
Guide to building reliable, secure, maintainable API integrations for Indonesian B2B systems.
Di 2026, hampir semua bisnis B2B modern melibatkan integrasi API antara sistem — ERP, CRM, e-commerce, payment, accounting. Integrasi yang asal-asalan bisa menyebabkan data loss, downtime, dan security breach. Berikut best practices yang kami terapkan.
1. Pilih Protokol yang Tepat
Untuk B2B Indonesia, ada 3 pilihan utama:
- 1REST API — paling umum, mudah debug, dokumentasi bagus. Cocok untuk CRUD operations 90% kasus
- 2GraphQL — lebih efisien untuk mobile (1 endpoint, banyak query). Cocok untuk data graph kompleks
- 3Webhook — untuk notifikasi event-driven (payment success, order created, dll)
2. Authentication & Authorization
Standar industri 2026:
- 1OAuth 2.0 + JWT untuk user-facing API
- 2API Key (long-lived, server-to-server only) — simpan di vault, jangan di env
- 3mTLS untuk high-security system (financial, healthcare)
- 4Refresh token rotation — jangan pakai long-lived access token
3. Error Handling & Retry Logic
Ini yang paling sering diabaikan:
- 1Idempotency keys — untuk POST operations yang aman di-retry tanpa double creation
- 2Exponential backoff — retry: 1s, 2s, 4s, 8s, max 5 attempts
- 3Circuit breaker — kalau downstream service gagal >N times, stop calling untuk X minutes
- 4Dead letter queue — messages yang gagal setelah max retry, disimpan untuk manual review
4. Rate Limiting & Throttling
Tanpa rate limiting, single client bisa overwhelm service:
- 1Token bucket algorithm — burst-friendly
- 2Per-API-key quotas — biar tahu consumption per client
- 3Per-IP fallback — kalau tidak ada auth, throttle by IP
- 4HTTP 429 + Retry-After header (industry standard)
5. Observability
"If you can't measure it, you can't fix it":
- 1Structured logging (JSON, request ID correlation)
- 2Distributed tracing (OpenTelemetry — track request across services)
- 3Metrics: p50/p95/p99 latency, error rate, throughput
- 4Real-time alerts: latency >2s, error rate >1%, queue depth >1000
6. Security Hardening
- 1TLS 1.3 only (no TLS 1.0/1.1, no SSL)
- 2Rate limit per endpoint + WAF (Web Application Firewall)
- 3Input validation — never trust client input, always validate on server
- 4SQL injection: parameterized queries only, no string concatenation
- 5CORS: explicit allowlist, not wildcard
- 6PII encryption at rest (AES-256) + in-transit (TLS)
Contoh: Integrasi ERP ↔ E-commerce di Klien Marketplace
Salah satu klien kami punya 4 channel e-commerce (Tokopedia, Shopee, website, app) + ERP. Tantangannya: stock selalu mismatch karena tiap channel punya inventory sendiri.
Solusi: bangun API middleware yang sync real-time:
- 1Webhook receiver dari tiap marketplace (order.created, product.updated)
- 2Sync engine yang push perubahan ke semua channel dalam <30 detik
- 3Event sourcing — semua perubahan stock dicatat dengan audit trail
- 4Conflict resolution — kalau ada double-booking, ERP (master) menang
Hasil
- 1Stock mismatch turun dari ~15% ke <1%
- 2Waktu admin berkurang 6 jam/hari
- 3Order processing turun dari 4 jam ke 30 menit
- 4ROI tercapai dalam 5 bulan
Penutup
API integration yang berhasil bukan cuma soal "kedua sistem bisa bicara" — tapi soal reliability, observability, dan maintainability. Investasi di proper architecture di awal menghemat puluhan jam debug di kemudian hari.
Need consultation for your project?
The NG Tech team is ready to help you design the right system for your business — free consultation, no commitment.
WhatsApp ChatWant the Latest Tech Insights?
Subscribe to NG Tech newsletter for curated tech articles every week.