|
Last week I ended on a button. The agent can hold a
credential, I wrote, it just cannot obtain one — every
door in the network still needs a human hand on it, and
everything upstream of that button is governed while the
button is not governed at all.
This week the industry answered a question I had not
asked. It gave the agent an identity.
Four vendors shipped it inside seventy-two hours.
HashiCorp took agentic IAM to GA, CrowdStrike announced an
agentic identity provider, AWS gave Bedrock AgentCore a
managed consent portal, and Auth0 shipped
enterprise-managed authorization for client apps. That is
a category forming in real time, and if you had asked me
in June what the agent-access problem needed, I would have
said roughly this.
And then, in the same seven days, at least four other
companies published the argument that it does not work.
Not that the products are bad. That the layer is wrong.
VentureBeat ran it twice. Cequence ran it. SpruceID ran
it. Arcade ran it. The sentence they are all circling is
that an agent which passes authentication is still an
agent — it can drift, it can be prompt-poisoned, it can be
handed a perfectly valid credential and do something
nobody authorized with it. HackerNoon put the cleanest
title on it: the impostor in your environment is the AI
agent holding a valid credential.
I want to be careful here, because there is a lazy version
of this observation and I do not want to write it. The
lazy version is "identity is dead, behavior is the
new perimeter," which is a vendor sentence wearing an
analyst costume. The honest version is smaller and more
useful: we spent the year narrowing the grant, and
narrowing the grant turns out to answer who is calling without answering what this call is for. Those
were the same question when a human sat behind every
token. They are not the same question anymore.
|
|
A vast dark neon grid at night where hundreds of
small angular light-vessels each carry a bright
glowing badge, passing unchallenged through a tall
gleaming gateway arch, while beyond the arch the
vessels scatter in every direction across an unlit
plain with no structures, no paths and nothing
watching them.
|
Identity Arrived for Agents, and Everyone Immediately Said
It Was Not Enough
The products, first, because they are real and they
shipped:
Then the counter-argument, from companies with no shared
incentive to make it:
-
VentureBeat, twice: identity and permissions are not enough to govern
agent behavior, and separately, agents that pass authentication can still drift,
expose data, or get memory-poisoned.
-
Cequence: agentic governance must focus on
behavior, not just identity. SpruceID: agents have an authorization problem, not
just an identity problem. Arcade: AI agent governance is not governing
people — which is the one I would read first, because it is
the only one that says out loud why the analogy
breaks. Our entire access-control vocabulary was built
for a principal that gets tired, gets bored, and does
one thing at a time.
-
Akeyless walked through the Hugging Face breach, where the rogue agents needed exposed credentials
to get in — a reminder that the boring failure is
still the common one. And JumpCloud published the operational sequel nobody
had written yet: what to actually do when you find
your first shadow agent. Shadow IT took fifteen years to get a playbook.
Shadow agents got one this week.
-
The plumbing kept improving underneath the
argument. WorkOS published refresh token behavior across
fourteen providers — genuinely useful empirical work of the kind almost
nobody does — plus a race condition in token refresh and why a
conditional write beats a distributed lock, keeping credentials out of an agent's context
entirely with Relay, and an argument that identity, authorization and audit
belong in the same place. Arcade made the operationally sane suggestion of
pre-authorizing all of an agent's tools up
front. BigID wrote up delegated authority, and Nudge Security wrote the best-titled post of the
week about OAuth grants as the new perimeter — the traffic cop is directing traffic on a road
nobody drives anymore.
Here is what I think is actually happening, and it is not
a failure. Identity had to ship first. You cannot reason
about what a call is for until you can say
reliably who is making it, and until this month you could
not. The four products above are the floor, not the
ceiling, and the four critiques are early rather than
wrong. What worries me is the gap between them — a floor
that shipped as a finished product, sold to enterprises
this quarter, against a ceiling that exists only as blog
posts. That gap is where the incidents live.
|
|
An immense dark neon grid where a long low counter
of small warmly lit openings runs across the
foreground, and rising directly behind it a tall
smooth featureless barrier wall pierced by a row of
round glowing scanning apertures, with small angular
light-vessels queuing first at the low openings and
then again at the apertures above.
|
MCP Moved From the Support Desk to the Security Desk
Last week I counted fourteen MCP posts published on help
desks and called it the tell that adoption had become
real. This week the count of third-party MCP-titled posts
went from 66 to 77, and the centre of
gravity moved again — not away from support, but on to a
second desk beside it.
-
The sharpest item of the week: MCP's new spec turns a planted prompt into a
stolen credential. Read that next to the section above. The protocol
added capability, the capability added an
authorization surface, and the authorization surface
is reachable by anything that can get text in front of
the model.
