January 2026 Summaries
17 posts from Kong
Filter
Month:
Year:
Post Summaries
Back to Blog
Organizations racing to deploy agentic AI technologies face increasing risks due to inadequate AI governance, with many lacking visibility into their AI data flows and security protocols. Shadow AI, the unsanctioned use of AI tools, poses significant challenges by creating untracked exposure and compliance violations. Effective AI governance is essential, as it enables sustainable velocity and allows companies to navigate regulatory scrutiny, security breaches, and operational obstacles more efficiently. The adoption of governance strategies, such as policy-as-code and agentic AI platforms, helps automate security measures, ensuring compliance and reducing risks without hindering innovation. Organizations that integrate governance into their deployment infrastructure from the outset can maintain competitive advantages by deploying AI rapidly and securely, while those that treat governance as an afterthought may suffer from breaches, rollbacks, and reputational harm. As AI regulation intensifies globally, companies must prioritize building governance frameworks to avoid fines and operational disruptions while fostering a culture that attracts top talent and encourages innovation.
Jan 30, 2026
2,352 words in the original blog post.
As organizations rapidly deploy AI agents, finance departments are facing significant challenges due to the hidden costs and fragmented management of AI resources, which are eroding gross margins. A staggering 84% of companies report more than 6% gross margin erosion from AI costs, with only 15% able to forecast these costs accurately. The erosion stems from untracked consumption, redundant spending, and inefficient resource management across teams, leading to a "fragmentation tax." This lack of visibility also hampers monetization efforts, as companies struggle to price and bill for AI-powered capabilities effectively. The disparity between public cloud and on-premises costs further complicates financial planning, necessitating a distinct approach to AI FinOps that differs from traditional FinOps. Organizations that can establish robust AI cost visibility and management practices are better positioned to make informed investments, achieve sustainable monetization, and maintain competitive advantage in the agentic era.
Jan 30, 2026
2,389 words in the original blog post.
Modern AI applications require more than just sending prompts to language models; they necessitate a robust architecture to handle orchestration, security, and control when interacting with real business data and APIs. This is achieved through a layered architecture involving Volcano SDK, DataKit, and Kong MCP Proxy, which collectively ensure secure AI agent deployment. The Model Context Protocol (MCP) acts as a universal language, providing a standardized way to expose data and functionality, thereby enhancing security and auditability. Volcano SDK simplifies agent development by focusing on intent-based definitions and automatic context management, while DataKit handles data orchestration and API governance. Kong AI Gateway further secures interactions by acting as a proxy, enforcing authentication, authorization, rate limits, and observability, preventing unauthorized access and prompt injection attacks. This architecture enables quick, secure, and scalable AI deployments, allowing developers to build agents efficiently while maintaining strict control over data access and policy enforcement.
Jan 27, 2026
1,369 words in the original blog post.
The Model Context Protocol (MCP) aims to enhance AI assistants' capabilities by providing them with domain-specific knowledge and tools they would otherwise lack. As an open standard for communication between AI clients and remote servers, MCP allows clients, such as Claude or VS Code, to access resources, tools, and prompts from external systems. These capabilities are crucial for AI assistants to better understand and interact with specialized syntax, component libraries, or APIs, as demonstrated by a real-world example involving the Kong Developer Portal. Here, MCP servers help AI assistants generate valid content using MDC syntax by providing syntax guides, component metadata, usage examples, and syntax validation tools. The protocol's ecosystem is designed to grow, allowing organizations to create tailored MCP servers that integrate company-specific data, internal tools, or workflows that AI assistants need to understand. By deploying MCP servers on platforms like Cloudflare Workers, developers can achieve globally distributed, low-latency solutions that automatically scale, enabling AI assistants to address a variety of internal development, workflow, and business operation needs.
Jan 26, 2026
2,335 words in the original blog post.
