SlideShare a Scribd company logo
Boost API Development with Practical AI Tooling
apidays 2025, New York
Sumit Amar
@ChiefCoder
May 15, 2025
Disclaimer
The opinions expressed in this presentation and on the following slides are solely
those of the presenter, and not necessarily those of WEX. Products, Sites, and tools
mentioned focus on commercially available technology, and are for illustrative,
educational purposes only. The views expressed in this presentation do not endorse
or recommend any commercial products, process, or service.
Sumit Amar
Sumit in the last 20 years:
VP of Engineering
Agenda
• Introduction and Outcomes
• Stages of API Development
• Challenges in API Development Cycle
• Remediating Challenges with AI Tools
• Summary
The Why
The Why
• About a quarter of the current YC
startups, 95% of the code was written
by AI – Gerry Tan, YC CEO
• “What that means for founders is that
you don’t need a team of 50 or 100
engineers,” Tan said. “You don’t have
to raise as much. The capital goes
much longer.”
Source: https://www.cnbc.com/2025/03/15/y-combinator-startups-are-fastest-growing-in-fund-history-because-of-ai.html
The Why – PwC
Source: https://www.pwc.com/gx/en/issues/c-suite-insights/the-leadership-agenda/AI-jobs-impact.html
The Why - HBR
Source: https://hbr.org/2024/11/research-how-gen-ai-is-already-impacting-the-labor-market
Primer of Stages in API Dev
• Design and Specification
• Code / Implementation
• Testing and Validation
• Monitoring
• Continuous Security Consideration
• Developer Experience (Portal,
Sandbox etc.)
Challenges in API Dev
• Slide in spec and implementation.
• Tedious, predictable, repetitive code a
and its review cycle.
• Lower than 90% code coverage.
• Keeping monitors and alarms up to
date, manually and via code.
• Expensive security / penetration testing.
• UI development cost for building portals.
• Managing public sandbox environments
Addressing The Design Phase
• Using GPT-4 (via ChatGPT or
Open AI API) and Claude
Sonnet in Copilot and Cursor
to generate OpenAPI 3.0
specs from descriptions
Generating Mundane Code
• GitHub Copilot (using GPT4, Gemini, Sonnet ) -
generates boilerplate code from comments or
API specs.
• Amazon CodeWhisperer - spits API Contracts
using Postman AI or (for serverless tech such as
Lambda contract generation and API
Gateway integration)
• Swagger Codegen / OpenAPI Generator -
generates scaffolding codebase / server stubs
and client SDKs (Java, Python, TypeScript, etc.)
from OpenAPI specs.
Developer Efficiency
• VS Code with Copilot to spec, generate code, and
find errors
• Cursor AI – a VS Code based native-AI IDE to
accelerate development initiatives by generating,
explaining, describing, and fixing code. Like Copilot it
integrates with several LLMs (such as Sonnet – which
helps in architecting, code gen, and code reviews)
• Tabnine – ML-powered code completion across
multiple languages.
• Cody (by Sourcegraph) – offers codebase-level Q&A
and refactoring guidance using AI over entire
repositories
Testing and Validation
• Testfully – an AI-powered API testing platform
that auto-generates test scenarios from
OpenAPI specs.
• PactFlow + Pact - to do consumer-driven
contract testing. PactFlow offers AI-powered
change analysis.
• Postman AI - to auto-generate test cases,
explain responses, and analyze test coverage.
• Diffblue Cover - Uses AI to write unit tests for
Java APIs by analyzing the codebase.
Monitoring
• Datadog Watchdog - uses machine
learning to detect anomalies in API
latency, throughput, and error rate—
alerting when there's an unexpected
pattern.
• ChatGPT – to craft contract intelligence,
which allows us to mine API logs to
surface most/least used endpoints,
detect deprecated usage, or suggest
caching strategies.
Security Considerations
• Snyk Code - can review code snippets
and flag potential risks before merge.
• StackHawk - can scan API code and
specs for common vulnerabilities (e.g.,
injection attacks, broken auth). It can
scan the API (via OpenAPI spec or CI
pipeline) for OWASP vulnerabilities like
broken auth or injection flaws.
Developer Experience
• ReadMe AI - auto-generates dynamic,
interactive API docs using OpenAPI specs and
custom content.
• Mintlify - automatically generates elegant
developer documentation from source code
and offers AI summaries for code comments.
• Swimm - helps explain and maintain code,
including legacy mainframe codebase.
• Chatbots - on DevEx to answer developers’
questions without having them raise customer
contacts / support tickets.
Demo
• VS Code with Copilot
• Cursor AI with Sonnet
Summary
• Using AI tooling in development Is Not
optional.
• AI tooling is abundant for all stages of the
cycle.
• AI tools are to be used to grow. business,
not only add efficiencies
• AI tooling could reduce the need of
multiple expert developers.
• AI tooling must be used to reason/explain
code.
Thank you

