Glossary

Short explanations of the terms used on ipaas.it. Select a tag to see the posts on that topic.

A

A2A (Agent2Agent)

An open protocol that lets AI agents find each other, hand over tasks and report back, even when they are built on different platforms. Google launched it in 2025, and it is now a Linux Foundation project. Where MCP connects an agent to tools and data, A2A connects agents to other agents.

Agent Card

A description an agent publishes in A2A, listing what it can do, how to reach it and how to authenticate. Other agents read the Agent Card to decide whether to send it a task.

Agent discovery

Automatically finding the AI agents, MCP servers and APIs that exist across a company's platforms, often by scanning cloud providers, data platforms and gateways. It is usually the first step towards an agent registry and governance.

Agent evals

Structured tests of an AI agent. You define test scenarios and success criteria, run the agent against them and score the results, much like automated tests for ordinary code. Evals show whether a change to a prompt, model or tool makes the agent better or worse.

Agent gateway

A gateway for traffic between AI agents, and between agents and their tools, often using A2A and MCP. It enforces security rules, checks identity, logs calls and tracks cost, much as an API gateway does for APIs.

Agent governance

The rules, processes and tools for keeping control of AI agents in an organisation. It covers which agents exist, what they may access, who owns them, how they are tested and what they cost.

Agent loop

The basic cycle an AI agent runs in. The language model reads the task, chooses a tool, looks at the result and decides the next step, until the task is done or a limit is reached. In integration platforms, the loop often runs as one step inside an ordinary, controlled workflow.

Agent registry

A central catalogue of the AI agents, and often the MCP servers, an organisation uses. It records what each one does, who owns it and what it may access, so they can be found, reused and governed.

Agent sandbox

An isolated runtime for an AI agent, with rules for which files, network addresses and data the agent process may reach. It limits the damage if an agent is tricked or makes a mistake, but it does not decide which business actions the agent may perform.

Agentic AI Foundation (AAIF)

A foundation under the Linux Foundation, formed in December 2025, that hosts open standards for AI agents, including MCP and, from August 2026, A2A. It gives the protocols neutral governance, so no single vendor controls them.

AI agent

Software that uses a language model to work towards a goal on its own. Unlike a chatbot, an agent can choose and use tools, such as looking up data or calling an API, and act on the results.

AI gateway

A gateway that sits between applications or agents and AI services such as language models and MCP servers. It applies the same kind of control as an API gateway to AI traffic, including authentication, rate limiting, cost tracking and logging.

API (application programming interface)

A defined way for one system to ask another for data or to perform an action. Most modern integration happens through APIs, usually over HTTP with JSON.

API gateway

The component that receives calls to your APIs and enforces the rules before they reach the systems behind. Typical tasks are authentication, rate limiting, routing and logging.

API management

Tools and processes for publishing, securing, documenting and monitoring APIs across their whole lifecycle. A solution usually includes an API gateway, a developer portal and a place to set policies and follow usage.

API product

A package of one or more APIs offered to developers as a unit, with its own documentation, access plans and usage limits. The package is published in a developer portal, where consumers subscribe to the product rather than to single endpoints.

Audit logging

A record of who did what, and when, that cannot easily be changed afterwards. For AI agents, it means logging every tool call with enough context to explain what the agent did and why.

C

Change data capture (CDC)

A way to pick up every insert, update and delete in a database as it happens, usually by reading the database log, and pass the changes on to other systems. It keeps copies up to date in near real time without reloading everything.

Connector

A ready-made building block in an integration platform that knows how to talk to a specific system, such as Salesforce, SAP or a database. Connectors save you from writing and maintaining the connection yourself, and the number and quality of them is often a deciding factor when choosing a platform.

Control plane

The part of a platform where you configure, govern and monitor, as opposed to the data plane where the actual traffic flows. In API management, policies are set in the control plane and enforced by gateways in the data plane. The term is now also used for tools that govern AI agents.

CRM (customer relationship management)

A system for managing customers, sales and customer service, such as Salesforce or Microsoft Dynamics 365. CRM is one of the most common sources and targets in integrations.

D

Data lineage

A map of where data comes from, how it is changed along the way and where it ends up. Lineage makes it possible to trace an error back to its source and to see what is affected by a change.

