Sign in

Bill Doerrfeld

@doerrfeldbill.bsky.social
154 followers 28 following 176 posts

Tech journalist and editor. Editor of Nordic APIs, the API blog. I also contribute to enterprise IT publications and provide content, analysis, and consulting for tech companies.

PostsRepliesMedia
Bill Doerrfeld @doerrfeldbill.bsky.social · 12h
Many CIOs are still in evaluation mode when it comes to alternative clouds. My latest @cio.com feature looks at what enterprises should consider before making the jump: www.cio.com/article/4223...
cio.com
How CIOs should evaluate alternative clouds
Enterprise executives aren't jumping blindly onto trendy neoclouds. They're assessing maturity and making pragmatic workload-to-cloud pairings.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 28/09/2026
Another virtual conference with AI Security University is on the books! 😎 The next one is on AI pen-testing. Register for the AI Pen-Testing Conference here: aisec.university/conferences/...
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 28/09/2026
2 weeks to go til Nordic APIs Summit. 🤯 The speaker lineup is one of the best we've ever assembled. nordicapis.com/events/platf...
nordicapis.com
Nordic APIs Summit 2026 | Nordic APIs
Join API industry leaders at Nordic APIs Summit 2026, our flagship event, to tackle the many challenges facing API-heavy enterprise software architectures.
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 28/09/2026
A new @yaleclimatecomm.bsky.social + @github.com survey finds most GitHub users believe AI contributes to climate change. It's more than AI doomerism, though. They recommend concrete actions IT can take to curb waste. My latest on @leaddev.com explores the report: leaddev.com/ai/developer...
leaddev.com
Developers want more sustainable AI
GitHub-Yale report: most developers want more sustainable AI, pointing to inefficient models and compute as the biggest culprits.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 25/09/2026
If you were to monetize MCPs, there's a few methods: - Monetize the underlying API - Gate MCP access as an upsell - Meter tool calls or successful calls - Bundle MCP interactions into agentic capabilities My post on @zuplo.com tries to make sense of MCP monetization: zuplo.com/blog/mcp-mon...
zuplo.com
4 MCP Monetization Models for Agentic Commerce - Zuplo
There are a number of emerging ways to monetize MCP: charge for the API underneath, gate access as a plan feature, meter tool calls, or bill by the outcome.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 25/09/2026
Another week, another bulletin from yours truly covering the cloud native world as we count down the days to KubeCon NA. This past week in cloud native saw a lot of movement in and around observability. Check it out on @thenewstack.io: thenewstack.io/opentelemetr...
thenewstack.io
OpenTelemetry and Prometheus are getting along. What’s still missing?
OpenTelemetry and Prometheus are getting easier to use together. Teams are seeing gains, but mismatched data models still complicate observability.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 23/09/2026
Last reminder that the virtual MCP Security Conference tomorrow, 12-3PM EST. Stop by for a solid panel discussion on MCP security issues, Q&A, a solution showcase, and talks from from an end user and MCP maintainer. aisec.university/conferences/...
aisec.university
MCP Security Conference — AI Security University
A free, half-day virtual conference on securing the Model Context Protocol — the layer connecting AI agents to tools and data. Featuring Bill Doerrfeld and a tour of the emerging MCP security stack: t...
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 18/09/2026
Prediction: using Kubernetes to run AI inference is going to be a hot topic at KubeCon this year... The second week of my Road to KubeCon column is now live on @thenewstack.io. Many nuggets, release updates, reports + more from the cloud-native world: thenewstack.io/kubernetes-a...
thenewstack.io
Kubernetes can run AI inference. But can it count the real cost?
One bank cut token-processing costs 60% with a Kubernetes stack. But a warning about its resource model raises questions about AI inference economics.
200
Bill Doerrfeld @doerrfeldbill.bsky.social · 11/09/2026
Just started a new weekly column for @thenewstack.io all on Kubernetes and cloud-native! The first edition kicks off an 8-part series. This one explores K8s 1.37, CNCF graduations, K8s access control, and more tidbits from the cloud-native ecosystem. ☸️☁️ thenewstack.io/kubecon-kube...
thenewstack.io
Kubernetes v1.37 brings 67 enhancements. Which matter for operators?
