Home / Companies / Kong / Blog / July 2026

July 2026 Summaries

27 posts from Kong

Filter
Month: Year:
Post Summaries Back to Blog
Kong has been recognized on the Fortune Best Workplaces in the Bay Area 2026 list, highlighting its strong workplace culture as rated by its employees. This achievement is based on confidential employee feedback that measures trust in leadership, connection with colleagues, and overall workplace experience, with 94% of Kong employees affirming it as a great place to work. The company's culture focuses on trust, inclusion, growth, and collaboration, guided by distinctive leadership principles such as "Lead Like an API" and "Balance the Power of Science and Art," which promote innovation and cross-functional teamwork. Kong prioritizes employee growth by offering flexibility, development opportunities, and a supportive work environment, fostering an inclusive atmosphere where employees have the autonomy to thrive. As Kong continues to expand, it remains committed to maintaining its valued culture while creating new opportunities for employees to contribute and shape the future, particularly in the realm of AI connectivity.
Jul 29, 2026 971 words in the original blog post.
The annual Kong Innovator Awards celebrate innovative achievements by engineers and teams using Kong to address complex problems in unexpected ways, recognizing efforts beyond mere participation. Previous winners included teams from major companies like United Airlines and BMW, who demonstrated significant advancements such as reducing AI service onboarding times and centralizing request validation for AI capabilities. The awards seek submissions from Kong customers who have developed creative solutions to complex challenges over the past two years, with winners evaluated on innovation, impact, and inspirational value. Winners will be announced in September at the API + AI Summit, where participants can engage in discussions on AI infrastructure. Submissions for the awards are open until September 11, and the summit invites industry leaders to explore real-world solutions, offering technical sessions and networking opportunities.
Jul 27, 2026 486 words in the original blog post.
API + AI Summit 2026, hosted by Kong, is a premier conference taking place from September 30 to October 1 at the InterContinental Los Angeles, bringing together leaders and experts from companies like Spotify, AWS, LinkedIn, and Dell. The event, now in its ninth year, offers a deep dive into the practical applications of AI and API technologies, focusing on topics such as token cost management, agentic architecture, context engineering, and AI governance. Attendees can engage in certification opportunities, hands-on workshops, and sessions led by industry experts sharing real-world experiences and lessons learned from deploying AI in production environments. Key highlights include insights from Southwest Airlines on AI agent implementation, Spotify's framework for AI observability, and LinkedIn's strategies for handling inference under real-world constraints. Participants are encouraged to partake in networking opportunities and "a-ha!" moments through interactive discussions and workshops designed to address shared infrastructure challenges and enhance their organization's technology strategies.
Jul 27, 2026 979 words in the original blog post.
Insomnia 13.1 enhances API testing workflows with improvements like the ability to use existing .gitconfig credentials for Git Sync, enabling easy project creation from a repository URL and offering real-time feedback in Collection Runner. The update also introduces features such as support for multiple routes per URL in mock servers and a more accessible Generate Collection function. Notably, Insomnia 13 integrated natively with Kong Konnect, aligning the testing environment with the platform team's source of truth by automatically pulling in live, canonical versions of services, specs, and routes. This integration ensures consistency and reliability, particularly as AI agents rely on accurate, versioned contexts. The update further includes enhancements to modals to prevent accidental workflow deletions and simplifies new project creation, while encouraging users to explore deeper integrations and test out the latest capabilities through downloadable resources.
Jul 23, 2026 789 words in the original blog post.
Enterprises are experiencing failures in AI agent deployments not due to issues with AI models themselves, but because of outdated integration architectures that fail to provide real-time, accurate, and semantically rich data. Traditional integration pipelines, which were designed for deterministic applications, are ill-suited for the dynamic and probabilistic nature of AI agents, leading to problems like stale data, brittle systems due to tight coupling, and latency issues that disrupt the decision-making loop. These failures stem from an inside-out design philosophy that focuses on existing data structures rather than the needs of AI agents, which require context and real-time data. The emerging solution is the Context Mesh, a real-time, event-driven integration layer that provides the necessary context for AI agents by maintaining state, memory, and events continuously available. This new approach does not replace existing infrastructure but enhances it to be "agent-ready," enabling enterprises to leverage their AI capabilities effectively by focusing on the quality of the data context over the intelligence of the models themselves.