-
I wrote the MCP authentication and authorization gap on Wednesday, and WorkOS published a genuinely good explainer of what
MCP authorization is and how OAuth works for
agents the same day — and, earlier in the week, the
distinction that most implementations are getting
wrong: scope step-up is not authentication step-up.
-
Trust is becoming a product category. ObservePoint published a security-and-trust page
for its own MCP server — a vendor documenting its server's threat
posture as a customer-facing artifact, which did not
exist as a genre six months ago. MCPVault launched to grade and verify MCP
servers, and Activepieces published safe tool-calling
practice. OWASP is drafting a common taxonomy for MCP
security risks, which is the signal I would weight
highest — a risk taxonomy is what a field produces
after it has enough incidents to sort.
-
The engineering work continued in parallel and got
more specific, which is its own maturity signal. LangChain shipped stateless protocol support and
elicitation, and RunPod wrote about designing MCP tools that do not
blow up your agent's context window. Elicitation is the interesting one — it is the
spec's answer to a server needing something from
the human mid-call, which is the multi-hop consent
problem I flagged last week arriving as an actual
protocol feature rather than a think-piece.
-
And the long tail kept shipping regardless: Crossbeam,
Zoho, Jitterbit, Scrapingdog, CloudConvert, Ahrefs,
Knack, Okendo, CloudZero, ToolJet, Appwrite, RemNote,
Solve Intelligence, plus Everlaw's second MCP integration in seven
days, this time with Microsoft Copilot. HackerNoon's newsletter opened the week with
the headline "MCP Was Declared Dead."
Seventy-seven posts later, it is not.
📄 Conversational API Governance — Everything above is an argument that our governance
reaches the wrong place. Your Spectral ruleset reaches the
IDE and it reaches the pipeline. It does not reach the
conversation, which is now where APIs actually get
designed — and it does not reach the agent, which is now
what calls them. This paper is the practical version:
wrapping the governance engine in a small MCP server so
your rules are reachable by the copilot and the agent, not
just by CI. It is also the thinking behind why I spent
this week forking Spectral. $25
|
|
A dark neon plain where an ornate old toll arch
stands stranded and dark beside an empty road, while
a short distance away a new low broad arch hums with
light and a dense braided stream of small angular
light-vessels pours through it, the new arch's
outline echoing the old one exactly.
|
The Gateway Word Changed Hands
I have been watching this one for a few weeks and it
tipped this week. "Gateway" now means AI gateway
by default in this corpus, and the API gateway has become
the thing you say the long name for.
-
Kong AI Gateway 2.0 went GA — Kong, of all companies, shipping the 2.0 of a
product whose name is a modifier on its own original
category. Cloudflare consolidated AI Gateway billing and
standardized model names, which is the least glamorous and most telling item
here: you do not consolidate invoice line items for a
product nobody is spending real money on.
-
Vercel shipped models to its AI Gateway on five
separate days this week. cData spent the week defining
the category from three directions — what an LLM gateway is and where it sits in the
stack, what an MCP gateway does that an API gateway
cannot, and an enterprise deployment guide. DigitalOcean shipped an Action Gateway for
connecting agents to SaaS tools without sharing
credentials — note that the pitch is a credential-isolation
pitch, which puts it squarely in the first section of
this issue.
-
I wrote a gateway nobody owns is just a load balancer with
a deploy pipeline on Monday, before most of this landed, and I would
say it harder now. Three gateway categories are being
sold into the same rack — API, LLM, MCP — and in most
orgs no single person owns all three. That is not an
architecture. That is three teams each holding a
chokepoint and nobody holding the policy.
The thing I would watch: none of this is standardizing.
Every gateway above is a product with a proprietary policy
model, arriving at the exact moment the industry decided
that policy — not identity — is where the agent problem
gets solved. We are about to encode the most important
control layer of the agentic era in five incompatible
configuration formats.
|
|
A dark neon expanse where five small angular
light-vessels attempt to pass a chain of glowing
waypoints by leaping between them through empty air,
each leap dimmer and more crooked than the last,
while alongside them a single vessel instead lays a
continuous solid glowing rail ahead of itself and
travels it smoothly past all five.
|
Moving Past About Five Tool Calls, You Are Gluing With
Inference
This was the week's convergence, and it came from
four unrelated directions.