More Related Content

Similar to apidays New York 2025 - Boost API Development Velocity with Practical AI Tooling by Sumit Amar (WEX) (20)

PPTX
Accelerate your Sitecore development with GenAI
Ahmed Okour
 
PPT
Six Steps To Build A Successful API
Chris Haddad
 
PPT
Six Steps to Build Successful APIs
WSO2
 
PDF
API SECURITY
Tubagus Rizky Dharmawan
 
PDF
API, Integration, and SOA Convergence
Kasun Indrasiri
 
PPTX
2022 APIsecure_Securing APIs with Open Standards
APIsecure_ Official
 
PDF
IBM API management Philip Little
Valeri Illescas
 
PDF
Oracle API Platform Cloud Service Best Practices & Lessons Learnt
luisw19
 
PDF
Api design best practice
Red Hat
 
PPTX
API Design – More than just a Payload Definition
Phil Wilkins
 
PDF
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2
 
PPTX
Design-first API Development using Swagger and Node
Apigee | Google Cloud
 
PPTX
API Gateways are going through an identity crisis
Christian Posta
 
PPTX
Extend soa with api management spoug- Madrid
Vinay Kumar
 
PDF
WSO2Con Asia 2014 - Building the API-Centric Enterprise
WSO2
 
PDF
Day 1 axway apim-training
Nextel Telecomunicações
 
PDF
Extend soa with api management Sangam18
Vinay Kumar
 
PPTX
the 12 facets of OpenAPI
Cisco DevNet
 
PPTX
Pain Points In API Development? They’re Everywhere
Nordic APIs
 
PDF
[WSO2 Integration Summit Bern 2019] API-led Integration
WSO2
 
Accelerate your Sitecore development with GenAI
Ahmed Okour
 
Six Steps To Build A Successful API
Chris Haddad
 
Six Steps to Build Successful APIs
WSO2
 
API, Integration, and SOA Convergence
Kasun Indrasiri
 
2022 APIsecure_Securing APIs with Open Standards
APIsecure_ Official
 
IBM API management Philip Little
Valeri Illescas
 
Oracle API Platform Cloud Service Best Practices & Lessons Learnt
luisw19
 
Api design best practice
Red Hat
 
API Design – More than just a Payload Definition
Phil Wilkins
 
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2
 
Design-first API Development using Swagger and Node
Apigee | Google Cloud
 
API Gateways are going through an identity crisis
Christian Posta
 
Extend soa with api management spoug- Madrid
Vinay Kumar
 
WSO2Con Asia 2014 - Building the API-Centric Enterprise
WSO2
 
Day 1 axway apim-training
Nextel Telecomunicações
 
Extend soa with api management Sangam18
Vinay Kumar
 
the 12 facets of OpenAPI
Cisco DevNet
 
Pain Points In API Development? They’re Everywhere
Nordic APIs
 
[WSO2 Integration Summit Bern 2019] API-led Integration
WSO2
 

More from apidays (20)

PDF
apidays Singapore 2025 - What exactly are AI Agents by Aki Ranin (Earthshots ...
apidays
 
PPTX
apidays Singapore 2025 - Enhancing Developer Productivity with UX (Government...
apidays
 
PDF
apidays Singapore 2025 - Building Finance Innovation Ecosystems by Umang Moon...
apidays
 
PPTX
apidays Singapore 2025 - 4 Identity Essentials for Scaling SaaS in Large Orgs...
apidays
 
PDF
apidays New York 2025 - Using GraphQL SDL files as executable API Contracts b...
apidays
 
PDF
apidays New York 2025 - The Future of Small Business Lending with Open Bankin...
apidays
 
