In this eye-opening talk from APISEC|CON, Michaela Halliwell—Senior Data Product Manager at HCSS and author of The API Nerd—unpacks the real-world anatomy of a great developer portal and the security risks you may be overlooking.
🚨 Why should security teams care about dev portals?
Because poorly structured portals, undocumented endpoints, and public exposure of internal logic can open the door to exploitation, abuse, and API-based attacks.
👀 In this session, you’ll learn:
The 20+ must-have features of modern, secure developer portals
How to audit your own portal live with Michaela’s interactive walkthrough
Where GenAI is transforming portal usability—and creating new security challenges
Why “Time to First Call” (TTFC) matters more than ever in securing APIs
Examples from Stripe, Spotify, Twilio, and HCSS to benchmark your own approach
How dev portals can signal trust or broadcast risk to potential attackers
🎯 Whether you’re a CISO, API Product Manager, DevRel lead, or AppSec pro, this talk will help you turn your dev portal from a neglected surface into a hardened, user-first product.
📌 Subscribe and explore more expert sessions at APISEC University.
#developerportals #apisecuritytesting #devsecops #appsec #genai #mcp #apisecurity #cybersecurity