Jul 23, 2026 868 words in the original blog post.
As technology evolves towards agentic AI, the traditional Integration Platform as a Service (iPaaS) model is proving inadequate due to its deterministic structure, which struggles to support the adaptive and real-time requirements of AI agents. Unlike deterministic applications that operate on predefined inputs and outputs, AI agents require real-time context, adaptable data consumption, and low-latency decision loops, which are not supported by the batch-oriented, rigid schema approaches of iPaaS. The emerging solution is a Context Mesh, which acts as a dynamic, ambient fabric providing real-time data availability and event streaming to meet the needs of AI agents. This system replaces static data transfers with continuous context availability, hybrid connectivity for dynamic data discovery, and adopts an outside-in design approach that prioritizes the agent's requirements over traditional database structures. Additionally, a Backend for Agents (BFA) layer is proposed to manage security, rate limiting, observability, and semantic caching, ensuring that AI agents operate efficiently and securely. The transition to a Context Mesh requires rethinking integration architectures to focus on agent needs, with platform teams asking what data agents require rather than what systems can expose. This shift in perspective necessitates a governance-ready control plane to manage API traffic, event streams, and AI concerns, laying the foundation for successful agentic AI implementations.
Jul 23, 2026 1,632 words in the original blog post.
AI initiatives often face integration challenges due to existing infrastructure limitations like batch data processing and fragmented governance, which hinder real-time event delivery and seamless operation of AI models. The proposed solution involves using Kong as a unified control plane to create a Context Mesh, which efficiently manages API, event, and AI traffic by providing intelligent connective tissue between existing compute, event streaming, data storage, and AI endpoints. Kong's AI Gateway offers features such as PII masking, confidence threshold enforcement, semantic caching, prompt injection detection, and cost attribution, thereby improving security, efficiency, and governance. Furthermore, Kong's Event and API Gateways ensure real-time context delivery and secure API calls, respectively, transforming the infrastructure to be agent-ready without overhauling existing systems. This scalable, governance-oriented architecture is adaptable across various deployment environments, including on-premises setups, and enables organizations to run reliable agentic AI at scale, independent of specific cloud providers or models.
Jul 23, 2026 1,788 words in the original blog post.
Recent research by Forrester's David Mooter emphasizes the critical importance of integration infrastructure in winning with agentic AI, highlighting that success will not be determined by the number of AI agents but by how well they are integrated into enterprise systems. The research identifies integration as a strategic capability, essential for AI agents to perform actions such as querying databases or triggering workflows, rather than just being expensive chatbots. New protocols like Model Context Protocol (MCP) and Agent-to-Agent (A2A) are reshaping integration by requiring agent-to-tool interfaces that offer semantic context, identity management, and curated action surfaces. However, while MCP adoption is rapid, governance and versioning standards lag, necessitating transformation layers and agent-specific registries for enterprise readiness. Forrester underscores the need to extend proven API governance practices to MCP, highlighting the importance of well-designed, task-oriented APIs that are AI-friendly. The research warns against overloading agents with unnecessary tools and stresses that early adoption of integration and MCP governance will give enterprises a competitive edge.
Jul 21, 2026 815 words in the original blog post.
AI traffic management now involves multiple patterns and requires centralized governance to address security, cost, and operational challenges. A universal AI reverse proxy, such as Kong AI Gateway, can centralize control by routing AI traffic through a single control point, enabling consistent enforcement of policies, authentication, cost controls, and observability. This approach mitigates risks associated with direct application-to-model provider connections, which lack central inspection and can lead to security exposures, unpredictable costs, and operational fragility. With AI adoption soaring to 78% of organizations in 2024 and projected AI spending expected to reach $1.5 trillion by 2025, effective traffic management and governance are crucial for enterprises to secure and scale their AI operations efficiently.
Jul 17, 2026 1,926 words in the original blog post.