PDF
apidays New York 2025 - Life is But a (Data) Stream by Sandon Jacobs (Confluent)
apidays
 
PDF
apidays New York 2025 - Beyond Webhooks: The Future of Scalable API Event Del...
apidays
 
PPTX
apidays New York 2025 - API Security and Observability at Scale in Kubernetes...
apidays
 
PDF
apidays New York 2025 - Unifying OpenAPI & AsyncAPI by Naresh Jain & Hari Kri...
apidays
 
PPTX
apidays New York 2025 - The Challenge is Not the Pattern, But the Best Integr...
apidays
 
PPTX
apidays New York 2025 - Why an SDK is Needed to Protect APIs from Mobile Apps...
apidays
 
PPTX
apidays New York 2025 - The FINOS Common Domain Model for Capital Markets by ...
apidays
 
PPTX
apidays New York 2025 - Fast, Repeatable, Secure: Pick 3 with FINOS CCC by Le...
apidays
 
PPTX
apidays New York 2025 - Why I Built Another Carbon Measurement Tool for LLMs ...
apidays
 
PPTX
apidays New York 2025 - Building Scalable AI Systems by Sai Prasad Veluru (Ap...
apidays
 
PPTX
apidays New York 2025 - Lessons From Two Technical Transformations by Leah Hu...
apidays
 
PDF
apidays New York 2025 - Breaking Barriers: Lessons Learned from API Integrati...
apidays
 
PPTX
apidays New York 2025 - Building Agentic Workflows with FDC3 Intents by Nick ...
apidays
 
PPTX
apidays New York 2025 - Computers are still dumb by Ben Morss (DeepL)
apidays
 
apidays Singapore 2025 - What exactly are AI Agents by Aki Ranin (Earthshots ...
apidays
 
apidays Singapore 2025 - Enhancing Developer Productivity with UX (Government...
apidays
 
apidays Singapore 2025 - Building Finance Innovation Ecosystems by Umang Moon...
apidays
 
apidays Singapore 2025 - 4 Identity Essentials for Scaling SaaS in Large Orgs...
apidays
 
apidays New York 2025 - Using GraphQL SDL files as executable API Contracts b...
apidays
 
apidays New York 2025 - The Future of Small Business Lending with Open Bankin...
apidays
 
apidays New York 2025 - Life is But a (Data) Stream by Sandon Jacobs (Confluent)
apidays
 
apidays New York 2025 - Beyond Webhooks: The Future of Scalable API Event Del...
apidays
 
apidays New York 2025 - API Security and Observability at Scale in Kubernetes...
apidays
 
apidays New York 2025 - Unifying OpenAPI & AsyncAPI by Naresh Jain & Hari Kri...
apidays
 
apidays New York 2025 - The Challenge is Not the Pattern, But the Best Integr...
apidays
 
apidays New York 2025 - Why an SDK is Needed to Protect APIs from Mobile Apps...
apidays
 
apidays New York 2025 - The FINOS Common Domain Model for Capital Markets by ...
apidays
 
apidays New York 2025 - Fast, Repeatable, Secure: Pick 3 with FINOS CCC by Le...
apidays
 
apidays New York 2025 - Why I Built Another Carbon Measurement Tool for LLMs ...
apidays
 
apidays New York 2025 - Building Scalable AI Systems by Sai Prasad Veluru (Ap...
apidays
 
apidays New York 2025 - Lessons From Two Technical Transformations by Leah Hu...
apidays
 
apidays New York 2025 - Breaking Barriers: Lessons Learned from API Integrati...
apidays
 
apidays New York 2025 - Building Agentic Workflows with FDC3 Intents by Nick ...
apidays
 
apidays New York 2025 - Computers are still dumb by Ben Morss (DeepL)
apidays
 
Ad

Recently uploaded (20)

DOCX
COT Feb 19, 2025 DLLgvbbnnjjjjjj_Digestive System and its Functions_PISA_CBA....
kayemorales1105
 
