Slides and Recording From My APISEC|Con 2024 Talk on API Sprawl

Bill Doerrfeld | May 22, 2024

What Is API Sprawl, And What Can You Do About It?


You may think your API portfolio looks well-maintained, like a pristine city. Well, think again — welcome to the desert of the real... a land full of zombie APIs and shadow endpoints...


Today, I presented at APIsec University's online conference, API|SEC CON 2024, which had over 1,700 people join to talk all things API security. In my session, What Is API Sprawl, And What Can You Do About It?, I went through some statistics about the state of API adoption and spotlighted some indications that API sprawl conditions are emerging. I ended with some ideas on how to avoid API sprawl. All with references to The Matrix, of course.


Thank you for inviting me to speak, it was a pleasure to be a part of the event!


Here are some of the resources I mentioned in my talk:


- APIFutures: API Sprawl to Be a Pressing Concern in 2024

- API Futures project

- Continuous API Sprawl: Challenges and Opportunities in an API-Driven Economy, F5 report, 2021.

- Why CIOs back API governance to avoid tech sprawl

- The 2022 API Security Trends Report, S&P Global Market Intelligence, 2022.

- The Nordic APIs blog and digest

- OWASP API Security Top 10 2023


Follow me on LinkedIn or X for updates about my articles and upcoming research into API governance!


Download the slides here:




Download Slides
By Bill Doerrfeld February 28, 2026
While hardware usually gets the spotlight in physical AI, the real differentiator won't be hardware. It'll be the models.
By Bill Doerrfeld February 27, 2026
In the latest DirectorPlus, Workato's CTO explains how MCP-enabled integration catalyzed internal AI usage and ROI.
By Bill Doerrfeld February 18, 2026
My latest on InfoWorld reviews MCP servers from 5 major cloud providers
By Bill Doerrfeld February 18, 2026
How are organizations actually using agentic knowledge bases in practice? My article for The New Stack looks at six emerging patterns.
eBPF in Production Report
By Bill Doerrfeld February 12, 2026
My report for the eBPF Foundation explores enterprise eBPF case studies, production deployments, and real business outcomes across cloud-native environments.
Close-up of whole bean coffee Bottomless
By Bill Doerrfeld February 10, 2026
Longtime Bottomless user sharing why I love automated coffee delivery triggered by a smart scale, plus a referral link for a free first bag.
By Bill Doerrfeld February 5, 2026
MCP servers can quickly drain context windows without guardrails. Thankfully, there are ways around this, say the experts.
By Bill Doerrfeld February 4, 2026
It may seem like AI agents are suddenly doing everything across industries. But in reality, the pace of agentic AI is moving carefully, and very deliberately, in highly regulated environments like finance and banking.
By Bill Doerrfeld February 3, 2026
My latest feature for InfoWorld explores when it makes sense to scrape public web sources, and when official API integrations are the better choice for external data.
By Bill Doerrfeld January 30, 2026
What does it mean to go nano with your software updates — to "carve with a scalpel" instead of swinging a hammer? For my latest DirectorPlus piece, I caught up with Chainguard VP Dustin Kirkland to dig into that idea.