June 11th, 2012

API Analytics Tech Talk Tuesday

API AnalyticsGet your API analytics questions ready! Tech Talk is coming up tomorrow, Tuesday June 12 – it’s live it’s interactive and CTO Scott Morrison will be our guest. Tweet questions to #layer7live.

Add it to your calendar

If you publish an API, you need a way to measure and understand how that API functions. You need a way to manage it. You need a way to measure it. APIs are becoming an essential part of the Internet and more enterprises are opening up their APIs to third-party developers.

Of course, API security is always a concern but if you publish an API, you also need to measure how it functions – what metrics are you concerned with? Are there any API errors my application is seeing? How does my API usually perform and is that changing? Is it slowing down or are there latency issues caused by using a proxy?

Key metrics API publishers need to consider include: errors, performance, availability, latency and response time. And with the Layer 7 API Portal, these metrics can be graphed and filtered by user, developer and API.

So be sure to join us tomorrow at 9am PDT when Layer 7 CTO Scott Morrison will take live questions from the stream. It’s a great chance to have your API analytics questions answered.

How to Attend:

Just visit the Layer 7 Facebook page at 9am PDT on June 12 and click the Livestream icon.

Don’t have Facebook? Simply click here to watch directly through Livestream.

How to Submit Questions:

On Facebook

•    Click on the Livestream PLAY button to join the stream
•    Click the red “Check in & Chat” button to submit questions

On Twitter
•    Tweet questions with the hashtag #layer7live

May 28th, 2012

Gluecon 2012

Gluecon LogoGlue Conference, aka Gluecon, is such a refreshing event – filled with API and application developers, not a single suit in sight, demo pods, hackathons, spheros etc.

APIs are popping up everywhere and creating amazing integration possibilities. One of the coolest demos I saw at Gluecon was Ducksboard’s dashboard service, which lets you create your own monitoring dashboard using a library of widgets for existing social and Cloud providers. You can even create your own widget and have your own data pushed to it via an API endpoint created just for you, on the fly – so sexy!

Thanks to everybody who came to my presentation Making Sense of API Access Control. I hope this shed some light on how to leverage OAuth for controlling access to REST-based APIs. A lot of the new APIs I discovered this week could certainly use some help in that regard. API key authentication in HTTP basic without password has its limitations. The slides from Making Sense of API Access Control are embedded below.

March 27th, 2012

M2M & the Digital Frontier

Written by
 

M2M API GatewayThe machine-to-machine (M2M) movement is having a broad impact across industries.  New business models are being powered by information distributed to and collected from smart meters in the utilities sector, connected vehicles in logistics, heart monitors in healthcare, RFID-tagged inventory in retail and digital signage in the media. M2M creates a vast “Internet of things” comprised of smart devices that produce data, networks that transmit data and applications that turn data into real-world insight.

The M2M paradigm presents an exciting new opportunity for companies to use Layer 7’s API Management products.  APIs represent the key to unlocking the value of M2M by linking devices in the field to the core enterprise applications that are able to analyze and apply the data these devices produce. Layer 7 empowers organizations to make that link in a secure, scalable way:

  • The SecureSpan SOA Gateway or API Proxy provides REST-based connectivity to heterogeneous enterprise systems
  • The Layer 7 API Portal allows M2M API owners to set and enforce SLAs and provide comprehensive information to API users (smart device developers, network operators)
  • The Layer 7 OAuth Toolkit configures access control policies that are fit for M2M and able to leverage existing back-end infrastructure

We already have customers achieving M2M success in the automotive, healthcare, media and energy industries. So, whether you’re a logistics company looking to get a real-time view of your global fleet, a retailer needing to manage your disparate warehouses or a telecommunications company providing a broad set of M2M services, we encourage you to apply our industry-leading technology as part of your solution.

Read the solution brief: Simplify M2M Integration with a SOA Gateway

March 21st, 2012

Implementing BYOD-centric Systems

Implementing BYOD-centric SystemsIn recent conversations with our service provider partners and customers, I’ve been hearing a common theme: their enterprise customers are scared of BYOD. The recent trend of employees using their own technology – iPads, smart-phones etc. – to connect with corporate assets worries them. Their main concern is that they won’t be able to keep up with the security and management requirements that go along with this new method of accessing data assets.

While there are existing solutions for playing keep-up, many of them rely on isolation and restriction to prevent corporate assets from traveling too far from the enterprise. Unfortunately, I think employees – especially the more tech-savvy among them – will resent having corporate security policies installed on their devices or being limited to separate-but-equal wireless networks with limited access to the resources necessary to do their jobs. By focusing on containment and control, enterprises are missing an amazing opportunity to make BYOD work for them.

The efficiencies gained by embracing the inevitable and implementing some BYOD-centric systems should not be overlooked. Layer 7 customers are creating mobile applications designed specifically to support their employees, whether their devices are employee-owned or provided by IT.  Our solutions for security and governance of the APIs used by those applications can prevent data leakage, protect against incoming threats and provide access to only appropriate personnel.

So, whether your employees are baggage handlers determining the destination for a piece of lost luggage, nurses providing care to house-bound patients or remote employees connecting to their peers through a corporate directory and communication hub, the real winner is the bottom line. BYOD and mobile workforce enablement are opportunities to embrace – not afflictions to be cured – and we’re here to help.

March 13th, 2012

Join Layer 7 for Tech Talk Tuesday, Live on Facebook

Written by
 

Layer-7 Facebook Tech TalkWe are going live for an exclusive, interactive event through our Facebook page and we want you to join us. We’ll be livestreaming a conversation with Layer 7 Director of Solutions Engineering Francois Lascelles on our live Facebook channel, next Tuesday. This will be the first in a bi-weekly series of interactive town hall meetings we’re calling “Tech Talk Tuesday”.

Simply go to the Layer 7 Facebook page and click the Livestream icon to start watching live on Tuesday March 20 at 9am PDT (12pm EDT, 4pm GMT). We’ll be discussing the topic of OAuth Best Practices for API Access Control. We’ll start by talking about the broader aspects of API access control before diving deep into the specifics of OAuth.

And here’s where you come in… We’d love to answer any questions you have concerning OAuth, like: how to incorporate an existing API and identity provider or how to apply the different grant types used in OAuth. The more questions, the better! So be sure to tell your friends and join us on Tuesday March 20 at 9am PDT | 12pm EDT | 4pm GMT.