Slides and Recording From My APISEC|Con 2024 Talk on API Sprawl

Bill Doerrfeld | May 22, 2024

What Is API Sprawl, And What Can You Do About It?


You may think your API portfolio looks well-maintained, like a pristine city. Well, think again — welcome to the desert of the real... a land full of zombie APIs and shadow endpoints...


Today, I presented at APIsec University's online conference, API|SEC CON 2024, which had over 1,700 people join to talk all things API security. In my session, What Is API Sprawl, And What Can You Do About It?, I went through some statistics about the state of API adoption and spotlighted some indications that API sprawl conditions are emerging. I ended with some ideas on how to avoid API sprawl. All with references to The Matrix, of course.


Thank you for inviting me to speak, it was a pleasure to be a part of the event!


Here are some of the resources I mentioned in my talk:


- APIFutures: API Sprawl to Be a Pressing Concern in 2024

- API Futures project

- Continuous API Sprawl: Challenges and Opportunities in an API-Driven Economy, F5 report, 2021.

- Why CIOs back API governance to avoid tech sprawl

- The 2022 API Security Trends Report, S&P Global Market Intelligence, 2022.

- The Nordic APIs blog and digest

- OWASP API Security Top 10 2023


Follow me on LinkedIn or X for updates about my articles and upcoming research into API governance!


Download the slides here:




Download Slides
Large action models LAMs story Bill Doerrfeld The New Stack
By Bill Doerrfeld June 10, 2025
AI researchers are calling the next class of models large action models (LAMs). For The New Stack, I explored what LAMs are, what examples are emerging in the market, and what experts think.
7 proven AI prompting strategies for coding to try today
By Bill Doerrfeld June 9, 2025
My article for LeadDev explores specific prompting techniques proven to sharpen your AI-assisted software development.
Nordic APIs ranked #1 API blog on the web
By Bill Doerrfeld June 7, 2025
Nordic APIs, the API-specific blog I edit, was recently ranked the top API blog online by FeedSpot. After ten years managing this presence, I reflect a bit on the journey thus far.
Tips to improve your AI vibe coding
By Bill Doerrfeld June 3, 2025
Developers are realizing that being productive with AI coding assistants takes a lot more than just asking nicely. There's real craft to it.
AI coding is the easy part. Now it's time to focus on production.
By Bill Doerrfeld May 30, 2025
AI coding is the easy part. Now it's time to focus on DevOps to get it into production. In a recent interview for LeadDev's DirectorPlus, Honeycomb's CTO, Charity Majors, shares expert tips on how to accomplish this.
New tools help LLM devs improve training data decisions
By Bill Doerrfeld May 29, 2025
My latest for The New Stack explores new research from Ai2, DataDecide, which helps LLM developers make better decisions around training data.
MCP security vulnerabilities
By Bill Doerrfeld May 21, 2025
My APISEC|CON talk covers the hype around agentic AI and MCP, and delves into inherent flaws in MCP architectures and suggests mitigations.
Knowing when to use AI coding assistants Doerrfeld InfoWorld
By Bill Doerrfeld May 6, 2025
AI coding assistants are a productivity dream in some cases — and a debugging nightmare in others. So, where’s the line?
How semantic caching reduces LLM API calls
By Bill Doerrfeld May 5, 2025
Semantic caching is like typical caching, but for AI. It could eliminate a lot of redundant API calls to LLMs, reducing costs and improving performance.
Using agentic AI for business workflows
By Bill Doerrfeld April 30, 2025
For CIO.com, leading executives shared with me how they're actively utilizing agentic AI to enhance core business workflows.
More Posts