May 2025 Summaries
11 posts from Tyk
Filter
Month:
Year:
Post Summaries
Back to Blog
Arazzo is a new specification designed to enhance AI supply chains by refining OpenAPI workflows for complex tasks, acting as a conveyor belt for completing specific workflows using APIs to achieve business outcomes. Tyk, a contributor to the OpenAPI Initiative, emphasizes the importance of Arazzo in standardizing and automating AI agent interactions, offering a consistent mechanism for AI models to interface with APIs. This specification is vital for ensuring contract adherence within API ecosystems and is seen as a critical component for organizations to become AI-ready. Arazzo complements existing protocols like the Model Context Protocol (MCP) and Agent2Agent (A2A), facilitating seamless interactions and collaborations among AI agents in enterprise environments. By providing declarative workflows, Arazzo allows AI agents to execute business processes with precision and testability, positioning it as an essential tool for modern enterprises aiming to leverage AI effectively.
May 30, 2025
936 words in the original blog post.
API governance is centered around people and is more than just a technical issue; it is a business matter that requires the active involvement of development teams to be successful. The 2025 LEAP 2.0 API Governance Conference emphasized that successful API governance empowers individuals by providing secure and efficient frameworks that enhance innovation, shorten release cycles, and improve scalability and compliance. Engaging teams early in the process to understand their tools, processes, and terminology can foster buy-in and ensure that governance aligns with business objectives. Effective governance involves creating processes and policies that ease the workload of developers, thereby preventing workarounds and maintaining the benefits of standardization and efficiency. Continuous engagement and regular reviews are crucial to keeping governance effective, and it can also open up opportunities for career growth and development in the API field.
May 29, 2025
806 words in the original blog post.
Moving artificial intelligence (AI) from proof of concept (PoC) to scalable production involves more than just a smart model; it requires robust API governance to ensure the operationalization of AI across business units. APIs serve as the critical interface through which AI systems interact with data and applications, making API governance essential for maintaining consistency, security, and interoperability. Without it, enterprises risk creating siloed, one-off AI solutions that are difficult to replicate and scale. The implementation of open standards and best practices in API governance, such as using the OpenAPI Specification, centralizing API registries, and ensuring secure access control, helps standardize interactions and reduces risks such as misinformation or incorrect API usage. As AI becomes an enterprise-grade solution, treating it as a product integrated with well-governed APIs enhances its capability to deliver business value, transforming isolated PoCs into comprehensive AI strategies.
May 27, 2025
858 words in the original blog post.
MCP, or Modular Communication Protocol, is criticized for its current implementation, which is fraught with security, versioning, and usability issues, making it less favorable compared to direct API integrations. Initially appealing as a plug-and-play tool for LLM clients, MCP has become problematic due to insecure, DIY server implementations and a lack of proper server-side support, leading to potential security risks from code run as local processes, often in languages like Python and NodeJS that are prone to vulnerabilities. Additionally, MCP lacks established versioning practices, complicating updates and dependency management, and presents usability challenges due to the need for language-specific tooling and complex configurations. The process has been likened to an overcomplicated SDK, with the article suggesting that frameworks like Huggingface’s SmolAgents, which allow for short-lived scripts in sandboxes rather than persistent infrastructure, are more aligned with the current state of LLMs. MCP's practicality is largely limited to chat interfaces, as direct API integrations remain a more efficient, secure, and manageable approach given the absence of generic agents in the AI landscape.
May 22, 2025
1,015 words in the original blog post.
Demonstrating Proof of Possession (DPoP) is an enhancement to OAuth2 security, designed to protect APIs against token theft and replay attacks, making it particularly useful for FAPI 2.0, PSD2, and mobile applications. Unlike traditional bearer tokens, which can be easily stolen and reused, DPoP binds access tokens to a cryptographic key, ensuring that only the holder of the private key can use it. This approach offers significant benefits, such as preventing token theft, providing replay protection, and being suitable for environments where storing secrets securely is challenging, like mobile apps and public clients. While mutual TLS (mTLS) has been the gold standard for secure token binding, DPoP achieves similar security at the application layer without the complexity of managing client certificates. DPoP is gaining traction in industries like banking, fintech, healthcare, and government, where strong API security is essential, aligning with regulatory standards such as FAPI 2.0 and open banking initiatives. By strengthening API security without compromising usability, DPoP provides a robust solution for protecting sensitive data across various sectors.
May 21, 2025
1,686 words in the original blog post.
