• [Why Kong ](/company/why-kong)Why Kong
  • _API & AI CONNECTIVITY TECHNOLOGIES_
    The Unified API and AI Platform
    []
    API ManagementAI ManagementEvent ManagementMonetization
    Migration Services
    API Advisory Services + Forward Deployed EngineersNEW
    • RUNTIMES
    • [API Gateway ](/products/kong-gateway)API Gateway
    • [AI Gateway HOT](/products/kong-ai-gateway)AI Gateway HOT
    • [Event Gateway ](/products/event-gateway)Event Gateway
    • [Service Mesh ](/products/kong-mesh)Service Mesh
    • [Context Mesh ](/products/kong-konnect/features/context-mesh)Context Mesh
    • [Kong Operator ](/products/kong-operator)Kong Operator
    • CORE SERVICES
    • [MCP Registry NEW](/products/mcp-registry)MCP Registry NEW
    • [API Service Catalog ](/products/kong-konnect/features/api-service-catalog)API Service Catalog
    • [APIOps & Automation ](/products/apiops-automation)APIOps & Automation
    • APPS & AI AGENTS
    • [Developer Portal ](/products/kong-konnect/features/developer-portal)Developer Portal
    • [Usage Billing & Metering ](/products/kong-konnect/features/usage-based-metering-and-billing)Usage Billing & Metering
    • [Observability ](/products/kong-konnect/features/api-observability)Observability
    • [KAi Agent ](/products/kong-konnect/features/kai-ai-agent)KAi Agent
    DEVELOPER TOOLS
    [Insomnia ](https://insomnia.rest/)Insomnia [Plugins ](https://developer.konghq.com/plugins/)Plugins [Volcano ](https://volcano.dev/)Volcano [Kong MCP ](https://developer.konghq.com/konnect-platform/konnect-mcp/)Kong MCP [Documentation ](https://docs.konghq.com/)Documentation [Open Source ](/community)Open Source
      • FOR PLATFORM TEAMS
      • [Developer Platform ](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices ](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability ](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming ](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity ](/ai-connectivity)AI Connectivity
      • [Open Banking ](/solutions/open-banking)Open Banking
      • [Legacy Migration ](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction ](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization ](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization ](/solutions/api-monetization)API Monetization
      • [AI Monetization ](/solutions/ai-monetization)AI Monetization
      • [AI FinOps ](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [Agent Gateway ](/agent-gateway)Agent Gateway
      • [AI Governance ](/solutions/ai-governance)AI Governance
      • [AI Security ](/solutions/ai-security)AI Security
      • [Token Cost Management ](/solutions/ai-cost-optimization-management)Token Cost Management
      • [Agentic Infrastructure ](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production ](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway ](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development ](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development ](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio ](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing ](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services ](/solutions/financial-services-industry)Financial Services
      • [Healthcare ](/solutions/healthcare)Healthcare
      • [Higher Education ](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance ](/solutions/insurance)Insurance
      • [Manufacturing ](/solutions/manufacturing)Manufacturing
      • [Retail ](/solutions/retail)Retail
      • [Software & Technology ](/solutions/software-and-technology)Software & Technology
      • [Transportation ](/solutions/transportation-and-logistics)Transportation
    NEW
    Kong for Startups
    Apply for $100k credits & 50% off AI Gateway
  • [Pricing ](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect ](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway ](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh ](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway ](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway ](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia ](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub ](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog ](/blog)Blog
      • [Customer Stories ](/customer-stories)Customer Stories
      • [Learning Center ](/blog/learning-center)Learning Center
      • [eBooks ](/resources/e-book)eBooks
      • [Reports ](/resources/reports)Reports
      • [Demos ](/resources/demos)Demos
      • [Videos ](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit ](/events/conferences/api-ai-summit)API + AI Summit
      • [Webinars ](/events/webinars)Webinars
      • [User Calls ](/events/user-calls)User Calls
      • [Workshops ](/events/workshops)Workshops
      • [Meetups ](/events/meetups)Meetups
      • [See All Events ](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started ](https://developer.konghq.com/)Get Started
      • [Community ](/community)Community
      • [Certification ](/academy/certification)Certification
      • [Training ](https://education.konghq.com)Training
      • COMPANY
      • [About Us ](/company)About Us
      • [We're Hiring! ](/company/careers)We're Hiring!
      • [Press Room ](/company/press-room)Press Room
      • [Contact Us ](/company/contact-us)Contact Us
      • [Kong Partner Program ](/partners)Kong Partner Program
      • [Enterprise Support Portal ](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation ](https://developer.konghq.com)Documentation
    REGISTER NOW
    API + AI Summit 2026
    Sept 30 - Oct 1, 2026 | Los Angeles
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway ](/blog/tag/ai-gateway)AI Gateway
  • [AI Security ](/blog/tag/ai-security)AI Security
  • [AIOps ](/blog/tag/aiops)AIOps
  • [API Security ](/blog/tag/api-security)API Security
  • [API Gateway ](/blog/tag/api-gateway)API Gateway
|
    • [API Management ](/blog/tag/api-management)API Management
    • [API Development ](/blog/tag/api-development)API Development
    • [API Design ](/blog/tag/api-design)API Design
    • [Automation ](/blog/tag/automation)Automation
    • [Service Mesh ](/blog/tag/service-mesh)Service Mesh
    • [Insomnia ](/blog/tag/insomnia)Insomnia
    • [Event Gateway ](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs ](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/kong-konnect/features/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Engineering
  4. Kong and Straiker: Runtime Security and Agent-Level Control for AI Agents
[Agentic AI](/blog/tag/agentic-ai)Agentic AI
September 10, 2026
5 min read

