// Writing
Engineering, security, AI infra.
September 1, 2026 · 8 min
Designing a Multi-Provider AI Gateway: Abstraction, Billing & a Reseller Tier
How I architected MecutinAI — one /v1 endpoint across many LLM providers, with token accounting, QRIS billing, and a reseller (agency) tier.
August 8, 2026 · 7 min
HMAC-SHA256 Webhook Verification in Production: A Field Guide
What I learned verifying webhooks across OTP top-ups, eSIM provisioning, and escrow — constant-time compares, idempotency, and replay protection.
July 20, 2026 · 6 min
Scaling a Streaming Catalog: Aggregating 24,000 Titles from 31 Providers
How Dramacin normalizes 31 fragmented providers into one catalog with TMDB metadata, PWA install, and real-time trending.
June 15, 2026 · 7 min
From Prompt Engineering to Agentic Workflows: Where I'm Betting Now
My shift from LLM API proxies to AI planning tools to agentic workflows — and where I think the real leverage is.
May 12, 2026 · 9 min
OWASP Top 10 for Full Stack Developers: What I Actually See in the Wild
The OWASP risks that show up in real SaaS builds — injection, broken auth, IDOR, misconfig — and how I harden against them.
April 18, 2026 · 6 min
From Monolith to Modular Architecture in Next.js
A modular approach for scaling product teams and codebases.
March 28, 2026 · 7 min
Secure API Integration Playbook
A practical API security checklist.
March 2, 2026 · 8 min
Building an AI Proxy with a Unified /v1 Endpoint
One endpoint across multiple AI providers.