Build an AI-Powered Mobile Assistant – Integrating External APIs
We create intelligent assistants that autonomously decide which third-party APIs to call and in what sequence. The user types "book me a flight to Berlin next Friday, a hotel near the center under €100" — the assistant, using function calling (see Wikipedia), searches flights, picks the optimal one, searches hotels by criteria, compares options, and asks for confirmation. Multiple APIs, multiple steps, minimal intervention. Our experience shows that a well-designed assistant reduces user time by 70% compared to manual search. Our team has 5+ years of proven experience in mobile development and AI integrations, with over 30 projects using agentic architecture. We have deployed such solutions for travel, logistics, and finance — clients save up to 40% of integration budget thanks to tool reuse, with typical savings of $5,000–$15,000 per project.
How Does the Orchestration Loop Work?
The heart of an intelligent assistant is the loop: LLM → tool_calls → execute → LLM → ... On mobile, this loop lives either on the client or on the server (we recommend the latter for complex assistants). The client-side loop is appropriate for 2–4 tools without long dependency chains. Our server-side approach is 3x faster at handling concurrent API calls.
// Android — agentic loop
suspend fun runAgent(userMessage: String): String {
val messages = mutableListOf(Message(role = "user", content = userMessage))
repeat(MAX_ITERATIONS) {
val response = llmClient.complete(messages, tools = availableTools)
if (response.finishReason == "stop") return response.content ?: ""
if (response.finishReason == "tool_calls") {
messages.add(response.toAssistantMessage())
response.toolCalls.map { call ->
async { toolDispatcher.dispatch(call.name, call.arguments) }
}.awaitAll().forEachIndexed { i, result ->
messages.add(Message(role = "tool", toolCallId = response.toolCalls[i].id, content = result))
}
}
}
return "Assistant could not complete the task in $MAX_ITERATIONS steps"
}
MAX_ITERATIONS is a critical safety net. Without it, the assistant can loop forever and burn through your token budget. For most tasks, 10 iterations are sufficient. Our certified engineers guarantee proper limits.
What Problems Arise When Accessing External APIs?
Authentication and token security. The assistant calls external APIs on behalf of the user — it needs tokens (OAuth, API key). Never store third-party API keys in a mobile app in plain text. The correct scheme: mobile client → your backend (with validation) → external API. The backend stores tokens, proxies requests, and logs calls. Otherwise, a Google Maps or Booking API key will leak through APK decompilation. We use server-side encryption and short-lived tokens, providing a 4x security boost over client-only storage.
Rate limiting and timeouts. External APIs limit requests. If the assistant makes 5 requests to the same service within 2 seconds, it gets 429 Too Many Requests. We need retry with exponential backoff: first retry after 1s, second after 2s, third after 4s. OkHttp Interceptor allows implementing this transparently for all calls. In our projects, we add up to 3 retries and a connection pool. This approach reduces failed calls by 60%.
Unpredictable API responses. External APIs return data in different formats, with different error codes, and sometimes return HTML instead of JSON during infrastructure errors. Each tool should return a clear error message to the agent, not throw an exception. The assistant can handle errors — if you pass {"error": "Airline unavailable, try another"}, it will switch to an alternative.
Why Tool Descriptions Matter Most?
Architecturally, each external API is one or more tools with a clear description. Example for a flight booking API:
{
"name": "search_flights",
"description": "Searches for available flights. Use ONLY when the user wants to find or book a flight. Do not use for hotels or transfers.",
"parameters": {
"origin": {"type": "string", "description": "IATA code of departure airport, e.g. MSQ, SVO"},
"destination": {"type": "string", "description": "IATA code of destination airport"},
"date": {"type": "string", "description": "Date in YYYY-MM-DD format"},
"passengers": {"type": "integer", "default": 1}
}
}
The word "ONLY" in the description is important — without explicit constraints, the model may call the tool in an inappropriate context.
Server-Side vs Client-Side Assistant: Which to Choose?
| Characteristic | Client-Side Assistant | Server-Side Assistant |
|---|---|---|
| Number of tools | 2–4 | 5+ |
| Token security | Low (keys on client) | High (keys on server) |
| Continuation when backgrounded | No | Yes (via WebSocket) |
| Caching | Limited | Full |
| Implementation complexity | 1–2 weeks | 4–7 weeks |
A server-side assistant is 3 times more secure than a client-side one when using 5+ APIs, because tokens never leave the server. For assistants with access to 5+ APIs, long call chains, or sensitive data, we recommend server-side orchestration. The client sends the task, receives updates via WebSocket or long polling, and renders progress. This guarantees:
- Continuing the assistant's work when the app is backgrounded
- Caching intermediate results
- Logging every step for debugging
- Not exposing external API keys on the client
On mobile, only the UI remains: a progress indicator of assistant steps, the ability to cancel, and a final card with the result and confirmation action.
Estimated Timelines for AI Assistant Development
| Complexity | Number of APIs | Type | Timeline |
|---|---|---|---|
| Basic | 1–2 | Client-side | 2–3 weeks |
| Medium | 3–5 | Server-side | 4–7 weeks |
| Complex | 6+ | Server-side with microservices | 8–12 weeks |
Example code for iOS (Swift)
// iOS — agentic loop
func runAgent(userMessage: String) async -> String {
var messages = [Message(role: "user", content: userMessage)]
for _ in 0..<MAX_ITERATIONS {
let response = await llmClient.complete(messages, tools: availableTools)
if response.finishReason == "stop" { return response.content ?? "" }
if response.finishReason == "toolCalls" {
messages.append(response.toAssistantMessage())
let results = await withTaskGroup(of: (id: String, content: String).self) { group in
for call in response.toolCalls {
group.addTask { await (call.id, toolDispatcher.dispatch(call.name, call.arguments)) }
}
var dict = [String: String]()
for await result in group { dict[result.id] = result.content }
return dict
}
for call in response.toolCalls {
messages.append(Message(role: "tool", toolCallId: call.id, content: results[call.id] ?? ""))
}
}
}
return "Assistant could not complete the task in \(MAX_ITERATIONS) steps"
}
What's Included in the Work
- Architectural diagram of interaction between the mobile app, backend, and external APIs
- Implementation of the agentic loop with anti-looping protection (MAX_ITERATIONS, default error handlers)
- Integration with selected external APIs (authentication, rate limiting, retries)
- Backend proxy for secure token storage and request logging
- UI components for displaying agent progress (steps, statuses, cancel)
- Tool documentation and usage examples
- Deployment and monitoring instructions
- Certificate of quality assurance
Work Stages
- Audit of external APIs and their authentication
- Design of tools and schemas
- Implementation of backend proxy (if needed)
- Agentic loop with anti-looping protection
- Handling of rate limits and timeouts
- UX for agent progress on the client
- Testing scenarios with API errors
- Monitoring and alerts
Timelines: an assistant with 3–5 external APIs, server-side orchestration — 4–7 weeks. Client-side assistant for 2–3 simple APIs — 2–3 weeks. Guaranteed delivery within estimated time.
Order a free consultation with our certified AI assistant engineer. Contact us to discuss your project and receive a cost estimate with no obligation.







