Strip away the technology and an API is a contract, and like every contract it encodes a power relationship. The provider decides what the consumer can access, what they may do with it, how much they can have, on what terms, and for how long. The consumer accepts or walks away — and walking away is harder than it looks, because by the time you have built on an API you have handed the provider a piece of your architecture.
I have been calling this the politics of APIs since 2014, and I am more convinced now than I was then that control, not technology, is the organizing principle of this ecosystem. The platform holding the data has power over the developers depending on it. The company controlling the algorithm has power over the people it affects. The regulator that mandates an API has power over the industry it regulates.
It works inside organizations too, in a smaller and more mundane way: the person who knows where all the APIs are has a kind of power, and that is precisely why inventory work meets resistance you cannot explain on technical grounds. Visibility and control are frequently at odds with somebody’s power and control.
None of this makes APIs bad. It makes them consequential. Treating them as a purely technical concern is how the consequential decisions get made by default, by whoever holds the terms.