<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>RequestRocket Blog</title>
    <link>https://requestrocket.com/blog</link>
    <description>Product updates, API governance, and engineering notes from RequestRocket.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 03 Jun 2026 14:44:22 GMT</lastBuildDate>
    <atom:link href="https://requestrocket.com/blog/rss.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title>AI Token Limits by Model: Per-Team Spend Control</title>
      <link>https://requestrocket.com/blog/ai-token-limits-by-model</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/ai-token-limits-by-model</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <description>Track and cap token use per AI model within a single proxy. Conditional meters apply independent limits to each model without touching your app code.</description>
    </item>
    <item>
      <title>Local AI Agent Monitoring: Visibility Into API Usage</title>
      <link>https://requestrocket.com/blog/monitoring-local-ai-agents-api-usage</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/monitoring-local-ai-agents-api-usage</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <description>Local AI agents make API calls your observability stack never sees. RequestRocket&apos;s request logs, telemetry, and meters give you full per-agent visibility without touching agent code.</description>
    </item>
    <item>
      <title>OpenClaw and NemoClaw: API Data Risks and Mitigations</title>
      <link>https://requestrocket.com/blog/openclaw-nemoclaw-data-risk</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/openclaw-nemoclaw-data-risk</guid>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <description>OpenClaw and NemoClaw access real APIs with real credentials. Here&apos;s how RequestRocket contains the blast radius when they misbehave or are compromised.</description>
    </item>
    <item>
      <title>OpenClaw API Security: Control What Your Agent Can Call</title>
      <link>https://requestrocket.com/blog/securing-apis-openclaw-uses</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/securing-apis-openclaw-uses</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <description>OpenClaw calls third-party APIs autonomously on your behalf. Here&apos;s how gateway-level credentials, rules, and filters lock down exactly what it can access.</description>
    </item>
    <item>
      <title>Connect Power BI to any API using Basic Auth — without compromising on security</title>
      <link>https://requestrocket.com/blog/connect-power-bi-to-any-api</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/connect-power-bi-to-any-api</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <description>Power BI&apos;s web connector speaks Basic Auth. Most modern APIs don&apos;t. RequestRocket bridges the gap: accept Basic Auth from Power BI and forward requests using OAuth2, bearer tokens, or any other auth type — with rotation, monitoring, and no credentials in your dataset.</description>
    </item>
    <item>
      <title>Introducing dedicated managed and fully self-hosted RequestRocket</title>
      <link>https://requestrocket.com/blog/dedicated-managed-self-hosted</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/dedicated-managed-self-hosted</guid>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <description>RequestRocket now offers dedicated managed and fully self-hosted deployment options — giving teams on Business tier dedicated data plane infrastructure while continuing to use the same central control plane, API, and management console they already know.</description>
    </item>
    <item>
      <title>Zero-downtime migration of API authentication systems</title>
      <link>https://requestrocket.com/blog/zero-downtime-migration-api-authentication</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/zero-downtime-migration-api-authentication</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
      <description>Use service abstraction at the gateway layer to migrate between authentication providers — moving your entire API consumer base without downtime, breaking changes, or flag-day cutover risks.</description>
    </item>
    <item>
      <title>The three pillars of a strong API program</title>
      <link>https://requestrocket.com/blog/three-pillars-strong-api-program</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/three-pillars-strong-api-program</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <description>Authentication, documentation, and protection are the foundational capabilities every successful API program needs. Here&apos;s how RequestRocket addresses each one in a unified gateway layer.</description>
    </item>
    <item>
      <title>Why RequestRocket has the most flexible rate limiter around</title>
      <link>https://requestrocket.com/blog/most-flexible-rate-limiter</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/most-flexible-rate-limiter</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description>A look at the rate limiting architecture that makes it possible to enforce different limits per proxy, credential, path, method, and header value — and why flexibility here matters for real-world API governance.</description>