Data plane

The part of a platform that handles the actual traffic, such as the API gateways or runtimes that process calls and messages. It can run in the vendor's cloud or be self-hosted close to your own systems, while the control plane manages it centrally.

E

EDI (Electronic Data Interchange)

Standard formats for exchanging business documents such as orders, invoices and delivery notices directly between companies' systems. EDI messages are often sent over AS2, a protocol that encrypts and signs each message and returns a receipt.

Embedded iPaaS

An integration platform built into another software product, so its users can connect it to other systems without a separate integration tool. It knows the product's own data model, but many embedded layers in one company can become hard to oversee.

ERP (enterprise resource planning)

The core business system for finance, purchasing, inventory and often production and HR, such as SAP, Oracle or NetSuite. Many integrations exist to move orders, invoices and master data in and out of the ERP.

ESB (enterprise service bus)

An integration platform installed in your own data centre, where systems exchange messages through a central bus. ESBs were the standard before iPaaS, and many organisations are now moving away from them.

EU AI Act

The EU regulation on artificial intelligence, which applies in stages from 2025. Among other things, it requires companies to tell people when they interact with an AI system and to mark AI-generated content, with rules on transparency applying from 2 August 2026.

Event streaming

Integration where systems publish events, such as "order created", to a stream that other systems subscribe to in real time. It is an alternative to one system calling another directly or collecting data at fixed intervals.

F

Forrester Wave

Forrester's evaluation of vendors in a market, where each vendor is scored on its current offering, strategy and market presence. The results are shown in a chart as Leaders, Strong Performers, Contenders and Challengers.

G

Gartner Emerging Market Quadrant

Gartner's analysis of a young market where products and vendors change quickly. Unlike a Magic Quadrant, it groups vendors by type rather than ranking them on a fixed scale.

Guardrails

Rules that check what goes into and comes out of a language model or agent, such as blocking personal data, harmful content or topics outside the agent's task. Guardrails often run in an AI gateway so the same rules apply whichever model is used.

H

Headless integration platform

An integration platform that can be fully operated without its visual interface, through APIs, a command-line tool or an MCP server. It lets developers and AI agents build and run integrations from the tools they already use.

I

iPaaS (integration platform as a service)

A cloud service for connecting systems, applications and data, so that information flows between them without manual work. The vendor runs the platform, and you build the integrations, often with low-code tools and ready-made connectors.

ISO/IEC 42001

An international standard for AI management systems, published in 2023. A certified organisation has shown an external auditor that it has roles, risk assessments and routines for developing and running AI responsibly. It certifies the organisation, not a single product feature.

ITSM (IT service management)

How an IT department delivers and supports its services, including incidents, changes, service requests and the CMDB, the register of IT assets and how they relate. ITSM platforms are often integrated with identity, developer and monitoring tools.

L

Legacy modernization

Moving integrations off old platforms, such as an ESB or self-built code, to a modern platform. It usually starts with analysing what exists, and vendors now use AI to map old flows and suggest how they should be rebuilt.

LLM (large language model)

An AI model trained on large amounts of text that can understand and write language, such as the models behind ChatGPT, Claude and Gemini. LLMs are the reasoning engine inside AI agents.

Low-code

Building software with visual tools, such as drag and drop and ready-made components, instead of writing all the code by hand. Most iPaaS products are low-code, so that more people than developers can build integrations.

M

Magic Quadrant

Gartner's yearly evaluation of vendors in a market, placed in four quadrants by ability to execute and completeness of vision. The quadrants are Leaders, Challengers, Visionaries and Niche Players.

MCP (Model Context Protocol)

An open standard for connecting AI agents and language models to tools and data. A system is made available once as an MCP server, and any agent that supports MCP can then use it. Anthropic launched MCP in 2024, and most integration platforms now support it.

MCP registry

A catalogue of the MCP servers an organisation uses, with what each one offers, who owns it and who may use it. It lets agents and developers find approved tools, and lets IT stop servers that are not approved.

MCP server and MCP client

An MCP server offers tools and data from a system, such as "look up customer" or "create order". An MCP client is the part of an AI application or agent that connects to MCP servers and calls their tools. Integration platforms can turn existing APIs and flows into MCP servers.

