Early bird pricing for Nordic APIs Platform Summit 2026 ends August 24. Three days in Stockholm on all things API in the agentic AI era. https://nordicapis.com/events/platform-summit-2026/
Nordic APIs
@nordicapis.com
A global community for API practitioners, hosting quality events and a high impact blog. Subscribe to our bi-weekly API Digest 📯 https://nordicapis.com/newsletter/
What does responsible stewardship of customer data look like? It means considering what data collection is truly necessary, revisiting SSO, and limiting standing privileges to sensitive data.
What Happens After Every Company Becomes a Data Company? | Nordic APIs |
Learn how responsible data stewardship, identity controls, and data minimization can protect customer data across APIs and AI agents.
nordicapis.com
There is an emerging machine-to-machine economy, says Kong's Chris Darvill, and APIs are at the heart of it. Today on the blog, he explores what this means for API marketplaces and the API economy at large.
API Marketplaces and the Invisible Economy: Trade Routes of the AI Era | Nordic APIs |
How API marketplaces turn APIs into tradable services for AI agents, enabling monetization, governance, and orchestration.
nordicapis.com
How can API management infrastructure support data residency, operational control, and regional compliance? Here we outline six approaches for building sovereign API management at scale.
6 Ways to Achieve Sovereign API Management | Nordic APIs |
Explore six sovereign API management strategies for data residency, regional compliance, and API infrastructure control.
nordicapis.com
It's easy to get lost in how many types of tokens there are in software development. Today, Janet Wagner walks us through tokens for authentication and authorization, AI and LLMs, crypto, applications, and APIs.
What Is a Token? A Developer's Guide to Every Type | Nordic APIs |
Learn the major types of tokens software developers use in authentication, LLMs, crypto, applications, and APIs.
nordicapis.com
Malicious API traffic can masquerade as authenticated users. J Simpson recommends watching for sequential enumeration, bulk download requests, unusual access patterns, and abnormal request volumes.
5 Signs That Authenticated API Traffic Is Actually Malicious | Nordic APIs |
Learn five signs that authenticated API traffic may be malicious, from unusual access patterns to error rates and bulk actions.
nordicapis.com
In many organizations, data is no longer a byproduct of commerce: it is a product in and of itself. With that shift comes new responsibility. Today on the blog, Art Anthony explores what responsible data stewardship requires.
What Happens After Every Company Becomes a Data Company? | Nordic APIs |
Learn how responsible data stewardship, identity controls, and data minimization can protect customer data across APIs and AI agents.
nordicapis.com
Multi-agent systems consist of multiple autonomous AI agents working together to complete a task or common goal. Here's how worker agents, leader agents, protocols, tools, and policies help support these systems.
What Is a Multi-Agent System? | Nordic APIs |
Learn what a multi-agent system is, how MAS components work, and how enterprises use AI agents across industries.
nordicapis.com
Agentic traffic can make API usage harder to understand. Here we explain how API providers can improve visibility, monitor agent behavior, and strengthen security through better observability practices.
How to Improve API Observability for AI Agents | Nordic APIs |
Learn how API providers can improve observability for AI agent traffic, MCP workflows, tool usage, and risk monitoring.
nordicapis.com
Digital sovereignty is changing how API infrastructure gets built. Today on the blog, Kristopher Sandoval explores six ways to make API management more sovereign, from self-hosted gateways to regional deployments and data residency-aware API layers.
6 Ways to Achieve Sovereign API Management | Nordic APIs |
Explore six sovereign API management strategies for data residency, regional compliance, and API infrastructure control.
nordicapis.com
JWT vs opaque tokens is not a binary decision. Many teams combine both to balance scalability and control. Learn how hybrid token strategies are shaping modern API authentication.
JWT vs Opaque Tokens: Choosing the Right Token for API Security | Nordic APIs |
Compare JWT vs opaque tokens for API security. Learn the differences in validation, performance, and when to use each approach.
nordicapis.com
Long-lived, over-permissioned API keys remain a major weakness in modern systems. Learn where they fall short and what more secure alternatives look like.
10 Security Issues With API Keys | Nordic APIs |
API keys introduce significant security risks due to their static, reusable nature and lack of identity context. Learn the top API key vulnerabilities and how to secure modern APIs.
nordicapis.com
Most companies now have various API styles, gateways, and management tools. So, how do you manage API sprawl? J Simpson provides some helpful tips on operating multiple APIs.
6 Tips For Managing Multiple APIs | Nordic APIs |
Learn six practical tips for managing multiple APIs, from API registries and governance to monitoring, gateways, and lifecycle planning.
nordicapis.com
The average enterprise continues to build and expose more APIs. But where are the biggest security gaps? J Simpson outlines five API vulnerabilities that may not all be the most common, but can be disastrous when exploited.
The 5 Most Disastrous API Vulnerabilities | Nordic APIs |
Explore five API vulnerabilities that can cause severe data breaches, fraud, infrastructure compromise, and system takeover.
nordicapis.com
Access control for AI agents is not about reinvention. It is about applying proven mechanisms like OAuth, tokens, and policy enforcement in new, runtime-driven contexts.
