API Developer Weekly
April 30, 2026 - Issue #574
|
|
After an extended break, we are back with more articles. In this edition, we look at why JSON Schema matters even more in the world of genAI, how to choose between JSON-RPC and REST, and MCP architecture for enterprises. We also have a spotlight on AI and API security, which is becoming more and more important as APIs are consumed by LLMs. We look at the business of APIs by exploring a new AI clause in SAP's API policy, how ING bank manages 2000 microservices, and a look at the USPS tracking API including pricing and terms of use. Finally, we have several thought pieces on AI, software development, and the potential end of 'Agile' as the SDLC changes to incorporate more AI workflows.
-- Happy Reading!
Featured Articles
Why JSON Schema matters more than ever in the age of generative AI
JSON Schema is essential for grounding unpredictable AI outputs. Discover why this standard ensures enterprise data reliability in 2026. by Charles Humble [share.google]
JSON-RPC vs. REST: When Should API Developers Use Each?
Compare JSON-RPC vs REST to understand their differences, strengths, and when developers should use each API design approach. by J Simpson [nordicapis.com]
Cloudflare Outlines MCP Architecture as Enterprises Confront Security and Governance Risks
Cloudflare has outlined a reference architecture for scaling Model Context Protocol (MCP) deployments across the enterprise, positioning centralized governance, remote server infrastructure, and cost controls as key requirements for production-ready agent systems. [infoq.com]
Speeding up agentic workflows with WebSockets in the Responses API
A deep dive into the Codex agent loop, showing how WebSockets and connection-scoped caching reduced API overhead and improved model latency. [share.google]
Scaling MCP adoption: Our reference architecture for simpler, safer and cheaper enterprise deployments of MCP
We share Cloudflare's internal strategy for governing MCP using Access, AI Gateway, and MCP server portals. We also launch Code Mode to slash token costs and recommend new rules for detecting Shadow MCP in Cloudflare Gateway. [share.google]
As agentic AI explodes, Amazon doubles down on MCP
AWS engineer Clare Liguori shapes the MCP spec as Amazon builds managed servers, contributes new features, and tests draft concepts in production. by Alex Wilhelm [share.google]
Four Open-Source Agentic Authorization Alternatives
OAuth was built for people, not for AI. by Bruno Pedro [apichangelog.substack.com]
Give agents what they want. Start with APIs.
Over the past two months, something happened that I've never seen before. The biggest names in tech started saying the same thing, independently, across podcasts, X threads, LinkedIn posts, and long-form essays. [linkedin.com]
Announcing Arazzo Editor: Build, Edit & Export API Workflows
Build and export API workflows with form-based editing and live diagrams. Arazzo Editor is free, browser-based, and fully standards-compliant. No raw YAML. [jentic.com]
Spotlight: AI and API Security
MCP 'design flaw' puts 200k servers at risk: Researcher
Bug or feature? [share.google]
API attacks surge as AI exposure raises cyber risk
Akamai survey finds APIs are now cybercriminals' main target, with AI-linked interfaces under attack and incidents costing organisations more than USD $700,000. by Sofiah Nichole Salivio [securitybrief.co.uk]
Cursor Extension Flaw Exposes Developer API Keys
Cursor flaw lets extensions steal API keys and session tokens without user interaction, according to researchers at LayerX by Alessandro Mascellino [infosecurity-magazine.com]
The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic's MCP
Anthropic design choice Exposes 150M+ Downloads and up to 200K Servers to complete takeover The OX Security Research team has uncovered a critical, systemic vulnerability at the core of the Model Context Protocol (MCP) - the industry standard for AI agent communication created and maintained by Anthropic. by Moshe Siman Tov Bustan [ox.security]
10 Tips for Securing Your API Keys From AI
Learn API key security best practices to protect AI systems, prevent leaks, and secure access in modern API-driven architectures. by J Simpson [nordicapis.com]
Business of APIs
AI clause in new SAP API policy provokes lock-in concern
Expert says it could push customers and partners to work with undocumented APIs [theregister.com]
How ING Bank Manages 2,000 Microservices With Service Mesh
How ING scaled 2,000 microservices with a service mesh, covering governance, discovery, and security lessons. by Bill Doerrfeld [nordicapis.com]
USPS Tracking API, by the numbers: Pricing, terms, and how it compares
USPS Tracking API, by the numbers: Pricing, terms, and how it compares Earlier I wrote about how USPS rolled out its API Access Control initiative without much advance communication. That post was ... by John M. Kuchta [medium.com]
(Un)Related
Shifting From Individual Contributor to Individual Architect
Learn how to develop a software architect mindset with systems thinking, ADRs, and practical strategies for better API and system design. by Art Anthony [nordicapis.com]
AI Didn't Kill Programming, You Did
You spent decades sucking all humanity out of programming and you're surprised it worked? [learncodethehardway.com]
Cloudflare rebuilds Wrangler CLI for broader API coverage
What, you think basic usability is improved just for your benefit, human? [theregister.com]
Saying Goodbye to Agile
Software's "Agile moment" has been and gone. [lewiscampbell.tech]
The keyboard was never the bottleneck
The art of programming isn't disappearing. It's migrating by Mike Amundsen [mamund.substack.com]
|
|
Have something to share?
As always, if you want to chat, share a link, or make a suggestion, feel free to drop us a quick note or tagging us on X/Twitter (@launchany and @caseysoftware) or by emailing us at: [email protected].
|
|
|
|
|