As AI agents begin using MCP servers to access enterprise tools, applications, and APIs, organizations face a new governance problem: They often do not know which MCP servers exist, what capabilities they expose, what data they can reach, or which agents are allowed to use them. This talk presents a practical framework for discovering MCP servers, mapping them to underlying APIs, scoring their risk, and enforcing governance controls before agentic workflows reach production.
Drawing on my work in API discovery, security, governance, and API risk management at TeejLab, Synopsys, and Black Duck, the session will show how teams can treat MCP servers as first-class enterprise assets rather than experimental connectors. It will cover key risks such as tool poisoning, prompt injection, overpermissioned agents, insecure authentication, shadow APIs, sensitive data exposure, and missing audit trails. Attendees will leave with a practical checklist for building secure agent-to-API access across cloud, SaaS, and internal API ecosystems.
High impact blog posts and eBooks on API business models, and tech advice
Connect with market leading platform creators at our events
Join a helpful community of API practitioners
Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.
By clicking below, you agree that we process your information per the terms in our Privacy Policy.
Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.