3 Core Pillars of AI Agent Access Control | Nordic APIs |
Learn how identity validation, token handling, and policy enforcement adapt to secure AI agents in modern API access control systems.
nordicapis.com
Over-permissioned agents can create unexpected outcomes when granted broad access. Kristopher Sandoval explains why traditional identity and access frameworks are underprepared for agentic AI.
5 Ways Agentic AI Can Act Unpredictably | Nordic APIs |
Explore how agentic AI unpredictability affects access control, API security, governance, and human oversight to prevent bad outcomes.
nordicapis.com
Multi-agent systems often need access to many APIs, tools, and underlying systems. But as permissions expand, so does the attack surface. Here's how to reduce privilege drift and keep agent access tightly scoped.
How to Manage Privilege Drift in Multi-Agent Systems | Nordic APIs |
Learn how privilege drift affects multi-agent systems and how to manage AI agent permissions with least privilege and JIT access.
nordicapis.com
Reports indicate that most malicious API traffic now occurs through authenticated requests. J Simpson outlines the behavioral signs that can reveal attacks, reconnaissance, and compromised access.
5 Signs That Authenticated API Traffic Is Actually Malicious | Nordic APIs |
Learn five signs that authenticated API traffic may be malicious, from unusual access patterns to error rates and bulk actions.
nordicapis.com
Scope sprawl happens when identities, applications, or tokens accumulate broader permissions than they need. Kristopher Sandoval explains why this creates risk across OAuth scopes, API keys, and SaaS integrations.
What Is Scope Sprawl? | Nordic APIs |
Define scope sprawl and learn how over-permissioned tokens, OAuth scopes, and long-lived credentials create API security risks.
nordicapis.com
How do you know whether AI agents are calling your APIs, and what their intent is? Kristopher Sandoval outlines what API providers should know about observability for AI agents.
How to Improve API Observability for AI Agents | Nordic APIs |
Learn how API providers can improve observability for AI agent traffic, MCP workflows, tool usage, and risk monitoring.
nordicapis.com
60+ speakers at Nordic APIs Summit 2026. Agentic AI. IAM. Data sovereignty. MCP. Real case studies. Stockholm, October 13–14: nordicapis.com/events/platform-summit-2026
"APIs are 100 times more important today than they were five years ago," Kin Lane tells Nordic APIs. Art Anthony caught up with Lane ahead of Nordic APIs Summit 2026 to discuss AI hype, agentic consumption, and the enduring role of APIs.
Kin Lane on AI and the Future of APIs | Nordic APIs |
Kin Lane discusses AI, APIs, data lock-in, and why API strategy still matters as agentic consumption grows.
nordicapis.com
What tools support MCP observability? Here's a rundown of six options for observing MCP tool calls, tracing agent activity, and monitoring interactions with MCP servers.
6 Tools for MCP Observability | Nordic APIs |
Explore six MCP observability tools for monitoring AI agents, tool calls, telemetry, and MCP server interactions.
nordicapis.com
Privilege drift is emerging as a major access control risk in enterprise AI. Janet Wagner explains how permissions can accumulate across multi-agent systems and what teams can do to manage them.
How to Manage Privilege Drift in Multi-Agent Systems | Nordic APIs |
Learn how privilege drift affects multi-agent systems and how to manage AI agent permissions with least privilege and JIT access.
nordicapis.com
The big question of the upcoming Nordic APIs Summit: what does it mean for your API infrastructure when AI agents are the primary consumers? October 13–14 in Stockholm. Early bird open until August 24. 👉 nordicapis.com/events/platform-summit-2026
SaaS isn't dead. But the consumption layer is changing, meaning SaaS companies must evolve to survive. Effective APIs continue to be the go-to mechanism for exposing data safely and securely, whether to humans or agents.
The Future of SaaS Is APIs Plus AI Agents | Nordic APIs |
AI agents are changing how users consume SaaS, making robust APIs essential for data access, workflows, and automation.
nordicapis.com
MCP adoption is growing quickly, but its security implications remain a concern. Here's we review the OWASP MCP Top 10 and explain how teams can respond to risks across agentic ecosystems.
Guide to the OWASP MCP Top 10 | Nordic APIs |
Learn the OWASP MCP Top 10 risks and best practices for securing MCP servers, tools, agents, and workflows.
nordicapis.com
It's easy to issue over-permissioned access tokens under pressure. But at scale, this can turn into scope sprawl, creating long-lived API security risks. Kristopher Sandoval explains the problem and how teams can respond.
What Is Scope Sprawl? | Nordic APIs |
Define scope sprawl and learn how over-permissioned tokens, OAuth scopes, and long-lived credentials create API security risks.
nordicapis.com
Our last year's API security unconference was a huge success: no agenda, no slides, just post-it notes and plenty of ideas. We're bringing it back for Day 0 of Nordic APIs Summit. Get a standalone ticket or grab the bundle: nordicapis.com/events/platform-summit-2026
Introducing a Nordic APIs Summit 2026 keynote speaker: Kin Lane! Ahead of the event, Art Anthony interviews Kin on the state of AI, APIs, and the growing risk of data becoming trapped in walled gardens.
Kin Lane on AI and the Future of APIs | Nordic APIs |
Kin Lane discusses AI, APIs, data lock-in, and why API strategy still matters as agentic consumption grows.
nordicapis.com