Rosemary Missier
Confessions of a
Product Geek :
My First API
Me, Product & Tech
•Engineering
•Research
•Academia
•Design
•Product
Agenda
Myths and Anti-patterns
•API Product
•API Process
•API Design
Anti-pattern - APIs are an afterthought!
API Product
•Part of the application development process
•Internal, Partner, and External APIs
•Data Driven
•APIs are first class citizens!
New York
JULY
Australia
SEPTEMBER
Singapore
APRIL
Helsinki & North
MARCH
Paris
DECEMBER
London
OCTOBER
Jakarta
FEBRUARY
Hong Kong
AUGUST
JUNE
India
MAY
Check out our API Conferences here
50+ events since 2012, 14 countries, 2,000+ speakers, 50,000+ attendees,
300k+ online community
Want to talk at one of our conferences?
Apply to speak here
Myth - APIs are technical solutions and NOT products
API Product
•API solutions
•Coupled to an initiative
•Rarely used
•API products - strategic partnerships
•Opens up new business channels
•Developer-driven business needs
Myth - API Development cannot be Agile!
API Process
•Waterfall vs Collective Ownership
•API-First Approach
•Collaborative design with all stakeholders
•Design a contract and Sandbox to
experiment
Anti-pattern - AI and APIs are not complementary
API Process
• API Usage Monitoring

Intelligent traffic monitoring
Unsupervised learning - clustering
• API security testing

Deception for detection and defence
Block access - bypass login, stolen tokens, etc
Usage pattern per api basis
I can make
your API security
smarter
Anti-pattern - APIs are not user-centric (DX)
API Process
•Low-cost investment in Design
•POC
•BYO client
•Usability Testing - Don’t document!
•Got the $$$ and time to invest?
•Collaborative design with all stakeholders
•Prototype, Test, and Validate
•Repeat!!!
•Document - API portal, API explorer, web content, channels, etc
Myth - APIs are CRUDdy!
API Design
•CRUD - Set of primitive operations
•Expose functionality beyond CRUD
•REST is bad - gRPC, GraphQL, Async
•Event Subscriptions, HATEOAS, Device APIs
Anti-pattern - APIs are black boxes!
API Design
•Error and Event Logging
Log data - request, response for investigation and
auditing needs
HTTP response code for retries
Reduce network congestion - exponential backoff
algorithm for retries
•Monitoring
•Security breaches, data leaks, etc
•Docs are the UI!
Myth - API’s cannot be hacked
API Design
•OAuth 2.0 and TLS are secure enough!
•Multi-layered
•Choose your app partners
•Security check-in every now and then
•Trust no one
THANK YOU !!!
www.linkedin.com/in/missier
Get in touch
New York
JULY
Australia
SEPTEMBER
Singapore
APRIL
Helsinki & North
MARCH
Paris
DECEMBER
London
OCTOBER
Jakarta
FEBRUARY
Hong Kong
AUGUST
JUNE
India
MAY
Check out our API Conferences here
50+ events since 2012, 14 countries, 2,000+ speakers, 50,000+ attendees,
300k+ online community
Want to talk at one of our conferences?
Apply to speak here

More Related Content

PPTX
INTERFACE, by apidays - The 8 Key Components of a Modern API Stack by Iddo G...
PDF
INTERFACE, by apidays - Low code APIs that don't break by Zdenek Nemec, Supe...
PDF
apidays LIVE Paris 2021 - Building an analytics API by David Wobrock, Botify
PDF
INTERFACE, by apidays - API Design is where culture and tech meet each other...
PDF
apidays LIVE Paris 2021 - Spatially enabling Web APIs through OGC Standards ...
PPTX
Api-First service design
PDF
apidays LIVE Paris 2021 - Automating API Documentation by Ajinkya Marudwar, G...
PDF
API Design Collaboration
INTERFACE, by apidays - The 8 Key Components of a Modern API Stack by Iddo G...
INTERFACE, by apidays - Low code APIs that don't break by Zdenek Nemec, Supe...
apidays LIVE Paris 2021 - Building an analytics API by David Wobrock, Botify
INTERFACE, by apidays - API Design is where culture and tech meet each other...
apidays LIVE Paris 2021 - Spatially enabling Web APIs through OGC Standards ...
Api-First service design
apidays LIVE Paris 2021 - Automating API Documentation by Ajinkya Marudwar, G...
API Design Collaboration

What's hot (20)