As APIs proliferate across teams, maintaining consistency becomes challenging, leading to difficulties in understanding, reviewing, and maintaining them. API linting provides a solution to this problem, and Kong Insomnia supports this through its Inso CLI and local project files, allowing for custom Spectral rules to be applied in various workflows. With the release of Insomnia 13, managing custom rulesets becomes more accessible as they can now be uploaded and managed directly from the Insomnia UI, enabling custom linting for any project type, including cloud projects. Developers can validate OpenAPI specifications against both baseline OpenAPI rules and custom team-specific standards. This integration allows platform teams to define standards once and apply them consistently across different stages of API development, ensuring both OpenAPI compliance and adherence to organization-specific style rules. The process involves addressing default linting issues and then applying a custom ruleset to enforce additional standards, thereby ensuring APIs remain consistent, reducing vulnerabilities, and streamlining the design and governance process within Insomnia.
Jul 17, 2026 1,085 words in the original blog post.
Kong and ModelOp have announced a strategic partnership aimed at addressing the challenges enterprises face in deploying AI technologies swiftly while maintaining regulatory and security compliance. The collaboration seeks to solve the "last mile" problem in AI delivery by integrating ModelOp's centralized AI governance with Kong's high-performance AI enforcement capabilities. This partnership aims to automate governance policies, ensuring that AI models, large language models (LLMs), and agentic tools are compliant before they handle any traffic. The integration bridges the gap between compliance approvals and operational reality, which often involves manual reviews and inconsistent governance. Kong serves as the unified API/AI platform, managing AI traffic and ensuring security and observability, while ModelOp functions as the AI command center, automating the AI lifecycle and ensuring policy adherence. Together, they promise a seamless, secure, and policy-driven AI platform, allowing enterprises to scale AI innovations with confidence in their security and compliance measures.
Jul 16, 2026 1,017 words in the original blog post.
Kong AI Gateway 2.0 has been launched in private beta, introducing a separate runtime and control plane designed specifically for AI workloads such as models, MCP servers, and agents, marking a significant departure from being a feature within the Kong API Gateway. This new version, which operates independently from the API gateway's conservative release schedule, caters to the rapidly evolving AI landscape by offering a dedicated runtime, an AI-focused admin API, and a revamped user experience in Konnect. It supports major AI providers and integrates seamlessly with existing GitOps workflows through kongctl, while ensuring current users of Kong Gateway can continue operating without disruption. The decoupling allows Kong AI Gateway to update quickly, adapting to new AI providers, policies, and primitives, with AI Gateway 2.1 already in progress for an August release, positioning it to keep pace with the fast-moving AI infrastructure landscape while the Kong Gateway maintains its stability-focused track.
Jul 16, 2026 1,122 words in the original blog post.
Kong Event Gateway 1.2 addresses common challenges faced by teams running Kafka at scale, such as field-level data protection, topic renaming, and visibility into event traffic, by implementing solutions at the gateway level instead of within application code. It introduces new policies for encrypting and decrypting specific fields in JSON or Avro records as they pass through the gateway, allowing the rest of the record to remain readable and eliminating the need for producers and consumers to make code changes. Additionally, the gateway enables flexible topic presentation by allowing topics to be exposed under different names, facilitating smoother migrations and creating alias-scoped views for different consumer groups, each with its own policy enforcement. For enhanced visibility, Kong Event Gateway 1.2 integrates a real-time analytics dashboard in Konnect, providing metrics such as total bytes produced and consumed, as well as insights into top producers and consumers by volume, helping teams quickly identify and address traffic spikes and operational issues. This release positions Kong Event Gateway 1.2 as a control plane for event data governance, offering field-level policy enforcement, flexible topic presentation, and built-in visibility, akin to the control provided by API gateways, while laying the groundwork for future schema-aware policy enforcement and governance across multiple event streams.
Jul 16, 2026 858 words in the original blog post.
Kong Insomnia has introduced Koh-CLI, a command-line interface that provides a standardized and secure method for agents to access API context such as governance rules, specifications, and testing conventions directly from Insomnia. This tool addresses the challenge of feeding AI coding tools like Claude Code and Codex with accurate context, which traditionally required developers to manually input information, often leading to inefficiencies. Koh-CLI serves as a thin, opinionated interface that ensures structured and consistent data access without running business logic, thus enhancing the security and effectiveness of AI-driven API development by reducing manual context assembly and token usage. Currently available as a tech preview on npm, Koh-CLI integrates seamlessly with existing agent workflows, offering a direct line to the most current and precise API information documented in Insomnia, while preserving security by executing requests within the platform rather than exposing credentials externally. This innovation is positioned as a critical link in agentic development, helping to maintain accuracy and efficiency without the need for developers to continuously recreate API understanding from scratch.