Konnect Metering & Billing offers a streamlined solution for transforming API and AI traffic management into new revenue streams, emphasizing the importance of financial governance and monetization in AI infrastructure. By providing a zero-to-hero demo, it illustrates how easily organizations can transition from simply managing traffic to generating revenue using a serverless gateway that handles both traditional REST APIs and AI traffic. Key features include automatic metering for APIs and AI, granular billing options, flexible product plans, and unified billing identities, all designed to enhance real-time visibility and prevent unexpected costs. This approach aims to turn AI infrastructure into a business asset, encouraging organizations to focus on achieving strong AI unit economics and offering tools for both external monetization and internal governance.
Jan 22, 2026
503 words in the original blog post.
Kong Mesh 2.13 introduces significant updates, including full support for Mesh Identity in both Kubernetes and Universal modes, and has been designated as a Long Term Support release with two years of support. Built on the open source Kuma service mesh, Kong Mesh simplifies operations for platform teams by offering security, observability, and traffic control for distributed applications across multiple zones, including cloud providers, Kubernetes clusters, and traditional server environments. The release enhances ease of deployment and management of mission-critical services with features like zero-trust security, global control planes, and support for SPIRE as an identity provider. Additionally, the update allows selective application of Fault Injection rules using new rule selectors and improves service encapsulation across zones with the MeshServicesMatched condition. The installation process now includes automatic CA bundle creation and optional certificate lifecycle management through cert manager. Kong Mesh 2.13 aims to accelerate deployments, reduce vulnerabilities, and provide real-time visibility, tailored to specific architecture and scale requirements.
Jan 22, 2026
402 words in the original blog post.
Kong has introduced an enhanced beta version of its AI assistant, KAi, powered by the Kong Konnect MCP Server, which enhances its capabilities within the API platform by integrating deeper access to the Konnect environment and tools for debugging, analytics, and configuration management. This updated version allows KAi to perform tasks such as setting up tracing sessions for debugging, querying analytics data directly, and conducting contextual documentation searches, all while respecting user permissions. The underlying infrastructure, the Model Context Protocol (MCP) server, enables interaction with external systems and is accessible from various platforms like IDEs, AI assistants, and terminals. This open protocol allows for the creation of custom agents that can automate tasks like monitoring traffic patterns, auditing gateway setups, and responding to incidents, making the API platform more accessible and efficient. The MCP server, available for direct use, supports integration with existing agent frameworks, allowing for multi-agent management of AI and API platforms. As KAi and the MCP server share the same infrastructure, any improvements to the server are immediately available in KAi, with Kong actively seeking feedback to enhance these tools further.
Jan 21, 2026
915 words in the original blog post.
AI agents are proliferating in organizations, leading to a surge in the use of Model Context Protocol (MCP) servers, which complicates authentication and scaling due to the "too many endpoints" issue. To alleviate these challenges, the MCP Gateway has emerged as a crucial infrastructure layer that provides a single, secure entry point for AI clients, functioning as a reverse proxy to manage authentication, routing, and policy enforcement. This centralization simplifies client configurations, ensures consistent security across multiple MCP servers, and enhances scalability and observability. The MCP Gateway addresses operational chaos by offering unified access with enterprise security measures, intelligent request routing, and dynamic tool discovery. As organizations expand their AI initiatives, the gateway becomes essential for managing multiple servers, meeting security requirements, and ensuring production readiness. Industry leaders recognize this pattern as fundamental to AI deployment, with OpenAI and other major players adopting the approach to enhance infrastructure security, optimize traffic routing, and improve visibility, thereby enabling effective scaling and innovation in AI systems.
Jan 21, 2026
2,250 words in the original blog post.
Kong Gateway Enterprise 3.9 will reach its End Of Life (EOL) in January 2026, after which it will enter a 12-month sunset support period aimed at assisting customers with upgrading to a newer version of the software. This period will conclude in January 2027, and customers using version 3.9 are strongly advised to transition to a more current version to continue receiving support. The support policy outlines the duration of support for each version, and upgrading can accelerate deployments, reduce vulnerabilities, and provide real-time visibility. Additionally, Kong offers personalized platform walkthroughs to align with specific architectural, use case, and scalability needs.
