Your APIs are already being called by agents
Nobody decided to expose them. An MCP server set up in an afternoon, a developer’s token, and the traffic arrives under a human identity. How to recognise it in your logs, and what to do next.
What we see in the field: product choices, real costs, migrations, operations. Nothing that does not come from a project.
Nobody decided to expose them. An MCP server set up in an afternoon, a developer’s token, and the traffic arrives under a human identity. How to recognise it in your logs, and what to do next.
The MCP protocol, the identity of the agent, the difference between discovering a tool and having the right to invoke it, and what per token billing changes.
The market is full of 'Apigee expert' profiles who have looked at a console. The signals that separate real platform skill from a line on a CV.
The maintenance window big bang does not work. The method of progressive cutover, consumer by consumer, and the five traps that make it fail.
A four-step selection method: frame with the pillars, rule out on operations, test on your own APIs, cost it over three years.
A proof of concept run by the vendor proves the vendor knows how to put on a demo. How to turn a POC into a trial that really predicts life in production.
APIM RFP grids run to a hundred lines on features and three on operations. The ten questions that are missing, and what their answers reveal.
When every internal call crosses four network layers, each justified on its own. How the stack builds up, what it costs, and how to reduce it.
The monetisation module sells licences and makes for handsome business cases. The revenue rarely turns up. What API billing actually takes.
The five billing models on the market, what they hide, and why the dominant line item at three years appears on no quote.
The SaaS versus self-hosted debate is usually settled on licence price or a principle of sovereignty. Both criteria are bad. The right one: who will carry operations.
'The platform is slow' is the first hypothesis of every latency incident, and almost always the wrong one. The diagnostic method, and the real suspects.
Promising a partner 99.9% without knowing what you actually hold is signing a blank cheque. The correct order: measure, commit internally, then contract.
When developers expose their APIs outside the gateway, the usual answer is an architecture memo. The cause lies elsewhere: the platform is slower than the bypass.
As long as the platform is configured with a mouse, it rests on the memory of the people who click. The realistic path to APIOps, step by step, without freezing everything.
An organisation's actual API estate always exceeds its catalogue, by a factor of up to three. Where ghost APIs come from, why they are the first risk, and how to flush them out.
Nobody breaks an API contract on purpose. You break it believing you are making a harmless change. The list of silent breaking changes, and the automated check that stops them.
A quota protects your backend against your legitimate clients. It protects next to nothing against an attacker. Telling the two apart avoids a false sense of protection.
A static key in a header is a password that never rotates, sent on every call. Where the key is enough, where it is guilty, and what to replace it with.
Every platform ships a developer portal. Most are empty six months later. It is not a tooling problem, it is a product problem.
Serving internal, partner and public traffic with one gateway looks economical. It is the shortcut that ends up emptying the platform of its reason to exist.