Model gateway

A type of AI gateway that routes calls to language models. It can choose between models from different vendors based on cost, speed or data sensitivity, and apply the same rules whichever model is used.

Multi-agent workflow

A process where several AI agents each handle their part of a task and pass work between them, often across platforms. Protocols such as A2A and a common layer for rules and tracing make it manageable.

N

No-code agent builder

A tool that lets business users build, publish and manage AI agents without writing code, usually with a visual designer and a built-in runtime. Gartner treats it as its own market from 2026.

Non-human identity

An identity that belongs to software rather than a person, such as a service account, an API key, an integration or an AI agent. Companies often have far more of these than human users, and they need the same control over rights and lifetime.

Nucleus Research Value Matrix

Nucleus Research's evaluation of vendors in a market, based on the usability and functionality customers get. Vendors are placed as Leaders, Experts, Accelerators or Core Providers.

O

OAuth 2.0

The standard way to give an application limited access to a service without sharing a password. With the on-behalf-of flow, an agent or service can act with the rights of the user who asked, instead of its own broad access.

Observability

The ability to see what is happening inside a system from its logs, metrics and traces. For integrations and agents, it means being able to follow one request through every step and system involved.

OpenTelemetry

An open standard for collecting traces, metrics and logs. When integration platforms support it, their data can be sent to the monitoring tools you already use, and a request can be traced across products from different vendors.

P

PII (personally identifiable information)

Information that can identify a person, such as name, national ID number, email or phone number. Gateways for APIs and AI can detect PII and stop or mask it before it reaches a language model or an external service.

Point-to-point integration

Integration where each pair of systems is connected directly with its own custom code. It works for a few systems, but the number of connections grows quickly and becomes hard to maintain, which is why central platforms such as ESB and iPaaS appeared.

Prompt injection

An attack where hidden instructions are placed in text an AI agent reads, such as an email, a document or a web page, to make it do something it should not. It is one of the main reasons agents need limited rights and gateways that filter what goes in and out.

R

RAG (retrieval-augmented generation)

A technique where relevant information is looked up in the organisation's own documents and data and given to the language model along with the question. The answer is then based on your own knowledge, not only on what the model learned in training.

Rate limiting

A limit on how many calls a user, application or agent may make in a given period, such as 100 per minute. It protects the systems behind from overload and keeps costs under control. Throttling is often used to mean the same thing, and calls over the limit usually get the HTTP error 429 Too Many Requests. Some products use throttling more narrowly, for slowing down or queuing traffic instead of rejecting it.

RBAC (role-based access control)

Access control where rights are given to roles, such as developer, operator or administrator, and users or agents get the roles they need. It makes it easier to give everyone only the access they actually require.

S

SaaS (software as a service)

Software you use as a service over the internet instead of installing it yourself, such as Salesforce, Microsoft 365 or Workday. The more SaaS an organisation uses, the more it needs integration between them.

Signed Agent Card

An Agent Card with a cryptographic signature, introduced in A2A 1.0. The receiver can check that the card really comes from the agent it describes and that no one has changed it, which makes it safer to trust agents from other organisations.

Stateless protocol

A protocol where each request carries everything the server needs, so the server does not have to remember earlier requests. Any server instance behind a load balancer can then answer, which makes scaling and recovery much simpler. MCP became stateless in its 2026-07-28 version.

Streamable HTTP

The standard transport for MCP over the network. The client sends requests over ordinary HTTP, and the server can answer with a single response or stream several messages back. It lets MCP servers run behind load balancers and gateways like other web APIs.

T

Token propagation

Passing the end user's identity token, or a narrowed version of it, along each step of a call chain, so the target system applies the user's own rights. Without it, an agent or integration often runs with a broad shared account that can do more than the user.

Tool call

When an AI agent decides to use one of its tools, such as calling an API or an MCP server, and gets the result back. Tool calls are where an agent actually does something in other systems, so they are what needs securing and logging.

Z

Zero-copy integration

Using data from another system where it is stored, instead of copying it into your own platform. It removes many copy jobs, but depends on the source offering the right interfaces and can make queries more expensive.