PDF
Essential Ingredients for a Successful API Program
PDF
apidays LIVE Paris 2021 - What Developers Want by Paul Ardeleanu, Vonage
PDF
apidays LIVE Paris 2021 - Test developer experience, not code by Kathrine Osa...
PDF
apidays LIVE London 2021 - API design is where culture and tech meet each oth...
PPTX
Open Event API
PDF
apidays LIVE Australia 2021 - From apps to APIs: how no-code is transforming ...
PDF
Evolution of API Management in the BBC
PDF
apidays LIVE Jakarta - What will the next generation of API Portals look like...
PDF
APIDays - API Design Workshop
PDF
APIdays Zurich 2019 - API management for event driven microservices, Fran Men...
PPTX
Your API Strategy: Why Boring is Best
PDF
A Snapshot of API Design Trends In 2019
PDF
INTERFACE, by apidays - Aligning teams and strategies behind API investment ...
PDF
apidays LIVE London 2021 - Confessions of a Product Geek by Rosemary Missier,...
PDF
Introduction to the Art of API Practice
PPTX
Blood, sweat, and creating an API handbook
PDF
apidays LIVE London 2021 - Moving from a Product as API to API as a Product b...
PDF
apidays LIVE Paris 2021 - API design is where culture and tech meet each othe...
PDF
apidays LIVE Australia 2021 - Designing APIs: Just Enough is Perfect! by Dami...
PDF
apidays LIVE Paris 2021 - 20 Minutes to Build a Serverless COVID-19 GraphQL A...
Essential Ingredients for a Successful API Program
apidays LIVE Paris 2021 - What Developers Want by Paul Ardeleanu, Vonage
apidays LIVE Paris 2021 - Test developer experience, not code by Kathrine Osa...
apidays LIVE London 2021 - API design is where culture and tech meet each oth...
Open Event API
apidays LIVE Australia 2021 - From apps to APIs: how no-code is transforming ...
Evolution of API Management in the BBC
apidays LIVE Jakarta - What will the next generation of API Portals look like...
APIDays - API Design Workshop
APIdays Zurich 2019 - API management for event driven microservices, Fran Men...
Your API Strategy: Why Boring is Best
A Snapshot of API Design Trends In 2019
INTERFACE, by apidays - Aligning teams and strategies behind API investment ...
apidays LIVE London 2021 - Confessions of a Product Geek by Rosemary Missier,...
Introduction to the Art of API Practice
Blood, sweat, and creating an API handbook
apidays LIVE London 2021 - Moving from a Product as API to API as a Product b...
apidays LIVE Paris 2021 - API design is where culture and tech meet each othe...
apidays LIVE Australia 2021 - Designing APIs: Just Enough is Perfect! by Dami...
apidays LIVE Paris 2021 - 20 Minutes to Build a Serverless COVID-19 GraphQL A...
Ad

Similar to apidays LIVE Australia 2021 - Confessions of a Product Geek : My First API BY Rosemary Missier, Xero (20)

PDF
Introduction to The 6 Insights of API Practice (Bill Doerrfeld)
PPTX
API Conference 2021
PPTX
Do's and Don'ts of APIs
PDF
Apidays Helsinki & North 2024 - Security Vulnerabilities in your APIs by Luká...
PDF
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
PPTX
Building a REST API for Longevity
PPTX
Make Your Contribution Count. Adding Value to the API as a Technical Communic...
PPTX
Lessons learned on the Azure API Stewardship Journey.pptx
PDF
APIdays Paris 2019 - Lessons Learned from Revamping our Doc Site by Ilona Ko...
PDF
Lessons Learned from Revamping Our Doc Site
PPTX
Swagger APIs for Humans and Robots (Gluecon)
PDF
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
PDF
Reduce API Security Risk by Leveraging Graph Analytics Webinar Slides
PPTX
APIs with Bounded Contexts: Modelling Apis with Domain-Driven Design
PDF
Inside Story: Scratching the Black Box - API
PDF
apidays LIVE Paris 2021 - Lessons from the API Stewardship Journey in Azure b...
PDF
Documentation, APIs & AI
PPTX
Practical Application of API-First in microservices development
PPTX
How Capital One Scaled API Design to Deliver New Products Faster
PPTX
STC Summit 2015: API Documentation, an Example-Based Approach
Introduction to The 6 Insights of API Practice (Bill Doerrfeld)
API Conference 2021
Do's and Don'ts of APIs
Apidays Helsinki & North 2024 - Security Vulnerabilities in your APIs by Luká...
apidays LIVE Paris - Succeeding with API Programs by Kiran Nadgir
Building a REST API for Longevity
Make Your Contribution Count. Adding Value to the API as a Technical Communic...
Lessons learned on the Azure API Stewardship Journey.pptx
APIdays Paris 2019 - Lessons Learned from Revamping our Doc Site by Ilona Ko...
Lessons Learned from Revamping Our Doc Site
Swagger APIs for Humans and Robots (Gluecon)
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
Reduce API Security Risk by Leveraging Graph Analytics Webinar Slides
APIs with Bounded Contexts: Modelling Apis with Domain-Driven Design
Inside Story: Scratching the Black Box - API
apidays LIVE Paris 2021 - Lessons from the API Stewardship Journey in Azure b...
Documentation, APIs & AI
Practical Application of API-First in microservices development
How Capital One Scaled API Design to Deliver New Products Faster
STC Summit 2015: API Documentation, an Example-Based Approach
Ad