Kubernetes is gaining AI and operations tools. Road to KubeCon explores what’s changing and the access-control gap teams still need to address.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 03/09/2026
My talking head letting you know about @nordicapis.com Summit 2026. 🏔️ Oct 12-14 in Stockholm Full agenda is now live 🎉https://nordicapis.com/events/platform-summit-2026/ #agentic #ai #api
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 01/09/2026
Teaming up with AI Security University to help put on a virtual #MCP Security Conference ‼️ Sept 24, 12-3pm ET Register here: aisec.university/conferences/...
aisec.university
MCP Security Conference — AI Security University
A free, half-day virtual conference on securing the Model Context Protocol — the layer connecting AI agents to tools and data. Featuring Bill Doerrfeld and a tour of the emerging MCP security stack: t...
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 01/09/2026
What are some tools for generating MCP servers? I reviewed 10 options for converting OpenAPI descriptions into #MCP servers on the @zuplo.com blog: zuplo.com/blog/mcp-ser...
zuplo.com
10 MCP Server Generators Compared - Zuplo
We compare 10 tools that turn an OpenAPI spec into an MCP server — gateway platforms, SDK tools, and open-source generators — and when to reach for each one.
151
Bill Doerrfeld @doerrfeldbill.bsky.social · 27/08/2026
My latest for @leaddev.com peeks inside Shopify's unique "high-intensity" culture. leaddev.com/culture/insi...
leaddev.com
Inside Shopify’s high-intensity engineering culture
Shopify’s high-intensity engineering culture doesn’t mean longer hours. It focuses on cutting meetings, pair programming, code deletion, and owning PRs.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 26/08/2026
Do new AI/MCP gateways replace your IdP? On the @zuplo.com blog, I make the case that MCP gateways and existing identity systems are complementary. zuplo.com/blog/mcp-gat...
zuplo.com
Why MCP Gateways Should Use Existing Authentication Services - Zuplo
An MCP gateway shouldn't replace the IdP you already run. Here's why identity servers and MCP gateways work best as separate, complementary concerns — and what 'bring your own IdP' should mean in prac...
111
Bill Doerrfeld @doerrfeldbill.bsky.social · 24/08/2026
Can neoclouds actually corner the AI compute market? Excited to share a deep feature today with @infoworld.bsky.social that tries to answer this question. www.infoworld.com/article/4211...
infoworld.com
Can neoclouds corner AI compute?
The race for AI compute is on. While neoclouds provide cheaper GPUs and more optimized infrastructure for AI processing, hyperscalers are better positioned to meet enterprise needs.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 10/08/2026
Chatting with Dan Barahona of AI Security University tomorrow about all the new infrastructure that's emerging to secure MCP use! Info and registration link here: aisec.university/events/mcp-s...
aisec.university
The MCP Security Market — AI Security University
A live webinar with Bill Doerrfeld — cybersecurity and MCP expert who built the MCP Stack — mapping the MCP security market: the technology and solution categories, the key vendors, and how the pieces...
110
Bill Doerrfeld @doerrfeldbill.bsky.social · 29/07/2026
Knowledge decay has plagued software teams for decades. But IBM's Neel Sundaresan thinks AI can finally help close this gap. My latest for @leaddev.com: leaddev.com/ai/how-to-av...
leaddev.com
How to avoid knowledge decay in software engineering
Can AI finally fix the knowledge decay issue that’s plagued software engineering teams for decades? Neel Sundaresan, GM at IBM, thinks so.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 14/07/2026
How do you avoid shadow MCP servers at enterprise scale? You can't. Just kidding. I left some recommendations on the @zuplo.com blog: zuplo.com/blog/how-to-...
zuplo.com
How to Avoid Shadow MCP Servers in the Enterprise - Zuplo
Shadow MCP servers are the new shadow IT. Here's how to bring them under enterprise governance with inventory, monitoring, least privilege, and a gateway.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 13/07/2026
What is zero standing privilege (ZSP)? Today, I look at this new and emerging cybersecurity topic and why it's so relevant in the agentic AI era. via @curity.io: curity.io/blog/what-is...
curity.io
What Is Zero Standing Privilege? | Curity
Zero standing privilege removes long-lived permissions entirely, granting identities temporary, task-specific access only at the moment of execution. Learn how it works, why it matters for agentic AI,...
