Most teams that go shopping for API management software already have working APIs. What they lack is a gateway in front of them: a single place to enforce authentication, throttle a partner who is hammering an endpoint, version a breaking change without an angry Slack thread, and hand a developer portal to outside integrators instead of a shared spreadsheet of base URLs. This ranking judges API management platforms on that job, not on how many logos sit on the homepage. We looked at how much work it takes to put a gateway in front of a real service, how pricing behaves once request volume climbs past a demo account, whether the specs, logs and analytics you accumulate can leave with you, and how much of the configuration is portable if you switch vendors. The buyer we had in mind runs somewhere between a handful and a few hundred APIs, not a telecom's entire network core.
Visibility in this ranking can be paid for. Payment moves a vendor's position within the
shortlist; it never adds a vendor, and it never changes a word of the review. The largest vendors in API management software
cannot hold places 1 to 3. How it works: placement disclosure ·
editorial process.
How we ranked these
Setup: standing up a gateway, not flipping a switch
Turning on API management is not a checkbox in an admin panel. Someone has to decide where the gateway runs (in front of a load balancer, inside a Kubernetes cluster as a sidecar, or as a managed edge service), point DNS or an ingress controller at it, and translate existing routes, auth schemes and rate limits into the vendor's policy format without breaking consumers who are already calling the backend directly. We weighted setup on how much of that config can be written as code and checked into version control rather than clicked through a console, how clearly the product handles a phased cutover (canary a percentage of traffic before moving everything), and whether a team with one platform engineer can get a first API live in a day rather than a sprint. Products built around OpenAPI import scored well here; those that require hand-building policy graphs from scratch did not.
The real price: what counts as an API call
Billing units in this category range from a flat per-gateway-node fee to a price per million API calls, and the definition of a chargeable call is not consistent between vendors: some count every request, some exclude failed auth attempts, some meter separately for the management API versus the data plane. A platform that looks cheap at the request volume of a pilot can become the most expensive line on the bill once a partner integration goes live and starts polling every few seconds. We priced each vendor at three volumes, roughly a thousand, a hundred thousand and ten million calls a day, and noted where a plan's included policy set (rate limiting, transformation, OAuth) is unlocked only on a higher tier. Self-hosted open-source cores remove the per-call meter entirely but shift the cost to infrastructure and the engineer running it.
Getting your data out: specs, logs and analytics
The valuable exhaust from an API gateway is not the request bodies, which usually should not be retained anyway, but the OpenAPI or AsyncAPI specs that describe each route, the access logs that prove who called what and when, and the aggregated analytics a team uses to decide which endpoints to deprecate. We checked whether specs can be exported in a standard format rather than a vendor-specific schema, whether raw or near-raw request logs can be streamed to a company's own log pipeline instead of being trapped in a proprietary dashboard, and how long analytics history stays queryable before it rolls off. Products that treat the developer portal's content, API keys and consumer records as exportable data, not just displayed data, made it easier for a team to rebuild elsewhere without starting the catalog from zero.
Independence from the vendor: policy syntax and plugin lock-in
The lock-in risk in this category is not the gateway itself, which mostly forwards HTTP traffic, but the policy language wrapped around it: rate-limiting rules, transformation scripts and auth chains written in one vendor's proprietary DSL do not move to a competitor's gateway without a rewrite, and the plugin ecosystems that extend each product are rarely compatible with each other. We favored platforms built on open specifications (OpenAPI for definitions, standard OAuth2/OIDC flows for auth, WASM or widely used scripting languages for custom logic) over those requiring a certified consultant to touch the policy graph. We also weighted whether a self-hosted or open-core option exists at all, since a product with no such option leaves a buyer entirely dependent on the vendor's uptime, roadmap and pricing decisions with no fallback.
Who it's for: teams publishing internal or partner-facing APIs
This ranking assumes a company running somewhere between a handful of APIs and a few hundred, published either internally across product teams or externally to partners and third-party developers, with one to a dozen people responsible for the platform. That covers a mid-sized SaaS company opening a public API, a bank exposing account data under open-banking rules, and an enterprise IT team standardizing how internal services talk to each other. It does not cover a telecom or a hyperscale consumer platform routing tens of billions of calls a day with a dedicated platform organization; those buyers are already deep in custom infrastructure conversations that this list will not settle. A single-developer side project calling three public APIs from its own code does not need any of these products and should not be shopping in this category at all.