More from apidays (20)

PDF
apidays Munich 2025 - The Physics of Requirement Sciences Through Application...
PDF
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
PDF
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
PDF
apidays Munich 2025 - Integrate Your APIs into the New AI Marketplace, Senthi...
PDF
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
PDF
apidays Munich 2025 - Let’s build, debug and test a magic MCP server in Postm...
PDF
apidays Munich 2025 - The life-changing magic of great API docs, Jens Fischer...
PDF
apidays Munich 2025 - Automating Operations Without Reinventing the Wheel, Ma...
PDF
apidays Munich 2025 - Geospatial Artificial Intelligence (GeoAI) with OGC API...
PPTX
apidays Munich 2025 - GraphQL 101: I won't REST, until you GraphQL, Surbhi Si...
PPTX
apidays Munich 2025 - Effectively incorporating API Security into the overall...
PPTX
apidays Munich 2025 - Federated API Management and Governance, Vince Baker (D...
PPTX
apidays Munich 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (Aavista Oy)
PPTX
apidays Munich 2025 - Streamline & Secure LLM Traffic with APISIX AI Gateway ...
PPTX
apidays Munich 2025 - Building Telco-Aware Apps with Open Gateway APIs, Subhr...
PPTX
apidays Munich 2025 - Building an AWS Serverless Application with Terraform, ...
PDF
apidays Helsinki & North 2025 - REST in Peace? Hunting the Dominant Design fo...
PDF
apidays Helsinki & North 2025 - Monetizing AI APIs: The New API Economy, Alla...
PDF
apidays Helsinki & North 2025 - How (not) to run a Graphql Stewardship Group,...
PDF
apidays Helsinki & North 2025 - APIs in the healthcare sector: hospitals inte...
apidays Munich 2025 - The Physics of Requirement Sciences Through Application...
apidays Munich 2025 - Developer Portals, API Catalogs, and Marketplaces, Miri...
apidays Munich 2025 - Making Sense of AI-Ready APIs in a Buzzword World, Andr...
apidays Munich 2025 - Integrate Your APIs into the New AI Marketplace, Senthi...
apidays Munich 2025 - The Double Life of the API Product Manager, Emmanuel Pa...
apidays Munich 2025 - Let’s build, debug and test a magic MCP server in Postm...
apidays Munich 2025 - The life-changing magic of great API docs, Jens Fischer...
apidays Munich 2025 - Automating Operations Without Reinventing the Wheel, Ma...
apidays Munich 2025 - Geospatial Artificial Intelligence (GeoAI) with OGC API...
apidays Munich 2025 - GraphQL 101: I won't REST, until you GraphQL, Surbhi Si...
apidays Munich 2025 - Effectively incorporating API Security into the overall...
apidays Munich 2025 - Federated API Management and Governance, Vince Baker (D...
apidays Munich 2025 - Agentic AI: A Friend or Foe?, Merja Kajava (Aavista Oy)
apidays Munich 2025 - Streamline & Secure LLM Traffic with APISIX AI Gateway ...
apidays Munich 2025 - Building Telco-Aware Apps with Open Gateway APIs, Subhr...
apidays Munich 2025 - Building an AWS Serverless Application with Terraform, ...
apidays Helsinki & North 2025 - REST in Peace? Hunting the Dominant Design fo...
apidays Helsinki & North 2025 - Monetizing AI APIs: The New API Economy, Alla...
apidays Helsinki & North 2025 - How (not) to run a Graphql Stewardship Group,...
apidays Helsinki & North 2025 - APIs in the healthcare sector: hospitals inte...

