43% of CISA's exploited vulnerabilities in 2025 were API-related. 59% need zero authentication to exploit. APIs are now the #1 attack surface — and most of these vulns are trivially easy to exploit. zuplo.link/4K76BEX
Zuplo
@zuplo.com
Zuplo enables developers to do more by doing what they love and build great experiences for other developers. Zuplo's API gateway helps you ship APIs you're proud of from day 1. https://zuplo.link/bluesky
By popular demand - we're hosting another workshop on #mcp this Friday! This time around, we'll be focusing on adding security to your remote Model Context Protocol server - so you can safely expose your platform and APIs to LLMs and AI Agents.
At Zuplo we believe every API should have beautiful and powerful API documentation. So, we're excited to announce that we've launched a major update to the Developer Portal we provide for every Zuplo project! Interested? Of course you are:
Introducing New Zuplo Developer Portals | Zuplo Blog
A major update to Zuplo's built-in developer portal delivers a sleeker interface, modernized architecture, and smarter tools for API testing and exploration that enables enhanced API documentation…
zuplo.link
Zudoku now has a native integration with Inkeep! You can now add AI search directly to your API documentation, which can: - Help potential customers navigate your catalog of APIs - Empower devs to onboard faster - Aid existing customers in their understanding of new APIs, versions, or migrations
Model Context Protocol 2025-06-18 is finally here - and it's jam-packed with new features and changes.
"[Zuplo] could be a one-stop shop to govern AI agent access, spin up your tools, and even monetize your MCP server. " We're already the leading API management platform for MCP support according to Nordic APIs - here what else they have to say here: nordicapis.com/10-api-gatew...
10 API Gateways That Support MCP | Nordic APIs |
Explore 10 API gateways that support MCP and learn how they enable AI agents and secure, context-rich interactions.
nordicapis.com
How do you demonstrate the value of API governance?? How do you begin to implement API governance at a large org? Travis Gosselin, Distinguished Engineer at SPS Commerce talks about how they did it without getting in their developers way, and demonstrating value first.
Check out TNS's summary of our talk on API monetization! If you're looking to monetize your #API or #MCP server - then check out Zuplo - it's free! #apis #apimonetization #apiproduct #apimanagement
Why API marketplaces are for suckers and how developers can monetize their APIs using one of three options.
Have you ever heard of AuthZEN? AuthZEN is the new Standard for Authorization, backed by the OpenID group. It aims to standardize the way components can communicate authorization relation information. The goal is to make it easier for developers to implement fine-grained authorization in their apps
Beware API Drift! Especially if you're building MCPs from your APIs When preparing for LLMs and AI Agents, don't forget the basics of good API best practices, and beware API drift! Emmanuel Paraskakis: www.linkedin.com/in/emmanuelp... Subscribe to API Excellence: www.youtube.com/@Zuplo
🚀 We announced support for the creation of remote Model Context Protocol (MCP) servers for any API in Zuplo as part of our MCP Week. If you missed any of it you can catch up on all the posts, videos and conversation at zuplo.link/mcpweek 🤖
🤖 MCP Week Day 5: AI Agents Are Coming for Your APIs! The question isn't whether AI agents will use your APIs, but whether you'll be ready when they do. John McBride from Zuplo explains why agents are already using your APIs (whether you know it or not) zuplo.link/mcpweek5
🚀 MCP Week Day 4: Introducing our new policies! 🤖 Prompt Injection Detection: Uses LLMs to identify and block malicious prompt poisoning 🤫 Secret Masking: Automatically redacts API keys and sensitive data from outbound requests Find out more and see the walkthrough video: zuplo.link/mcpweek4
🤖 MCP Week Day 3! The harsh reality of AI agent reliability. Today we're exploring AI agent reliability when working with APIs, tool discovery, and API design challenges with Zdenek Nemec, Co-Founder and CTO at Superface. Lots more in the post (plus video): zuplo.link/mcpweek3
MCP Week Day 2! 🔥 Today we're launching the ability to create remote Model Context Protocol (MCP) servers for your APIs directly in Zuplo! 🔥 Quickly expose your API as MCP tools for Cursor, Anthropic Claude Desktop, OpenAI, and many more! Get started for free: zuplo.link/mcpweek2
Introducing: Remote MCP Servers for your APIs | Zuplo Blog
Using our new MCP Server Handler you can transform any API you manage through Zuplo into a remote Model Context Protocol (MCP) server.
zuplo.link
🚀 It's MCP Week at Zuplo! Day 1 kicks off TODAY with API strategist Kevin Swiber, who explores how MCP is reshaping APIs rather than posing a threat that would kill it completely, and what it means for developers building the next generation of AI-powered applications. zuplo.link/mcpweek1
Explaining n+1 in GraphQL - and how Hasura solved it! What is n+1? Adam Malone from Hasura explains what it is and tells us why Hasura isn't prone to this due to their approach to multiple record queries. Subscribe to API Excellence to get these insights before anyone else: www.youtube.com/@Zuplo
What's the difference between GraphQL & REST?? Mike Watson from Apollo GraphQL discusses the differences between REST APIs and GraphQL APIs. Subscribe to API Excellence to get these insights before anyone else: www.youtube.com/@Zuplo Recorded at Kubecon North America, Utah, November 2024
Just dropped a quick tutorial video on using Zuplo's new Web Bot Auth policy with HTTP Message Signatures to control which bots can access your endpoints. Great for maintaining API performance, preventing unwanted data scraping and protecting your rate limits from unwanted traffic: zuplo.link/httpms
How should you adopt API Standards? What should you consider when adopting API standards at your organization? Is custom, in house standard always the best way or are there other choices out there that will work better? Travis Gosslin, Distinguished Engineer at SPS Commerce explains his journey:
Async APIs vs REST APIs - what's the difference??? When it comes to Event Driven Architecture (EDA), asynchronous APIs are necessary, but how should you think about them versus traditional REST APIs? Budhaditya Bhattacharya from Tyk explains.
What the Heck is PromptQL??? Adam Malone, Director of Worldwide Solutions Engineering at Hasura talks about PromptQL can be used to surface the unknown unknowns when building data products.
What Does API Governance Look Like At Scale? Travis Gosselin, Distinguished Engineer at SPS Commerce explains what API governance looks like for them and how they designed their approach to work internally, and at scale.
Call us germaphobes - but we've been a bit obsessed with SOAP lately We've just completed an entire anthology on SOAP APIs on our blog - here's what you missed:
Zuplo has landed on the AWS Marketplace! Tired of wrangling multiple AWS services together, just to get a functional API out the door? Ditch AWS API Gateway's service spaghetti and finally experience REAL API Management. Check it out: zuplo.link/aws
If you're a #Golang API Developer - you need to start using Huma! It's a lightweight and easy-to-use framework for building APIs in Go, with built-in support for OpenAPI and some neat features that make it a great choice for developers.
API gateway setup: 👨💻 Traditionally? Hours of configs, docs, YAML pain 😭 ⚡ With Zuplo? 10 minutes. Done. In our latest video, Zuplo co-founder and CEO Josh walks you through it step by step. Including: Rate limiting, auth, RBAC, dev portal, and global deployment! 👉 zuplo.link/10minwin
API Management vs API Gateways - what's the difference? API Gateways are the traffic controllers of your API ecosystem. They direct the flow between clients and backend services, acting as a single entry point for all API calls.
Want to know how Hookdeck embedded code directly into their API docs? Well the answer is Markdown - and if you aren't using Markdown to explain workflows within your API, your docs are half-baked.