A study on the state of the API industry found that more than half of all APIs are not what Treblle calls “AI-ready” — they are not designed with LLM consumption in mind.
AI is also increasing API complexity. , while in 2024 it was 42. And just like abandoned containers and microservices that no one knows what to do with, 35% of them are zombie endpoints.
Of course, all this is not to mention that, according to Gartner, 71% of enterprises use APIs through third parties. And the growth of AI-related integrations only increases security risks and complexity. But on the other hand, AI will be invaluable in helping with API discovery.
While there are benefits to using AI for your APIs, we know that most organizations are focusing on the use case around AI-powered code generation. Since more AI means more code and more problems, it’s no surprise that decreased security and increased API sprawl go hand in hand. Most AI-enabled APIs are built using JavaScript-based languages — in most cases, proxy APIs. The report also found that JavaScript-based APIs have the lowest quality and security scores of any language. The average API language scored 57 out of 100, while Javascript scored 42.
The bar for API security is generally very low, the australia mobile database found, with 52% of the requests examined not having any form of authentication. Add to that the fact that 85% of all APIs examined do not use any form of rate limiting, leaving them wide open to attack. This further highlights just how public so-called “private” APIs really are.
In addition to the grim statistics above, 55% of requests do not use SSL or TSL encryption.
The report gave enterprise API management programs an average API security score of 40 out of 100.
We also need to keep in mind the need to prepare APIs for agent-based AI, where integrators are no longer static, immutable, or human-driven, but rather react to bots based on tasks launched to achieve specific goals. At a time when short-term integrations are becoming the norm, organizations cannot afford to leave endpoints open or to let them become a dead end.
Whether you're planning to invest in AI this year or not, it's clear that your organization needs to invest in a better API strategy.
The average API in 2023 had 22 endpoints
-
- Posts: 398
- Joined: Tue Dec 03, 2024 10:15 am