
 so that a developer can interact

0:04:54.180000 --> 0:04:58.480000
 with the web application or the web service
 that way, you're just setting

0:04:58.480000 --> 0:05:03.100000
 a web service up so that two systems,
 web apps, whatever can communicate

0:05:03.100000 --> 0:05:08.360000
 with one another with really no interaction
 or no involvement of human

0:05:08.360000 --> 0:05:09.220000
 beings or developers.

0:05:09.220000 --> 0:05:15.560000
 With an API, you're exposing or you have
 an endpoint that exposes functionality

0:05:15.560000 --> 0:05:22.420000
 of the actual web application so that
 developers can then use that to

0:05:22.420000 --> 0:05:26.380000
 interact with the web application in
 a different way or in a specific

0:05:26.380000 --> 0:05:29.960000
 way. Okay, so hopefully you're
 getting the difference now.

0:05:29.960000 --> 0:05:35.540000
 Now to extrapolate on this, web services
 are meant to provide a standardized

0:05:35.540000 --> 0:05:42.140000
 way for various applications, often on
 different platforms and using different

0:05:42.140000 --> 0:05:45.560000
 programming languages to
 interact with each other.

0:05:45.560000 --> 0:05:49.500000
 So I'm now fleshing out the definition
 so you can start to see the other

0:05:49.500000 --> 0:05:53.440000
 differences or the nuances, you
 know, within each of these.

0:05:53.440000 --> 0:05:59.280000
 In the case of APIs, they provide access
 to the functionality or data

0:05:59.280000 --> 0:06:05.320000
 of an application or service for developers
 to use in their own applications.

0:06:05.320000 --> 0:06:09.240000
 So in the previous video, I used the
 example of QuickBooks and your online

0:06:09.240000 --> 0:06:16.100000
 banking portal. In that case, your
 online banking portal or your bank

0:06:16.100000 --> 0:06:21.680000
 would need to set up or expose an API
 specifically for integration with

0:06:21.680000 --> 0:06:26.500000
 QuickBooks and vice versa, but
 I'm just using a basic example.

0:06:26.500000 --> 0:06:31.220000
 Now in this case, why would your banking
 portal use an API over a web

0:06:31.220000 --> 0:06:36.120000
 service? The reason they would use an
 API over a web service is because

0:06:36.120000 --> 0:06:38.920000
 APIs are designed for that.

0:06:38.920000 --> 0:06:44.380000
 They are designed to essentially provide
 access to the functionality or

0:06:44.380000 --> 0:06:49.600000
 data of an application or service for
 developers to then utilize within

0:06:49.600000 --> 0:06:54.880000
 their own web applications or integrate
 into their own web applications.

0:06:54.880000 --> 0:07:00.500000
 So for example, if I had a, let's say,
 a weather website, right, and you

0:07:00.500000 --> 0:07:05.180000
 know, I wanted to make it easier for developers
 to pull the latest information

0:07:05.180000 --> 0:07:09.740000
 from my service into their own website
 or whatever, I would typically

0:07:09.740000 --> 0:07:15.060000
 utilize an API. But if I was developing
 a web application infrastructure,

0:07:15.060000 --> 0:07:19.960000
 and I wanted one or two of my web applications
 to communicate with one

0:07:19.960000 --> 0:07:25.220000
 another without again thinking or even
 considering, you know, exposing

0:07:25.220000 --> 0:07:28.700000
 that to developers, I would
 use a web service.

0:07:28.700000 --> 0:07:32.920000
 So the point is that the reason why
 you don't hear about web services

0:07:32.920000 --> 0:07:36.140000
 that often is because you're
 not supposed to.

0:07:36.140000 --> 0:07:40.460000
 They're designed for machine
 to machine communication.

0:07:40.460000 --> 0:07:46.020000
 And going deeper into web services,
 when we explored, you know, XML RPC

0:07:46.020000 --> 0:07:51.360000
 and the implementations, they just
 provide a standardized way for the

0:07:51.360000 --> 0:07:55.560000
 applications to communicate or for the
 machines to communicate with one

0:07:55.560000 --> 0:08:00.300000
 another. So you can think of those implementations
 as languages or frameworks

0:08:00.300000 --> 0:08:02.460000
 for that communication.