Jan 20, 2026
124 words in the original blog post.
Gartner's recent report, "How to Enable Agentic AI via API-Based Integration," highlights the need for a transformative integration model called a "real-time context mesh" to effectively support agentic AI systems, moving beyond traditional APIs and connector-based integrations. This new model facilitates agents in securely discovering state, reasoning across systems, and triggering actions, thereby addressing the limitations of existing "inside-out" integration approaches that prioritize legacy systems. The report emphasizes the importance of "outside-in" integration, which starts from the agent's perspective and user needs, requiring enhancements like delegated identity, real-time data foundations, and hybrid connectivity. Gartner warns that without this shift, 40% of agentic AI initiatives may fail by 2027 due to outdated infrastructure. The concept aligns closely with AI connectivity, illustrating the necessity for unified governance and dynamic discovery, and predicts that by 2030, many early implementations will struggle unless the integration and governance requirements are met. This shift requires fundamentally new infrastructure, moving away from the iPaaS model, to support autonomous systems effectively.
Jan 16, 2026
1,907 words in the original blog post.
The emergence of the agentic era in AI is highlighting significant gaps in enterprise infrastructure, as AI agents transition from experimental to widely adopted in organizations. These agents are now autonomously making decisions, orchestrating workflows, and interacting with services in real time, but existing infrastructures, which are fragmented and reliant on manual processes, are ill-suited to support this shift. A new comprehensive developer platform is needed, one that addresses the unique demands of agentic AI by treating AI workloads as integral components alongside traditional APIs and architectures. This platform is structured around five essential pillars: Build, Run, Discover, Govern, and Monetize. These pillars ensure that developers can build AI applications with reduced friction, run them reliably, discover and connect to enterprise capabilities, govern them securely, and manage costs effectively. Unlike traditional API gateways, this infrastructure must accommodate the complex, stateful interactions of AI agents, offering features like semantic caching and intelligent routing to enhance efficiency and control costs. The platform not only facilitates development and deployment but also integrates governance and monetization strategies to sustain growth and innovation in the agentic era.
Jan 15, 2026
2,193 words in the original blog post.
Kong Insomnia 12.3 introduces several enhancements aimed at improving workflow efficiency by reducing maintenance tasks and increasing collaboration capabilities. The update includes reusable Git credentials, allowing users to authenticate once and use their credentials across multiple projects, which can save significant time. Additionally, Insomnia MCP clients now integrate seamlessly with existing security infrastructures, such as Okta, and SCIM tokens automatically refresh every 90 days, ensuring continuous authentication without manual intervention. These features, along with smarter Git repository search, clear project connections, and improved organization visibility, contribute to a smoother user experience. The release also expands MCP capabilities with options like sampling and elicitation support and the ability to disable SSL verification for development environments. The Inso CLI tool has been enhanced with structured test results and a request timeout feature, providing better automation control. As Insomnia continues to evolve, users can expect further refinements and features in upcoming versions, with a focus on accelerating deployments, reducing vulnerabilities, and enhancing real-time visibility.
Jan 15, 2026
619 words in the original blog post.
Kong AI Gateway 3.13 introduces MCP Tool ACLs, offering a solution to the 'all-or-nothing' access problem by enabling granular authorization and security policies for AI agent tools. This feature addresses challenges posed by modern AI agents interacting with external systems via the Model Context Protocol (MCP), allowing organizations to implement detailed authorization policies at the gateway layer. MCP Tool ACLs provide the ability to filter tools based on identity, apply default-deny policies, and leverage consumer group functionalities, ensuring that only authorized tools are accessible to specific users or applications. The feature integrates seamlessly with OAuth2/OIDC for robust authentication and offers dynamic tool filtering to ensure only permitted tools are visible to clients. This development is crucial for securing and governing AI agent architectures, especially in regulated industries, by facilitating compliance and auditability while enabling safer and more compliant AI systems. Organizations can now deploy AI agents with confidence, applying fine-grained tool authorization to enhance their AI governance approach.