The 16 tools, reviewed
#1 Gravitee.io
Open-source API gateway, governance and developer portal · United States · gravitee.io
Open-source core API governance Developer portal
Gravitee earns the top spot because it does not force a choice between running an open-source gateway and having a usable governance layer on top of it. The policy studio covers the routing, transformation and rate-limiting work most teams need without writing custom code, the developer portal is editable enough to hand to a partner-facing team, and API governance scoring flags specs that drift from a company's own standards before they ship. Engineering roots in Lille, France sit alongside a Denver headquarters and a London office, which shows in decent multi-region support coverage rather than a single time zone.
Where it falls short
Advanced policies, the AI gateway mode and multi-region control plane deployment are held back for the Enterprise tier, and pricing there is negotiated rather than published, so budgeting requires a sales conversation earlier than with some rivals. The plugin ecosystem, while open, is smaller than Kong's, and some third-party integrations lag behind the bigger incumbents.
Wrong for
A team that wants a single managed SaaS gateway with no self-hosting option at all should look elsewhere, since Gravitee's strongest economics come from running the open-source core yourself.
Pricing: Open-source Community Edition is free to self-host; commercial Enterprise and Cloud tiers are negotiated per deployment rather than published as a fixed price list. (open source)
Visit Gravitee.io →
#2 Tyk
Open-source gateway with GraphQL federation, self-host or cloud · United Kingdom · tyk.io
Open-source gateway GraphQL federation Self-hosted first
Tyk built its reputation on shipping a real, unrestricted open-source gateway rather than a crippled trial version of the commercial product, and that continues to be its strongest argument. GraphQL federation is more mature here than at most competitors, useful for a team consolidating several backend services behind one schema, and the plugin system supports writing custom middleware in several common languages rather than a proprietary scripting dialect. Tyk Cloud's request-based pricing is published rather than hidden behind a sales call, which makes early budgeting easier than with most enterprise rivals.
Where it falls short
The admin interface is less polished than newer, design-forward competitors, and some configuration still happens through raw JSON rather than a guided flow. Enterprise-grade support, SSO and advanced analytics sit behind the paid tier, and the gap in refinement between self-hosted and managed Tyk Cloud is noticeable when switching between them.
Wrong for
A team with no engineer willing to own gateway operations, and no interest in GraphQL, will find simpler managed options elsewhere; Tyk rewards teams prepared to get hands-on with configuration.
Pricing: Tyk Gateway is free and open source to self-host; Tyk Cloud is priced by API and request volume on published starter tiers, with an Enterprise tier quoted separately. (open source)
Visit Tyk →
#3 Zuplo
Edge-native API gateway configured as code · United States · zuplo.com
Edge deployment Config as code Transparent pricing
Zuplo's whole design argument is that a gateway should deploy like an application: routes and policies live in a config file, changes go through a normal pull request and CI pipeline, and the result runs on edge infrastructure with no server for the team to patch. For a startup or a small platform team shipping a handful of APIs, that setup speed is the entire pitch, and the published, usage-based pricing means a founder can estimate the bill without a call. Support for MCP and AI gateway patterns arrived earlier here than at most larger rivals.
Where it falls short
The company is young and has not built out the governance catalog, multi-team access controls or compliance certifications that larger enterprises expect from an API management purchase, and the partner and analyst ecosystem around it is thin next to established vendors. Enterprise pricing starts high relative to the self-serve tiers, reflecting a product still aimed primarily at smaller teams.
Wrong for
A large enterprise managing hundreds of APIs across many teams with formal governance requirements needs a deeper catalog and audit trail than Zuplo currently offers; Gravitee or WSO2 fit that job better.