Jul 15, 2026 958 words in the original blog post.
Kong API Gateway 3.15 introduces several enhancements aimed at closing the gap between platform needs and operational complexity as API footprints expand. The release features Plugin Cloning, allowing multiple instances of the same plugin logic without duplicating code, and Plugin Streaming, which enables the instant distribution of custom plugins to all data plane nodes directly from the Control Plane. Conditional Policy Execution, now generally available, allows expression-based plugin logic for more precise policy enforcement. Security enhancements include Azure Key Vault certificate rotation, file-based vault secret resolution, and Proof of Possession token validation behind web application firewalls. The introduction of distroless images with a reduced attack surface enhances security and compliance, while full governance of applications registered in the Developer Portal ensures consistent policy enforcement across entities. These updates position the Konnect Control Plane as the central source for gateway configuration and logic, paving the way for future capabilities in plugin versioning and composition, ultimately advancing Kong towards a unified, cloud-native API governance platform.
Jul 14, 2026 1,292 words in the original blog post.
Running Apache Kafka on Amazon Managed Streaming for Apache Kafka (MSK) offers a managed service with benefits like automated patching and multi-AZ replication, but lacks a secure way to extend Kafka access beyond VPC boundaries. The article explores the DMZ pattern for MSK using Kong Event Gateway, highlighting its suitability for organizations needing to share Kafka access across VPCs or organizational perimeters. The DMZ pattern isolates Kafka access through a controlled gateway that authenticates clients and applies policies, keeping MSK brokers private and secure. This architecture offers advantages over MSK's public access options by hiding broker topology, reducing operational costs, and enabling centralized control and audit capabilities. Kong Event Gateway, deployed on AWS ECS Fargate, is stateless and integrates with Kong's Konnect for configuration management, enhancing scalability and operational simplicity. The setup ensures that external access doesn't impact internal MSK stability, and compliance is centralized at the gateway. The article further provides resources for implementing this architecture using Terraform, promoting a GitOps-compatible approach to manage the infrastructure.
Jul 14, 2026 2,589 words in the original blog post.
Kong has expanded its Kong Identity platform to include a centralized principals directory, offering a unified identity management solution across API and event gateways, as well as developer portal applications. This development aims to address the complexity of managing distributed API estates by providing a single source of truth for authentication across diverse consumer populations, including internal developers, external partners, and AI agents. The principals directory allows for flexible credential lifecycle management and supports multiple authentication strategies, integrating seamlessly with existing workflows and systems like Okta and Cognito. It enhances security by enabling identity-aware policies and fine-grained access control, thus reducing vulnerabilities and improving governance. The directory supports the dynamic injection of metadata into policy decisions, facilitating a consistent identity model across API and event traffic, and is designed to streamline operations for platform teams through various management interfaces. The introduction of this feature promises to accelerate deployments and provide real-time visibility, ensuring a cohesive security infrastructure for modern enterprises.
Jul 14, 2026 1,087 words in the original blog post.
Kong Gateway 3.15 introduces a distroless image variant aimed at addressing security and compliance challenges faced by enterprise customers, particularly in regulated sectors such as government, finance, and healthcare. Traditional container images typically include a full Linux distribution, which can lead to unnecessary vulnerabilities, but Kong's distroless approach minimizes these risks by removing non-essential components, leaving only what's necessary for application execution. Built on Wolfi's apko declarative build system, the distroless image maintains Kong's functionality while reducing the attack surface, as it lacks package managers, shells, and runtime installation capabilities, resulting in significantly fewer CVEs and a more secure environment. The distroless image is compatible with existing workflows, ensuring that Kong's features like routing, TLS termination, and logging integrations remain unchanged, although interactive debugging requires alternative methods due to the absence of a shell. This new variant is available alongside the standard image, offering a secure, efficient, and seamless integration into current deployments.
Jul 14, 2026 784 words in the original blog post.
