Disclaimer: I am not a staff member so this is not "official." Additionally, I have developed a number of scripts and programs that use the API, but I will be as unbiased as possible.
Staff: Yes, this is about the API, but it is not about "API Development," so it should not go in the API Development forums. This is intended as a guide for users wishing to learn more about the API.
Before we begin...
PURPOSE
The purpose of this is to help educate you on what an API is, how they work, and why they exist. From there we'll discuss the Torn API and its features. Finally, we'll discuss security and other additional snippets of information.
TERMS
I realize I may interchange terms a few times in this article. Basically, think back to this...
"provider," "service," "host" = Torn
"client," "script" = API script/program/tool
"user," "player" = You
On to business...
What is an API?
Literally, API stands for Application Programming Interface - but that doesn't really tell you much. In a sort, it's a way for one program or service to do something with information from another program or service. Sort of a middle-man, with limitations and rules.
I recently saw a video that equated an API to a server at a restaurant. When you go to a restaurant you are presented with a menu to order food from, and your goal is to pick something from the menu and have the kitchen prepare it so you can eat it. The restaurant server is what takes your order from the menu and presents it to the kitchen, and then takes your completed food from the kitchen back to you to eat. In the same way an API accepts requests for information and asks the host program for that information, then returns that information to you.
To break this down using the Torn API as an example - A script may need to know the current price of a lion plushie, so the script says "Yo, API, what's a lion plushie cost?" and the API takes that question to the Torn servers which then respond with the price, and the API then comes back to the script and says "20 thousand bucks, dawg." Forgive the crude humor, but that's the gist of it.
Why do APIs exist?
Ultimately, they exist so someone else can do something with something someone else made. For Torn, it's so that independent developers can make scripts and programs that use information from Torn. For a hotel (random example), it's so that travel websites can see what rooms are available on what days.
Why use an API and not just get the data directly?
Well, there's a lot of reasons. For one, a service can't just open up their database for the world to read - some information may be private or incomplete. And, it would be horribly inefficient - the host would need to train every third-party how to use their internal database(s) and software.
A service, such as Torn, can choose information they want to be publicly available. There's tons of private data and even "hidden stats" - such as your crime experience - that they simply don't want out there. Plus there's information that is either delayed or manipulated before being released publicly to prevent abuse. An API allows the service to choose what information is available, and how it is delivered. This allows third-parties to independently create tools and resources that use the service's information. Like Torn, many services that provide an API don't care, test, or review what third-parties create - the service is already in control of and limiting what information is shared, so beyond that, it's all fair game.
What is an API key?
An API key is sort of like a username and password combo. It not only identifies the user or script/program that's requesting the information, but it also grants permission to actually use the API. In most cases, including Torn, the API key is provided by the service and cannot be selected by the user.
Torn's API
Torn's API shares a lot of information - ranging from your individual player information (battle stats, work stats, properties, money, messages, events, etc.), city information (stocks, items, bazaars, prices, education courses, company perks, etc.), faction information (members, attack history, news, perks, etc.), company information (employees, prices, stock, perks, etc.), and much MUCH more. The API can only provide information that is already available elsewhere in Torn - such as player stats, items, city info, etc - so it doesn't provide any "extra" information, just a different (and potentially more efficient) way to get it.
Torn's official API documentation can be found here, along with a demo page so you can see all the possibilities of what information is available and what gets returned from the server.
It's also interesting to note that the API, and the information provided by the API, is available at any time. Meaning that even while you are in jail, the hospital, traveling, etc., you can still get all the same information - which makes it very powerful, depending how you use it.
Your Torn API Key
Your Torn API Key can be found in your preferences by clicking the gear icon in the top-right of the Torn webpage, then choosing "API Key" from the menu. This is also where you can reset your API Key.
The API is Read-Only
The API is read-only, meaning it can only GET information from Torn, it cannot write (add or change) information.
Torn API Security
As previously mentioned, your API Key works sort of as a username and password combo - not only identifying who you are, but also giving you permission to use the API. In this way you can use your API Key to get your battle stats but not somebody else's.
Any legitimate API script or program will ONLY need your API Key. DO NOT give your Torn username, email address, or password to anyone or enter it into any website, script, or program.
Some third-party services that use the Torn API, such as TornStats, have you create a username and password - please note that this is perfectly fine, and it's asking you to provide a unique username and password for TornStats - it is NOT asking for your Torn username and password, it's asking you to create a username and password for their specific site. Please be vigilant to recognize the difference.
This seems as good as place as any to mention that the Torn API CANNOT get your email address or password. Your username and ID (McNeo [864688]), yes (which is already public information anyway) - but your login credentials (email and password), no.
Note: When I previously referred to an API Key as a sort-of username-password hybrid, please note that it has nothing to do with your actual username and password - it's completely independent and unrelated. Example... If your username is "abc" and your password is "123" your API key might be "R6d4M89a" (or any other random string) - your API key is NOT any sort of hash or equation using your ACTUAL username and password - it's a totally independent, random, bullshit string of text.
Can the Torn API and my API Key be used against me?
Short answer, yes - but it's not as bad as you may think, please read on.
First, as mentioned earlier, the API does NOT have access to your login credentials (email address and password) - secondly, again as previously mentioned, it is read-only, so nothing can actually be changed.
Anyone who has your API key can see all the same stuff you can - battle stats, money, messages, events, trades... Really though, unless someone is hardcore stalking you with a serious vengeance, the worst someone could or would do is get your battle stats and money information and share it.
If you feel that your API key has been compromised or used without permission you can reset it in your preferences by clicking the gear icon in the top-right of the Torn webpage, then choosing "API Key" from the menu, and clicking the "reset" button. This will change your API key and EVERYTHING you've entered your API key in to will stop working - after resetting you API key be sure to update any services you actually use and trust with your new key.
It's important to trust where you put your API Key. Some things to consider:
- Is the person who created this program/script well-known?
- Is this program/script used by a lot of people?
- Does this program/script have good reviews?
- Is the creator open about their intentions and purpose of the program/script?
Please don't misinterpret my intention here... I personally use a number of userscripts - they're not bad or untrustworthy - but again, take care of what you trust and who you share your information with.
Unfair Advantage
A popular subject of the Torn API is creating an unfair advantage that some players may have over others. This is probably the most talked-about thing regarding the API and - as much as I hate to discuss it - I feel I must add something about it here.
First, consider the difference between "advantage" and "unfair advantage." There's a number of things that may give a player an advantage over another - the most obvious may be age, level, and stats; but there's also the user's activity level and what time of day they access Torn to consider. YOU, yes YOU, in one way or another, have a number of advantages over other players - as they do over you. That's what makes this a competitive game, and not just a race to the top of a database.
There's a ton of scripts and programs out there - some that use the API and some that don't - that definitely create an "advantage." I mean, if they didn't create some sort of an advantage, then why would they even exist?
To date, as far as I know, no API script/program/tool has been blocked, questioned, or shot down by staff. Yes, an "unfair advantage" is possible - but so far, despite a number of questions and disagreements, Torn staff have not taken action against any of them.
It's also important to note that scripting is not a new thing, and it didn't start with the release of the Torn API. Scripting in Torn has been around, likely, since 2 days after Torn's inception. The key thing is that the API helps more clearly - but not perfectly - define what's legal and illegal. If anything, the API reduces the likelihood of an unfair advantage, because it allows more players to have more access to more things to help them play the game (rather than just the script-kiddies having the advantage).
And, again... The API can only provide information that is already available elsewhere in Torn - such as player stats, items, city info, etc - so it doesn't provide any "extra" information, just a different (and potentially more efficient) way to get it.
Please be respectful
This thread/post is of course going to start a discussion - that's the joys of a forum. If you have a question or comment on this, of course, feel free to post below. However, please consider starting your own forum thread if you foresee a longer or pointed debated on a specific subject. I'd like for this thread to not get locked, and live on to encourage the Torn API.
OP will be updated as needed to provide relevant information.
Mentions: McNeo [864688]