Pricing: Free plan covers 100,000 requests a month; Builder starts at $25 a month plus usage beyond the included volume; Enterprise starts around $1,000 a month on an annual contract. (free plan)
Visit Zuplo →
#4 Kong
Dominant open-source gateway with a large plugin ecosystem · United States · konghq.com
Largest install base Kubernetes-native Deep plugin ecosystem
Kong Gateway is the API gateway most platform engineers have already run at some job, and that familiarity, combined with the largest plugin catalog in this category, makes it the safe default for a team standardizing on Kubernetes. Konnect adds a genuinely useful hosted control plane for teams that outgrow managing the open-source version by hand, and Kong has moved quickly to add AI gateway plugins for teams proxying LLM traffic. Its scale and market position keep it out of the top three under this ranking's rule against dominant incumbents holding those places.
Where it falls short
The line between what is free in Kong Gateway and what requires an Enterprise license is not always obvious until a team hits it mid-project, and several of the most useful plugins (advanced rate limiting, some auth methods) are commercial-only. Konnect pricing scales quickly with traffic and can surprise teams that budgeted from the open-source version's cost of zero.
Wrong for
A small team with no Kubernetes footprint and no appetite for plugin sprawl will find Kong more machinery than the job needs; Zuplo or Tyk's cloud tiers are a simpler starting point.
Pricing: Kong Gateway is free and open source; Kong Konnect (the managed control plane) is priced on published usage-based tiers, with Enterprise features quoted separately. (open source)
Visit Kong →
#5 Postman
API platform for design, testing and governance, with gateway features · United States · postman.com
Design-first Huge existing user base Governance add-on
Postman's enormous existing footprint in API design and testing gives it a natural path into governance: because so many teams already write and share their OpenAPI specs inside Postman, adding linting rules, a spec catalog and gateway integrations meets developers where they already work rather than asking them to adopt a second tool. For an organization standardized on Postman for design and testing, the governance layer is a lower-friction add than switching to a dedicated API management vendor. It ranks fifth because its production gateway capability is newer and thinner than the runtime-first products above it.
Where it falls short
The gateway and runtime traffic-management features are less mature than purpose-built gateways, and teams needing serious rate limiting, transformation or multi-region routing at production scale will find the runtime layer underpowered. Per-user pricing gets expensive fast for larger API programs, since it charges for people rather than traffic.
Wrong for
A team whose primary need is production traffic management, not design and testing, should pick a runtime-first gateway; Postman is a stronger fit for the design-and-collaboration side of the job.
Pricing: Free plan covers individual use and small teams; paid plans are priced per user per month on published tiers, with governance and enterprise features on the higher plans. (free plan)
Visit Postman →
#6 Azure API Management
Microsoft's API gateway and management layer inside Azure · United States · azure.microsoft.com
Azure-native Hybrid gateway Entra ID integration
Azure API Management is the reasonable default for an enterprise that already runs its infrastructure on Azure, because it inherits identity, networking and monitoring from the rest of the platform instead of requiring a separate integration project. The self-hosted gateway option lets a company keep traffic on-premises or in another cloud while still managing policy centrally from Azure, which is a genuine hybrid story most pure-play vendors cannot match. Capacity-based pricing is predictable once traffic is understood, and the Consumption tier gives a low-volume starting point.
Where it falls short
The XML-based policy pipeline has a real learning curve compared with newer products built around OpenAPI and code-first config, and the console can feel like it was designed for an Azure administrator rather than an API developer. Costs rise sharply moving from Consumption to the capacity-based tiers needed for production SLAs, and the product is a harder sell for a company not otherwise committed to Azure.
Wrong for
A multi-cloud company with no particular Azure commitment gets little benefit from the deep platform integration that is this product's main selling point; a cloud-neutral gateway is a better starting point.
Pricing: Capacity-based tiers billed per gateway unit per month, plus a pay-as-you-go Consumption tier billed per API call; Azure's general free-account trial credits apply to early testing. (free trial)
Visit Azure API Management →
#7 Google Apigee
Enterprise API platform with monetization and deep analytics · United States · cloud.google.com
Deep analytics API monetization Enterprise-scale
Apigee's origins as a standalone API analytics company show in how much more detail it exposes about API consumption than most competitors: cohort analysis of developers, revenue reporting for monetized APIs, and traffic anomaly detection are genuinely deeper here than elsewhere in this list. Google acquired the product specifically to compete at the top of the enterprise market, and it shows in the roadmap around AI-assisted spec design and multi-region hybrid deployment for companies not fully committed to Google Cloud. It sits in the middle of this ranking because that depth comes with enterprise pricing and complexity most buyers in this list's target range do not need.