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 08/07/2026
What's the difference between an MCP registry and an MCP gateway? Both are evolving quickly: here are the early patterns and what the early examples look like right now. zuplo.com/blog/mcp-reg...
zuplo.com
MCP Registry vs. MCP Gateway: What's the Difference? - Zuplo
A registry is a static catalog for discovery, whereas a gateway is the control plane to manage, curate, and secure MCP tool access.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 07/07/2026
3 years into AI coding, code duplication is up 81%, code reuse is down 70%, and legacy refactoring fell 74%. Guess creating new code is "easier" than maintaining old code... GitClear analyzed 623M real-world code changes, covered first on @leaddev.com leaddev.com/ai/code-main...
leaddev.com
Code maintainability plummets in the AI coding era
New research reveals that AI coding is driving up duplication, suppressing errors, and leaving legacy code untouched.
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 29/06/2026
If you're using #MCP in your workflows or building MCP servers, be sure to avoid these common MCP security anti-patterns. via @zuplo.com zuplo.com/blog/7-commo...
zuplo.com
7 Common MCP Security Flaws and Vulnerabilities - Zuplo
If you're using MCP in your workflows or building MCP servers, be sure to avoid these common MCP security anti-patterns.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 25/06/2026
AI-coding agents are the default. So, what now? Synced with Tom Moor, head of engineering at Linear, for this piece on @leaddev.com to find out. Give it a read: leaddev.com/ai/ai-coding...
leaddev.com
AI-coding agents are now the default. What comes next?
How Linear went agent-first overnight, what the productivity numbers look like, and what to manage when AI agents become the default.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 22/06/2026
AI got proprietary, fast. But open infrastructure still matters. My latest feature for @infoworld.bsky.social makes the case why open infrastructure will define the AI era. www.infoworld.com/article/4186...
infoworld.com
Why open infrastructure will define the AI era
Remember when writing code was free? AI is pushing software development into usage-billed proprietary platforms. But history repeats itself, and open foundations tend to win.
000
Reposted by Bill Doerrfeld
Charity Majors @charity.wtf · 18/06/2026
writing my second response on AI, this one on ethics. here's my list, what am I missing? come on bsky, you were built for this day 😉 * datacenters that are too loud and use fresh water * data labeling work that is extractive & exploitative, chasing low pay * models trained on data without consent
299120
Bill Doerrfeld @doerrfeldbill.bsky.social · 17/06/2026
How do you get AI costs down? It takes a combination of visibility, governance, smart model selection, quality API design, MCP optimizations, and more. Yesterday's LiveCast on AI cost control is now live on the @nordicapis.com YouTube here: youtu.be/TWB9J-4oswg?...
youtu.be
LiveCast: AI Cost Control
YouTube video by Nordic APIs
1371
Bill Doerrfeld @doerrfeldbill.bsky.social · 17/06/2026
The rapid shutdown of Fable and Mythos demonstrates why engineering teams need model-agnostic foundations. @leaddev.com leaddev.com/ai/ai-models...
leaddev.com
AI models can disappear overnight. Is your engineering team built to survive it?
The quick Mythos and Fable shutdown demonstrates why engineering teams need a model-agnostic foundation to hedge their bets.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 10/06/2026
AI layoffs seem everywhere. But they're overshadowing the real economic reasons behind cuts and the net-positive talent redistributions happening at large. My latest for @leaddev.com digs in: leaddev.com/ai/the-ai-ta...
leaddev.com
The AI talent story everyone is missing
AI isn’t eliminating engineering jobs – it’s redistributing them, and the companies navigating this well are hiring for judgment, not output.
021
Bill Doerrfeld @doerrfeldbill.bsky.social · 08/06/2026
What MCP servers are there for working with databases? My latest for @infoworld.bsky.social reviews a handful of MCP servers and agent-ready tools for database management. www.infoworld.com/article/4181...
infoworld.com
10 MCP servers to connect LLMs with databases
Use these official MCP servers to interact with the leading database platforms via natural language through your LLM-assisted tools.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 05/06/2026
The MCP infrastructure space is booming. Nowhere is this more evident than the surge in MCP gateways. Here's my comparison of 10 standout ones: zuplo.com/blog/mcp-gat...
zuplo.com
MCP Gateway Comparison: 10 Tools for Governing AI Agent Access - Zuplo
An MCP gateway is becoming table stakes for governing AI agent access to tools and APIs. We compare 10 leading MCP gateways across security, observability, deployment model, and standout features.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 28/05/2026
When do you call it quits? Real software leaders know you can't have endless innovation without also knowing when to cancel unviable projects. But it takes a certain muscle to know when to pull the plug. My latest DirectorPlus via @leaddev.com: leaddev.com/leadership/w...
leaddev.com
When to kill a software project
How NinjaOne’s SVP of data and AI uses timeboxing, kill criteria, and a single dissenter model to cut failing projects early and protect engineering resources.
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 25/05/2026
MCP is a force multiplier for context engineering. See my latest @infoworld.bsky.social feature for more... context. Hehe. www.infoworld.com/article/4175...
infoworld.com
The role of MCP in context engineering
Developers are discovering that Model Context Protocol shines at providing AI coding agents with highly relevant software engineering context, on demand, at run time.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 21/05/2026
What's wrong with API keys? Well, they're long-lived, leaked constantly, easily reused by hackers, rarely cycled, and usually provide overpermissioned access. More thinking on this on @nordicapis.com here: nordicapis.com/10-security-...
nordicapis.com
10 Security Issues With API Keys | Nordic APIs |
API keys introduce significant security risks due to their static, reusable nature and lack of identity context. Learn the top API key vulnerabilities and how to secure modern APIs.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 18/05/2026
My takeaways from last week's apidays New York: nordicapis.com/5-key-takeaw...
nordicapis.com
5 Key Takeaways From apidays New York 2026 | Nordic APIs |
Explore apidays New York 2026 takeaways on APIs as the AI execution layer for agents, security, governance, and optimization.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 15/05/2026
Well, apidays NYC 2026 is a wrap! The most obvious focus this year? Agents. APIs are a form of context for agentic AI, and there are emerging tactics for setting them up for success.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 15/05/2026
Had a blast MC'ing sessions at apidays NYC this week!
020
Bill Doerrfeld @doerrfeldbill.bsky.social · 13/05/2026
95% faster seller prep time. 16% better attainment. $2.7 million in new sales opportunities. 1,700 hours saved. My latest for @cio.com features real results from CIOs actively deploying AI agents to accelerate sales and revenue workflows. www.cio.com/article/4164...
cio.com
How CIOs use AI agents to accelerate revenue growth
Sales and revenue combine as a key ROI-focused domain for enterprise AI agents. CIOs are locking in to how they aid workflows, from targeted prospecting and account research, to follow-ups and other r...
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 12/05/2026
My latest for @infoworld.bsky.social looks at the downsides of hastily bolting AI onto existing products, and what to do instead. www.infoworld.com/article/4161...
infoworld.com
How to add AI to an existing product (without annoying users)
Bolting AI onto your product willy-nilly can hurt more than it helps. Experts weigh in on common mistakes around AI feature creep and how to guide successful pilots.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 06/05/2026
Excited to share that I’ll be at apidays NYC next week! I'll be helping MC tracks across both days. Who's gonna be around? www.apidays.global/events/new-y...
031
Bill Doerrfeld @doerrfeldbill.bsky.social · 01/05/2026
Cloudflare rebuilt Next.js over a weekend using agentic coding. I caught up with Cloudflare CTO Dane Knecht to chat about the implications for software strategy. As he says, "This kind of reinvents the factory floor." leaddev.com/ai/how-cloud...
leaddev.com
How Cloudflare rebuilt Next.js in a weekend
Cloudflare rebuilt Next.js in a matter of days. CTO Dane Knecht says it’s only the tipping point of what’s to come with agentic coding.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 29/04/2026
Join us in Stockholm to talk agentic AI and APIs! Super early bird registration for @nordicapis.com yearly summit is open 😎 🎟️ tickets: nordicapis.com/events/platf... 🎤 speak: nordicapis.com/call-speakers/
nordicapis.com
Platform Summit 2026 | Nordic APIs
Join API industry leaders at the Platform Summit, Nordic APIs’ flagship event, to tackle the many challenges facing API-heavy enterprise software architectures.
