TL;DR: API and platform teams increasingly shape identity boundaries for services, secrets, and agentic workloads, and Kong Connect 2026 is an in-person conference in Los Angeles on Sept. 30 to Oct. 1, 2026, with keynotes, product launches, hands-on workshops, deep technical sessions, and an optional certification training track limited to 100 seats, according to Kong.
Editorial analysis by NHI Mgmt Group, based on content published by Kong: “# Sponsors”.
By the numbers:
- Kong Connect 2026 runs in Los Angeles from Sept. 30 to Oct. 1, 2026.
- Only 100 seats are available for the certification training add-on.
Key questions
Q: How should security teams govern API access as a non-human identity?
A: Security teams should inventory APIs as identities, assign an accountable owner, and enforce lifecycle controls for issuance, rotation, expiry, and revocation.
Q: Why do builder platforms create governance gaps for service accounts and tokens?
A: Because builders can create, embed and reuse access in the same workflow that ships code.
Practitioner guidance
- Map platform ownership of access decisions Identify where API gateways, service meshes, developer portals or runtime tooling currently create or broker access for non-human identities.
- Review secrets handling in builder workflows Trace how API keys, tokens and certificates move through build, test and deployment workflows.
- Align certification training with control ownership Use the conference training signal to identify whether your platform engineers and identity team share the same vocabulary for least privilege, service authentication and offboarding.
Bottom line: API and platform teams are increasingly shaping identity boundaries for services, secrets and emerging automated workloads.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
API infrastructure is increasingly where identity governance is actually enforced, even when IAM teams do not own it. Conferences like this matter because gateway, platform, and developer tooling now sit on the path of authentication, token exchange, and service-to-service access. That makes the operational boundary between API management and identity management far less clean than most programmes assume. Practitioners should treat API layers as identity control points, not just application plumbing.
A few things that frame the scale:
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, according to The 2024 Non-Human Identity Security Report.
- 35.6% of organisations cite managing consistent access across hybrid and multi-cloud environments as their top NHI security challenge.
A question worth separating out:
Q: Who should own access decisions when identity controls are spread across multiple platforms?
A: One accountable owner should be assigned for each control layer that can grant, narrow, or revoke access. Without that split of responsibility, identity control plane drift sets in and no team can explain which system is authoritative for denial, revocation, or audit evidence.
👉 Read our full editorial: Kong Connect 2026 in Los Angeles: IAM implications for builders
API infrastructure is increasingly where identity governance is actually enforced, even when IAM teams do not own it. Conferences like this matter because gateway, platform, and developer tooling now sit on the path of authentication, token exchange, and service-to-service access. That makes the operational boundary between API management and identity management far less clean than most programmes assume. Practitioners should treat API layers as identity control points, not just application plumbing.
A few things that frame the scale:
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, according to The 2024 Non-Human Identity Security Report.
- 35.6% of organisations cite managing consistent access across hybrid and multi-cloud environments as their top NHI security challenge.
A question worth separating out:
Q: Who should own access decisions when identity controls are spread across multiple platforms?
A: One accountable owner should be assigned for each control layer that can grant, narrow, or revoke access. Without that split of responsibility, identity control plane drift sets in and no team can explain which system is authoritative for denial, revocation, or audit evidence.
👉 Read our full editorial: Kong Connect 2026 in Los Angeles: IAM implications for builders
Builder platforms now shape identity outcomes before IAM teams do. When an API platform becomes the place where access is designed, the governance problem shifts left into developer workflows. That means the most important control decisions may be made before central identity teams ever see the request. For practitioners, this is a reminder that identity architecture is increasingly distributed across the platform layer, not just managed in a directory or access request tool.
A question worth separating out:
Q: How can organisations tell whether platform identity governance is keeping up?
A: Look for whether access decisions, credential issuance and revocation are documented at the platform layer and not just in policy. If teams cannot show who owns service authentication, where secrets live, and how access is removed when workloads change, the governance model is lagging the architecture.
👉 Read our full editorial: Kong Connect 2026 in Los Angeles: IAM implications for builders