    </item>
    <item>
      <title>Debug faster with RequestRocket&apos;s built-in debugging tools</title>
      <link>https://requestrocket.com/blog/debug-faster-with-requestrocket</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/debug-faster-with-requestrocket</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <description>Stop guessing at what&apos;s happening inside your gateway. The request log, per-request inspection, and telemetry API give you the information you need to diagnose integration issues quickly.</description>
    </item>
    <item>
      <title>Add Auth0 JWT authentication to any API in minutes</title>
      <link>https://requestrocket.com/blog/add-auth0-jwt-authentication-to-any-api</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/add-auth0-jwt-authentication-to-any-api</guid>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <description>A quick-start guide to integrating Auth0 JWT authentication at the RequestRocket gateway layer — protecting your upstream API without any backend code changes.</description>
    </item>
    <item>
      <title>Route API traffic by Auth0 JWT claim values</title>
      <link>https://requestrocket.com/blog/route-api-traffic-by-auth0-jwt-claims</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/route-api-traffic-by-auth0-jwt-claims</guid>
      <pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate>
      <description>Use the claims inside Auth0 JWT tokens to make intelligent routing decisions at the RequestRocket gateway — directing traffic to different targets or applying different policies based on user attributes.</description>
    </item>
    <item>
      <title>API keys and JWTs: stronger together</title>
      <link>https://requestrocket.com/blog/api-keys-and-jwts-stronger-together</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/api-keys-and-jwts-stronger-together</guid>
      <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
      <description>API keys and JWTs aren&apos;t competing mechanisms — they solve different parts of the authentication problem. Here&apos;s how to layer them on the same proxy for defence in depth.</description>
    </item>
    <item>
      <title>How to extract and use JWT claims in your API gateway</title>
      <link>https://requestrocket.com/blog/how-to-extract-and-use-jwt-claims</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/how-to-extract-and-use-jwt-claims</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <description>Practical techniques for pulling data out of JWT tokens at the gateway layer — and using those claims to enforce fine-grained access control, tenant isolation, and per-user response redaction without touching your backend.</description>
    </item>
    <item>
      <title>How to make API governance actually manageable</title>
      <link>https://requestrocket.com/blog/api-governance-manageable</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/api-governance-manageable</guid>
      <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
      <description>API governance fails when it becomes a process overhead nobody follows. Here&apos;s how combining a gateway, explicit proxy records, rules, and telemetry turns governance into something teams will actually use.</description>
    </item>
    <item>
      <title>Shadow APIs outnumber known APIs 10-to-1 in financial services</title>
      <link>https://requestrocket.com/blog/shadow-apis-financial-services</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/shadow-apis-financial-services</guid>
      <pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate>
      <description>Unmanaged API sprawl is a ticking compliance clock in fintech. Why API governance isn&apos;t optional when operating in regulated markets — and what a practical remediation looks like.</description>
    </item>
    <item>
      <title>Archive every API request to AWS S3 with custom policies</title>
      <link>https://requestrocket.com/blog/archive-api-requests-to-s3</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/archive-api-requests-to-s3</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
      <description>How to use RequestRocket&apos;s filter system to capture and archive every inbound request and its response to S3 — useful for audit trails, compliance, and debugging without touching your backend.</description>
    </item>
    <item>
      <title>API Monitoring Tools: Real-time Observability for Every Outbound API Call</title>
      <link>https://requestrocket.com/blog/better-api-monitoring-opentelemetry</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/better-api-monitoring-opentelemetry</guid>
      <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
      <description>Monitor API latency, error rates, and request volume across all your upstream dependencies. RequestRocket exports telemetry to any OpenTelemetry-compatible backend — Datadog, Tempo, New Relic, and more.</description>
