We're back with another set of curated content. In this edition, we have a thoughtful piece on why the API-first economy may experience a second wave due to AI and LLMs. We also look at the 5 most common API vulnerabilities and how you can protect your own APIs. Along the same topic, we look at predator bots and API abuse that is only growing with the introduction of AI.
Google has released two new inference tiers in their Gemini API that includes options for lower-cost API usage. I suspect this kind of pricing model will become the norm soon, with high priority, standard, and low priority API requests offering different pricing structures. While this approach is primarily seen in the LLM space today, it may be time to start working with an expert team to see where you may need to adjust your API pricing strategy.
Finally, we have a slightly off-topic video on HyperCard and why it changed everything. While the video doesn't get into hypermedia, it does show some of the earliest instances of hypermedia links to connect and relate data and capabilities.
-- Happy Reading!
Featured Articles
The Second Wave of the API-first Economy
APIs were meant to make the web programmable and interoperable. A combination of revenue chasing, security concern, and abuse reversed the trend for a decade as walls went up instead of down. Today, LLMs are changing the equation. People want agents that act on their behalf, and the services that ship APIs will have a decisive edge over those that don’t. by Brandur Leach [brandur.org]
The 5 Most Common API Vulnerabilities in 2026
Top API vulnerabilities in 2026 explained, including broken authentication, BOLA, and security misconfiguration, plus mitigation strategies. by Bill Doerrfeld [nordicapis.com]
When 'Normal' Traffic Isn't Normal: Predator Bots and the Hidden War on Business Logic
How predator bots exploit APIs to abuse business logic and bypass traditional defenses - and how API security teams can detect and stop them. by Eric Schwake [nordicapis.com]
New ways to balance cost and reliability in the Gemini API
Google is introducing two new inference tiers to the Gemini API, Flex and Priority, to balance cost and latency. [blog.google]
How to build an enterprise-grade MCP registry
MCP registries are emerging as the new integration catalog for AI agents. Building one for the enterprise requires semantic discovery, strong governance, and developer-friendly controls. by Maxwell Cooter, Gyana Swain, David Linthicum, Anirban Ghoshal [infoworld.com]
Business of APIs
The API economy may soon grow by tens of millions of customers-here's why
Agentic commerce, or AI agents using blockchain-based micropayments, is quickly becoming a reality. by Jeff John Roberts [fortune.com]
(Un)Related
HyperCard Changed Everything
Before the web, there was HyperCard. It gave ordinary people the power to create, to explore - and even led to the best-selling computer game of all time. So, what happened to it? This video was a ton of work, and I'd like to thank archive.org as well as Epidemic Sound. by dreamwieber [youtube.com]
Copilots vs. Agents
A framework for healthcare AI tools by Brendan Keeler [healthapiguy.substack.com]
Exposed API keys found in JavaScript and website code
Thousands of hidden API credentials found across public webpages quietly exposing cloud services, payment systems, and developer tools to potential abuse [techradar.com]
What Are Agent Skills?
Agent skills have seen rapid adoption. Learn what they are, how they work in AI agents, and how they differ from protocols like MCP. by J Simpson [nordicapis.com]
Squarespace redraws the boundaries of platform engineering
AI is transforming platform engineering from a support function into a more agile hands-on discipline, reshaping teams and accelerating migrations. by Bill Doerrfeld [leaddev.com]
|
|