API Developer Weekly
Dec 4, 2025 - Issue #565
|
|
Whew! You take a couple of weeks off and the review queue grew! This week, we look at a retrospective from a first-time API builder and what it taught about being human, along with a distilled list of good API design. We also have videos of the Platform Summit 2025 on YouTube, what happens when APIs become a vulnerability, and details about a recent ChatGPT attack.
I added a spotlight section to separate out the articles about MCP, which is gaining quite a bit of traction lately. Love it or hate it, for now it is part of our API world. So, check out the insights provided to us about the granularity of an MCP (I recently posted on LinkedIn that MCP is the BFF for APIs), whether we should use stdio for MCP in the enterprise, MCP URL elicitation spec, and a look at MCP through the eyes of CGI (yep, that CGI that powered Perl and PHP scripts for many years).
Be sure to check out the LinkedIn post from John Sheehan on the details of how he sold Runscope not once, but twice. John is a long-time friend of the newsletter and many of you API veterans may remember Runscope. I knew that things were challenging for him, but wow!
Finally, there have been quite a few product announcements and how-tos for specific vendors and programming languages, so I put those in the (Un)Related section for this edition of the newsletter.
And a big wave ๐ to all of my friends attending APIdays Paris. I won't be there this year, but I hope you have a safe and fun time chatting everything APIs.
-- Happy Reading!
P.S. I just released a report that details how you can use LLMs to assist your API design efforts, speeding up the process by 60% or more. The approach takes an "AI-in-the-loop" perspective that blends your expertise with the LLM's ability to speed up artifact generation and catch gaps in your assumptions. Check it out here to learn more about how to do it, what it looks like, and which LLMs are the best choice.
Featured Articles
What Building My First API Taught Me About Life's Architecture
What Building My First API Taught Me About Life's Architecture How struggling with endpoints, error codes, and statelessness made me a better human I didn't build my first API-I wrestled it ... by Mubashir [medium.com]
Everything I know about good API design
Most of what modern software engineers do involves APIs: public interfaces for communicating with a program, like this one from Twilio. I've spent a lot of time... [seangoedecke.com]
Platform Summit 2025
Speaker sessions, keynotes, and panels from Platform Summit 2025, Nordic APIs' flagship yearly event in Stockholm, which brings together leading API industry... [youtube.com]
When APIs become the enterprise backdoor -- securing AI's most vulnerable link [Q&A]
APIs were once treated as behind-the-scenes connectors. Today, they are the enterprise nervous system, linking cloud workloads, data platforms, SaaS tools, and increasingly, autonomous AI agents. This centrality makes them irresistible targets. According to multiple industry reports, API-related vulnerabilities are among the fastest-growing classes of security incidents. by Ian Barker [betanews.com]
ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets
A Server-Side Request Forgery (SSRF) vulnerability in OpenAI's ChatGPT. The flaw, lurking in the Custom GPT "Actions" feature, allowed attackers to trick the system into accessing internal cloud metadata, potentially exposing sensitive Azure credentials. [cybersecuritynews.com]
Spotlight: Model Context Protocol (MCP)
Why MCP Shouldn't Wrap an API One-to-One | Nordic APIs |
Learn why one-to-one MCP API wrappers fail and how to design Model Context Protocol tools around intent for effective AI agent interaction. by Kristopher Sandoval [nordicapis.com]
Client Registration and Enterprise Management in the November 2025 MCP Authorization Spec
The new MCP authorization spec is here! Today marks the one-year anniversary of the Model Context Protocol, and with it, the launch of the new 2025-11-25 specification. I've been helping out with the authorization part of the spec for ... [aaronparecki.com]
Avoid stdio! MCP Servers In Enterprise Should Be Remote
Enterprises see the power in connecting their data and functionality directly to AI models but most are still treading lightly. The Model Context Protocol (MCP) has quickly emerged as the de facto standard for this kind of AI connectivity, yet it remains very early in its enterprise maturity. [blog.christianposta.com]
MCP's URL Elicitation Spec: Real Authorization for Agents
MCP lacked secure OAuth flows for production agents. URL Elicitation fixes that. Learn how Arcade's spec enables enterprise-grade agent authorization. by Nate Barbettini, Wils Dawson [blog.arcade.dev]
Tools Gone Wild
When the web was young, most 'dynamic' web sites were built via CGI. That's Common Gateway Interface for all you kids in the back row, and it was the way web servers were able to call out and execute external code. [linkedin.com]
Business of APIs
How I sold my startup...twice.
This story starts in the fall of 2015 after almost a year of failing to raise a Series B for Runscope, the API tools startup I founded with Frank Stratton in 2013. We had been grinding through pitch meetings for months, and on paper the business actually looked good. [linkedin.com]
(Un)Related
Amazon API Gateway adds MCP proxy support - AWS
Discover more about what's new at AWS with Amazon API Gateway adds MCP proxy support [aws.amazon.com]
OpenAPI.NET: The Biggest Update Ever - OpenAPI at Microsoft
A celebratory announcement of what is new in OpenAPI.NET v2 and v3. by Darrel Miller [devblogs.microsoft.com]
Spring Boot Built-in API Versioning - Piotr's TechBlog
This article explains how to use Spring Boot built-in API versioning feature to expose different versions of REST endpoints. by piotr.minkowski [piotrminkowski.com]
What Is OpenFGA?
Learn how OpenFGA enables fine-grained, relationship-based authorization for APIs, complementing OAuth and OpenID Connect for better data access control. by Kristopher Sandoval [nordicapis.com]
Shai-Hulud - What Happened, How We Fixed It, and What We Learned
A postmortem of the supply-chain compromise that affected published packages on npm and related registries. [asyncapi.com]
Introducing the fully managed Amazon EKS MCP Server (preview) | Amazon Web Services
Learn how to manage your Amazon Elastic Kubernetes Service (Amazon EKS) clusters through simple conversations instead of complex kubectl commands or deep Kubernetes expertise. This post shows you how to use the new fully managed EKS Model Context Protocol (MCP) Server in Preview to deploy applications, troubleshoot issues, and upgrade clusters using natural language with no deep Kubernetes expertise required. [aws.amazon.com]
Amazon API Gateway now supports response streaming for REST APIs - AWS
Discover more about what's new at AWS with Amazon API Gateway now supports response streaming for REST APIs [aws.amazon.com]
|
|
Upcoming Events
apidays Paris
API governance, monetization, and future trends
December 9โ11, 2025
Paris, France
Details and registration
API Economy Summit / Paris
"Powering the API Economy"
Headliners TBA
December 10, 10am-4pm
Details and registration (Contact Bertrand Masson)
|
|
|
Have something to share?
As always, if you want to chat, share a link, or make a suggestion, feel free to drop us a quick note or tagging us on Twitter (@launchany and @caseysoftware) or by emailing us at: [email protected].
|
|
|
|
|