Our services

If you can think it, we can make it brainsoft.

When a slow third-party API becomes your actual bottleneck

Written By: BrainSoft In Backend

You’ve tuned your database, added indexes, scaled your servers, and yet response times are still terrible. If your application depends on an external API, that service might be the real bottleneck. Third-party APIs are outside your control, but they don’t have to sink your performance.

This post explains how to confirm a slow external API is the culprit, measure its impact, and apply fixes like caching, timeouts, asynchronous calls, and fallbacks. You’ll get practical steps to keep your app responsive even when someone else’s service is slow.

How to tell if a third-party API is your bottleneck

Start by measuring where time is actually spent. Instrument your code to log the duration of each external call. If you use an APM tool, look for spans that correspond to HTTP requests to external hosts. A simple way is to wrap calls with timing logs.

const start = Date.now();
const res = await fetch('https://api.example.com/data');
console.log(`External call took ${Date.now() - start}ms`);

If those durations consistently dominate your request time, you’ve found the bottleneck. Also check for retries or timeouts that multiply the delay. A single slow call can cascade into many.

Strategies to mitigate a slow third-party API

Once confirmed, you can reduce the impact. The right approach depends on how fresh the data must be and how critical the API is to your core functionality.

  • Cache responses – If the data doesn’t change often, store it locally with a TTL. Even a 60-second cache can absorb spikes.
  • Set aggressive timeouts – Don’t let a hanging request tie up resources. Use a timeout and fail fast.
  • Make calls asynchronously – If the API result isn’t needed immediately, move it to a background job or queue.
  • Implement circuit breakers – After a few failures, stop calling the API for a while and serve stale data or a fallback.
  • Use a fallback or degrade gracefully – Show a cached version, a default value, or a message instead of blocking the whole page.

For example, adding a timeout with AbortController in Node.js:

const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), 2000);
try {
  const res = await fetch(url, { signal: controller.signal });
  // process response
} catch (err) {
  // fallback
} finally {
  clearTimeout(timeout);
}

If the API is essential and cannot be cached or deferred, consider negotiating with the provider or switching to a faster alternative. Sometimes the only fix is to replace the dependency. If you need help auditing and refactoring integrations, our services cover performance tuning and enterprise integration.

Monitoring and preventing future bottlenecks

After you’ve applied fixes, keep an eye on external call latency. Set up alerts for when p95 latency exceeds a threshold. Track error rates and timeout counts. This way you’ll know if the API degrades again before your users complain.

Also review your dependencies regularly. A third-party API that was fast last year might be slow today due to growth or infrastructure changes on their side. Having a fallback plan in place makes your system resilient.

Frequently asked questions

How can I measure the impact of a third-party API on my app's performance?

Instrument your code to log the duration of each external call. Use an APM tool or simple timing logs to see how much of the total request time is spent waiting for the API. If it’s a large percentage, it’s likely the bottleneck.

What’s the quickest win to reduce the impact of a slow API?

Add caching if the data allows it. Even a short TTL can dramatically cut the number of slow calls. If caching isn’t possible, set a strict timeout so slow responses don’t hold up your entire application.

Should I always avoid synchronous calls to third-party APIs?

Not always. If the user needs the data immediately and there’s no alternative, you have to call it synchronously. But you can still use timeouts, retries with backoff, and a fallback UI to keep the experience acceptable.


#Backend