Where it falls short
The pricing and packaging are dense enough that most buyers need a sales conversation to understand what a real deployment will cost, and the platform's monetization and analytics depth is wasted on a company that is not actually selling API access as a product. Implementation for a hybrid deployment can take real project time rather than a self-serve afternoon.
Wrong for
A team that just needs auth, rate limiting and a developer portal, without monetization or deep analytics, is paying for capability it will not use; a leaner gateway is a better fit.
Pricing: Priced per API call on published tiers, with an evaluation organization available for testing before committing to a paid plan. (free trial)
Visit Google Apigee →
#8 AWS API Gateway
Serverless-native API gateway for AWS workloads · United States · aws.amazon.com
Serverless-native Lowest cost at low volume AWS-only
AWS API Gateway is the obvious choice for a team already building on Lambda and other AWS services, because it wires into IAM, CloudWatch and the rest of the AWS control plane without a separate account or integration step, and its per-call pricing is genuinely inexpensive at moderate volume. It is less a full API management platform than raw, well-integrated gateway infrastructure: there is no built-in developer portal or governance layer, so a company publishing to outside partners typically pairs it with a separate portal product or builds one.
Where it falls short
There is no native developer portal, and API governance, spec cataloging and consumer-facing documentation all have to be built or bought separately, which raises the real cost of a full management setup above the advertised per-call price. Configuration through the console or CloudFormation has a learning curve, and the product is tightly coupled to AWS, offering no realistic path to running the same config on another cloud.
Wrong for
A company publishing APIs to external partners who need a self-service developer portal will find this product incomplete on its own; Gravitee or Azure API Management ship that layer built in.
Pricing: Priced per million API calls on a published pay-as-you-go rate, with a free tier of API calls included for a company's first 12 months on AWS. (free trial)
Visit AWS API Gateway →
#9 MuleSoft Anypoint Platform
Enterprise integration platform with API management built in · United States · mulesoft.com
Full integration suite Salesforce-owned Enterprise contracts
MuleSoft's API Manager is genuinely capable, but it is sold and used as part of a much larger integration platform rather than as a standalone gateway purchase, which is exactly the point for an enterprise that is buying Anypoint to connect Salesforce, SAP, mainframes and everything in between and wants API governance folded into that same contract. Since Salesforce's acquisition, it has continued to be the connective tissue vendor of choice for large, systems-heavy organizations, with a deep connector library that a pure API gateway does not attempt to match.
Where it falls short
Buying API management here effectively means buying the integration platform around it, which is a heavier and more expensive commitment than a company only wanting a gateway should take on. Contracts are quote-only and typically annual, implementation involves MuleSoft-trained specialists, and the pricing model is opaque until well into a sales process.
Wrong for
A company that only needs a gateway and developer portal, with no broader integration platform requirement, is buying far more product than the job calls for; a dedicated API management tool costs less and takes less time to stand up.
Pricing: Quote-only annual contracts, typically bundling API management with the platform's broader integration and connector licensing. (free trial)
Visit MuleSoft Anypoint Platform →
#10 IBM API Connect
Enterprise API gateway with hybrid and mainframe integration · United States · ibm.com
Hybrid deployment Mainframe integration Long track record
IBM API Connect has been in this market long enough to have built genuinely deep hybrid deployment options, including the ability to front mainframe and legacy IBM middleware transactions with a modern REST or GraphQL interface, which is a real and specific capability few competitors bother to maintain. For a bank or insurer with a large existing IBM footprint and compliance requirements around where data physically runs, that continuity carries real weight in a purchasing decision, and IBM's support organization is built for exactly this kind of long procurement cycle.
Where it falls short
The console and configuration model show their age next to gateways built in the last five years, licensing is opaque without a direct sales conversation, and smaller teams report a longer time to a first working API than with lighter competitors. The product is strongest when paired with other IBM infrastructure, which is not a fit for a company running elsewhere.
