AiVibe

Cloud & AI Infrastructure

API Gateway

An API gateway is a single entry point that receives client API requests, applies policies such as authentication, rate limiting and validation, and routes each request to the appropriate back-end service.

An API gateway is a server or managed service that sits between clients and a set of back-end services and acts as the single entry point for API traffic. It receives each request, applies cross-cutting policies such as authentication, rate limiting and request validation, and routes the request to the appropriate service, sometimes aggregating responses or translating between protocols. Responses can be cached and every call logged for monitoring and billing.

API gateways are central to microservices and serverless designs, where they hide internal service structure from mobile, web and partner clients and let teams change back ends without breaking consumers. Managed examples include Amazon API Gateway, Azure API Management and Apigee on Google Cloud, while open-source gateways such as Kong are self-hosted. Gateways are also used to expose plant or machine data to enterprise applications through controlled interfaces.

As a shared entry point, the gateway can become a bottleneck or single point of failure, so it is normally deployed redundantly and scaled automatically. Business logic should stay in the services rather than the gateway. Security controls at the gateway complement, but do not replace, authorisation inside each service, and the OWASP API Security Top 10 is a common reference for testing exposed APIs.

Key points

Where AiVibe comes in

AiVibe Software Services delivers cloud solutions on AWS, Microsoft Azure, Google Cloud or on-premise, together with cloud security, legacy modernisation, data analytics and AI and machine learning services.

Explore AiVibe’s work in Cloud & AI Infrastructure →

Related terms

Terms that refer to API Gateway

Ask AiMuruga can explain API Gateway for your plant, product or security programme, and draw how it fits.