# Kong and Straiker: Runtime Security and Agent-Level Control for AI Agents

Claudio Acquaviva
Principal Architect, Kong
Parth Shah
Head of Product, Straiker

Kong and Straiker are partnering to help enterprises secure AI agents across the traffic, tools, and systems they already manage through [_Kong AI Gateway_](https://konghq.com/products/kong-ai-gateway)_Kong AI Gateway_. The integration brings [_Straiker_](https://www.straiker.ai/?utm_source=kong&utm_medium=partner_blog&utm_campaign=kong_straiker_integration)_Straiker_ into the Kong ecosystem, giving customers a way to add deeper security visibility, testing, LLM runtime protection, and response without changing the gateway architecture they already use.

Kong AI Gateway already gives platform teams a central place to route, observe, and enforce policy across AI traffic. Security teams working alongside those platform teams often need another set of answers: Which agents are connected? Which attack paths actually succeed against them? What happened across the full session or tool chain? And if an agent is compromised, can its next action be stopped before it reaches an enterprise system?

The integration is designed to be complementary. Kong continues to govern and enforce AI traffic, while Straiker adds the security context teams need to understand agent behavior, validate risk, and escalate from a request-level block to broader containment when necessary.

## How does the Straiker integration work in the Kong request path?

Kong AI Gateway handles the traffic patterns production agent systems depend on. The Straiker integration can be applied to configured traffic so the relevant request context is evaluated before the action continues.

For LLM traffic, Straiker evaluates risks such as prompt injection, jailbreak attempts, sensitive-data exfiltration, unsafe output, and policy violations in the context of the broader agent workflow.

At runtime, the flow is intentionally simple: Kong receives the AI traffic, Straiker evaluates the configured context and returns a security verdict, and Kong enforces the resulting action in the request path. That lets customers preserve Kong as the enforcement point while adding security analysis designed specifically for agent behavior.

### Example: What happens when an indirect prompt injection turns into an MCP action?

  1. - An agent retrieves a document or message containing hidden instructions to move sensitive information.
  2. - The agent follows the instruction and attempts to call an MCP tool that can send data to an external destination.
  3. - Kong mediates the MCP request as part of the normal traffic path.
  4. - Straiker evaluates the semantics of the request and tool arguments and returns a block decision when the action violates policy or matches malicious behavior.
  5. - Kong blocks the transaction. If the behavior indicates that the agent itself is compromised or unsafe, the response can escalate beyond that single request.
Architecture diagram showing the integration between Kong AI Gateway and Straiker Cloud for AI agent security, including detection and runtime.

## Why does agent-level containment matter if Kong can already block a request?

Per-request enforcement solves the immediate transaction. It does not necessarily solve the actor generating the transaction. A compromised agent can try a different tool, start another session, or pass malicious context downstream.

Straiker's [_Agentic Kill Switch_](https://www.straiker.ai/blog/agentic-kill-switch-for-coding-agents)_Agentic Kill Switch_ is the escalation path for that case. Security teams can move from blocking an unsafe action to containing the agent itself, including revoking tools, suspending a session, freezing memory, or taking the agent or a fleet of agents offline. Kong continues to enforce traffic policy; Straiker provides the agent-level response when the security problem extends beyond one transaction.

That distinction matters operationally. A security team can stop the malicious action in the traffic path first, then remove the agent's ability to continue acting when the evidence points to broader compromise.

**This content contains a video which can not be displayed in Agent mode**

## What does this look like in regulated enterprise environments?

The requirements behind this integration are familiar from customer deployments and active proofs of value across healthcare, life sciences, health insurance, and financial services. In those environments, AI traffic can touch sensitive data and high-impact systems while multiple application teams share the same platform infrastructure.

Security teams in those organizations typically want more than another block list. They want the evidence around the decision: which agent initiated the behavior, what it was connected to, what happened earlier in the session, which attack path succeeded during testing, and whether the event should be contained at the request level or escalated to the agent itself.

Kong provides a consistent place to govern and observe the AI traffic. Straiker adds the agent-specific security context and response around that traffic. This gives platform and security teams a shared operating model instead of separate architectures and separate views of the same workflow.

## How should Kong customers roll out the integration?

The lowest-friction motion is to start with production workflows already routed through Kong, prove the runtime value against real traffic, and expand the security program only where the customer needs it.

1. Select one or more production agent workflows already routed through Kong AI Gateway.

2. Start in detect or observe mode and review the security decisions against normal production behavior.

3. Move high-confidence controls into inline enforcement through Kong.

4. Add inventory, posture, and adversarial testing where the security team needs deeper context around the agent and its connected tools.

5. Define Agentic Kill Switch criteria for incidents where the agent itself must be contained, not just the latest request.

This gives customers a practical adoption path: protect what is already running, validate the signal in their own environment, and add broader agent security capabilities without rebuilding the gateway architecture.

## How do Kong and Straiker fit together as agents become more autonomous?

As agents gain access to more tools and data, platform and security teams need to stay aligned on the same execution path. Kong gives platform teams the controls to govern AI traffic consistently. Straiker gives security teams the agent-specific insight to understand how that traffic can be abused and what to do when the agent itself becomes unsafe.

*"Straiker is creating the agentic security control plane for security teams: a place to see what agents are connected to, test how they can be compromised, stop malicious actions at runtime, and contain the agent when the risk goes beyond a single request. Kong gives platform teams the trusted gateway and enforcement layer. Together, we give enterprises one operating model for scaling agents while keeping security and platform teams in control."*
Ankur Shah
-
CEO/Cofounder, Straiker

## What does this partnership give Kong customers in practice?

Kong customers should not have to choose between standardizing AI traffic through the gateway they already operate and giving security teams deeper visibility into agent behavior. The partnership is designed to bring those two requirements together.

Kong remains the place where AI traffic is routed, governed, observed, and enforced. Straiker adds a complementary agent security layer that can provide deeper security insight, adversarial validation, runtime decisions, and agent-level containment as customer needs grow. That lets teams start with a focused integration and expand without creating a second AI traffic architecture. For a deeper technical look at how Straiker extends Kong AI Gateway across adversarial testing, runtime defense, and agent-level containment, read [_Straiker’s guide to the Kong + Straiker integration_](https://www.straiker.ai/blog/kong-straiker-agentic-ai-security?utm_source=kong&utm_medium=partner_blog&utm_campaign=kong_straiker_integration&utm_content=straiker_deep_dive)_Straiker’s guide to the Kong + Straiker integration_.

To learn more, visit [_Straiker_](https://www.straiker.ai/?utm_source=kong&utm_medium=partner_blog&utm_campaign=kong_straiker_integration)_Straiker_, [_request a demo_](https://www.straiker.ai/demo-request?utm_source=kong&utm_medium=partner_blog&utm_campaign=kong_straiker_integration&utm_content=demo_cta)_request a demo_ to evaluate the integration against your own agent workflows, or explore the [_Kong Technology Partner Program_](https://konghq.com/partners)_Kong Technology Partner Program_.

## Frequently Asked Questions

**How does Straiker complement Kong AI Gateway's existing security capabilities?**

Kong provides the gateway controls, observability, authentication, AI governance, and native protections used to manage LLM, MCP, and A2A traffic. Straiker adds agent-specific security analysis and response, including deeper context around agent behavior, connected tools, attack paths, and cases where the agent itself may need to be contained.

**What types of AI traffic can the integration evaluate?**

The integration is designed around the same traffic patterns Kong AI Gateway manages: LLM requests and responses, MCP and tool calls, and agent-to-agent communication. The exact context and enforcement behavior can be configured for the customer's deployment. This can span coding, homegrown, and other types of agents.

**Can customers start by observing security decisions before they enable blocking?**

Yes. A detect-first rollout gives platform and security teams a way to review decisions against normal traffic, validate the signal in their own environment, and move high-confidence policies into enforcement through Kong when they are ready.

**How does the integration help platform and security teams work together?**

Both teams can work from the same AI traffic path rather than introducing a separate proxy or security architecture. Kong remains the gateway and enforcement point, while Straiker adds the agent-specific security context security teams need to investigate behavior, validate risk, and determine the appropriate response.

**What happens when the security issue extends beyond a single malicious request?**

Kong can enforce the immediate request-level action. If the evidence indicates that the agent itself is compromised or unsafe, Straiker can escalate to agent-level containment through the Agentic Kill Switch. That separates immediate traffic enforcement from the broader incident response needed to stop repeated malicious action.

- [Agentic AI](/blog/tag/agentic-ai)Agentic AI- [AI Security](/blog/tag/ai-security)AI Security- [MCP](/blog/tag/mcp)MCP- [AI Gateway](/blog/tag/ai-gateway)AI Gateway

Table of Contents

  • How does the Straiker integration work in the Kong request path?
  • Why does agent-level containment matter if Kong can already block a request?
  • What does this look like in regulated enterprise environments?
  • How should Kong customers roll out the integration?
  • How do Kong and Straiker fit together as agents become more autonomous?
  • What does this partnership give Kong customers in practice?
  • Frequently Asked Questions

## More on this topic

_Webinars_

## You Secured Your APIs. Then You Added AI.

_Reports_

## Enterprise AI Governance Gap Report 2026

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [Agentic AI](/blog/tag/agentic-ai)Agentic AI- [AI Security](/blog/tag/ai-security)AI Security- [MCP](/blog/tag/mcp)MCP- [AI Gateway](/blog/tag/ai-gateway)AI Gateway
Claudio Acquaviva
Principal Architect, Kong
Parth Shah
Head of Product, Straiker

Recommended posts

# Governing Claude Code: How To Secure Agent Harness Rollouts with Kong AI Gateway

[Engineering](/blog/tag)EngineeringMarch 7, 2026

Claude Code is Anthropic's agentic coding and agent harness tool. Unlike traditional code-completion assistants that suggest the next line in an editor, Claude Code operates as an autonomous agent that reads entire codebases, edits files across mult

Alex Drag

# Model Context Protocol (MCP) Security: How to Restrict Tool Access Using AI Gateways

[Engineering](/blog/tag)EngineeringFebruary 3, 2026

MCP servers expose all tools by default. There are two problems with this: security (agents get capabilities they shouldn't have) and performance (too many tools degrade LLM tool selection). The solution? Put a gateway between agents and MCP server

Deepak Grewal

# Your Multi-Agent System Is Only as Reliable as Its Context Layer

[Engineering](/blog/tag)EngineeringAugust 19, 2026

Multi-agent workflows live and die on context. Every agent-to-agent call and every agent-to-tool call is either a retrieval — fetching information the agent needs — or a mutation — changing state that downstream agents will depend on. At prototype s

Hugo Guerrero

# The Architecture Decision Your Multi-Agent System Will Live With

[Engineering](/blog/tag)EngineeringAugust 13, 2026

Multi-agent systems are, at their core, context distribution systems. Every agent in your workflow is a consumer and producer of context. The interesting architectural questions are all about how that context moves. Two operations drive everything:

Hugo Guerrero

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# AI Gateway vs. Direct LLM API Integration: The Architecture Decision Defining Your AI Strategy

[Engineering](/blog/tag)EngineeringJuly 2, 2026

Most teams start the same way. A developer creates an API key, calls OpenAI or Anthropic, and ships a prototype. The problems surface when that prototype becomes five production services calling three providers. Hardcoded provider dependencies are

Kong

# Building the Agentic Commit Log: A Technical Blueprint with Apache Kafka and Kong

[Engineering](/blog/tag)EngineeringJune 19, 2026

The architecture is built around two data planes, both managed by Kong. The first is the sync data plane — Kong AI Gateway — which handles all synchronous traffic between your agents and the outside world. Every inbound client request, every outbo

Hugo Guerrero

# Governing Claude Code: How To Secure Agent Harness Rollouts with Kong AI Gateway

[Engineering](/blog/tag)EngineeringMarch 7, 2026

Claude Code is Anthropic's agentic coding and agent harness tool. Unlike traditional code-completion assistants that suggest the next line in an editor, Claude Code operates as an autonomous agent that reads entire codebases, edits files across mult

Alex Drag

# Model Context Protocol (MCP) Security: How to Restrict Tool Access Using AI Gateways

[Engineering](/blog/tag)EngineeringFebruary 3, 2026

MCP servers expose all tools by default. There are two problems with this: security (agents get capabilities they shouldn't have) and performance (too many tools degrade LLM tool selection). The solution? Put a gateway between agents and MCP server

Deepak Grewal

# Your Multi-Agent System Is Only as Reliable as Its Context Layer

[Engineering](/blog/tag)EngineeringAugust 19, 2026

Multi-agent workflows live and die on context. Every agent-to-agent call and every agent-to-tool call is either a retrieval — fetching information the agent needs — or a mutation — changing state that downstream agents will depend on. At prototype s

Hugo Guerrero

# The Architecture Decision Your Multi-Agent System Will Live With

[Engineering](/blog/tag)EngineeringAugust 13, 2026

Multi-agent systems are, at their core, context distribution systems. Every agent in your workflow is a consumer and producer of context. The interesting architectural questions are all about how that context moves. Two operations drive everything:

Hugo Guerrero

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# AI Gateway vs. Direct LLM API Integration: The Architecture Decision Defining Your AI Strategy

[Engineering](/blog/tag)EngineeringJuly 2, 2026

Most teams start the same way. A developer creates an API key, calls OpenAI or Anthropic, and ships a prototype. The problems surface when that prototype becomes five production services calling three providers. Hardcoded provider dependencies are

Kong

# Building the Agentic Commit Log: A Technical Blueprint with Apache Kafka and Kong

[Engineering](/blog/tag)EngineeringJune 19, 2026

The architecture is built around two data planes, both managed by Kong. The first is the sync data plane — Kong AI Gateway — which handles all synchronous traffic between your agents and the outside world. Every inbound client request, every outbo

Hugo Guerrero

# Governing Claude Code: How To Secure Agent Harness Rollouts with Kong AI Gateway

[Engineering](/blog/tag)EngineeringMarch 7, 2026

Claude Code is Anthropic's agentic coding and agent harness tool. Unlike traditional code-completion assistants that suggest the next line in an editor, Claude Code operates as an autonomous agent that reads entire codebases, edits files across mult

Alex Drag

# Model Context Protocol (MCP) Security: How to Restrict Tool Access Using AI Gateways

[Engineering](/blog/tag)EngineeringFebruary 3, 2026

MCP servers expose all tools by default. There are two problems with this: security (agents get capabilities they shouldn't have) and performance (too many tools degrade LLM tool selection). The solution? Put a gateway between agents and MCP server

Deepak Grewal

# Your Multi-Agent System Is Only as Reliable as Its Context Layer

[Engineering](/blog/tag)EngineeringAugust 19, 2026

Multi-agent workflows live and die on context. Every agent-to-agent call and every agent-to-tool call is either a retrieval — fetching information the agent needs — or a mutation — changing state that downstream agents will depend on. At prototype s

Hugo Guerrero

# The Architecture Decision Your Multi-Agent System Will Live With

[Engineering](/blog/tag)EngineeringAugust 13, 2026

Multi-agent systems are, at their core, context distribution systems. Every agent in your workflow is a consumer and producer of context. The interesting architectural questions are all about how that context moves. Two operations drive everything:

Hugo Guerrero

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# AI Gateway vs. Direct LLM API Integration: The Architecture Decision Defining Your AI Strategy

[Engineering](/blog/tag)EngineeringJuly 2, 2026

Most teams start the same way. A developer creates an API key, calls OpenAI or Anthropic, and ships a prototype. The problems surface when that prototype becomes five production services calling three providers. Hardcoded provider dependencies are

Kong

# Building the Agentic Commit Log: A Technical Blueprint with Apache Kafka and Kong

[Engineering](/blog/tag)EngineeringJune 19, 2026

The architecture is built around two data planes, both managed by Kong. The first is the sync data plane — Kong AI Gateway — which handles all synchronous traffic between your agents and the outside world. Every inbound client request, every outbo

Hugo Guerrero

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo

## step-0

    • Company
    • [About Kong ](/company)About Kong
    • [Customers ](/customer-stories)Customers
    • [Careers ](/company/careers)Careers
    • [Press ](/company/press-room)Press
    • [Events ](/events)Events
    • [Contact ](/company/contact-us)Contact
    • [Pricing ](/pricing)Pricing
      •    * [Terms](/legal/terms-of-use)
      •    * [Privacy](/legal/privacy-policy)
      •    * [Trust and Compliance](https://trust.konghq.com/)
    • Platform
    • [Kong AI Gateway ](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect ](/products/kong-konnect)Kong Konnect
    • [Kong Gateway ](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway ](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia ](/products/kong-insomnia)Kong Insomnia
    • [Documentation ](https://developer.konghq.com)Documentation
    • [Book Demo ](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives ](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee ](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs AWS ](/performance-comparison/kong-vsaws)Kong vs AWS
    • [Kong vs IBM ](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Mulesoft ](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • [Kong vs Postman ](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs LiteLLM ](/performance-comparison/kong-vs-litellm)Kong vs LiteLLM
    • Explore More
    • [Kong for Startups ](/solutions/startup-program)Kong for Startups
    • [Open Banking API Solutions ](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions ](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration ](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management ](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy ](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • Open Source
    • [Kong Gateway ](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma ](https://kuma.io/)Kuma
    • [Insomnia ](https://insomnia.rest/)Insomnia
    • [Kong Community ](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • English
  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
[Everything is 200 OK](https://status.konghq.com/)
© Kong Inc. 2026
Interaction mode