Wrong for
A company with no existing IBM footprint and no mainframe integration need will find lighter, faster-to-deploy products a better match; the legacy integration strength here is wasted on a greenfield stack.
Pricing: Quote-only licensing, typically sold in tiers by deployment size, with a lighter-weight edition available for smaller deployments. (free trial)
Visit IBM API Connect →
#11 SAP API Management
API gateway inside SAP Business Technology Platform · Germany · sap.com
SAP BTP-native S/4HANA integration Consumption billing
SAP API Management is really a module of SAP Integration Suite, and it is a sensible default for a company that already runs S/4HANA and BTP, since it ships pre-built connectors to SAP's own APIs and bills through a BTP contract a customer already has. For an SAP-centric IT organization, exposing SAP data and processes to external partners or internal apps through this layer avoids standing up and licensing a separate vendor relationship for what is functionally an extension of software already purchased.
Where it falls short
Outside the SAP ecosystem this is a weak general-purpose gateway; non-SAP API traffic gets little benefit from the product's main strengths, and the BTP consumption pricing model is confusing to reason about without an existing SAP licensing relationship to compare it against. The developer portal and analytics are noticeably thinner than the dedicated API management specialists in this list.
Wrong for
A company with no SAP footprint should not consider this product; the connectors and billing model that make it convenient for SAP shops offer nothing to anyone else.
Pricing: Consumption-based pricing through SAP BTP credits, billed per API call volume against a company's existing BTP contract. (free trial)
Visit SAP API Management →
#12 WSO2
Open-source API management with strong on-premises support · Sri Lanka · wso2.com
Open-source stack On-premises option Now PE-owned
WSO2 built its business on shipping a complete, genuinely open-source API management stack years before that was a common strategy, and the product still shows that discipline: governance, identity and gateway components are designed to work together rather than bolted on after an acquisition. That makes it a credible choice for a bank, telecom or government agency that needs to run the whole stack on its own infrastructure for regulatory reasons. EQT Private Capital Asia's 2024 acquisition ended its run as an independent company, though it remains headquartered in Colombo and the product roadmap has continued.
Where it falls short
The developer experience and documentation trail newer, venture-backed competitors, and the interface across the stack's several components feels less unified than a product built from one codebase. New ownership under a private equity buyer raises the usual questions about roadmap priorities and long-term pricing that any recently acquired vendor invites.
Wrong for
A small team wanting the fastest path to a first live API, with no regulatory requirement to self-host, will find the setup heavier than Zuplo or Tyk Cloud for no corresponding benefit.
Pricing: WSO2 API Manager is free and open source to self-host; subscription support and the managed Choreo/Private Cloud offerings are quoted separately. (open source)
Visit WSO2 →
#13 Axway Amplify
Legacy-integration-focused API management, publicly listed · France · axway.com
Legacy integration Publicly listed Enterprise contracts
Axway grew out of a 2011 spinoff from Sopra Group and has spent the years since specializing in exactly the kind of integration work newer, cloud-native gateways avoid: fronting mainframes, managed file transfer and older B2B protocols with a modern API layer. For an enterprise with a genuine legacy integration problem, that specialization is worth more than a slicker interface, and being a public company on Euronext Paris gives buyers financial transparency that privately held rivals do not offer.
Where it falls short
The product suite feels assembled from several product lines built at different times rather than one coherent platform, and the console is noticeably less modern than newer entrants in this list. Licensing is opaque without a sales conversation, and the company's growth has been slow relative to the venture-backed vendors it competes against, which shows in a smaller pace of new feature releases.
Wrong for
A company with no legacy or mainframe integration need, building purely cloud-native APIs, gets no benefit from Axway's core specialization and will find faster, cheaper options elsewhere in this list.
Pricing: Quote-only enterprise licensing, typically structured as an annual contract sized to deployment volume. (none)
Visit Axway Amplify →
#14 Sensedia
API management specialized in open banking and open finance · Brazil · sensedia.com
Open finance specialist Latin America focus ISO 27001 certified
Sensedia's most defensible advantage is not a general gateway feature but a specific one: it has built and maintained first-class support for Brazil's open finance mandate, including the consent-management and mutual-TLS auth flows the regime requires, well ahead of most competitors that treat regulated finance as a custom implementation project rather than a shipped product feature. For a bank or fintech operating under that framework, or elsewhere in Latin America under similar rules, that head start is worth more than a broader feature list built for a different market.
