If you don’t give agents an API, they’ll make one out of your UI
Blog post from Tyk
Martin Buhr highlights the challenges posed by agents that reverse-engineer user interfaces (UI) to create APIs when official APIs are unavailable, emphasizing that these agents will exploit any UI vulnerabilities to achieve their goals. He discusses how this behavior leads to the emergence of "shadow APIs," which are not malicious but result from users and agents trying to complete tasks that official APIs don't support. Buhr warns that relying on UI-derived automation can lead to governance and security issues, as it lacks the control and auditability of formal APIs. He suggests that organizations should anticipate and address this by offering robust, well-documented APIs and implementing strict governance policies to manage agent interactions, thereby avoiding operational chaos. Buhr concludes by noting the importance of being proactive in API management to ensure that automation remains within controllable and secure boundaries.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 3,533 | 369 | 145 | -53% |
| LLM | 2 | 3,751 | 612 | 168 | -39% |
| Observability | 2 | 1,844 | 344 | 128 | -56% |
| Kubernetes | 1 | 1,260 | 165 | 75 | -41% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.