PPTX
Monitoring Improvement ( Pomalaa Branch).pptx
fajarkunee
 
PDF
Blood pressure (3).pdfbdbsbsbhshshshhdhdhshshs
hernandezemma379
 
DOCX
brigada_PROGRAM_25.docx the boys white house
RonelNebrao
 
PDF
TCU EVALUATION FACULTY TCU Taguig City 1st Semester 2017-2018
MELJUN CORTES
 
PDF
Datàaaaaaaaaaengineeeeeeeeeeeeeeeeeeeeeee
juadsr96
 
PPTX
Indigo dyeing Presentation (2).pptx as dye
shreeroop1335
 
PPTX
Project_Update_Summary.for the use from PM
Odysseas Lekatsas
 
PPTX
RESEARCH-FINAL-GROUP-3, about the final .pptx
gwapokoha1
 
PPTX
Krezentios memories in college data.pptx
notknown9
 
PPTX
MENU-DRIVEN PROGRAM ON ARUNACHAL PRADESH.pptx
manvi200807
 
PDF
CT-2-Ancient ancient accept-Criticism.pdf
DepartmentofEnglishC1
 
PDF
Informatics Market Insights AI Workforce.pdf
karizaroxx
 
PPTX
Daily, Weekly, Monthly Report MTC March 2025.pptx
PanjiDewaPamungkas1
 
PDF
ilide.info-tg-understanding-culture-society-and-politics-pr_127f984d2904c57ec...
jed P
 
PDF
Exploiting the Low Volatility Anomaly: A Low Beta Model Portfolio for Risk-Ad...
Bradley Norbom, CFA
 
PDF
Microsoft Power BI - Advanced Certificate for Business Intelligence using Pow...
Prasenjit Debnath
 
PPTX
Mynd company all details what they are doing a
AniketKadam40952
 
PDF
GOOGLE ADS (1).pdf THE ULTIMATE GUIDE TO
kushalkeshwanisou
 
PPTX
Data anlytics Hospitals Research India.pptx
SayantanChakravorty2
 
COT Feb 19, 2025 DLLgvbbnnjjjjjj_Digestive System and its Functions_PISA_CBA....
kayemorales1105
 
Monitoring Improvement ( Pomalaa Branch).pptx
fajarkunee
 
Blood pressure (3).pdfbdbsbsbhshshshhdhdhshshs
hernandezemma379
 
brigada_PROGRAM_25.docx the boys white house
RonelNebrao
 
TCU EVALUATION FACULTY TCU Taguig City 1st Semester 2017-2018
MELJUN CORTES
 
Datàaaaaaaaaaengineeeeeeeeeeeeeeeeeeeeeee
juadsr96
 
Indigo dyeing Presentation (2).pptx as dye
shreeroop1335
 
Project_Update_Summary.for the use from PM
Odysseas Lekatsas
 
RESEARCH-FINAL-GROUP-3, about the final .pptx
gwapokoha1
 
Krezentios memories in college data.pptx
notknown9
 
MENU-DRIVEN PROGRAM ON ARUNACHAL PRADESH.pptx
manvi200807
 
CT-2-Ancient ancient accept-Criticism.pdf
DepartmentofEnglishC1
 
Informatics Market Insights AI Workforce.pdf
karizaroxx
 
Daily, Weekly, Monthly Report MTC March 2025.pptx
PanjiDewaPamungkas1
 
ilide.info-tg-understanding-culture-society-and-politics-pr_127f984d2904c57ec...
jed P
 
Exploiting the Low Volatility Anomaly: A Low Beta Model Portfolio for Risk-Ad...
Bradley Norbom, CFA
 
Microsoft Power BI - Advanced Certificate for Business Intelligence using Pow...
Prasenjit Debnath
 
Mynd company all details what they are doing a
AniketKadam40952
 
GOOGLE ADS (1).pdf THE ULTIMATE GUIDE TO
kushalkeshwanisou
 
Data anlytics Hospitals Research India.pptx
SayantanChakravorty2
 
Ad

apidays New York 2025 - Boost API Development Velocity with Practical AI Tooling by Sumit Amar (WEX)

  • 1. Boost API Development with Practical AI Tooling apidays 2025, New York Sumit Amar @ChiefCoder May 15, 2025
  • 2. Disclaimer The opinions expressed in this presentation and on the following slides are solely those of the presenter, and not necessarily those of WEX. Products, Sites, and tools mentioned focus on commercially available technology, and are for illustrative, educational purposes only. The views expressed in this presentation do not endorse or recommend any commercial products, process, or service.
  • 3. Sumit Amar Sumit in the last 20 years: VP of Engineering
  • 4. Agenda • Introduction and Outcomes • Stages of API Development • Challenges in API Development Cycle • Remediating Challenges with AI Tools • Summary
  • 6. The Why • About a quarter of the current YC startups, 95% of the code was written by AI – Gerry Tan, YC CEO • “What that means for founders is that you don’t need a team of 50 or 100 engineers,” Tan said. “You don’t have to raise as much. The capital goes much longer.” Source: https://www.cnbc.com/2025/03/15/y-combinator-startups-are-fastest-growing-in-fund-history-because-of-ai.html
  • 7. The Why – PwC Source: https://www.pwc.com/gx/en/issues/c-suite-insights/the-leadership-agenda/AI-jobs-impact.html
  • 8. The Why - HBR Source: https://hbr.org/2024/11/research-how-gen-ai-is-already-impacting-the-labor-market
  • 9. Primer of Stages in API Dev • Design and Specification • Code / Implementation • Testing and Validation • Monitoring • Continuous Security Consideration • Developer Experience (Portal, Sandbox etc.)
  • 10. Challenges in API Dev • Slide in spec and implementation. • Tedious, predictable, repetitive code a and its review cycle. • Lower than 90% code coverage. • Keeping monitors and alarms up to date, manually and via code. • Expensive security / penetration testing. • UI development cost for building portals. • Managing public sandbox environments
  • 11. Addressing The Design Phase • Using GPT-4 (via ChatGPT or Open AI API) and Claude Sonnet in Copilot and Cursor to generate OpenAPI 3.0 specs from descriptions
  • 12. Generating Mundane Code • GitHub Copilot (using GPT4, Gemini, Sonnet ) - generates boilerplate code from comments or API specs. • Amazon CodeWhisperer - spits API Contracts using Postman AI or (for serverless tech such as Lambda contract generation and API Gateway integration) • Swagger Codegen / OpenAPI Generator - generates scaffolding codebase / server stubs and client SDKs (Java, Python, TypeScript, etc.) from OpenAPI specs.
  • 13. Developer Efficiency • VS Code with Copilot to spec, generate code, and find errors • Cursor AI – a VS Code based native-AI IDE to accelerate development initiatives by generating, explaining, describing, and fixing code. Like Copilot it integrates with several LLMs (such as Sonnet – which helps in architecting, code gen, and code reviews) • Tabnine – ML-powered code completion across multiple languages. • Cody (by Sourcegraph) – offers codebase-level Q&A and refactoring guidance using AI over entire repositories
  • 14. Testing and Validation • Testfully – an AI-powered API testing platform that auto-generates test scenarios from OpenAPI specs. • PactFlow + Pact - to do consumer-driven contract testing. PactFlow offers AI-powered change analysis. • Postman AI - to auto-generate test cases, explain responses, and analyze test coverage. • Diffblue Cover - Uses AI to write unit tests for Java APIs by analyzing the codebase.
  • 15. Monitoring • Datadog Watchdog - uses machine learning to detect anomalies in API latency, throughput, and error rate— alerting when there's an unexpected pattern. • ChatGPT – to craft contract intelligence, which allows us to mine API logs to surface most/least used endpoints, detect deprecated usage, or suggest caching strategies.
  • 16. Security Considerations • Snyk Code - can review code snippets and flag potential risks before merge. • StackHawk - can scan API code and specs for common vulnerabilities (e.g., injection attacks, broken auth). It can scan the API (via OpenAPI spec or CI pipeline) for OWASP vulnerabilities like broken auth or injection flaws.
  • 17. Developer Experience • ReadMe AI - auto-generates dynamic, interactive API docs using OpenAPI specs and custom content. • Mintlify - automatically generates elegant developer documentation from source code and offers AI summaries for code comments. • Swimm - helps explain and maintain code, including legacy mainframe codebase. • Chatbots - on DevEx to answer developers’ questions without having them raise customer contacts / support tickets.
  • 18. Demo • VS Code with Copilot • Cursor AI with Sonnet
  • 19. Summary • Using AI tooling in development Is Not optional. • AI tooling is abundant for all stages of the cycle. • AI tools are to be used to grow. business, not only add efficiencies • AI tooling could reduce the need of multiple expert developers. • AI tooling must be used to reason/explain code.