Recently uploaded (20)

PPTX
Module 1 Introduction to Web Programming .pptx
PPTX
Internet of Everything -Basic concepts details
PDF
Ensemble model-based arrhythmia classification with local interpretable model...
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PDF
Electrocardiogram sequences data analytics and classification using unsupervi...
PDF
EIS-Webinar-Regulated-Industries-2025-08.pdf
PDF
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
PDF
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
PDF
Co-training pseudo-labeling for text classification with support vector machi...
PDF
Human Computer Interaction Miterm Lesson
PPTX
Build automations faster and more reliably with UiPath ScreenPlay
PDF
Introduction to MCP and A2A Protocols: Enabling Agent Communication
PDF
SaaS reusability assessment using machine learning techniques
PDF
ment.tech-Siri Delay Opens AI Startup Opportunity in 2025.pdf
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PDF
Advancing precision in air quality forecasting through machine learning integ...
PDF
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
PDF
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
PDF
Data Virtualization in Action: Scaling APIs and Apps with FME
PDF
LMS bot: enhanced learning management systems for improved student learning e...
Module 1 Introduction to Web Programming .pptx
Internet of Everything -Basic concepts details
Ensemble model-based arrhythmia classification with local interpretable model...
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
Electrocardiogram sequences data analytics and classification using unsupervi...
EIS-Webinar-Regulated-Industries-2025-08.pdf
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
Co-training pseudo-labeling for text classification with support vector machi...
Human Computer Interaction Miterm Lesson
Build automations faster and more reliably with UiPath ScreenPlay
Introduction to MCP and A2A Protocols: Enabling Agent Communication
SaaS reusability assessment using machine learning techniques
ment.tech-Siri Delay Opens AI Startup Opportunity in 2025.pdf
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
Advancing precision in air quality forecasting through machine learning integ...
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
Data Virtualization in Action: Scaling APIs and Apps with FME
LMS bot: enhanced learning management systems for improved student learning e...

apidays LIVE Australia 2021 - Confessions of a Product Geek : My First API BY Rosemary Missier, Xero

  • 1. Rosemary Missier Confessions of a Product Geek : My First API
  • 2. Me, Product & Tech •Engineering •Research •Academia •Design •Product
  • 3. Agenda Myths and Anti-patterns •API Product •API Process •API Design
  • 4. Anti-pattern - APIs are an afterthought! API Product •Part of the application development process •Internal, Partner, and External APIs •Data Driven •APIs are first class citizens!
  • 5. New York JULY Australia SEPTEMBER Singapore APRIL Helsinki & North MARCH Paris DECEMBER London OCTOBER Jakarta FEBRUARY Hong Kong AUGUST JUNE India MAY Check out our API Conferences here 50+ events since 2012, 14 countries, 2,000+ speakers, 50,000+ attendees, 300k+ online community Want to talk at one of our conferences? Apply to speak here
  • 6. Myth - APIs are technical solutions and NOT products API Product •API solutions •Coupled to an initiative •Rarely used •API products - strategic partnerships •Opens up new business channels •Developer-driven business needs
  • 7. Myth - API Development cannot be Agile! API Process •Waterfall vs Collective Ownership •API-First Approach •Collaborative design with all stakeholders •Design a contract and Sandbox to experiment
  • 8. Anti-pattern - AI and APIs are not complementary API Process • API Usage Monitoring Intelligent traffic monitoring Unsupervised learning - clustering • API security testing Deception for detection and defence Block access - bypass login, stolen tokens, etc Usage pattern per api basis I can make your API security smarter
  • 9. Anti-pattern - APIs are not user-centric (DX) API Process •Low-cost investment in Design •POC •BYO client •Usability Testing - Don’t document! •Got the $$$ and time to invest? •Collaborative design with all stakeholders •Prototype, Test, and Validate •Repeat!!! •Document - API portal, API explorer, web content, channels, etc
  • 10. Myth - APIs are CRUDdy! API Design •CRUD - Set of primitive operations •Expose functionality beyond CRUD •REST is bad - gRPC, GraphQL, Async •Event Subscriptions, HATEOAS, Device APIs
  • 11. Anti-pattern - APIs are black boxes! API Design •Error and Event Logging Log data - request, response for investigation and auditing needs HTTP response code for retries Reduce network congestion - exponential backoff algorithm for retries •Monitoring •Security breaches, data leaks, etc •Docs are the UI!
  • 12. Myth - API’s cannot be hacked API Design •OAuth 2.0 and TLS are secure enough! •Multi-layered •Choose your app partners •Security check-in every now and then •Trust no one
  • 15. New York JULY Australia SEPTEMBER Singapore APRIL Helsinki & North MARCH Paris DECEMBER London OCTOBER Jakarta FEBRUARY Hong Kong AUGUST JUNE India MAY Check out our API Conferences here 50+ events since 2012, 14 countries, 2,000+ speakers, 50,000+ attendees, 300k+ online community Want to talk at one of our conferences? Apply to speak here