In this edition, we look at API marketplaces and how they are becoming a hub for AI agents, Janet Wagner covers the different kinds of tokens you may encounter, and MailKite offers a webhook-based solution to parsing and processing inbound email. We also have insights into the latest MCP specification that was released last week, a PII disclosure in Keycloak, and Bing is retiring SOAP/POX APIs at the end of August. Finally, we look at what happens when every company becomes a data company, APIs in the insurance industry, and three things Mike Amundsen has learned about software.
-- Happy Reading!
Featured Articles
API Marketplaces and the Invisible Economy: Trade Routes of the AI Era
How API marketplaces turn APIs into tradable services for AI agents, enabling monetization, governance, and orchestration. by Chris Darvill [nordicapis.com]
What Is a Token? A Developer's Guide to Every Type
Learn the major types of tokens software developers use in authentication, LLMs, crypto, applications, and APIs. by Janet Wagner [nordicapis.com]
Email parser API: parse inbound email to JSON with a webhook - MailKite
An email parser API that turns inbound email into structured JSON - no templates, no IMAP, no MIME parsing. Point your MX at MailKite and get a signed... [mailkite.dev]
MCP goes stateless with headers. Do you need an MCP-native data plane?
Stateless, header-forwarding MCP makes servers easier to scale out but introduce attack vectors [agentgateway.dev]
Escape Research team found a PII disclosure in Keycloak. It's now CVE-2026-17059.
Keycloak filters its main users list so a restricted admin sees nothing. The endpoint that lists a role's members skips that filter and hands the same account everyone's email and name. Escape research found it, reported it, and it's now tracked as CVE-2026-17059. [escape.tech]
Bing Webmaster Tools SOAP/POX APIs Retires August 31, 2026
Microsoft will be retiring the Bing Webmaster Tools SOAP/POX APIs on August 31, 2026. If you use these legacy APIs you should begin to migrate to the JSON/HTTP (REST) API version. by Barry Schwartz [seroundtable.com]
Google Now Requires Passkeys For New Google Ads API Refresh Tokens
Google now requires passkeys for new Google Ads API OAuth refresh tokens starting August 5. Existing tokens remain valid. See what developers and agencies must prepare for. [almcorp.com]
AI-Assisted API Design
The traditional API design process today is bottlenecked by limited time and budgets, forcing teams to choose between delivery speed and design quality. This report reveals a game-changing shift: using LLMs as interactive API design coaches.
Learn more and download the full report.
Business of APIs
What Happens After Every Company Becomes a Data Company?
Learn how responsible data stewardship, identity controls, and data minimization can protect customer data across APIs and AI agents. by Art Anthony [nordicapis.com]
Guardian's API push raises questions for brokers
What brokers should really be asking their carriers next [insurancebusinessmag.com]
(Un)Related
Three Things I've Learned About Software
From idea to install. by Mike Amundsen [mamund.substack.com]
How AgentCore Gateway supports the MCP 2026-07-28 spec
The Model Context Protocol (MCP) published its 2026-07-28 specification, the largest revision since launch: MCP is now stateless, with a governed extensions system and hardened authorization. Learn what changed and how to enable the new version on Amazon Bedrock AgentCore Gateway with a single UpdateGateway call. [aws.amazon.com]
A unified API for AI model routing
Discover how developers can configure Google Cloud API Gateway to dynamically route OpenAI-compatible requests without managing open-source proxies. [developers.googleblog.com]
|
|