Where it falls short
Brand recognition and community size outside Latin America are limited, documentation and support are strongest in Portuguese and Spanish-speaking markets, and a company outside financial services or outside the region gets little benefit from Sensedia's core specialization. Everything is sold through a direct enterprise sales process with no self-serve entry point.
Wrong for
A company outside Latin American financial services, with no open banking obligation, will find broader, better-known gateways a more natural fit; Sensedia's depth is narrow by design.
Pricing: Quote-only enterprise contracts, sold through a direct sales and implementation engagement rather than self-serve signup. (none)
Visit Sensedia →
#15 Akana
Enterprise API lifecycle management under Perforce · United States · perforce.com
API lifecycle governance Perforce-owned Enterprise licensing
Akana has a long history in API lifecycle governance, the formal process of designing, reviewing, versioning and retiring APIs on a defined schedule, and that discipline is still its strongest feature for an enterprise that needs an audit trail on every API decision rather than a fast-moving startup workflow. Since Perforce folded it into a broader DevOps and version-control portfolio, it has become a component of a larger tooling sale rather than a standalone product with its own aggressive roadmap, which suits a buyer who already trusts Perforce for other infrastructure.
Where it falls short
Product development has slowed visibly since the acquisition, with fewer independent releases than the actively developed open-source and venture-backed products in this list, and the interface has not kept pace with newer competitors. It is sold entirely through enterprise licensing with no self-serve or transparent pricing option.
Wrong for
A team wanting an actively evolving product with a fast release cadence, or any self-serve entry point, will be better served by Gravitee, Tyk or Zuplo than by a product now positioned as one line item in a larger Perforce contract.
Pricing: Quote-only enterprise licensing, sold as part of Perforce's broader DevOps and API lifecycle product line. (none)
Visit Akana →
#16 API7
Commercial platform built on the open-source Apache APISIX gateway · China · api7.ai
Apache APISIX steward High-performance gateway Open source
Apache APISIX, the open-source project API7 stewards, has a genuine performance reputation, built on NGINX and etcd for low-latency routing, and has grown into a Cloud Native Computing Foundation project with adoption well beyond API7's own customer base, including multi-protocol support for gRPC, MQTT and WebSocket traffic that most gateways in this list do not handle natively. API7 Cloud, the managed layer the company sells on top, gives a team the performance of the open-source core without running etcd and the control plane by hand.
Where it falls short
API7 Cloud's commercial track record and support presence outside China are thinner than the long-established gateway vendors above it, documentation for the managed product lags the open-source project's own docs, and enterprise buyers with strict vendor-diligence requirements may need to do more legwork evaluating the company than with better-known incumbents.
Wrong for
An enterprise that needs an established support organization with a long regional track record and formal SLAs will find the surrounding commercial layer newer than the underlying open-source gateway; larger incumbents offer more support maturity.
Pricing: Apache APISIX is free and open source under Apache 2.0; API7 Cloud and Enterprise add-ons are priced on request. (open source)
Visit API7 →
Questions and answers
What is the best API management software in 2026?
Gravitee is the best overall pick for most teams: it pairs an open-source gateway with governance and a developer portal capable enough for both internal and partner-facing APIs, without forcing a full enterprise contract to get there. Tyk is the better choice for a team that wants to self-host from day one and values a transparent, request-based price on the managed option. Zuplo suits a small engineering team shipping a handful of APIs that wants the fastest path from OpenAPI spec to a live, git-managed gateway with no infrastructure to run.
Do we need a dedicated API gateway, or can our cloud provider's built-in option cover it?
If every API you run lives on one cloud and stays there, the built-in gateway (Azure API Management, AWS API Gateway or Google Apigee) removes a vendor relationship and bills alongside the rest of your cloud spend, which is a reasonable starting point. The case for a dedicated product grows once you run workloads across more than one cloud or on-premises, need policy configuration that survives a future cloud migration, or want a developer portal with more editorial control than the cloud provider's default.
What is the difference between an API gateway and full API management?