If that read is right, it reframes the whole MCP tooling
conversation. The valuable MCP server is not the one with
the most tools. It is the one whose tools compose into a
program the model can write once and execute
deterministically — which is an API design problem, and an
old one, wearing a new protocol.
|
|
A long dark neon avenue lined with tall unmarked
doorways, each with a small glowing hand-crank and
no automatic mechanism, small angular light-vessels
stalled at four of them, while at the avenue's
far end a single vast blank hall stands open and
empty, its floor unmarked, with several faint
competing boundary lines drawn across it that do not
meet.
|
From My Desk: Where a Specification Lives, and Who
Registers What
One number before the links. Across 8,601 unique posts
this week, OpenAPI was named in exactly one third-party post
title — Redocly's, on generating agent-friendly SDKs and
tooling from an OpenAPI description. One. The description layer everything above depends on
is invisible in the discourse again, two weeks after it
briefly reappeared as a malware vector. That is the whole
reason I spent this week on the registry.
-
The extension-registration thread. Redocly already knows how to register an OpenAPI
extension — they do it correctly and almost nobody noticed. Speakeasy has thirty-six OpenAPI extensions and
zero registered. RFC 10008 left a slot open and somebody is standing
in it. And the frame underneath all three: every specification is a land grab. Registration is the cheapest governance act in our
entire stack and the least performed.
-
A conversation with Lukasz Gornicki on what the
Linux Foundation actually gave AsyncAPI, why a
sponsor walked away because of it, and Open Source
Europe as a home for a specification. Lukasz ran AsyncAPI as executive
director, which means he has already run the
experiment everyone else is theorizing about. I
brought him the question I have been carrying since I
forked Spectral: where should a rule-set specification
live? What I got back was not a recommendation, it was
a set of distinctions — the Linux Foundation gave
AsyncAPI intellectual property and trademark
protection and very little else, protection that turns
out to mean a free letter from a lawyer after which
you need a litigation budget you do not have. It funds
no engineering. And one sponsor declined to renew specifically because AsyncAPI joined. If you are about to put your
specification in a foundation, listen to this before
you sign anything. Related: what matters most in forking Spectral.
-
A conversation with Jens Neuse on GraphQL
federation, deterministic joins, and why MCP has
very little to do with agents calling APIs. Jens is co-founder and CEO of
WunderGraph, whose Cosmo federation stack runs inside
Mercedes, Rivian and eBay. Two halves: what federation
actually buys you — fragments so a UI can evolve
without leaving dead fields in a REST API forever,
entities so separate teams can join data
deterministically rather than hopefully — and then the
five-tool-call claim in the section above. He also
points out, correctly and a little witheringly, that
we invented Web MCP while the user agent has been
sitting in the HTTP header the entire time.
-
The onboarding series kept grading doors, and the doors kept failing in new and specific
ways. Zoom gets the headless half right. Mintlify put signup in the CLI when it was already
in the protocol. Salesforce actually has a create-an-app API and
still makes you work for it. Square made the OAuth dance scriptable but left
onboarding at the dashboard door. PayPal lets you mint a token, but not register the
app. Then I turned the grader on myself: I graded everyone else's onboarding, here is
mine.
-
Also this week: the four plans I landed on for APIs.io and inside the agent-readiness score. I want you to own the integration. The blog was the retrieval layer all along — which, after a week of reading 8,601 of them, I
believe more than when I wrote it. Agents will make everything you left undone
visible. And I am leaving Naftiko behind to focus on API
Evangelist and APIs.io.
Two things worth putting next to each other on the way
out.
Agent payments, which had four competing protocols and a
volume fight two weeks running, produced five posts this week. Not a collapse — a pause. But if you were told in
August that agentic commerce was the story of the autumn,
note that it went quiet the same week identity got loud,
and draw whatever conclusion you like about how many
things this industry can pay attention to at once.
And the number I keep coming back to: 435 of this
week's 8,601 posts carried an API signal in the
title. Five percent. We have built an entire agentic
apparatus — identity providers, gateways, protocols,
taxonomies — on top of a description layer that
ninety-five percent of the people writing about it never
mention. Every argument in this issue eventually
terminates in a question about what an API actually does
and who said so. That answer lives in a document almost
nobody is talking about, and which one company registered
its extensions for.
See you next week.
🔌 APIs.io Understanding — the security and scopes
collections — This entire issue argues that authorization, not
identity, is where the agent problem gets decided. The
part I can actually hand you is the evidence: every OAuth
scope and every security definition extracted from every
API in the catalog, as collections you can query.
Eighteen of the twenty per-artifact endpoints on APIs.io
are free. security and scopes are the two that are not, and they are the two people
push on hardest — a keyless call to either returns a 402 naming the tier, which is the honest version of a
paywall.
The operation worth your week: before you
write another scope string, go read how a few hundred
other providers named and split theirs, then check which
auth schemes those same providers actually declare.
curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/scopes?limit=50" curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/security?limit=50"
Same data as the find_scopes and find_security MCP tools, if you would rather ask an agent than write a
loop. Understanding is $199/mo, or $1,990/yr — log in with GitHub for a free Learn key first and see how far the free tier
carries you.
|