Guides / Concepts explained

What Is an SDK? Software Development Kits Explained Simply

An SDK is a ready-made toolkit for using a service or platform from your code. How SDKs differ from APIs and libraries, with examples and what to ask your AI.

Mythex Team · 2026-09-29 · 6 min read

An SDK (software development kit) is a ready-made toolkit that a company gives developers so they can use its service or platform without building everything from scratch. It usually includes a code library for a specific programming language, documentation and examples, and sometimes extra tools like testing utilities. When your app "uses the Stripe SDK," it means your code calls Stripe's pre-built functions instead of writing every request to Stripe's API by hand.

Why SDKs matter when you build with AI

When you ask an AI builder to add payments, AI chat, maps or email, it will usually install that provider's SDK and write a few lines that call it. Knowing what an SDK is helps you:

  • Understand what's being added to your project. An SDK is a dependency — outside code your app now relies on.
  • Spot the setup it needs. Almost every SDK needs an API key, and many have separate "server" and "browser" versions with different rules about which keys are safe to use.
  • Ask for the right thing. "Use the official Stripe SDK on the server" is a clearer instruction than "add Stripe."
  • Read errors. Many errors in AI-built apps come from an SDK being misconfigured, outdated or used in the wrong place.

An everyday analogy

Imagine you want to put up shelves.

  • The API is the building's rules: which walls can take screws, what load they hold, where the pipes are. You could work from those rules alone, measuring and drilling everything yourself.
  • The SDK is a flat-pack shelf kit from the same company that made the walls: pre-cut parts, the right screws, a bracket that fits their walls exactly, and an instruction booklet.

You still decide where the shelf goes and what goes on it. The kit just saves you from cutting wood and guessing at screw sizes — and it's less likely to end with a hole in a water pipe.

SDK vs API vs library vs framework

These terms overlap, which confuses a lot of people:

TermWhat it isExample
APIThe rules for talking to a service: which requests it accepts and what it returnsStripe's REST API at api.stripe.com
SDKA provider's toolkit for using its API or platform from a particular language, with docs and toolsStripe's official Node.js library
LibraryAny reusable code you add to a projectA date-formatting package
FrameworkA larger structure your whole app is built insideReact, Next.js, Django

An SDK usually contains a library, and that library usually calls an API. For a web service, "SDK" and "client library" are often used interchangeably.

Some SDKs aren't about web services at all. Apple and Google publish SDKs for building iOS and Android apps, which include compilers, simulators and platform code. The idea is the same: everything you need to build for their platform, in one kit.

What an SDK does for you

Here's the same task — creating a customer at a payment provider — done two ways.

Without an SDK, your code has to build the HTTP request itself: set the URL, add the secret key in the right header, format the data the way the API expects, send it, check the status code, parse the response, and handle retries if the network blips.

With an SDK, it's closer to one line:

const customer = await stripe.customers.create({ email: "lena@example.com" });

Behind that line, the SDK handles:

  • Authentication — attaching your key correctly to every request
  • Data formatting — converting your data into what the API expects, and the response back into objects
  • Errors — turning status codes into clear error types your code can catch
  • Retries — trying again safely when a request fails for temporary reasons (many official SDKs do this)
  • Types — in TypeScript, telling your editor which fields exist, so mistakes show up before you run the code

A worked example: adding AI replies to a support app

You ask an AI builder: "When a customer submits a support ticket, generate a suggested reply using an AI model."

  1. The AI installs the model provider's official SDK as a package in your project (on JavaScript projects, from the npm registry).
  2. You add the provider's API key as a project secret. The SDK reads it from an environment variable on the server.
  3. The AI writes a server route that calls the SDK with the ticket text and a short instruction, and saves the suggested reply to the database.
  4. The browser never sees the key; it only calls your own server route.

If the provider later changes its API, it usually releases a new SDK version. Updating the package — and checking the release notes for breaking changes — is often all it takes.

Key terms

TermMeaning
DependencyOutside code your project relies on. An SDK is one.
Package / package managerA downloadable bundle of code, and the tool that installs it (npm for JavaScript, pip for Python).
Client libraryCode that makes calling a particular API easier. Often what "SDK" means for web services.
Server-side SDKRuns on your backend and can safely use secret keys.
Client-side / browser SDKRuns in the user's browser. Only ever given public or "publishable" keys.
VersionEach SDK release has a number (like 4.2.0). Big jumps often mean breaking changes.
Breaking changeAn update that requires you to change your code.
Changelog / release notesThe provider's list of what changed in each version.

Common misconceptions

  • "An SDK and an API are the same thing." The API is the service's interface; the SDK is a convenience layer on top. You can call most web APIs without an SDK — it's just more work.
  • "If the SDK is installed, the integration is done." You still need an account with the provider, the right keys, and code that handles what happens when things fail.
  • "Any package with the right name is the official one." Attackers sometimes publish look-alike packages. Check the provider's docs for the exact package name.
  • "The browser SDK can use my secret key." Never. Anything in browser code is visible to visitors. Secret keys belong in server-side code only — see how to keep API keys safe.
  • "SDKs never need updating." Old versions stop receiving fixes and eventually stop working when providers retire old API versions.

What to ask your AI builder

  • "Use the provider's official SDK, not a third-party wrapper. Tell me the exact package name and version you installed."
  • "Use the SDK only on the server, and read the key from an environment variable."
  • "Which parts of this SDK run in the browser, and which keys do they use?"
  • "What happens if the SDK call fails or times out? Show the user a clear message and log the error."
  • "List every SDK and package this app depends on and what each one is for."
  • "Check whether any of our SDKs are out of date or have known security issues."

SDKs in Mythex

The Mythex agent can install packages in your project sandbox using the normal package manager for your stack, including providers' SDKs — name the package and the feature you want it for. See Using npm packages. Mythex doesn't ship a catalogue of pre-built integrations for your app: you store the provider's key as a project secret and ask the agent to call the service from the server side, as described in Integrate any API.

For the layer underneath SDKs, read what an API is. For two common SDK-based features, see how to add payments to your app and how to use LLM APIs.

Questions

What is an SDK in simple terms?

An SDK (software development kit) is a bundle of ready-made code, documentation and tools that a company provides so developers can use its service or platform easily. Instead of writing every request to an API by hand, you call simple functions the SDK already provides.

What is the difference between an SDK and an API?

An API is the set of rules for talking to a service — the requests it accepts and the responses it returns. An SDK is a toolkit built on top of that API, usually for one programming language, that makes those requests for you and handles details like authentication, retries and data formats.

Are SDKs free?

Most SDKs for web services are free and open source to download, but the service they connect to may charge for usage. Using the Stripe or OpenAI SDK costs nothing in itself; the payments or AI requests it makes are billed by the provider.

Is an SDK safe to use?

Official SDKs from the provider are generally the safest way to call their service, since they're maintained and handle security details. Install them from the official package registry, keep them updated, and be careful with unofficial packages that have similar names.

Keep reading

  • Frontend vs Backend: What's the Difference? — The frontend is what users see in the browser; the backend runs on a server and handles data, logic and security. How the two fit together, with an example.
  • How Domains and DNS Work: A Guide for Non-Developers — How domain names and DNS connect example.com to your app: registrars, nameservers, A, CNAME, MX and TXT records, propagation, and connecting a custom domain.
  • How to Add Payments to Your App: Checkout, Subscriptions and Webhooks — How to take payments in an app you built: Stripe Payment Links vs Checkout vs subscriptions, webhooks, test mode, going live, and what to know about tax.
  • How to Keep API Keys Safe in Your App — Keep API keys out of your code, browser and chat: store them as secrets, use them only on the server, restrict them, and rotate any key that leaks.
  • How to Use LLM APIs: Tokens, Costs, Keys and Your First AI Feature — What an LLM API is, how tokens, context windows and per-token pricing work, how to keep your API key safe, and how to add a first AI feature to your app.
  • Native Apps vs Progressive Web Apps: Which Do You Need? — Native apps vs progressive web apps (PWAs): what each can do, iPhone limits as of September 2026, costs, and how to choose for your first version.

Start building free · Templates · Docs