A gateway is the runtime component that sits in the traffic path enforcing auth, rate limits and routing; API management is the broader product, which adds a control plane for defining those policies, a developer portal for publishing documentation and issuing keys, and analytics on usage. Some products, particularly the open-source gateway cores, can be run alone without the portal or analytics layer, which is enough for a purely internal, engineer-only use case but not for publishing an API to outside partners.
Should the API gateway also handle service-to-service traffic inside our own systems?
Usually not with the same product. Internal, east-west traffic between microservices is more often handled by a service mesh (such as Istio or Linkerd) built for that pattern, while the API gateway products in this ranking are designed for north-south traffic entering from outside a trust boundary, whether that is a partner, a mobile app or a third-party developer. Some vendors, notably Kong, sell products in both categories, but treating them as the same purchase decision usually adds complexity without a matching benefit.
How hard is it to migrate an existing set of APIs onto a new gateway?
It depends almost entirely on how the current routing, auth and rate-limit rules are documented. A team with clean OpenAPI specs for every route can usually import them and get a first cutover done in days, testing with a small percentage of traffic before moving the rest. A team relying on undocumented rules baked into application code should expect the migration itself, not the gateway setup, to be the slow part, and should budget time to reconstruct the specs as a byproduct of the move regardless of which vendor is chosen.
Is open source enough, or do we need the commercial version?
Open-source cores from Kong, Tyk, Gravitee, WSO2 and API7 handle routing, auth and rate limiting competently and are a defensible choice for a team with the engineering capacity to run and patch them. What the commercial tiers usually add is a managed control plane, multi-region deployment, advanced analytics, enterprise auth integrations and support contracts with response-time guarantees. A company with no dedicated platform engineer, or one operating under a compliance regime that expects a vendor support agreement, generally ends up paying for the commercial layer regardless of which gateway it starts with.
How should we think about rate limiting for partner-facing APIs specifically?
Partner and public APIs need tiered limits keyed to the consumer, not a single global ceiling, because a misbehaving integration should degrade gracefully for that one partner rather than throttle every consumer at once. Check whether a product supports per-key or per-application quotas out of the box, whether limits can be raised for a specific partner without a deploy, and whether the response a throttled caller receives includes clear retry-after guidance, since a silent 429 with no explanation generates more support tickets than the rate limit itself was meant to prevent.
Do these platforms handle API versioning well?
Most support versioning through path or header-based routing, letting v1 and v2 of an endpoint run side by side while consumers migrate on their own schedule, and the better developer portals show which version each documented endpoint belongs to. What varies more is deprecation tooling: whether the platform can flag which consumers are still calling a retiring version, notify them automatically, and report a clean cutoff date, versus leaving that tracking to a spreadsheet someone maintains by hand.
What does an AI gateway add that a regular API gateway does not?
An AI gateway, now offered as an add-on or built-in mode by several vendors in this list, applies the same rate-limiting and auth concepts to calls made to large language model providers, plus token-based cost metering, prompt or response logging for audit purposes, and semantic caching to cut repeat-query costs. It matters specifically for a company routing its own or its customers' LLM traffic through a controlled layer; a team with no AI-facing product surface gets no benefit from paying for this feature.
Can a small team realistically run a self-hosted gateway, or is that only for large platform teams?
A single platform engineer can run a self-hosted open-source gateway for a modest number of APIs, particularly with the container images and Helm charts most of these projects publish, but it is an ongoing operational responsibility: patching, capacity planning and on-call for a component now sitting in front of every API call. Teams without spare engineering capacity for that tend to be better served by a managed cloud plan, even at a higher list price, because the alternative cost shows up as an outage nobody had time to prevent.
How do open banking or open finance rules affect which vendor to pick?
Regulated markets running open banking or open finance mandates, including Brazil's framework, typically require specific consent-management flows, mutual TLS or FAPI-compliant auth, and audit logging beyond what a generic gateway ships by default. Vendors with a track record in a specific regulated market, such as Sensedia in Brazil, have usually built those flows as first-class features rather than custom work, which is worth weighing heavily if your APIs fall under one of these regimes rather than treating it as a checkbox any gateway can satisfy.