0:08:02.460000 --> 0:08:07.580000
 And the same goes for APIs with the
 use of, you know, REST, for example.

0:08:07.580000 --> 0:08:11.840000
 So I'm pretty sure you've gotten the
 difference between the two now.

0:08:11.840000 --> 0:08:14.040000
 It really is very, very simple.

0:08:14.040000 --> 0:08:18.380000
 And it all comes down to your implementation
 or and what you require.

0:08:18.380000 --> 0:08:22.200000
 If I wanted, if I was setting up, you
 know, a set off web applications

0:08:22.200000 --> 0:08:26.040000
 that are all supposed to work to each
 other with each other or interact

0:08:26.040000 --> 0:08:28.260000
 with each other, I would
 use a web service.

0:08:28.260000 --> 0:08:32.920000
 If I was exposing a piece of functionality
 of my web application, that

0:08:32.920000 --> 0:08:37.160000
 individuals can use either for, you know,
 just to get data or to integrate

0:08:37.160000 --> 0:08:41.240000
 into their own web application,
 then I'll utilize an API.

0:08:41.240000 --> 0:08:44.680000
 Okay, so very, very simple in
 terms of the differences.

0:08:44.680000 --> 0:08:47.560000
 And I've classified this in a table here.


0:08:47.560000 --> 0:08:51.820000
 All right, so just like the previous
 video, the table is structured the

0:08:51.820000 --> 0:08:55.480000
 same where we have the aspect and
 then web services and APIs.

0:08:55.480000 --> 0:09:00.600000
 So in the case of the purpose, web services
 facilitate data exchange between

0:09:00.600000 --> 0:09:01.900000
 software systems.

0:09:01.900000 --> 0:09:06.220000
 In the case of APIs, they provide access
 to the functionality or data

0:09:06.220000 --> 0:09:11.680000
 of an application or service for developers,
 primarily, even you can interact

0:09:11.680000 --> 0:09:15.820000
 with an API. The only reason why I say
 developers is because, you know,

0:09:15.820000 --> 0:09:19.120000
 in most cases, the only reason why
 you'd want to take a look at an API

0:09:19.120000 --> 0:09:22.700000
 or something like that is because,
 you know, you want to find a way of

0:09:22.700000 --> 0:09:27.540000
 interacting with the actual web application
 or its functionality.

0:09:27.540000 --> 0:09:29.520000
 So I'll give you an example.

0:09:29.520000 --> 0:09:36.120000
 When I was developing, when I worked
 briefly as a developer, and we would

0:09:36.120000 --> 0:09:40.620000
 essentially be developing, let's say,
 you know, when I was working for

0:09:40.620000 --> 0:09:44.840000
 again in the finance sector, we were
 developing custom web applications

0:09:44.840000 --> 0:09:49.360000
 for, you know, for various types of
 clients or even just improving the

0:09:49.360000 --> 0:09:51.260000
 online banking portal.

0:09:51.260000 --> 0:09:56.540000
 When we had the integration call with
 QuickBooks, and I think I can say

0:09:56.540000 --> 0:10:01.420000
 this, we were essentially talking about
 the API and understanding from

0:10:01.420000 --> 0:10:06.600000
 the QuickBooks team what they required
 from our end, keeping aside the

0:10:06.600000 --> 0:10:11.220000
 security of the actual API and, you know,
 authentication and all of that.

0:10:11.220000 --> 0:10:16.960000
 So the bottom line is web applications
 have APIs so that they can provide

0:10:16.960000 --> 0:10:22.460000
 developers with a way to interact with
 the web application or a part of

0:10:22.460000 --> 0:10:24.120000
 its functionality.

0:10:24.120000 --> 0:10:29.340000
 Moving on, in terms of communication protocols,
 web services can use various

0:10:29.340000 --> 0:10:36.380000
 protocols, including SOAP, REST,
 XML, RPC, JSON, RPC, and more.

0:10:36.380000 --> 0:10:40.640000
 In the case of APIs, they can also utilize
 various protocols and are often

0:10:40.640000 --> 0:10:52.380000
 associated with services, utilize multiple
 data formats such as XML and

0:10:52.380000 --> 0:10:57.040000
 JSON. And in the case of APIs, they can
 work with different data formats,

0:10:57.040000 --> 0:11:02.100000
 including JSON, XML or even custom
 formats or whatever you want.

