ROVQIX designs and builds REST and GraphQL APIs in Node.js and TypeScript, including authentication, authorisation, versioning, rate limiting, pagination, webhooks and OpenAPI documentation — plus integrations with third-party APIs that keep working when the provider does not.
An API is a contract you cannot quietly change once someone depends on it. Most of the work is in the decisions that are expensive to reverse: error shape, pagination, versioning and auth.
Documented at delivery
From v1, not later
Writes safe to retry
Per key, documented
Consistent naming, predictable status codes and one error shape across every endpoint, agreed before implementation.
API keys, OAuth or JWT depending on who is calling, with permissions checked at the data layer on every request.
Cursor pagination that stays correct while data changes, plus filtering and sorting that use real indexes.
Per-key limits with standard headers so clients can back off intelligently instead of hammering you.
Signed, retried, idempotent outbound events with a delivery log your support team can actually inspect.
OpenAPI specification generated from the code, with examples and a changelog — not a wiki page that goes stale.
Error format, pagination style, versioning scheme and auth model. Everything else can evolve.
| Decision | Cheap to change | Expensive to change |
|---|---|---|
| Adding a field | Yes | |
| Adding an endpoint | Yes | |
| Error response shape | Yes — every client parses it | |
| Pagination style | Yes — changes every list call | |
| Versioning scheme | Yes — affects every URL or header | |
| Auth mechanism | Yes — every integration re-implements |
REST for public and partner APIs, where caching, tooling and predictability matter most. GraphQL when your own varied clients need to shape their own queries. We will recommend based on who is calling, not on preference.
Yes. We reverse-engineer the current behaviour into an OpenAPI specification, flag inconsistencies, and propose a path to fixing them without breaking existing clients.
Additive changes go into the current version. Breaking changes get a new version with both running in parallel, a written deprecation timeline, and usage monitoring so you know who still needs to migrate.
Yes — gateway configuration, key management, usage dashboards and a self-service portal where your integrators can get started without contacting support.
Indicative ranges in USD. Every engagement is quoted to a written scope before work starts, so the number you approve is the number you pay.
$2,000 – $4,500
1–2 weeks
Best for: Getting the contract right before building
$8,000 – $30,000
4–12 weeks
Best for: Public or partner-facing APIs
$3,000 – $12,000
2–6 weeks
Best for: Connecting to a third-party system
How we think about this work, in more depth.
API development
A 30-minute call, then a written proposal with scope, price and timeline within two to three working days. No retainer required to get a real number, and no obligation if the answer is that we are not the right fit.