560 blogs tracked4,950 posts indexed

#blog

50 posts · 3 companies · newest first

1

Guide to the OWASP LLM Top 10 (opens on the source site)

Large language models (LLMs) have become mainstream. Recent estimates suggest there are over 1.1 billion ChatGPT users. LLMs and AI agents have become a part of every aspect of our lives, from writing emails to coding and everything in between. Yet, this scenario is a cybersecurity incident waiting to happen. Many developers aren’t used to ...

blogsecurityexcerpt only · body stays at the source
From the web
2

Why In-Person Tech Conferences Still Matter (opens on the source site)

As we get prepared to meet again in Stockholm for the Nordic APIs Summit (this will be our ninth Summit), I wanted to take a moment to reflect on the importance of in-person events. Especially the importance of in-person technology conferences that get real humans together to talk shop. We all know the excitement, energy, ...

blogapi-communityexcerpt only · body stays at the source
From the web
3

How AI Agents Are Changing API Architecture (opens on the source site)

AI agents have rapidly become a new kind of software consumer. Where traditional applications analyze and recommend, autonomous agents can now interpret goals, make decisions, find tools, and take actions. Through API integrations and interactions, agents can coordinate actions across a range of systems and chain together their own workflows that might initially seem fairly ...

blogai-agentsexcerpt only · body stays at the source
From the web
4

Are Standards Still for Humans or Agents? In Conversation With Lorna Mitchell (opens on the source site)

Ahead of her Nordic APIs Summit 2026 talk on API standards for agents, TM Forum’s Lorna Mitchell joins us to talk about how — or whether — agentic has changed what good API design looks like. There are those who believe that the rise of agentic API consumption will change what software development looks like ...

blogai-agentsexcerpt only · body stays at the source
From the web
6

Understanding Determinism and Non-Determinism (opens on the source site)

Non-determinism is a concept that has existed for decades. However, it has rarely been a central part of software design — until the rise of large language models (LLMs). These models enable developers to build probabilistic AI applications, such as autonomous AI agents. Traditionally, developers build deterministic software that initiates concrete, repeatable actions, where they ...

1blogai-agentsexcerpt only · body stays at the source
From the web
7

Why Developer Portals Must Evolve in the AI Agent Age (opens on the source site)

The age of AI is firmly upon us — and as more teams adopt artificial intelligence and agentic flows, providers are increasingly finding that their old strategies and approaches need to shift. One area where this is rapidly becoming a concern is in the domain of developer portals. Developer portals were built around a very ...

blogai-agentsexcerpt only · body stays at the source
From the web
8

AI Agent Security in the Enterprise: Interview With Isabelle Mauny (opens on the source site)

AI agents are quickly rising in the enterprise. They’re granting more powers to knowledge workers across sales, finance, engineering, marketing, and other disciplines in the process. Yet, as most quick technological adoptions go, security is often falling by the wayside or being implemented after the fact. Ahead of Nordic APIs Summit 2026, we’re connecting with ...

blogaccess-controlexcerpt only · body stays at the source
From the web
9

6 Ways Traditional API Design Has Changed Forever (opens on the source site)

For over two decades, API design and architecture remained remarkably consistent. Perhaps it’s the outsized influence of Roy Fielding’s RESTful dissertation, but API designers have stuck to the principles of stateless architecture, resource-based endpoints, and HTTP commands to an impressive degree. That’s all starting to change, now that we’ve radically recontextualized the way we use ...

blogai-agentsexcerpt only · body stays at the source
From the web
10

Thinking Like A Naturalist: An Interview with Claire Barrett (opens on the source site)

Ahead of Nordic APIs Summit 2026, we catch up with speaker Claire Barrett on the mindset shift needed for adopting AI-enabled strategies. “Imagine driving around an old town,” responds Claire Barrett when asked to describe what it means to be AI-ready from an integration perspective. “Imagine a European city that’s been inhabited for thousands of ...

blogai-agentsexcerpt only · body stays at the source
From the web
12

Beyond the 200 OK: Architecting Observability for AI (opens on the source site)

Traditional monitoring tools, such as application performance monitoring (APM), were engineered to monitor deterministic software where specific inputs reliably lead to predictable outputs through hard-coded logic. When a traditional API fails, it usually throws a 500 Internal Server Error. But when an AI agent fails, it might return a perfectly healthy 200 OK status code ...

blogai-agentsexcerpt only · body stays at the source
From the web
13

Coherence, Connections, and… Spacetime Crystals (opens on the source site)

