World Congress 2025 β€’ Aug 20, 2025 β€’ Session details

Lessons learned from observing a billion API requests

Pratim Bhosale

An analysis of a billion API requests reveals a shocking vulnerability: nearly half lack basic authentication. Learn to secure your architecture and prepare your endpoints for AI consumers.

Pause
Mute Enter Fullscreen
#1 about 4 min

The current state of enterprise APIs and security trends

The explosive growth of internal APIs reveals critical vulnerabilities like the lack of basic authentication.

#2 about 3 min

Security comparisons across web frameworks and development languages

Opinionated architectural frameworks provide robust default security environments compared to generic router libraries.

#3 about 5 min

Understanding the four core pillars of API scoring

Evaluating API quality requires measuring design standards, performance characteristics, internal security measures, and AI readiness.

#4 about 5 min

Improving API scores through practical OpenAPI specification audits

Reviewing production OpenAPI documents reveals that explicit HTTP response codes and rich metadata dramatically improve compliance.

#5 about 2 min

Optimising operation IDs and documentation for AI consumers

Defining descriptive operation IDs and extensive examples allows large language models to accurately implement programmatic SDKs.

#6 about 3 min

Implementing application-level security and masking sensitive responses

Embedding rate limit logic directly into services mitigates automated agent scraping while protecting sensitive user data.

#7 about 2 min

Achieving full traceability for API observability and debugging

Tracking granular service communication is essential for debugging unexpected interactions triggered by third-party data consumers.

#8 about 2 min

Designing use-case driven APIs and consolidating broad endpoints

Structuring endpoints around specific business requirements instead of database schemas mitigates sprawl and simplifies version control.

#9 about 3 min

Building composable interfaces and data sources for agents

Exposing structured and predictably versioned endpoints transforms standard APIs into native training sources for autonomous frameworks.

Matching moments

9:56 min

Final code walk-through and audience Q&A session

GermÑn Álvarez · LIVE

1:40 min

Summarizing key engineering lessons for platform API development

Anto Anto Β· World Congress 2024

2:00 min

Key architectural takeaways for building secure APIs

Philippe De Ryck Β· LIVE

3:26 min

Designing APIs for security from day one

Philippe De Ryck Β· LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler Β· LIVE

2:04 min

Clarifying API technologies and future scope

Simon Auer Simon Auer Β· World Congress 2025