CloudAPPi Takes MCP Governance to apidays Munich
apidays Munich 2026 —part of FOST Munich, with 1,000+ attendees, 400+ companies and more than 100 sessions— brought together architects, platform engineers and AI leaders around the future of APIs and AI. CloudAPPi joined as a partner, with its own stand and two talks.
On day one, Marco Antonio Sanz took the stage to share his vision of the API ecosystem and the MCP DevOps revolution. On day two, our Head of API Department, Jesús Vallejo, delivered “Building MCP in the Era of Governance” — the session we unpack in this article.
The Age of the Agent Meets the Age of Governance
AI agents are no longer “the next big thing”: they are already in production, hitting your APIs and consuming your data through the Model Context Protocol (MCP). As Jesús put it at apidays, the question is no longer whether to adopt MCP, but how to govern it, because agents:
- Generate “shadow traffic”: massive, unpredictable requests, often outside expected usage patterns.
- Act autonomously: chaining multiple tool and API calls in milliseconds to complete a task.
- Consume resources without limits: burning cost and expanding the attack surface if no controls are in place.
- Standardise on MCP: the protocol connecting agents to tools needs a dedicated control layer.
MCP Ops: Governing the Protocol at Scale
The heart of Jesús’s talk was MCP Ops: applying to MCP the same operational discipline we already know for REST APIs. Four pillars stood out.
Access control
Agents should not have unrestricted access to your systems. Policies define which operations each agent can execute —and in which context— before it can invoke any internal tool.
Compliance and traceability
Every interaction is logged and auditable. A complete audit trail turns autonomous behaviour into something you can explain, review and defend.
Security
Authentication, authorization and sandboxing sit between the agent and your infrastructure, guarding against unauthorized access, unwanted actions and prompt injection.
Observability
Full traces of each agent conversation —which tools it invoked, how many tokens it consumed, what errors it produced— are essential for debugging, optimizing and auditing agents in production.
The MCP Gateway: Closing the Security Gap
Think of MCP as the “USB-C of agents”: a universal way for any model to connect with any tool in a predictable manner. But that openness, left uncontrolled, introduces risk.
The security problem MCP introduces
Without an intermediate control layer, MCP exposes your infrastructure to unauthorized access to sensitive data, execution of unwanted actions in critical systems and prompt injections that manipulate agent behaviour.
MCP Gateway: closing the gap
The MCP Gateway acts as the intermediary between the agent and internal tools: it enforces access policies, logs all interactions and limits which operations each agent can run in each context.
What the apidays Munich Audience Took Home
Beyond the theory, Jesús’s session connected with an audience already operating agents in production. Here is CloudAPPi’s apidays Munich in two parts.
Part 1: The Talk
Presented by Jesús Vallejo · Head of API Department
- Agents in production and the challenge of “shadow traffic”.
- MCP as the new standard for agent-to-tool integration.
- MCP Ops: control, compliance, security and observability.
- The MCP Gateway as a governance and security layer.
Part 2: CloudAPPi at apidays
The team on the ground
- Marco Antonio Sanz’s day-one talk on the API ecosystem and MCP DevOps.
- The CloudAPPi stand, represented by Milan Kekić, a meeting point across both days.
- Networking with architects, platform engineers and AI leaders.
- 1,000+ attendees, 400+ companies and 100+ sessions at FOST Munich.
Our Speaker
Jesús Vallejo, Head of API Department at CloudAPPi, led the talk “Building MCP in the Era of Governance”, with a practical vision of how to implement the Model Context Protocol while maintaining control, compliance and security in modern API ecosystems.
Marco Antonio Sanz opened CloudAPPi’s participation on day one, sharing his vision of the API ecosystem and the MCP DevOps revolution.
📅 apidays Munich 2026 · 8–9 July · MCP in the Era of Governance
Govern MCP and AI Agents at Scale
Ready to bring control, compliance and security to your MCP and agent ecosystem? CloudAPPi’s MCP 360 helps you govern the Model Context Protocol end to end — from strategy to production.
Author