Skip to main content

API Gateway

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/api-gateway

In short

An API gateway is a server that sits in front of a group of backend services and acts as the single entry point that receives, checks, and routes API requests.

What is an API gateway?

An API gateway is a single front door for many backend services. Clients send every request to the gateway, which decides which internal service should handle it, forwards the request, and returns the response. Clients never need to know how many services exist behind it or where they run.

Besides routing, a gateway handles cross-cutting concerns, meaning tasks every service would otherwise have to implement itself: authentication checks, rate limiting, TLS termination, logging and metrics, caching, and sometimes translating between protocols such as REST and gRPC. Examples include Kong, Amazon API Gateway, Azure API Management, Apigee, Tyk, and gateways built on NGINX or Envoy.

Think of the reception desk in a large office building: visitors check in at one desk, show their ID, and are sent to the right floor, instead of wandering the halls looking for the right person. API gateways are most common in microservices architectures, where a single app or website would otherwise have to call dozens of services directly.

An API gateway is often confused with a reverse proxy or a load balancer. A reverse proxy forwards requests to backend servers and a load balancer spreads traffic across copies of the same service, while an API gateway is a reverse proxy specialized for APIs that adds features like authentication, API keys, and per-client rate limits. Because every request passes through it, the gateway must be highly available, or it becomes a single point of failure.

At a glance

A browser and a mobile app send every request to one API gateway, which checks authentication, applies rate limits and routes each request by its path: /users to the user service, /orders to the order service and /payments to the payment service.Internal services/users/orders/paymentsBrowserMobile appAPI gatewaysingle entry pointAuthenticationRate limitingRouting by pathUserserviceOrderservicePaymentservice
Clients only know the gateway. It runs the shared checks once and sends each request to the right internal service.

Key takeaways

  • An API gateway is the single entry point for clients calling many backend services.
  • It routes each request to the right service based on its path, host, or headers.
  • It centralizes authentication, rate limiting, logging, and TLS.
  • It is a specialized reverse proxy, most common in microservices architectures.
  • It must be scaled and made highly available, since all traffic flows through it.

Example

Routing and rate limiting in a gateway config (Kong)yaml
# One public entry point in front of two internal services
_format_version: "3.0"
services:
  - name: users-service
    url: http://users.internal:8080
    routes:
      - paths: ["/api/users"]
  - name: orders-service
    url: http://orders.internal:8080
    routes:
      - paths: ["/api/orders"]
plugins:
  # Applied to every route: at most 100 requests per minute per client
  - name: rate-limiting
    config: { minute: 100 }

Readers ask

What is the difference between an API gateway and a load balancer?

A load balancer spreads traffic across several copies of the same service to share the load. An API gateway routes requests to different services based on the API path and adds features like authentication and rate limiting, and it often sits in front of load balancers.

What is the difference between an API gateway and a reverse proxy?

An API gateway is a kind of reverse proxy. A plain reverse proxy mainly forwards traffic, while an API gateway adds API-specific features such as API key checks, per-client rate limits, and request transformation.

Do I need an API gateway?

Not always. A single monolithic application can often handle authentication and rate limiting itself, but a gateway becomes valuable once clients would otherwise call many separate services directly.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings