WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [Event Gateway](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Product Releases
  4. Shine a Light on Shadow APIs Lurking in Your IT Infrastructure
[Product Releases](/blog/product-releases)Product Releases
September 11, 2024
5 min read

# Shine a Light on Shadow APIs Lurking in Your IT Infrastructure

Miko Bautista
Staff Product Manager, Kong

### Discover and manage shadow APIs with Konnect Service Catalog, a single source of truth for all your services and APIs

The service catalog is an essential tool that all organizations invested in effective IT management should own and maintain. Without an up-to-date system of record of all services and APIs, organizations run the risk of having what we call “Shadow APIs” — or APIs that are undiscovered, unmanaged, and pose significant security risks to the entire company.

So, why is gaining visibility into these services and APIs such a big deal?

Among the tens of thousands of API endpoints that might be running in an organization’s infrastructure, every single one can be thought of as a unique attack vector, especially if left unprotected without authentication, authorization, and rate limiting. 

According to Security Magazine, over 50% of organizations experienced at least one API-related breach in the last year, a reflection of how difficult it is to ensure API security at scale. And it looks as if the trend will only increase. Kong [forecasts](https://konghq.com/resources/reports/ai-and-api-adoption-challenges)forecasts the number of annual API attacks will grow 548% by 2030.  

In addition, API deployments have noticeably increased in complexity over the last several years. As organizations continue to break down their monolith, they’ve struggled to deal with a variety of API implementations — REST, GraphQL, gRPG, to name a few — across both hybrid and multi-cloud environments.

Finally, APIs can be expensive liabilities when left unmanaged. ITIC found that a staggering 81% of organizations reported that experiencing just one hour of unplanned API downtime often costs them upwards of $300,000. 

## Enter the service catalog!

We know [APIs are mission critical](https://konghq.com/blog/enterprise/apis-are-mission-critical)APIs are mission critical. So, what exactly can organizations like yours do to protect themselves? It may be worth your time to invest in a service catalog.

An effective service catalog serves as an all-encompassing repository for an organization’s services and APIs. Managing and maintaining this asset can have tremendous benefits across different teams.

For example, the service catalog not only provides Platform Teams with the ability to retroactively secure existing APIs, but also enables them to proactively enforce rules and regulations, so that moving forward, newly-created APIs are properly governed as well. 

The service catalog also has the potential to boost developer productivity across Application Teams. This tool is meant to aggregate dispersed information about an organization’s services: their code repositories, CI/CD pipelines, dependency trees, API specs, documentation files, lists of recent incidents, and so on. The ability to search across the entire catalog and view a quick 360 summary on any given entry can improve Application Teams’ productivity across a variety of use cases — identifying upstream/downstream dependencies when triaging incidents, and leveraging existing code to save development time, just to name a couple.

## The Konnect Service Catalog is now available in Public Beta

Our team at Kong has been working diligently to deliver a product that thoughtfully addresses all the points described above, and more.

Today, we're excited to announce that the Konnect Service Catalog (or simply, “Service Catalog”) is now available in Public Beta!

## Comprehensive visibility to help secure the entire service and API ecosystem

Out of the box, Service Catalog comes with pre-built integrations designed to identify live services and APIs running in an organization's infrastructure. Service Catalog’s discovery engine ingests these services and APIs from sources such as Kong Gateway and Kong Mesh — with more to come soon, such as Kubernetes, Apigee, and AWS Lambda.

### Leverage the Traceable integration to discover and manage “Shadow APIs” in your infrastructure

We’re also thrilled to announce that we’ve joined forces with our [Premium Technology Partner,](https://konghq.com/blog/news/premium-technology-partner)Premium Technology Partner, Traceable AI — an API security and observability platform that empowers Platform Teams to discover "Shadow APIs" at the kernel level through its formidable array of discovery mechanisms, including bleeding-edge [eBPF technology](https://www.traceable.ai/blog-post/ebpf-and-api-security-with-traceable)eBPF technology. By integrating Traceable and Service Catalog, we're able to transport previously undiscovered services into the Kong Konnect ecosystem.