    </item>
    <item>
      <title>Fine-grained authorization with RequestRocket and OktaFGA</title>
      <link>https://requestrocket.com/blog/fine-grained-authorization-requestrocket-oktafga</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/fine-grained-authorization-requestrocket-oktafga</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <description>Combine RequestRocket&apos;s gateway with OktaFGA&apos;s relationship-based access control to enforce authorization policies that go well beyond simple role checks — without modifying your backend.</description>
    </item>
    <item>
      <title>The API gateway at the centre of the AI revolution</title>
      <link>https://requestrocket.com/blog/api-gateway-at-the-centre-of-ai-revolution</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/api-gateway-at-the-centre-of-ai-revolution</guid>
      <pubDate>Thu, 25 Dec 2025 00:00:00 GMT</pubDate>
      <description>APIs are the connective tissue linking AI models to real-world data and actions. The gateway is the layer that makes those connections safe, observable, and scalable — here&apos;s why that matters now.</description>
    </item>
    <item>
      <title>Two essential security policies for AI and MCP endpoints</title>
      <link>https://requestrocket.com/blog/two-essential-security-policies-for-mcp</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/two-essential-security-policies-for-mcp</guid>
      <pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate>
      <description>Prompt injection detection and secret masking are the two gateway policies every team should implement before exposing endpoints to LLM-driven traffic. Here&apos;s how to configure both.</description>
    </item>
    <item>
      <title>Controlling what MCP callers can access using JWT claims</title>
      <link>https://requestrocket.com/blog/oauth-secured-remote-mcp-access</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/oauth-secured-remote-mcp-access</guid>
      <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
      <description>How RequestRocket sits between MCP clients and your target API to inspect JWT claims — including sub — and block requests that shouldn&apos;t reach the underlying service.</description>
    </item>
    <item>
      <title>Defending MCP servers against prompt injection attacks</title>
      <link>https://requestrocket.com/blog/defending-mcp-servers-against-prompt-injection</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/defending-mcp-servers-against-prompt-injection</guid>
      <pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate>
      <description>Prompt injection is a real and growing threat for MCP-connected services. Here&apos;s how to use gateway-level filter rules to detect and block injection attempts before they reach your LLM.</description>
    </item>
    <item>
      <title>JWT vs API key auth for machine-to-machine APIs</title>
      <link>https://requestrocket.com/blog/jwt-vs-api-key-auth-m2m</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/jwt-vs-api-key-auth-m2m</guid>
      <pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate>
      <description>A practical comparison of JWT and API key authentication for M2M use cases — covering security, complexity, and the real-world scenarios where each approach makes sense.</description>
    </item>
    <item>
      <title>API key authentication: best practices and security guidance</title>
      <link>https://requestrocket.com/blog/api-key-authentication-best-practices</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/api-key-authentication-best-practices</guid>
      <pubDate>Thu, 13 Nov 2025 00:00:00 GMT</pubDate>
      <description>A practical guide to API key generation, storage, scoping, rotation, and revocation — with concrete patterns for keeping credentials out of your source code and blast radius small.</description>
    </item>
    <item>
      <title>In defence of API keys as a security mechanism</title>
      <link>https://requestrocket.com/blog/in-defence-of-api-keys</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/in-defence-of-api-keys</guid>
      <pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate>
      <description>API keys have been called outdated and insecure. That view is wrong for most practical scenarios. Here&apos;s the case for why they remain a sound, auditable choice — and how to use them well.</description>
    </item>
    <item>
      <title>Taming API key chaos for autonomous AI agents</title>
      <link>https://requestrocket.com/blog/taming-api-key-chaos-for-ai-agents</link>
      <guid isPermaLink="true">https://requestrocket.com/blog/taming-api-key-chaos-for-ai-agents</guid>
      <pubDate>Thu, 30 Oct 2025 00:00:00 GMT</pubDate>
      <description>As AI agents scale across your stack, credential management spirals fast. Here&apos;s how a gateway-first approach brings order to key rotation, scoping, and access control for agent-driven traffic.</description>
    </item>
  </channel>
</rss>