Ahead of his Nordic APIs Summit 2026 talk on API coherence, London Stock Exchange Group’s Gareth Faull joins us to talk about the art of aligning APIs with organizational intent. Measuring the performance of an API is a relatively straightforward process: ensure observability is in place, follow governance best practices, measure uptime, track usage statistics, ...

blogai-agentsexcerpt only · body stays at the source
From the web
15

MCP Went Stateless: What Now? (opens on the source site)

The latest release of the Model Context Protocol (MCP) specification has created a lot of buzz in tech circles. Why? Primarily because this AI communication protocol has now gone stateless! This shift from stateful to stateless impacts how developers of MCP servers and AI tools use the protocol moving forward. In addition, the change impacts ...

blogstrategyexcerpt only · body stays at the source
From the web
16

How Identity Federation Empowers Partner API Strategy (opens on the source site)

Business identity is a complex issue rife with risks across the board. Large enterprises often require deep, flexible integrations with dozens or hundreds of partners, but this comes with significant risk — between the potential for information leakage, concerns around replays or data usage for continued insecure access, and the sheer friction of such a ...

blogsecurityexcerpt only · body stays at the source
From the web
17

10 Tips for Preparing APIs for Agentic Access (opens on the source site)

In May 2026, Cloudflare released a new tool called isitagentready.com. It analyzes a URL for everything an agentic AI would need to interact with a site and then returns a score out of 100. Even better still, it breaks down its assessment by category, letting you know how your site performs for discoverability, accessibility from ...

blogai-agentsexcerpt only · body stays at the source
From the web
20

Native Async/Coroutine Reads in RocksDB (opens on the source site)

A point lookup that misses RocksDB’s block cache can spend most of its time waiting for storage. The traditional way to keep more reads in flight is to add threads. That works, but each outstanding read parks a thread, carries a stack, and adds context-switching overhead. RocksDB now has experimental asynchronous Get and MultiGet APIs backed by native C++ coroutines. When a read reaches storage, RocksDB can suspend the request, let its read-executor worker run another ready task, and resume the request when the filesystem reports completion. A small executor can therefore maintain more…

blogexcerpt only · body stays at the source
From the web
22

How Fuzz Testing for APIs Is Evolving (opens on the source site)

Ahead of Nordic APIs Summit 2026, we check in with speaker Andrea Arcuri on how fuzz testing for APIs is evolving. “You cannot really check security properties if all your HTTP calls fail with a 4xx because your techniques can’t generate the right test data to pass the first layer of input validation,” answers Andrea ...

blogapi-securityexcerpt only · body stays at the source
From the web
24

Are We Overengineering Modern Infrastructure? (opens on the source site)

Ahead of his 2026 Nordic APIs Summit talk on scaling data ingestion without turning to Kubernetes, we check in with Bauer Media Group UK’s Faith Sodipe to talk about infrastructure complexity. In the tech space, perhaps more than in any other, we are always looking for the next big thing. Whenever a new platform, standard, ...

blogapi-loggingexcerpt only · body stays at the source
From the web
25

API Gateways, AI Gateways, and MCP Gateways: Are Enterprises About to Pay Twice Again? (opens on the source site)

Over the last decade, enterprises invested heavily in API infrastructure. They purchased API management platforms, deployed gateways across business units and regions, built developer portals, introduced security and observability tools, and encouraged teams to adopt API-first development. The business case was compelling. APIs would make enterprise capabilities easier to reuse, shorten integration timelines, improve partner ...

blogplatformsexcerpt only · body stays at the source
From the web
27

7 Tools for Multi-Agent Infrastructure (opens on the source site)

A single agentic workflow calling a single API is an easily tractable engineering problem — the solutions exist, and it’s ultimately just a problem of visibility and integration. A fleet of specialized agents delegating tasks to each other, sharing state, and discovering tools at runtime is decidedly more difficult — almost an order of magnitude ...

blogplatformsexcerpt only · body stays at the source
From the web
28

API Marketplaces and the Invisible Economy: Trade Routes of the AI Era (opens on the source site)

APIs are like the backstage crew of the digital economy. They’re not front and center, but they’re essential for putting on a show. Yet, from a business perspective, APIs have traditionally been regarded as a form of “operational plumbing,” with many enterprises treating them as technical infrastructure rather than strategic assets. However, companies like Stripe, ...

