What is an API gateway?
The front door for microservices and public APIs
An API gateway is a reverse proxy that sits in front of your APIs and handles cross-cutting concerns — authentication, rate limiting, caching, routing, request/response transformation, and observability — so individual services don't have to.
For microservices, the gateway is the single entry point from external clients (web, mobile, partners). It routes each request to the appropriate backend service and consolidates responses when needed.
For public APIs, the gateway enforces API management: who can call what, how often, from which plan tier, with what SLA.
Modern API gateways support REST, GraphQL, gRPC, and WebSocket protocols. The best API gateway tools also offer API analytics, monetization, developer portals, and policy-as-code.
API gateway benefits
Why teams add a gateway (and when they regret it)
Security: centralized authentication (API keys, OAuth, JWT, mTLS), authorization, and threat protection (WAF, rate limiting, bot detection) instead of implementing in every service.
Reliability: circuit breakers, retries, timeouts, and backpressure applied at the edge instead of per-service.
Observability: single point for logs, metrics, and traces across every API call — vital for distributed systems.
Developer experience: a single endpoint, a single auth scheme, a single developer portal — far simpler than exposing every service individually.
Monetization: usage-based billing, plan tiers, and quota enforcement — the gateway is often where API-as-a-product companies ship billing logic.
Caution: a gateway is still a single point of failure. If it goes down, every API is down. Deploy in HA from day one.
The best API gateway tools (2026 edition)
Features, limitations, and best-fit scenarios
Kong Gateway: open source + enterprise, Nginx + Lua or OpenResty-based, plugin ecosystem is largest in open source. Best fit: cloud-agnostic teams with heavy plugin needs.
AWS API Gateway: fully managed by AWS, deep integration with Lambda, Cognito, and IAM. REST + HTTP + WebSocket. Best fit: AWS-native serverless architectures.
Azure API Management (APIM): Microsoft's managed gateway, strong developer portal, built-in versioning. Best fit: Azure-centric enterprises.
Google Cloud API Gateway + Apigee: Apigee is Google's enterprise-tier gateway, best for API-as-a-product with monetization. Best fit: large enterprises needing full API lifecycle.
Tyk: open-source + enterprise, Go-based (lightweight), GraphQL and gRPC first-class. Best fit: performance-sensitive teams who want OSS freedom.
KrakenD: open source + enterprise, declarative config, aggregates multiple backends into one response — best for BFF patterns.
Envoy / Istio Gateway: service-mesh-grade proxy; often used as north-south ingress with policies managed in Istio. Best fit: Kubernetes-first platforms.
Traefik: Go-based, Docker/Kubernetes-native service discovery, lightweight. Best fit: container-first teams needing simple ingress.
Features to evaluate
The dimensions that actually decide the choice
Protocol support: REST, GraphQL, gRPC, WebSocket, SOAP — match to your actual API shape.
Deployment model: SaaS (managed) vs self-hosted vs sidecar. Managed is faster to adopt; self-hosted gives data-residency control.
Plugin ecosystem: authentication providers, rate-limiting algorithms, custom transformations. Open-source gateways compete heavily on plugins.
Policy management: GUI-driven, declarative YAML, or Kubernetes CRDs. Match to your team's workflow.
Observability: native metrics, distributed tracing, access logs. All modern gateways expose Prometheus metrics and OpenTelemetry traces.
Developer portal: if you expose APIs externally, the quality of the generated docs, interactive explorer, and signup flow matters.
Monetization and plans: for API-as-a-product, built-in billing + quota + plan tiers avoid building a billing system.
Common API gateway patterns
How gateways are actually deployed
Edge gateway: single entrance for external traffic, in front of multiple backend services. The classic pattern.
Backend-for-Frontend (BFF): one gateway per client (web, mobile, partner), each shaping responses for its specific consumer.
East-west + north-south: service mesh (Istio, Linkerd) handles east-west service-to-service; a separate ingress gateway handles north-south external traffic.
API gateway + load balancer stack: cloud load balancer (ALB, Cloudflare) does L4 + TLS termination; gateway does L7 policy. Common in enterprise.
Multi-region gateways: gateways deployed per region with health-based routing and failover. For global APIs with strict latency SLAs.
Observability for API gateways
Monitoring the front door
Request rate, latency percentiles, and error rate per route per plan tier — the fundamental signals.
Rate-limit rejections: track 429 responses and the clients driving them. Often indicates abusive usage or missing plan upgrades.
Upstream service health: when a backend service fails, the gateway surfaces 502/503/504. Correlate with service APM.
Authentication failures: track 401 responses by client and route. Spikes indicate credential rotation issues or attacks.
Atatus API analytics ingests gateway logs and metrics from Kong, AWS API Gateway, Azure APIM, Tyk, and others — correlating per-API traffic with APM traces of the backend services.
Key Takeaways
- API gateways centralize auth, rate limiting, routing, caching, and observability for microservices and public APIs.
- Best open-source API gateways: Kong, Tyk, KrakenD, Envoy, Traefik.
- Best managed API gateways: AWS API Gateway, Azure APIM, Apigee.
- Choose based on protocol support, deployment model, plugin ecosystem, and observability.
- Deploy in HA from day one; the gateway is a single point of failure.
- Pair with APM for end-to-end visibility from the client through gateway to backend services.