- Ikenna Consulting Newsletter
- Posts
- Issue #45
Issue #45
IGT-API: Governance for RESTful Platform APIs.

Contents
Introduction
Interesting Content for the week
FeedBack & Share
Upcoming Conferences
Introduction
In this issue, I discuss how my IGT-API framework provides an governance framework for a platforms REST APIs. And I present the usual interesting links. Enjoy!
IGT-API: Governance for RESTful Platform APIs.
The IGT-API is a framework for governing and managing software platform interfaces that expose business capabilities via RESTful APIs. These business capability interfaces expose operations from the business domain and facilitate the building of an ecosystem of complementary applications and services [GregorHohpe1, AmritTiwana1].
In other words, the IGT-API framework is concerned with governing the APIs of business capability platforms - software platforms that power businesses. These platforms are usually built in-house in an organisation, and may be exposed to customers as part of a product offering (public APIs), exposed to third parties to create a partner ecosystem (private APIs), or consumed by internal services (private APIs). Business capability APIs are different from what I would call base APIs - APIs that provide technical products and services for software teams [GregorHohpe1].
In a future issue, I’ll discuss more on the principles of the IGT-API.
Interesting Content for the Week
AI-API Consumption Governance
Prevent MCP Tool Poisoning With a Registration Workflow: Christian Posta focuses on preventing Model Context Protocol (MCP) tool poisoning through the implementation of a robust registration workflow. It highlights the importance of secure MCP and Agent-to-Agent (A2A) registration workflows for building a trustworthy AI agent ecosystem.
10+ API Gateways That Support MCP: This article presents ten specific API Gateways that offer MCP support. For each gateway, it provides details on their open-source status, the extent of their MCP support, ideal use cases, and their primary strengths.
Platform API Production Governance
Can TypeSpec Be an Alternative to OpenAPI?: This article discusses how TypeSpec offers a more developer-friendly, code-centric approach to API design, aiming to reduce the verbosity and complexity often associated with OpenAPI specifications. The author shares personal experiences and insights into how TypeSpec improves productivity and clarity in API development.
Ask Your Docs: Building a Chatbot for Documentation: Ganesh Patil walks through how to build a smart chatbot that can answer questions directly from your documentation using a technique called Retrieval-Augmented Generation (RAG).
OpenAPI 🤝 OpenMCP: Alexander Karan highlights OpenMCP as a tool for converting OpenAPI documents into MCP servers and emphasises best practices for these servers, including scaling and authorisation.
API Gateway vs Service Mesh - Which One Do You Need: This article discusses two architectural patterns commonly used in modern software systems to address the complexity due to the shift from monolithic architectures to service-based architectures.
7 Signs Your Kafka Environment Needs an API Platform: Umair Waheed explores the difficulties in managing Kafka environments and how an API platform can provide solutions. It outlines seven indicators that suggest a Kafka environment would significantly benefit from the structured approach of API management.
Breaking Down Silos: Aligning QA, Dev, and DevOps to Build Better APIs: Steven Pepa addresses the challenges organisations face in maintaining high API quality due to teams (QA, Development, and DevOps) operating in silos. It proposes strategies to foster a culture of shared quality to overcome these issues.
Building a Secure Foundation: Compliance-Driven API Posture Governance: Eric Schwake analyses the critical role of compliance in driving robust API security and data protection within organisations. Eric argues that adhering to industry and governmental regulations is a fundamental element in establishing a strong API security posture.
Automating API Discovery with RFC 9727: Bruno Pedro articles highlights three major ideas: the challenge of API discovery for machines, an introduction of RFC 9727 as a Solution, and the mechanism and functionality of RFC 9727.
What Is API Gateway Federation? A Guide to Centralised API Management: Dakshitha Ratnayake discusses API Gateway Federation, benefits of Federated API Gateways highlighting several advantages of adopting federated API gateways.
Open Policy Agent: Unified Control for API Security: In this article the authors explore how the Open Policy Agent (OPA) enables centralised, automated, and consistent policy enforcement across APIs, cloud infrastructure, and Kubernetes environments. By adopting the Policy as Code (PaC) approach, OPA allows organisations to define, test, and deploy security and governance rules just like software—improving reliability, traceability, and scalability in complex systems.
What do you think of this newsletter issue? |
I appreciate your feedback. If you find my newsletter useful, please forward and share it with a friend.
Upcoming API Conferences
APIdays Germany: Theme: “Accelerate AI Use Cases with APIs” Date: July 2nd & 3rd, 2025. Location: Smartvillage Bogenhausen, München, Germany. Register Here
Platform Summit 2025: Date: October 13-15, Location: Stockholm, Theme: Engineer Next-Gen API Architectures Register to get your tickets.
Kong API Summit Live 2025, Join developers, leaders, and visionaries from around the world as we explore the latest innovations around APIs, microservices, and AI. Date: Oct 14 - 15, 2025, Location: New York City
APIdays London: Theme: “No AI Without APIs” Conference Date: September 22nd - 24th, Location: Convene 155 Bishopsgate, London EC2M 3YD
API Conference Berlin: Theme: The Conference for Web APIs, API Design & Management, Date: October 20 - 22, 2025. Register to get your tickets.
API Governance Consulting
Is poor API governance slowing down your delivery? Do you experience API sprawl, API drift and poor API developer satisfaction? I'll provide expert guidance and a tailored roadmap to transform your API practices. |
Ikenna® Delivery Assessment → Identify your biggest API delivery pain points. Ikenna® Delivery Canvas (IDC) & API Transformation Plan → Get a unified, data-driven view of your API delivery and governance process. Ikenna® Improvement Cycles → Instil a culture of scientific, measurable progress towards API governance. Ikenna® Governance Team Model → Set up and improve your governance team to sustain progress. Ikenna® Delivery Automation Guidance → Reduce lead time and improve API quality through automation |
Schedule your consultation here. |
Reply