Tyk 5.8 has adopted an OpenAPI-first approach, enabling the OpenAPI Specification (OAS) to be the default for all API definitions, which facilitates secure, interoperable, and governance-focused API experiences. This update achieves feature parity between Tyk Classic and Tyk OAS, allowing users to configure any feature of Tyk Gateway using OAS, enhancing the developer experience by supporting YAML or JSON formats and improving onboarding for new Tyk Cloud users. The focus on OAS provides a blueprint for API development and management, offering interoperability, faster integration, and access to a wide range of tools without the need for custom integrations. These benefits extend to enhanced upstream authentication and a more intuitive testing and debugging experience, alongside seamless integration with CI/CD pipelines. Additionally, adopting open standards ensures greater compatibility with AI tools, promoting interoperability across AI ecosystems. Migrating to Tyk OAS is streamlined through support for Enterprise Edition users, and users can explore the new features via Tyk Docs, webinars, and demos.
May 16, 2025
801 words in the original blog post.
Deploying the Tyk API Gateway using unikernels was explored through a proof of concept (PoC) that demonstrated the feasibility of such an implementation using Unikraft, a secure, open-source unikernel development kit. The PoC involved a hybrid architecture with the data plane hosted on the Unikraft Cloud and the control plane managed locally, illustrating the potential for distributed deployment while maintaining centralized control. The use of unikernels offers security, performance, and efficiency advantages, aligning well with the needs of API gateways. The PoC highlighted key technical insights, such as the importance of boot time for effective stateful caching and the necessity of appropriately setting cooldown times to prevent premature scaling down. The experiment also revealed infrastructure resource limitations, such as the single-core nature of Unikraft Cloud and the need for horizontal scalability. Configuration management was streamlined using environment variables, similar to Docker compose deployments, to handle sensitive information securely. The PoC results, including efficient boot times and successful state caching, suggest that unikernel-based API gateways like Tyk could offer a promising approach for modern, scalable deployments.
May 15, 2025
1,389 words in the original blog post.
As artificial intelligence becomes increasingly integrated into software development, API governance is evolving to address its dual role as both a developer tool and a consumer. Experts in the field, including leaders from Tyk and Level 250, agree that while AI can accelerate prototyping, AI-generated APIs are not yet ready for production due to issues like hallucination and unreliable outputs. To mitigate these challenges, clear guidelines and standards should be embedded in AI prompts, and human reviewers and deterministic tools should validate outputs. Moreover, AI's role as a consumer presents its own set of challenges, with Model Context Protocols (MCPs) offering a way to bridge the gap by simplifying complex APIs for AI agents. Effective API governance in this context involves prioritizing clarity, consistency, and structured documentation to improve API design, ensuring that both human and machine consumers can interact seamlessly with APIs. This approach, supported by tools like Tyk AI Studio, aims to enhance productivity and create APIs that are efficient and reliable for both developers and AI-driven systems.
May 09, 2025
1,097 words in the original blog post.
Scott's introductory post on WordPress, dated May 7, 2025, prompts new users to edit or delete the default welcome message and begin their writing journey. The post also highlights related articles discussing the importance of efficient API calls in financial services and updates to Tyk, a platform for managing modern APIs, including its enhanced security and flexibility features. Additionally, it encourages users to explore the Tyk Cloud platform, offering a quick setup for APIs, complete with a free trial and demo to facilitate an easy start.
May 07, 2025
113 words in the original blog post.
A well-governed AI supply chain is essential for enterprises to balance innovation, security, and compliance while integrating AI technology. The AI supply chain includes vendors, interfaces, data, and tooling, with APIs serving as the crucial connective tissue enabling modularity and interoperability. Enterprises face a choice between closed ecosystems and modular components, similar to the decision between Apple's controlled environment and Android's open one, impacting their AI infrastructure's scalability and security. A structured AI supply chain ensures flexibility, allowing companies to switch AI models or providers without disruption, while maintaining control over proprietary data. As AI adoption grows, managing this supply chain effectively becomes vital, with tools like Tyk AI Studio offering solutions for governance, model connections, and privacy filtering. Enterprises must focus on embedding AI seamlessly into existing tools and processes, supported by a governance framework that fosters innovation and progress.
May 02, 2025
1,842 words in the original blog post.
Many organizations struggle with transforming AI potential into a secure and well-governed reality, and Jennifer Craig's guide offers seven steps to achieve AI readiness and responsible implementation. The steps emphasize the importance of API governance, controlling AI costs, developing a robust data strategy, and building a cross-functional AI team to ensure cohesive decision-making aligned with business goals. Ethical AI practices are essential, alongside preparing for AI scalability through centralized management and fostering a culture of AI adoption. Tools like Tyk AI Studio can aid in managing AI usage, ensuring compliance, and optimizing resources, while a cultural shift within the organization is vital for embracing AI's benefits and accelerating business growth.
May 01, 2025
1,070 words in the original blog post.