Jan 14, 2026
1,293 words in the original blog post.
APIs are crucial to the digital and AI landscapes, acting as the strategic connective tissue that can drive enterprise growth if managed effectively. Organizations often struggle to maximize API value due to a disconnect between business goals and technical execution, highlighting the importance of full-lifecycle API product management. This involves clear upfront strategy, robust contract design, and scalable developer experiences. The role of the API Product Manager is central as they oversee the API lifecycle from inception to retirement, ensuring alignment between business objectives and technical implementation to enhance customer experiences, partner ecosystems, and innovation. Effective API management requires a focus on strategy, contract design, developer experience, and documentation, with an emphasis on alignment between business and engineering teams to prevent APIs from being reduced to mere integration tools. Success in API initiatives depends on robust planning, thoughtful design, and continuous evolution without disrupting existing clients, supported by metrics to track adoption, business value, and operational health. The process is further enhanced by clear communication, structured feedback, and maintaining a flexible, strategic roadmap.
Jan 14, 2026
3,844 words in the original blog post.
The rapidly evolving enterprise AI landscape necessitates the use of AI Gateways and MCP Gateways, which complement each other in managing different aspects of AI infrastructure. AI Gateways function as "brain traffic managers," optimizing interactions with large language models (LLMs) by implementing smart caching, rate limiting, and failover strategies to control costs and ensure reliability. On the other hand, MCP Gateways act as "hands and tools managers," using the Model Context Protocol to securely govern AI agents' access to internal tools and data, ensuring compliance and centralized tool management. Together, these gateways enable organizations to scale AI deployments efficiently while maintaining security and compliance, crucially forming the backbone of enterprise AI governance. As the AI market continues to grow, the strategic implementation of these gateways becomes essential for future-proofing architectures and achieving competitive advantage.
Jan 14, 2026
2,112 words in the original blog post.
Kong AI/MCP Gateway and the Strands framework, introduced by AWS, aim to streamline the development of AI agents by providing a secure and efficient interface for interacting with AI models and tools. The integration of Kong AI/MCP Gateway with Amazon Bedrock facilitates scalable access to foundational models, enabling agents to leverage these models in a unified manner. The Gateway acts as a protective and interfacing layer, offering specific AI-based plugins, such as AI Proxy and AI Proxy Advanced, to handle load balancing and observability metrics. It utilizes advanced prompt engineering techniques and supports various plugins for security, traffic control, and observability, making it highly adaptable for AI applications. Additionally, the Gateway's compatibility with OpenAI APIs and EKS Pod Identity enhances flexibility and security. By using the Strands SDK, developers can construct production-ready AI agents, transforming complex workflows into maintainable logic. The architecture supports deployment across various platforms, including Kubernetes and multiple cloud environments, ensuring reduced complexity and enhanced visibility for AI-driven applications.
Jan 12, 2026
4,282 words in the original blog post.
Organizations looking to control AI costs in 2026 can benefit from using Konnect Metering & Billing, a newly available platform that integrates monetization, billing, and real-time cost governance for APIs, AI gateways, and event streams. As many enterprises face negative ROI from AI investments due to inadequate financial governance, Konnect offers a solution by providing a unified system for metering, billing, and governance across AI data paths. This platform supports various pricing models and enforces usage limits and entitlements at runtime, helping organizations turn AI and API traffic into revenue while maintaining cost control. By offering real-time visibility and proactive financial operations (FinOps), Konnect enables businesses to treat AI as a strategic asset rather than a costly experiment, ultimately aiming for improved margins and clearer cost structures.
Jan 06, 2026
925 words in the original blog post.