All articles

8,601 unique posts across 1,971 provider blogs between August 30th and September 6th. Four identity vendors shipped agent-identity product inside a seventy-two hour window, and in the same seven days at least four other companies published the argument that identity is the wrong layer to solve this at. MCP finished its migration from the engineering blog to the support desk and started a second one, to the security desk. And OpenAPI was named in exactly one third-party post title all week.

Sep 7, 2026

6,768 unique posts across 1,927 provider blogs between August 23rd and 30th. Last week consent grew a scope selector. This week the enterprise version of it went generally available, and the harder problem showed up right behind it — a grant is one hop, and agents make several. Meanwhile OpenAPI reappeared in third-party headlines for the first time in a fortnight, and it reappeared because somebody trojanized its codegen. And one in five MCP posts this week was not an announcement at all. It was a support article.

Aug 31, 2026

6,583 posts across 1,735 provider blogs between August 15th and 22nd. For three weeks the industry has been working out how an agent proves who it is. This week it moved on to the harder half of the question — how much that agent is allowed to do — and shipped it as product: task-based OAuth consent at Cloudflare, custom scopes at Clerk, enterprise-managed cross-app access at Auth0, step-up challenges at WorkOS, identity propagation from AWS through to JFrog. Meanwhile 76 posts named MCP in their title and not one third-party post in the whole network named OpenAPI, AsyncAPI, GraphQL, JSON Schema, Arazzo or gRPC.

Aug 24, 20261 likes

5,806 posts across the 5,299 API-bearing providers I track between August 7th and 15th. Last week the identity vendors reached into a drawer of old RFCs to answer who is calling. This week the network layer answered a different question — what is this traffic? — and answered it by inspecting headers and guessing. Cloudflare Gateway now detects MCP by protocol heuristics, Fingerprint will tell you which AI tool called your server, and OWASP has an MCP Top 10. Meanwhile Google did the opposite thing and put AI model routing inside an OpenAPI document, where it is declared rather than inferred. That contrast is the whole issue.

Aug 18, 2026
Aug 10, 20261 likes
Aug 3, 2026
Jul 27, 2026
Jul 20, 2026
Jul 13, 2026
Jul 6, 2026
Jun 29, 20261 likes
Jun 22, 2026
Jun 15, 2026
Jun 8, 2026
Jun 2, 20261 likes
May 27, 20261 likes
May 18, 2026
May 11, 2026
May 4, 2026
Apr 29, 2026