000
Reposted by Bill Doerrfeld
fkilcommins @fkilcommins.bsky.social · 22/04/2026
Nice to be part of this @infoworld.bsky.social feature by @doerrfeldbill.bsky.social on building enterprise-grade agentic systems. Hot take: Determine what's adaptive vs. deterministic, and codify the latter. Not everything needs an LLM in the loop. www.infoworld.com/article/4154...
infoworld.com
Best practices for building agentic systems
Which technologies, designs, standards, development approaches, and security practices are gaining momentum in multi-agent enterprise systems? We asked the experts.
031
Bill Doerrfeld @doerrfeldbill.bsky.social · 20/04/2026
What actually goes into building enterprise-grade AI agents? My latest for @infoworld.bsky.social explores the emerging best practices behind agentic systems: www.infoworld.com/article/4154...
infoworld.com
Best practices for building agentic systems
Which technologies, designs, standards, development approaches, and security practices are gaining momentum in multi-agent enterprise systems? We asked the experts.
021
Bill Doerrfeld @doerrfeldbill.bsky.social · 15/04/2026
Today I look into ING Bank's journey developing a custom-made service mesh to manage its 2k microservices portfolio. We covered their API-first transition on @nordicapis.com in 2017, so it's pretty cool to see the journey coming full-circle after 9 years. nordicapis.com/how-ing-bank...
nordicapis.com
How ING Bank Manages 2,000 Microservices With Service Mesh | Nordic APIs |
How ING scaled 2,000 microservices with a service mesh, covering governance, discovery, and security lessons.
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 14/04/2026
Calling out folks in the Stockholm and Nordic area: @nordicapis.com, Akamai, and @curity.io are hosting a pretty dreamy event next month: a dinner cruise through the Stockholm archipelago 🚢 Check out the details and register interest here: nordicapis.com/events/api-s...
nordicapis.com
AI & API Security Dinner | Nordic APIs
Join Nordic APIs, Akamai and Curity for a night of dinner, AI & APIs onboard a classic archipelago ship.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 31/03/2026
What goes into an enterprise-grade MCP registry? My latest for @infoworld.bsky.social goes deep into this topic: www.infoworld.com/article/4145...
infoworld.com
How to build an enterprise-grade MCP registry
MCP registries are emerging as the new integration catalog for AI agents. Building one for the enterprise requires semantic discovery, strong governance, and developer-friendly controls.
010
Bill Doerrfeld @doerrfeldbill.bsky.social · 30/03/2026
My first-ever contribution to @csoonline.bsky.social looks at the shifting landscape, from perimeter-based security to #API security, and how CISOs are responding. www.csoonline.com/article/4148...
csoonline.com
APIs are the new perimeter: Here’s how CISOs are securing them
Today’s attack surface is shifting from the endpoint to the API, and AI and third-party SaaS are worsening the issue. CISOs offer advice for API defense.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 29/03/2026
Okay, how do we fix open source Slopmageddon? My latest feature is live on the @thenewstack.io: thenewstack.io/ai-slop-open...
thenewstack.io
96% of codebases rely on open source, and AI slop is putting them at risk
AI-generated slop is overwhelming open source maintainers with low-quality pull requests. Here's how projects are fighting back with policies and new tools.
000
Bill Doerrfeld @doerrfeldbill.bsky.social · 27/03/2026
Platform engineering is being redefined in the agentic era: less shared code, slimmer platforms, more focus on developer experience. In my latest for @leaddev.com, I interview Squarespace director of engineering Jon Thornton on the shift: leaddev.com/ai/squarespa...
leaddev.com
Squarespace redraws the boundaries of platform engineering
AI is transforming platform engineering from a support function into a more agile hands-on discipline, reshaping teams and accelerating migrations.
210
Bill Doerrfeld @doerrfeldbill.bsky.social · 26/03/2026
"We know that API breaches in general are much more severe than a common data breach," says @curity.io's CTO, Jacob Ideskog. Now with AI agents using APIs, "take that and multiply it." via @nordicapis.com nordicapis.com/tackling-api...
nordicapis.com
Tackling API Security in the AI Era | Nordic APIs |
How AI accelerates API security risks and why access control and IAM remain critical safeguards.
110