Once these services are ingested into Konnect, users can begin protecting their related APIs by configuring Kong Gateway to serve as a reverse proxy. From here, authentication, authorization, and rate limiting can easily be enforced via [Kong Plugins](https://konghq.com/products/kong-plugins)Kong Plugins. The end result is that joint customers of both Kong and Traceable have a slick end-to-end experience whereby they can easily identify and subsequently mitigate risky APIs that exist in their infrastructure.

*This combined solution ensures you can confidently secure your entire API and service ecosystem, reducing the risk of data breaches and other security incidents. *

## Boost developer productivity with a 360-degree view

Service Catalog aggregates critical information from systems like PagerDuty and Datadog — with upcoming support for Jira, Slack, Snyk, and SonarQube — into a single, comprehensive view. Its integrations with various observability, incident management, and issue tracking systems mean that Application Teams can have a unified interface whereby they can easily search for all services in the organization across different dimensions: by team owner, engineering department, Jira board, and Slack channel. Without leaving the Service Catalog UI, they're able to view more details about a given service: upstream/downstream dependencies, API specs, and documentation files. 

Having this information accessible at their fingertips allows Application Teams to be more productive in their day-to-day activities, including when identifying the root cause of a recent service failure or when searching for the API of an existing service that they might want to integrate with.

## Coming soon: Enforce policy and governance with Scorecards

Ensuring that all teams across an organization adhere to the company’s maturity standards and industry-defined best practices can be challenging initiatives to drive for Platform Teams, especially those who work at large enterprises. These initiatives typically involve kicking off huge cross-functional processes spanning multiple teams, each with its own cultures, timelines, and priorities. Given both its breadth and depth of understanding of an organization’s service ecosystem, Service Catalog is well-positioned to solve this problem for Platform Teams.

By codifying these guidelines, represented in the form of a Scorecard, Platform Teams are able to identify which services fail to adhere to their custom-defined standards and industry best practices. They're then able to view a list of service owners whom they should follow up with to implement change. Ultimately, Service Catalog’s Scorecards feature imparts Platform Teams with confidence when quantitatively tracking improvement in company-wide compliance.

Here are some examples of criteria that a Platform Team can embed into their Scorecards:

  • - All Kong Gateways have the OIDC plugin installed
  • - All Kong Meshes have mTLS enabled
  • - All API specs must be properly linted
  • - All GitHub repositories must have 5 or fewer open pull requests
  • - All PagerDuty services must have 2 or fewer incidents triggered in the last 7 days
  • - All Datadog monitors are configured and enabled

And much more!

## Secure and control your API infrastructure today

Take control of your API infrastructure with Service Catalog today! Check it out, either by logging into [Kong Konnect](https://cloud.konghq.com/login)Kong Konnect or by registering to get started in [Kong Konnect Plus](https://konghq.com/products/kong-konnect/register)Kong Konnect Plus.

Want to learn more? It's not too late to [register for API Summit](https://konghq.com/events/conferences/api-summit/register-now)register for API Summit where we’ll discuss all things Service Catalog with Traceable. Or, dig into [Service Catalog’s documentation](https://docs.konghq.com/konnect/service-catalog/)Service Catalog’s documentation for more technical details.

If you have any questions about Service Catalog or API Summit, reach out to us at [konnect-feedback@konghq.com](mailto:konnect-feedback@konghq.com)konnect-feedback@konghq.com.

As you explore Service Catalog, don’t forget to vote for which Integrations you’re most looking forward to!

