> Markdown version of [/events/world-congress-2025/sessions/845-lessons-learned-from](https://www.wearedevelopers.com/events/world-congress-2025/sessions/845-lessons-learned-from). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lessons learned from observing a billion API requests - **Date:** Friday, Jul 11, 2025 - **Time:** 13:40–14:10 (30 min) - **Room:** Stage 5 - **Event:** World Congress 2025 - **Tags:** apis, cybersecurity, data engineering, databases, go, javascript, php ## Recording [Watch recording](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) ## Description What if I told you that after studying and analyzing a billion API requests and 15,000 APIs, I found that Javascript APIs are the most insecure APIs? This talk is about learning from data and patterns. We’ll look at: How I processed and analyzed javascript APIs. Some cool database queries. How javascript frameworks rank in API security and design. What is the definition of a good API design? Most common design decisions taken by teams that lead to insecure APIs. What can we learn from other frameworks to build better APIs? Go was mentioned as the most highly used language to build APIs by Cloudflare. We will take a look at the complications that the AI wave has brought in API design and security. For anyone building or managing APIs, this talk will provide a clear look at what’s happening across the API ecosystem and what to do about it. ## Speaker ### [Pratim Bhosale](https://www.wearedevelopers.com/@pratim-bhosale) Senior Developer Experience Engineer ## Related talks at this congress - [API = Some REST and HTTP, right? RIGHT?!](https://www.wearedevelopers.com/events/world-congress-2025/sessions/628-api-some-rest-and) — Rustam Mehmandarov - [Bullet-Proof APIs: The OWASP API Security Top Ten](https://www.wearedevelopers.com/events/world-congress-2025/sessions/496-bullet-proof-apis) — Christian Wenz - [Lessons from Our API Past: Evolving to a Resilient API Future](https://www.wearedevelopers.com/events/world-congress-2025/sessions/916-lessons-from-our-api) — Yousaf Nabi - [REST in Peace? What does the API protocol of the future look like? Or do we have it already?](https://www.wearedevelopers.com/events/world-congress-2025/sessions/589-rest-in-peace-what) — Simon Auer