Week of September 27 – October 3, 2026
The Agent Got a Wallet, and Its Keys Are Still in Someone Else's Pocket
By Kin Lane · Sent October 5, 2026
This was APIDays London week, and the days before you get on a plane to talk about APIs are a good time to find out whether what you are going to say is still true.
So I did two things before I left. I re-scored twenty-six thousand companies on the Kin Score, five days ahead of the date I had pinned it to, so that a full re-score would not be the last thing I did before getting on a plane. And I read all 110 sessions on the APIDays London agenda and mapped every one of them to the facet of the Kin Score it speaks to. Agent readiness was the main subject of 33 talks and came up in 61.
The industry spent the same week answering a question the agenda only gestured at. Last week everyone rebuilt the front door for agents. This week they put a till behind it.

The Agent Got a Wallet
- Cloudflare opened Monetization Gateway in closed beta. Sellers define which requests require payment, what they cost, and where the money goes — for APIs, MCP tools, sites and datasets. The New Stack asked the right follow-up in its headline: Cloudflare brings paid access to MCP tools, so who controls the agent’s spending? Nobody has a good answer to that yet, and it is going to matter more than the price.
- AWS Marketplace shipped an AI agent skill for usage-based metering — an agent-guided way for sellers to build and validate pay-as-you-go metering from inside their coding assistant. The meter is now something an agent helps you build.
- I spent the week on the provider’s side of the same idea. Pipedrive put a price on every tool call: 371
x-token-costvalues across its operations, from 1 to 40, sitting right underneath an agent-facing description. Every operation in the API is priced, in the contract, where an agent can read it before it calls. - The cost-control layer kept forming around it. Kong pitched AI Gateway as the place to take control of the economics of AI and shipped Kong AI Gateway 2.2. Cloudflare’s AI Gateway now shows where a model is more capable than the task needs. Telnyx gave each team its own models, budgets and guardrails. And the most concrete number of the week came from Meta and Google: Instagram Direct cut token cost per agent session by 33% by rebuilding the UI architecture underneath it.
- Agentic commerce is no longer hypothetical in the data. Forter published what AI agents are already ordering on its network across August and September. Auth0 wrote up securing agentic commerce with the Universal Commerce Protocol. And DatoCMS made the point most of the commerce conversation skips: shopping agents decide what to recommend by reading your content, so the content is the storefront.
Two weeks ago this newsletter was about the bill the agent runs up. This week it is about the bill the agent pays. Those are the same meter read from opposite sides, and the description layer — what an operation is, what it costs, what it needs — is the only place both sides can read the same number.

Three MCP Auth Bugs in Thirty Days, One Root Cause
Last week I wrote that WorkOS had the best-titled post of the week. They have the best-titled post of this one too: three MCP auth bugs in 30 days, one root cause — trusting what the other side said. The MCP Python SDK, the Rust SDK and LiteLLM each accepted authentication input that nobody verified.
- The good news is that the fixes are now arriving in the specification and the SDKs, not just in blog posts. The official MCP SDK shipped DPoP and scope challenges, turning the 2026-07-28 spec’s authorization hardening into code. Cloudflare’s Workers OAuth Provider went v1 with full support for MCP 2026-07-28, splitting the authorization server from the MCP resource server. Qlik now supports OAuth Client ID Metadata Documents for MCP connections. Those are the unglamorous pieces that make agent auth work without a human pasting a key somewhere.
- The bad news is the gap that is left. Bifrost’s MCP flaw shows the protocol still has no client-authentication story. An MCP event subscription is a credential, and almost nobody is treating it as one. CoPhish turned an agent-building platform into an OAuth phishing vector.
- And the credential problem underneath all of it got a number. VentureBeat reports that 22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials — which means they can enforce a permission but cannot tell you which agent used it. Akeyless walked through the limits of vaulting agent credentials, using Unit 42’s prompt-injected AgentCore agent that stole and replayed a credential that was stored correctly.
- The answers being built all look the same: let the agent use the credential without ever holding it. DigitalOcean on how it manages credentials for autonomous agents. Lit Protocol’s Agent Keychain, with an honest section on what it does not protect against. GitGuardian’s look at AWS Dogwood and stateful authorization for agents. And on the standards side, WorkOS on SCIM for AI one year later — the two competing IETF agent identity drafts are now one draft, written together.
- If you are choosing where to put that middle layer, WorkOS compared the MCP gateways from Cloudflare, Okta, Auth0 and Microsoft, including what your MCP server still has to do itself. That last part is the part to read.
📄 The Pricing of AI APIs — Cloudflare will now let you charge an agent per call, and Pipedrive has already priced every operation it has. Before you put a number on yours, look at how the model labs do it. They turned out to be the most pricing-transparent class of API provider I found anywhere in the catalog — real per-token rates, the discount levers the headline number hides (caching, batch, committed use), and where pricing hides everywhere else — and that transparency is the lesson. This paper ends with a plain playbook for pricing your own API. $25