## Developer agility meets compliance and security. Discover how Kong can help you become an API-first company.

[Get a Demo](/contact-sales)Get a Demo[Start for Free](/products/kong-konnect/register)Start for Free
- [API Security](/blog/tag/api-security)API Security

## More on this topic

_Webinars_

## Quarterly Platform Updates & Roadmap Webinar

_Videos_

## PEXA’s Resilient API Platform on Kong Konnect

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [API Security](/blog/tag/api-security)API Security
Miko Bautista
Staff Product Manager, Kong

Recommended posts

# Bringing Identity-Aware Security & Policy Enforcement to Event Streaming

[Product Releases](/blog)Product ReleasesMarch 25, 2026

The widespread adoption of Kafka and event streaming platforms is evident across several enterprises, where they serve as the backbone of critical operations, ranging from financial transactions to AI inference pipelines. However, in the domains of

Hugo Guerrero
[](https://konghq.com/blog/product-releases/kong-event-gateway-1-1)

# Expanded Observability, Orchestration, and Security with Kong Gateway 3.13

[Product Releases](/blog)Product ReleasesDecember 18, 2025

As API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y

Amit Shah
[](https://konghq.com/blog/product-releases/kong-gateway-3-13)

# Kong Cloud Gateways: A Year in Review

[Product Releases](/blog)Product ReleasesDecember 17, 2025

A quick refresher: Kong Cloud Gateways Kong Cloud Gateways are fully managed, high-performance data planes running on customer-dedicated infrastructure, orchestrated and operated by Kong through Kong Konnect . Customers can choose between: Serverle

Josh Wigginton
[](https://konghq.com/blog/product-releases/kong-cloud-gateways-2025-news-recap)

# Practical Strategies to Monetize AI APIs in Production

[Engineering](/blog)EngineeringMarch 27, 2026

Traditional APIs are, in a word, predictable. You know what you're getting: Compute costs that don't surprise you Traffic patterns that behave themselves Clean, well-defined request and response cycles AI APIs, especially anything that runs on LLMs

Deepanshu Pandey
[](https://konghq.com/blog/engineering/monetize-ai-apis)

# Evaluating API Testing Tools: Insomnia vs Postman

[Enterprise](/blog)EnterpriseMarch 26, 2026

Free collaboration with Postman — a myth On March 1st, 2026, Postman discontinued free collaboration for small teams. Now , Git or Cloud-native collaboration requires a Team plan starting at $19 per person per month. That means even a 3-person team

Haley Giuliano
[](https://konghq.com/blog/enterprise/insomnia-vs-postman-evaluating-api-testing-tools)

# Connecting Kong and Solace: Building Smarter Event-Driven APIs

[Engineering](/blog)EngineeringMarch 20, 2026

Running Kong in front of your Solace Broker adds real benefits: Authentication & Access Control – protect your broker from unauthorized publishers. Validation & Transformation – enforce schemas, sanitize data, and map REST calls into event topics.

Hugo Guerrero
[](https://konghq.com/blog/engineering/smarter-event-driven-apis-kong-solace)

# Create an Internal API and Service Inventory with Konnect Service Catalog

[Product Releases](/blog)Product ReleasesJuly 1, 2025

When speaking with our customers, and particularly with platform teams, we repeatedly hear about how difficult it is to discover and govern all the services and APIs that actively run on their infrastructure. In ever-expanding and changing environm

Erin Choi
[](https://konghq.com/blog/product-releases/create-an-internal-api-and-service-inventory)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo
Ask AI for a summary of Kong
  • [](https://chatgpt.com/s/t_69b981cfa37081919ce25ce107c431c1)
  • [](https://share.google/aimode/hyefOiNwl8pg8W99d)
  • [](https://www.perplexity.ai/search/what-solutions-does-kong-offer-VsYWPddxQjajgvLA4B9hjQ)
Stay connected

## step-0

    • Company
    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
    • Legal
    • [Terms](/legal/terms-of-use)Terms
    • [Privacy](/legal/privacy-policy)Privacy
    • [Trust and Compliance](https://trust.konghq.com)Trust and Compliance
    • Platform
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • Explore More
    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • Open Source
    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode