Slides and Recording From My APISEC|Con 2024 Talk on API Sprawl

Bill Doerrfeld | May 22, 2024

What Is API Sprawl, And What Can You Do About It?


You may think your API portfolio looks well-maintained, like a pristine city. Well, think again — welcome to the desert of the real... a land full of zombie APIs and shadow endpoints...


Today, I presented at APIsec University's online conference, API|SEC CON 2024, which had over 1,700 people join to talk all things API security. In my session, What Is API Sprawl, And What Can You Do About It?, I went through some statistics about the state of API adoption and spotlighted some indications that API sprawl conditions are emerging. I ended with some ideas on how to avoid API sprawl. All with references to The Matrix, of course.


Thank you for inviting me to speak, it was a pleasure to be a part of the event!


Here are some of the resources I mentioned in my talk:


- APIFutures: API Sprawl to Be a Pressing Concern in 2024

- API Futures project

- Continuous API Sprawl: Challenges and Opportunities in an API-Driven Economy, F5 report, 2021.

- Why CIOs back API governance to avoid tech sprawl

- The 2022 API Security Trends Report, S&P Global Market Intelligence, 2022.

- The Nordic APIs blog and digest

- OWASP API Security Top 10 2023


Follow me on LinkedIn or X for updates about my articles and upcoming research into API governance!


Download the slides here:




Download Slides
Brain in a gravitational well, surrounded by concentric circles, with blue lines extending from the brain.
By Bill Doerrfeld December 8, 2025
My latest for InfoWorld breaks down 10 MCP servers powering next-gen devops workflows, from GitHub and Atlassian to AWS and Pulumi.
Man speaking at
By Bill Doerrfeld December 2, 2025
Excited to share my talk from Nordic APIs' Platform Summit 2025. As the opening talk of the event, I wanted to address the elephant in the room head-on: MCP.
Panel discussion on stage with five speakers and audience in front of a blue screen with speaker names.
By Bill Doerrfeld December 1, 2025
Watch all the great API talks, keynotes, and panel discussions from this year's Nordic APIs Platform Summit, now available on YouTube.
Open source flag leaddev directorplus doerrfeld Block
By Bill Doerrfeld November 28, 2025
Block's open source initiative is helping to build brand reputation, attract talent, boost partnerships, guide internal open source best practices, and aid long-term system reliability.
How CIOs are getting a return from AI
By Bill Doerrfeld November 26, 2025
Achieving ROI with AI requires a mix of strong leadership stewardship upfront, shifting the talent framework, and embedding proper monitoring and governance throughout the lifecycle.
Knowledge base for AI agents
By Bill Doerrfeld November 24, 2025
I recently explored what goes into creating a solid AI agent knowledge base — from the types of data it should contain to the retrieval mechanisms and architecture patterns that support reliable agentic behavior.
linkedin ai assistant hiring agent
By Bill Doerrfeld October 31, 2025
I recently spoke with LinkedIn VP of Engineering Prashanthi Padmanabhan about the making of their Hiring Assistant, an agent recruiters are using to optimize the applicant selection process.
How to fail at platfom engineering
By Bill Doerrfeld October 22, 2025
How do you fail at platform engineering? Make it 100% UI-first. Don't market it. Survey no one. Measure success by who's onboarded. And just copy what others are doing.
Platform summit conference nordic apis stockholm bill doerrfeld
By Bill Doerrfeld October 21, 2025
This year's Platform Summit felt reinvigorated, with many new motivations and areas to discuss. Of course, AI agents and MCP stole the show.
Colorful hot air balloons against a bright blue sky.
By Bill Doerrfeld September 26, 2025
For my latest DirectorPlus edition, I interviewed Thomas Johnson, co-founder and CTO of Multiplayer, about lessons learned releasing their MCP server.