In this newsletter, we take a look at LLMjacking, where hackers find ways to obtain API tokens and keys, resulting in tens of thousands of dollars in bills. We also look at the new RCNS standard for runtime contract negotiation through the addition of some new methods, if MCP or CLI is more efficient, and the increase of API sprawl due to MCP. Finally, we look at the evolution of API products in the AI era, metrics that matter for your API, GitLab's Act 2 announcement that focuses heavily on APIs, and designing idempotency keys for output event delivery.
-- Happy Reading!
Featured Articles
LLMjacking: Hackers Steal AI API Keys, Cause Bill Shock
Hackers are increasingly targeting AI API keys through 'LLMjacking' to incur massive charges on victims' accounts, as highlighted in a recent Security Intellige by StartupHub.ai [startuphub.ai]
Move over REST, Introducing Runtime Contract Negotiation Substrate (RCNS)
About 10 years ago, I was speaking to an audience and floated an idea around what intelligent APIs in the future might look like. The premise was simple: there would come a day when APIs could be dynamically generated rather than requiring developers to design, document, and map them out in advance. [linkedin.com]
MCP vs. CLI: Which Is Better for Agentic AI?
Compare MCP vs CLI for agentic AI. Learn tradeoffs in performance, flexibility, and when each approach works best. by J Simpson [nordicapis.com]
MCP Is Making API Sprawl Worse
MCP and AI agents worsen API sprawl and governance challenges, especially at enterprise scale. Here's what teams can do to regain control by Art Anthony [nordicapis.com]
Why Token Handling Must Evolve for AI Agents
Token handling for AI agents requires real-time authorization, scoped access, and short-lived tokens to improve API security. by J Simpson [nordicapis.com]
Business of APIs
Building API Products in the AI Era
How API products evolve for AI agents and developers, covering design, protocols, monetization, and developer experience by Janet Wagner [nordicapis.com]
What to Measure in Your API Program: The Metrics That Actually Matter | Apiable
Most API teams track uptime and latency. But if you're running a partner program, those aren't the metrics your CFO cares about. Here are the ones that are. [apiable.io]
(Un)Related
GitLab Act 2
A letter to our customers and our investors. [about.gitlab.com]
Designing idempotency keys for outbound event delivery
Most idempotency guidance is written for receivers. The emitter side under fan-out is harder. Design keys that survive retries, replays, and multi-destination. [meshes.io]
|
|