blogstrategyexcerpt only · body stays at the source
From the web
31

What Is a Token? A Developer’s Guide to Every Type (opens on the source site)

If you’re an API or application developer, you likely hear the term “token” a lot. However, that term has entirely different meanings depending on the developer and the industry. Maybe you’re a developer who just implemented token-based authentication or found out the AI agent you built uses far too many LLM tokens. Perhaps you’re experimenting ...

blogstrategyexcerpt only · body stays at the source
From the web
32

What Happens After Every Company Becomes a Data Company? (opens on the source site)

In a 2018 Forbes article, Jedidiah Yueh and Randy Bean argued that every company is now a data company. “Leveraging data — in an ethical manner — has to be at the heart of your company and product strategy,” they wrote. “Collect, sift, then monetize.” Just shy of a decade later, virtually every company (in ...

blogsecurityexcerpt only · body stays at the source
From the web
33

6 Ways to Achieve Sovereign API Management (opens on the source site)

The regulatory framework has changed significantly over the last decade. GDPR was once largely theoretical. But now, multi-billion euro fines have made it a solid statement on European privacy. India’s DPDP Act has enforced privacy protections for Indian citizens, Brazil’s LGPD is actively enforced against multinational corporations, and China’s PIPL and DSL impose strict cross-border ...

blogplatformsexcerpt only · body stays at the source
From the web
34

5 Signs That Authenticated API Traffic Is Actually Malicious (opens on the source site)

A recent report from Salt Security published a truly alarming statistic. According to the report, 95% of API attacks come from authenticated sources. This should raise alarms for anyone who knows anything about cybersecurity, as it means API attacks are seemingly real transactions. These attacks won’t even be noticed by average cybersecurity systems, as, for ...

blogsecurityexcerpt only · body stays at the source
From the web
37

Linux Server Health Checks: 10 Metrics Every Sysadmin Should Monitor (opens on the source site)

Servers give you warnings before they fail. Most sysadmins performing Linux server monitoring miss them because they're watching the wrong numbers. The metrics that actually matter are one level deeper: iowait instead of CPU percentage, active swap paging instead of memory usage, inode counts instead of just disk space.Continue reading...

blogguestsexcerpt only · body stays at the source
From the web
42

watch Command in Linux: Real-Time Monitoring with Examples (opens on the source site)

The watch command runs any Linux command repeatedly at a set interval and displays the output full-screen, making it one of the quickest ways to monitor live system activity without writing a script. This guide covers all the key options with practical examples for real sysadmin use cases.Continue reading...

bloglinuxexcerpt only · body stays at the source
From the web
43

Range Tombstone Conversion: Faster Scans Over Long Runs of Deletes (opens on the source site)

RocksDB has historically been known for poor performance when tombstones accumulate. This has become a common problem within Meta, and the community has raised it as well. Here, we introduce an optimization that attempts to convert contiguous tombstones into a range tombstone during scans. As a result, instead of skipping through N tombstones, we only need to skip through a single range tombstone. Background: point tombstones and range tombstones RocksDB is an LSM-tree, so a delete does not erase data in place. It writes a tombstone: a marker that shadows older values. A point tombstone (from…

blogexcerpt only · body stays at the source
From the web
44

Blob Direct Write With Partitioned Blob Files (opens on the source site)

TL;DR Blob Direct Write moves large-value separation earlier in RocksDB’s write path. When enable_blob_files and enable_blob_direct_write are enabled, values at or above min_blob_size can be written directly to blob files during a write, while the WAL and memtable store a compact BlobIndex reference instead of the full value. The companion partitioning support makes this more than a write-path optimization. A column family can have multiple direct-write blob partitions, and applications can provide a BlobFilePartitionStrategy to choose where each large value goes. That turns blob files into a…

blogexcerpt only · body stays at the source
From the web
45

FIFO KV-Ratio Compaction for BlobDB-Backed TTL Workloads (opens on the source site)

RocksDB 11.0 added CompactionOptionsFIFO::max_data_files_size and CompactionOptionsFIFO::use_kv_ratio_compaction for a specific but important shape of workload: FIFO compaction, integrated BlobDB, large values, point lookups, and data that naturally expires by TTL or by a bounded data-size budget. The implementation was added in pull request #14326. The goal is to keep FIFO’s low write amplification while reducing the read overhead caused by many small L0 files. The new picker uses the observed ratio between SST bytes and blob bytes to choose a stable target SST size, then moves L0 files…

blogexcerpt only · body stays at the source
From the web
50 shown

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.