API Gateway
In short
An API gateway is a server that sits in front of a group of backend services and acts as the single entry point that receives, checks, and routes API requests.
What is an API gateway?
An API gateway is a single front door for many backend services. Clients send every request to the gateway, which decides which internal service should handle it, forwards the request, and returns the response. Clients never need to know how many services exist behind it or where they run.
Besides routing, a gateway handles cross-cutting concerns, meaning tasks every service would otherwise have to implement itself: authentication checks, rate limiting, TLS termination, logging and metrics, caching, and sometimes translating between protocols such as REST and gRPC. Examples include Kong, Amazon API Gateway, Azure API Management, Apigee, Tyk, and gateways built on NGINX or Envoy.
Think of the reception desk in a large office building: visitors check in at one desk, show their ID, and are sent to the right floor, instead of wandering the halls looking for the right person. API gateways are most common in microservices architectures, where a single app or website would otherwise have to call dozens of services directly.
An API gateway is often confused with a reverse proxy or a load balancer. A reverse proxy forwards requests to backend servers and a load balancer spreads traffic across copies of the same service, while an API gateway is a reverse proxy specialized for APIs that adds features like authentication, API keys, and per-client rate limits. Because every request passes through it, the gateway must be highly available, or it becomes a single point of failure.
At a glance
Key takeaways
- An API gateway is the single entry point for clients calling many backend services.
- It routes each request to the right service based on its path, host, or headers.
- It centralizes authentication, rate limiting, logging, and TLS.
- It is a specialized reverse proxy, most common in microservices architectures.
- It must be scaled and made highly available, since all traffic flows through it.
Example
# One public entry point in front of two internal services
_format_version: "3.0"
services:
- name: users-service
url: http://users.internal:8080
routes:
- paths: ["/api/users"]
- name: orders-service
url: http://orders.internal:8080
routes:
- paths: ["/api/orders"]
plugins:
# Applied to every route: at most 100 requests per minute per client
- name: rate-limiting
config: { minute: 100 }Readers ask
What is the difference between an API gateway and a load balancer?
A load balancer spreads traffic across several copies of the same service to share the load. An API gateway routes requests to different services based on the API path and adds features like authentication and rate limiting, and it often sits in front of load balancers.
What is the difference between an API gateway and a reverse proxy?
An API gateway is a kind of reverse proxy. A plain reverse proxy mainly forwards traffic, while an API gateway adds API-specific features such as API key checks, per-client rate limits, and request transformation.
Do I need an API gateway?
Not always. A single monolithic application can often handle authentication and rate limiting itself, but a gateway becomes valuable once clients would otherwise call many separate services directly.
Often compared
See also
- MicroservicesSoftware Architecture, p. 27Microservices are an architectural style where an application is split into small, independently deployable services that communicate over a network.
- Reverse ProxyDevOps & Cloud, p. 44A reverse proxy is a server that sits in front of web servers, accepts client requests on their behalf, and forwards each request to the right backend server.
- Load BalancerDevOps & Cloud, p. 34A load balancer is a server or service that spreads incoming traffic across several backend servers so no single one is overloaded and the app stays available.
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- Backend for FrontendSoftware Architecture, p. 2Backend for frontend is an architecture pattern in which each kind of client, such as a web or mobile app, gets its own small backend tailored to its needs.
Spotted a mistake or something missing on this page?Suggest an edit