Designing Scalable, Secure, and AI-Ready APIs - Full Day
APIs are no longer just integration endpoints. APIs are the control surface where humans, applications, automations, and AI agents turn intent into action.
In the past, APIs were mostly consumed by web apps, mobile apps, partner integrations, and backend services. In the AI era, the same APIs may be called by LLMs, autonomous agents, workflow engines, developer portals, SDKs, and multi-channel applications.
That shift changes API design.
A traditional API may be acceptable when a human developer reads documentation and writes careful client code. But when an AI agent consumes the API, vague contracts, ambiguous errors, non-idempotent writes, broad permissions, silent version changes, and weak telemetry become production risks.
This workshop gives participants a practical playbook for designing APIs that are:
contract-first
machine-readable
secure by scope
agent-safe
deterministic
retry-safe
observable
cost-aware
versioned
developer-friendly
The running case study is DreamMart, an e-commerce platform exposing APIs for product search, eligibility, checkout, order status, returns, and refunds across web, mobile, partner, and AI-agent channels.
Workshop Outcomes
- Redesign vague APIs into strict, machine-readable API contracts.
- Use OpenAPI 3.1 and JSON Schema for human and AI consumption.
- Design operationIds, schemas, examples, and metadata that agents can use safely.
- Apply agent-aware security with scoped authority, risk tiers, quotas, and kill switches.
- Prevent duplicate writes using idempotency keys, request hashes, dedupe stores, and status checks.
- Design structured errors with retryable, nextAction, remediation, and escalation guidance.
- Scale APIs for bursty, fan-out-heavy agent traffic using QPS, EPS, caching, and circuit breakers.
- Version APIs safely for long-lived human, partner, SDK, and AI-agent consumers.
- Trace AI vs human API traffic using agent_run_id, chain_id, tool_id, tenant_id, schema_version, and cost_usd.
- Apply the 10 Launch Gates to decide whether an API is ready for production AI consumption.
Who Should Attend
- Backend Developers & API Designers creating APIs for human + machine interfaces
- Software & Enterprise Architects designing multi-cloud, AI-integrated systems
- Security Engineers protecting APIs against agent misuse and AI-driven threats
- DevRel & Product Teams building public API ecosystems and developer experiences
Key Takeaways
- How to design AI-readable APIs with contract-first principles
- Security blueprints to protect APIs from human and agent-driven abuse
- Strategies for scalable, cost-aware, and resilient API operations
- Practical patterns for versioning, governance, and lifecycle management
- Techniques to deliver amazing developer experiences for humans + AI agents
About Rohit Bhardwaj
Rohit Bhardwaj is a Director of AI & Data Architecture at Salesforce, where he focuses on enterprise AI, agentic systems, cloud-native architecture, distributed systems, data platforms, security, and large-scale transformation.
Over his career, Rohit has designed and led complex enterprise platforms across AWS, Google Cloud, microservices, real-time data, API ecosystems, resilient distributed systems, and AI-enabled architectures. His work increasingly focuses on the challenges enterprises face as software evolves from deterministic services to AI-native and agentic systems—particularly around reliability, governance, evidence, security, observability, cost, and safe autonomy.
Rohit is the author of System Design with AI Interview Guide: Designing Scalable, Agentic, and Defensible Systems, published by Apress. The book presents a modern approach to system design covering scalability, distributed systems, AI architecture primitives, security, reliability, economics, agentic systems, and real-world architectures including e-commerce, ride sharing, payments, fraud detection, messaging, video streaming, file storage, and search. (Springer Link)
Book:
Amazon: https://a.co/d/09Zs1twa
Publisher / Springer Nature: https://link.springer.com/book/10.1007/979-8-8688-2782-2
O'Reilly: https://learning.oreilly.com/library/view/system-design-with/9798868827822/
Rohit is also an O’Reilly instructor and a frequent speaker at technology conferences including No Fluff Just Stuff, UberConf, GIDS, and other international events. His talks focus on practical architecture lessons from building and operating complex systems, including AI control planes, trusted agents, inference at scale, evidence-first RAG, AI security, distributed-system failure, and AI-era software architecture.
As a trusted advisor and architecture leader, Rohit works at the intersection of business strategy and deep technical architecture—helping teams translate complex business problems into scalable, resilient, secure, and economically sustainable systems.
Rohit holds an MBA in Corporate Entrepreneurship from Babson College and graduate-level education in Computer Science from Boston University and Harvard University.
Connect with Rohit:
LinkedIn: http://linkedin.com/in/rohit-bhardwaj-cloud
X / Twitter: @rbhardwaj1