Slides and Recording From My APISEC|Con 2024 Talk on API Sprawl

Bill Doerrfeld | May 22, 2024

What Is API Sprawl, And What Can You Do About It?


You may think your API portfolio looks well-maintained, like a pristine city. Well, think again — welcome to the desert of the real... a land full of zombie APIs and shadow endpoints...


Today, I presented at APIsec University's online conference, API|SEC CON 2024, which had over 1,700 people join to talk all things API security. In my session, What Is API Sprawl, And What Can You Do About It?, I went through some statistics about the state of API adoption and spotlighted some indications that API sprawl conditions are emerging. I ended with some ideas on how to avoid API sprawl. All with references to The Matrix, of course.


Thank you for inviting me to speak, it was a pleasure to be a part of the event!


Here are some of the resources I mentioned in my talk:


- APIFutures: API Sprawl to Be a Pressing Concern in 2024

- API Futures project

- Continuous API Sprawl: Challenges and Opportunities in an API-Driven Economy, F5 report, 2021.

- Why CIOs back API governance to avoid tech sprawl

- The 2022 API Security Trends Report, S&P Global Market Intelligence, 2022.

- The Nordic APIs blog and digest

- OWASP API Security Top 10 2023


Follow me on LinkedIn or X for updates about my articles and upcoming research into API governance!


Download the slides here:




Download Slides

Other Blog Posts

By Bill Doerrfeld June 10, 2026
I'm working with Zuplo on some new content around their MCP Gateway release. First up: a deep comparison of MCP gateways on the market!
By Bill Doerrfeld June 10, 2026
The constant barrage of AI layoffs is overshadowing the economic reasons behind these cuts, as well as the net-positive talent redistribution happening at large.
By Bill Doerrfeld June 8, 2026
My latest for InfoWorld reviews MCP servers and agent-ready tools for connecting AI agents with popular database styles.
By Bill Doerrfeld May 29, 2026
For my latest DirectorPlus edition, Joel Carusone from NinjaOne shares how engineering leaders can build the muscle for making tough calls.
Close-up of a glowing laptop keyboard in blue light, viewed at an angle with the screen above
By Bill Doerrfeld May 25, 2026
My latest InfoWorld feature explores how Model Context Protocol (MCP) supports context engineering for AI-assisted coding.
A set of metal keys on a keyring resting on a wooden surface.
By Bill Doerrfeld May 22, 2026
My latest for Nordic APIs explores 10 API key security risks and what to use alongside keys for stronger API security.
By Bill Doerrfeld May 18, 2026
The yearly API conference, apidays New York, is a hotbed for solid discussion on what's top of mind in the API space, and as MC I had a front row seat.
By Bill Doerrfeld May 13, 2026
My latest for CIO Online features real results form CIOs actively deploying AI agents to empower sales and revenue teams.
By Bill Doerrfeld May 12, 2026
Reports say consumers are souring on AI everywhere, all the time. So, at the risk of losing trust, or even potential business, is adding AI to an existing product really worth it?
By Bill Doerrfeld May 1, 2026
Cloudflare rebuilt Next.js over a weekend using agentic coding.