0:11:02.100000 --> 0:11:06.540000
 In terms of the interface, web services
 do not have a user interface for

0:11:06.540000 --> 0:11:08.660000
 direct human interaction.

0:11:08.660000 --> 0:11:14.220000
 APIs follow the same trend, however,
 so they do not have a user interface,

0:11:14.220000 --> 0:11:19.280000
 but are used by developers to build
 applications with user interfaces.

0:11:19.280000 --> 0:11:23.580000
 So you can essentially take data that you're
 getting from an API or functionality

0:11:23.580000 --> 0:11:28.360000
 from an API and then integrate
 that into an interface.

0:11:28.360000 --> 0:11:32.840000
 So for example, when someone clicks a
 button, you can configure that button

0:11:32.840000 --> 0:11:35.980000
 to, you know, essentially
 execute an API call.

0:11:35.980000 --> 0:11:40.320000
 That's, you can start to get an understanding
 now as to why one would

0:11:40.320000 --> 0:11:43.600000
 use an API over a web service.

0:11:43.600000 --> 0:11:50.340000
 In terms of the scope, web services are
 seen as a subset of APIs, specifically

0:11:50.340000 --> 0:11:55.400000
 focused on machine to machine
 web-based data exchange.

0:11:55.400000 --> 0:12:00.740000
 APIs on the other hand are a broader
 concept that encompass various types

0:12:00.740000 --> 0:12:04.100000
 of interfaces for software interaction.

0:12:04.100000 --> 0:12:08.660000
 In the case of standards, so think of,
 you know, just communication standards

0:12:08.660000 --> 0:12:14.460000
 or protocols. In the case of web services,
 we typically have WS security,

0:12:14.460000 --> 0:12:18.720000
 WS policy for soap-based web services.

0:12:18.720000 --> 0:12:22.560000
 And in the case of APIs, most of you
 know about this, we have Open API.

0:12:22.560000 --> 0:12:26.460000
 It's just a framework that again ensures
 that there is standardization

0:12:26.460000 --> 0:12:28.060000
 of the communication.

0:12:28.060000 --> 0:12:33.240000
 So Open API, which is formerly swagger
 for documenting RESTful APIs and,

0:12:33.240000 --> 0:12:40.380000
 you know, I'm pretty sure that this
 has now given you an understanding

0:12:40.380000 --> 0:12:45.160000
 as to where the actual line
 is drawn in terms of both.

0:12:45.160000 --> 0:12:49.740000
 But you can also start to understand why
 people use these terms interchangeably.

0:12:49.740000 --> 0:12:54.140000
 Typically, they'll also call a web
 service and API, which is fine.

0:12:54.140000 --> 0:12:58.860000
 But you need to understand the definition
 based on, you need to understand

0:12:58.860000 --> 0:13:04.520000
 the differences between the two based
 on how they were designed to work.

0:13:04.520000 --> 0:13:08.080000
 Now, you can configure a web service and
 you can a human being can interact

0:13:08.080000 --> 0:13:12.600000
 with it. The point I'm trying to make
 is that web services were not designed

0:13:12.600000 --> 0:13:16.080000
 for that. So you, you know, you sort
 of need to fill in the blanks.

0:13:16.080000 --> 0:13:21.260000
 Whereas APIs are, you know, essentially
 designed to be utilized by developers,

0:13:21.260000 --> 0:13:26.600000
 which means they're fairly easy to understand
 in terms of making requests,

0:13:26.600000 --> 0:13:30.920000
 getting specific data,
 so on and so forth.

0:13:30.920000 --> 0:13:34.920000
 With that being said, I'm really happy
 that I was able to explain the

0:13:34.920000 --> 0:13:38.420000
 differences between the two because
 I didn't want you completing this

0:13:38.420000 --> 0:13:40.340000
 course and not knowing the difference.

0:13:40.340000 --> 0:13:43.260000
 So that brings us to the
 end of this video.

0:13:43.260000 --> 0:13:45.520000
 And I will be seeing you
 in the next video.

