Reading Time: 11 minutes

Overview

For years, MuleSoft has given enterprises a strong governance posture. Governance rulesets, conformance scoring, and policy enforcement prevent issues and consistently enforce governance across APIs and MCP servers.  Once traffic starts flowing a different class of governance risk emerges: shadow APIs and MCP servers, broken authentication observed in live requests, sensitive data leaving through unprotected endpoints, and behavioral attack patterns that no static ruleset can predict. 

You simply cannot protect what you can’t see.

Which is why we’re excited to announce the general availability of MuleSoft’s integration with Akamai API Security. 

We previously announced our strengthened partnership to help enterprise customers strengthen API security and governance which is now expanding to a fully fledged integration.

In the first phase of this solution, we’re bringing API runtime threats discovered by Akamai API security into MuleSoft by analyzing real API traffic at CDN scale.  MuleSoft cannot see these threats on its own– with this integration, those runtime signals flow directly into the MuleSoft platform and are surfaced alongside the design-time and runtime conformance results our customers already use every day.

The result is a complete API and MCP security lifecycle management in a single platform: govern your assets, get notified when an asset is exposed at design time or runtime, and mitigate the risk through governance policies. Because the integration is built into the platform, users get one consistent experience across MuleSoft and external (Akamai) security signals, with no context switching and no separate console to learn.

Why It Matters

As AI adoption accelerates, APIs are becoming the connective tissue between apps, data, models, and agents. If your APIs are unmanaged, you’re exposed to ungoverned risk. 

Until today, closing that gap meant running two disconnected tools: MuleSoft for API governance and a separate security console for runtime findings. Security teams had to manually correlate findings back to the right API instance, remediations went unapplied, and the CISO had no coherent view of the overall security posture.

The Akamai API Security integration brings  runtime security signals into MuleSoft governance workflow. Security, platform, and integration teams benefit through:

  • Full lifecycle coverage: Design-time conformance and runtime threat detection combined in one governance report, so a “compliant” rating actually reflects what is happening in production
  • Faster detection to remediation: Findings surface in context on the affected API or instance, with recommended remediation policies applicable directly from the same interface
  • Accurate correlation, automatically: The integration maps every traffic observation precisely to the right MuleSoft asset instance with no manual matching required
  • One experience, no context switching: Violations, warnings, and info-level findings from Akamai appear in the same Governance views as MuleSoft’s internal rulesets, so users learn one workflow
  • A coherent CISO view: Risk levels and violation counts roll up at both the API and instance level, giving security leadership a posture statement they can stand behind

Use Cases

Capability ThemeUse CaseBusiness Impact
Runtime Threat DetectionAkamai analyzes live north-south traffic flowing through the CDN to customer-registered domains and detects threats such as authentication gaps and behavioral anomalies on governed MuleSoft APIs and MCPs.Catches the runtime issues that design-time governance structurally cannot see, closing the largest blind spot in the API security lifecycle.
Unified Security PostureA CISO or Security Architect reviews conformance status and Akamai security findings together in MuleSoft Governance, with violation counts and risk levels at both the API and instance level.Produces a complete risk posture view from a single platform, eliminating manual correlation across separate security tooling.
Sensitive Data Exposure VisibilityA compliance officer identifies which APIs are serving PII, PHI, or financial data without adequate authentication, based on Akamai’s traffic-based data classification.Scopes remediation programs around the endpoints most likely to constitute a reportable breach event.
In-Context RemediationA platform operator drills into a specific finding, filters by severity (violations, warnings, info), and applies a recommended MuleSoft remediation policy in one click.Shrinks the window between detection and mitigation, and keeps a full audit trail of who applied what and when.
Design-Time Policy AlignmentGovernance reports for governed APIs reflect a combination of MuleSoft’s internal rulesets and Akamai’s security signals, informing which MuleSoft policies and controls should be applied.Ensures new and existing APIs carry governance coverage that maps to the threats actually observed in runtime traffic.
Scheduled, Governed IngestionCustomers configure the Akamai scanner frequency (for example daily or weekly), and findings and incidents are pulled into the Governance layer on that schedule.Puts the customer in control of the integration cadence while keeping findings continuously fresh in the platform.

Key Features

  • Akamai scanner in MuleSoft: Add an Akamai scanner using the ‘providers’ tab in enhanced experience. Provide the tenant base URL, Client ID, and Client Secret, then set the scan frequency. No custom integration work required.
  • Automatic correlation policy: The integration automatically applies an API Identification Header policy that injects Business Group ID and Instance ID into API responses, allowing Akamai to map each observed endpoint to its exact MuleSoft instance.
  • Pull-based findings retrieval: The scanner connects to the Akamai management APIs on the configured schedule and writes findings and incidents into the MuleSoft Governance service, enriching existing API assets rather than creating duplicates.
  • Unified governance reporting: Security findings from Akamai appear alongside MuleSoft’s internal ruleset results in the governance strategy views, with metrics such as violation counts and risk levels at both the API and instance level.
  • Severity filtering and drill-down: Users can drill into individual findings and filter by severity class (violations, warnings, info) to prioritize what matters most.
  • Recommended remediation policies: For each finding, the platform surfaces recommended MuleSoft remediation policies that can be applied directly within the interface, with attribution captured for the audit trail.
  • Broad gateway support: The integration is supported across hubs using MuleSoft Omni Gateway, covering the mainstream MuleSoft deployment topologies.
  • Bi-directional platform connectivity: A connected app in MuleSoft enables Akamai to communicate securely with the platform, completing the two-way integration.

Watch our demo to see the complete flow, from connecting Akamai to remediating a live finding, all inside the MuleSoft console.

What’s Next

The current release focuses on the assets that MuleSoft already knows about: governed APIs and MCPs receiving runtime security signals from Akamai. 

In the upcoming phase, we will bring over from Akamai the ungoverned APIs and MCPs, meaning the APIs and MCP servers that Akamai observes in live traffic but that have never been registered in MuleSoft. These discovered assets will surface inside the platform so teams can see their full enterprise API and MCP surface, quantify their ungoverned exposure, and prioritize bringing shadow assets under MuleSoft governance. 

It’s the natural extension of the lifecycle story: first secure what you govern, then govern what you discover.