Gartner's inaugural Magic Quadrant for AI Governance Platforms (AIGP) reflects the growing demand for structured AI governance solutions, with the market expected to expand significantly from $65 million in 2024 to $1.434 trillion by 2030. The report emphasizes that AI governance cannot be fully managed by a single platform, requiring a composed stack that integrates multiple capabilities such as AI discovery, compliance management, policy enforcement, and interoperability. Unlike traditional Governance, Risk, and Compliance (GRC) tools, AIGPs are designed for real-time policy enforcement across an organization's AI operations. A key component of this ecosystem is the connectivity layer, where platforms like Kong AI Gateway operate, enabling runtime enforcement through infrastructure controls such as traffic routing, access controls, and data sanitization. The Gartner report highlights the need for AI governance and connectivity infrastructure to work together, with AI governance platforms setting policies and gateways ensuring their operational implementation. As AI-powered autonomous agents become more prevalent in enterprise workflows, the need for robust runtime enforcement infrastructure becomes critical to manage the complexity and risks associated with AI governance.
Jul 09, 2026 1,382 words in the original blog post.
Kong Konnect's Metering & Billing system introduces prepaid credits as a strategic financial tool, offering businesses the advantage of collecting payments before consumption to safeguard margins against token-cost spikes and mitigate collections risks. The system's architecture is built on an immutable ledger that logs every financial transaction, ensuring transparency and preventing issues like double-charging or untraceable edits. By separating fiat payment from live consumption, it provides an audit trail crucial for revenue recognition, allowing businesses to choose between a 'Credits only' model or an 'Invoice overage' approach, depending on their financial strategy. The flexible credit system accommodates various settlement modes, prioritization of credit usage, and currency-specific balances, providing businesses with the ability to manage financial risk effectively and enhance customer engagement through promotional credits or negotiated rates. Konnect's implementation details, including the roles required for managing credits and the ability to handle multiple grants, underscore the system's robust design, aimed at ensuring financial integrity and strategic decision-making in credit management.
Jul 08, 2026 1,575 words in the original blog post.
Shadow AI detection involves identifying and managing unsanctioned AI tools, models, and API integrations that employees deploy without security approval, posing significant risks to enterprise data security and compliance. Unlike shadow IT, which remains within a known perimeter, shadow AI routes live data such as customer records and source code to external models, leading to potential data exfiltration, compliance violations, and supply-chain vulnerabilities as illustrated by the Cordyceps disclosure. This detection requires visibility at the traffic layer, where AI calls happen, and is often implemented via an AI gateway, which serves as a control plane ensuring that every AI API request is visible, logged, and subject to policy enforcement, thereby transforming shadow AI from an invisible risk into a governed flow. The urgency of addressing shadow AI is highlighted by IBM's research indicating that 20% of breaches involve shadow AI, with such incidents adding significant costs to data breaches, and a large majority of AI-related breaches lacking proper access controls. Federated AI governance provides a framework where a central team sets baseline policies, and individual teams operate within these, ensuring consistent governance across multi-cloud and hybrid environments, which is crucial as AI adoption spreads across organizations.
Jul 07, 2026 1,645 words in the original blog post.
Kong's AI Gateway addresses the challenges of integrating Enterprise-Managed Authorization (EMA) across Model Context Protocol (MCP) environments by acting as a bridge between clients and servers that are not yet EMA-ready. The introduction of the id-jag-relay plugin enables Kong to handle Identity Assertion JWT Authorization Grant (ID-JAG) exchanges, upgrading existing credentials and ensuring seamless connectivity without altering client or server architectures. This setup allows enterprises to centralize access policies at the Identity Provider (IdP) level, enhancing security and governance by maintaining an unbroken delegation chain and providing a comprehensive audit trail. By positioning itself at the network layer, Kong facilitates real-time visibility, reduces vulnerabilities, and accelerates the adoption of EMA, supporting a gradual transition for organizations with diverse technological infrastructures.
Jul 03, 2026 1,925 words in the original blog post.
Enterprise AI adoption is rapidly increasing, with a significant number of organizations planning to boost their AI-related budgets. However, scaling AI from pilot projects to full production reveals challenges, particularly with direct LLM API integration, which creates fragility and complexity. A crucial decision for organizations is choosing between direct integration and using an AI gateway, the latter of which serves as a dedicated infrastructure layer that offers centralized management of routing, failover, rate limiting, authentication, observability, and policy enforcement. This approach minimizes the need for bespoke infrastructure for each provider and reduces migration efforts by up to 80%, making it more suitable for production environments that require security, compliance, and cost control. The AI gateway, distinct from a regular API gateway, addresses specific AI capabilities like semantic caching and prompt filtering, enabling companies to switch providers through configuration updates rather than code rewrites. As enterprise AI budgets are expected to rise significantly, centralized AI traffic management is becoming essential to avoid vendor lock-in, manage costs effectively, and ensure system resilience and observability.
