The letter

One letter a week, starting soon.

The week's signal, what shipped, what is worth running tonight, and the editor's note. No tracking, no ads, nothing else.

We keep your address, your language and the date you joined, nothing else. Every letter has a one-click unsubscribe link that deletes the record.

← Accept All   Editor’s notes
Editor’s note

An Old API Learns to Speak in Tools Overnight

October 10, 2026Yuki Halvorsen

At one in the morning I pointed curl at an endpoint I wrote three years ago — it converts a product barcode into a shelf location, nothing more — and for the first time something other than a browser or a cron job was about to call it.

A tool an agent can call needs exactly three things: a name, a sentence describing what it does, and a schema of what it expects and what it hands back. Every team I have worked with ends up hand-writing that wrapper, endpoint by endpoint, by hand, in whatever spare hour a sprint leaves lying around, which is how a whole afternoon disappears into busywork nobody will remember doing.

Google's new API Gateway reads the OpenAPI file my endpoint already had — the same document that has been describing it to humans for years — and writes that wrapper itself. An agent finds the tool the way it finds everything else on a server that is run properly: through a directory it can query, not a paragraph I typed into a prompt and hoped it would remember.

I ran it against my own three endpoints before breakfast. Two came through clean on the first try. The third needed a parameter renamed, because a field called 'loc' means nothing to a model reading a schema cold at three in the morning — a gateway can translate a protocol, but it cannot translate a lazy variable name back into English for you.

The part that should worry a team more than any of this is not whether the agent behaves itself. It is which endpoints someone points the gateway at. My barcode lookup is harmless to expose to anything that asks. A colleague's internal pricing endpoint is not, and the gateway will wrap that one just as happily and just as fast, with the same three lines of configuration. Deciding what an agent is allowed to ask for is still entirely a human decision, and the easier this gets, the easier it is to forget that you are the one making it, every single time, not the tool.

By the time the kettle had boiled, the same old endpoint that used to answer only a browser was answering a question nobody had ever typed, in a shape it had never once been asked for before.

On the wire this week

  1. Turn your REST APIs into MCP tools with Google Cloud API Gateway Google Developers Blog

Yuki Halvorsen was born in Sapporo to a Norwegian father and a Japanese mother, wrote her first program on a school computer that took ten seconds to draw a circle, and spent eight years as an engineer in Stockholm before Tokyo pulled her back. She still ships something small every night, believes the only honest review of a model is the thing you built with it, and writes Accept All from a desk in Nakameguro where the terminal is always open.