Ninety Thousand MCP Servers Scored, and 0.28% Earn an A
This was a measurement week, and I was not the only one doing it.
- Arcade’s ToolBench rescored more than 90,000 MCP servers and 630,000 tools, six months after its first pass. Only 0.28% earn an A, and the finding I would underline is the other one in their summary: the riskiest tools get the least documentation. That is backwards, and it is the kind of backwards that only shows up when someone counts.
- WorkOS on what 15,465 ungoverned MCP servers tell us about the authorization gap — a registry audit that counted servers rather than security controls, and why that number matters more than it sounds like it should.
- TestMu found that 66% of live registry MCP servers return server instructions at connection time, which makes the instructions field a prompt-injection surface before a single tool is called. Their companion piece on regression-testing a stateless MCP migration is the practical one for anyone moving to the new spec.
- And the governance products shipped to match: Snyk’s Evo agent-behavior governance went GA, starting with MCP, and Salt launched continuous MCP server visibility for Claude Enterprise.
My own numbers moved too. Kin Score 0.23 moved 25,659 of 26,192 composite scores — 7,456 up, 18,203 down, a median change of −0.8 — and 2,078 providers changed band. I did not re-cut the bands; no band’s share of the catalog moved by more than 1.4 points. I wrote out the standards that make your business agent-ready — nineteen dimensions, 139 points, almost every one of them a published standard — and started walking through the Kin Score facet by facet.
I also had to correct myself, publicly. I have been saying “16% human” about my own traffic for months. I re-measured it, and I had it backwards: 17.6% of 11.7 million requests across 27 sites came from something that declared itself an AI agent. Sixteen percent was never the human share. It was the share that tells you it is a bot.

MCP, CLI, Skills, or Your Own Agent
Measured the same way as last week, I count 77 third-party posts naming MCP in a title this week, out of 7,411. Thirteen of those are PyPI package releases rather than posts; take them out and it is 64. Last week, re-counted today with the late-arriving posts included, was 65 out of 6,260, or 63 without its two PyPI releases — I published 61 out of 6,061, and the corpus filled in after I counted. So MCP held at roughly one post in a hundred for the third week running.
The more interesting thing is what the posts are now arguing about. It is no longer whether to ship MCP. It is which surface to ship it through.
- Arize introduced its AX MCP with a post on when to use MCP, a CLI, or skills, and its framing is the right one: the question is not which one wins, it is where the agent runs and who is asking. Sentry wrote the same post from its side — Seer, the MCP server, the CLI, or your own coding agent. Apify asked whether you should build an agent or an MCP server, including what a connection costs in context. Retool wrote a version of this last week and Postman the week before. That is five vendors in three weeks publishing the same decision tree.
- Google did something worth noticing: a remote MCP server for the Google Cloud CLI, powered by
gcloudandbq. The CLI, served as MCP. And the AWS MCP Server arrived in six more regions, which is the kind of announcement you only make about infrastructure. - Skills kept arriving as their own artifact. AWS published best practices for writing DevOps agent skills, and Chainguard asked how you harden an agent skill — “the simple file type with serious complexities” is exactly right.
- The launches: Recorded Future, Zyte, CompStak’s Agent Connect (sold as its own tier, which is the commerce section again), and Supabase, which now gives every app its own MCP server for its users’ agents. And the help-centre pattern continued — Podia published five MCP pages in a day, from getting started to security and troubleshooting.

From My Desk: One Key, Three Shapes
Across 7,411 third-party posts, OpenAPI appeared in two titles, and one of them was a CISA vulnerability advisory. The other was Geoapify publishing its OpenAPI specs for AI coding tools — which is exactly the right reason to publish one in 2026, and I wish more providers framed it that way.
- The
x-mcpseries. Three companies in my catalog use an OpenAPI extension calledx-mcp, and none of them knows the others exist. Demodesk has the richest version — an object withenabled,toolNameandtitle. Eon writes a bare boolean, with two undocumented dialects in the same document. And Ripio wroteenabled: false, which a tool expecting Eon’s bare boolean will read as true. That is the post I would hand to anyone who thinks unregistered vendor extensions are a tidiness problem. They are a bug that inverts an exposure decision. - Upsert. A LinkedIn question asked why upsert is not required of every CRM API, so I measured it across 119,154 OpenAPIs from 8,006 providers: ten percent have upsert, and one percent tell you what it did.
- OpenAPI 3.2, a year later. Fastify now speaks OpenAPI 3.2. One line of release notes, and the kind of release I pay most attention to — a specification version only becomes real when the code-first frameworks that generate contracts can produce it.
- The Kin Score, facet by facet. Discoverability, contract quality, contract governance and developer ergonomics so far. And the four ways providers react to a Kin Score: silence, a takedown request, a roadmap, or a pull request.
- The view from outside. You cannot see your own API from the outside — everyone tests from inside their own advantage, logged in, on the VPN, with the environment variable already set.
- And one ask. I am looking for design partners for APIs.io On-Premise. The profiling that powers the public catalog now runs on a box, which means the question I have been answering “not yet” for twelve years — can I run this inside my company? — finally has a different answer. If your organization cannot say what APIs it has, I would like to talk.
I want to end on the thread connecting the money and the keys, because it is the same thread. Cloudflare will let you charge an agent per call. Pipedrive already priced every operation. And twenty-two of thirty-seven companies cannot tell you which of their agents made a given call, because their agents share a credential. You cannot bill an identity you cannot see.
Charging agents is going to make the identity problem urgent faster than any security incident has, because unattributed spend gets noticed by finance, not just by security. The companies that can say, in a contract, what each operation costs, which identity is calling it, and what it is allowed to do will be the ones that can actually get paid.
See you next week.
🔌 APIs.io — read any provider’s Kin Score for a penny — Since I spent this issue on agents paying per call, here is ours, described plainly.
Every provider’s Kin Score page is free to read in a browser. Through the API, one provider’s rating, its facets, or its rating history costs $0.01 per call on the Access plan — with a card, or paid with x402 in USDC with no account at all. Call it without a key and the 402 response tells an agent how to pay for that one request. The 0.23 movers — who went up, who went down — are $0.05 a call, and the whole scored dataset is the Understanding plan.
curl -i "https://apis.io/api/v1/providers/stripe/rating"
And the catalog’s 6,714 MCP server profiles remain free, no key, no tier.