Jul 02, 2026 1,893 words in the original blog post.
In June 2026, two major AI agent platforms, Langflow and Dify, experienced significant security breaches, highlighting a critical gap between rapid deployment and security maturity in AI infrastructure. Langflow faced multiple vulnerabilities, including a severe unauthenticated remote code execution flaw, while Dify's issues involved cross-tenant data exposure and unauthorized API access, undermining its multi-tenant architecture's isolation guarantees. These incidents reflect a broader pattern seen in the early days of web applications, where initial fast-paced developments lacked robust security measures. The proposed solution mirrors the evolution of web application security, advocating for a gateway-level security layer, similar to Web Application Firewalls (WAFs), to enforce authentication, input validation, and rate limiting across AI agent interactions. Kong AI Gateway has been introduced to address these challenges, providing traffic-layer security controls to protect AI agents by enforcing identity verification, input filtering, and zero-trust principles, aiming to contain potential threats before they reach application logic. With AI agent traffic expanding rapidly, the importance of integrating such governance into AI infrastructure is underscored, echoing the historical shift in web application security practices.
Jul 02, 2026 1,816 words in the original blog post.
In June 2026, the shutdown of Anthropic's Claude Fable 5 and Mythos 5 models highlighted the critical issue of AI vendor lock-in, as enterprises relying on these models faced immediate operational disruptions. This unexpected event underscored the broader risks associated with vendor concentration, where reliance on a single provider can lead to cascading failures across AI-powered systems. Organizations have traditionally underestimated the complexities of switching AI providers, which often require significant code and infrastructure changes. The solution lies in adopting an AI gateway architecture, exemplified by Kong AI Gateway, which facilitates multi-provider routing, automatic failover, and provider abstraction without altering application code. This approach ensures resilience and continuity by decoupling applications from specific model dependencies, allowing enterprises to manage AI resources with a single control plane for authentication, observability, and cost control. As AI vendor lock-in poses a real business continuity threat, enterprises are encouraged to implement robust infrastructure configurations to absorb provider changes seamlessly.
Jul 02, 2026 1,452 words in the original blog post.
Kong Insomnia 13 introduces native integration with the Kong Konnect Gateway, enabling developers to query live gateway configurations directly from their terminals, thus ensuring tests align with the current deployed state without manual spec imports or outdated collections. This integration bridges a gap between API governance and development workflows, ensuring that testing aligns with live production configurations and extends governance coverage across the entire API lifecycle. By eliminating the need for separate exports and manual syncing, Insomnia 13 enhances testing fidelity, ensuring that routes, policies, and security rules are always up-to-date, reducing the risk of deployment failures caused by configuration drift. The Enterprise version of Insomnia 13 further bolsters governance and security features by including RBAC, SSO, data residency, and Git Sync at no extra cost, unlike its competitor Postman, which charges per user for similar capabilities. This integration not only improves testing accuracy but also maximizes the value of investments in the Kong Konnect platform by maintaining a single source of truth throughout the API development process.
Jul 01, 2026 1,396 words in the original blog post.
Kong Konnect's prepaid credits system offers a strategic approach to managing AI-related costs and financial risks associated with usage-based products. By allowing customers to purchase credits upfront, businesses can stabilize their revenue streams and avoid the unpredictability of post-pay billing, especially when AI consumption can fluctuate dramatically. This system decouples the cost of tokens from the value customers spend, providing a buffer against sudden usage spikes and frequent model updates. Prepaid credits are stored in customer wallets and can be consumed via promotional, invoiced, or externally settled credits, each tied to a specific fiat currency to ensure consistency. This approach not only protects financial interests but also enhances customer flexibility, enabling them to adapt quickly to new AI capabilities without constant price adjustments. With promotional credits functioning as onboarding incentives or loyalty rewards, businesses can transform growth strategies into configurable tasks rather than complex engineering challenges, making prepaid credits an attractive option for AI companies seeking a robust metering and billing foundation.
Jul 01, 2026 1,075 words in the original blog post.