Integrations
API Gateways
An API gateway is where Apiable imports your APIs from and deploys subscriptions to. Connect Amazon API Gateway through the guided setup, or Azure API Management, Kong or Apigee through their connect forms.
An API gateway is where Apiable imports your APIs from and deploys your subscriptions to. You connect the gateway that runs your APIs once, then package its APIs into plans. Amazon API Gateway connects through the guided setup and has the deepest support.
What does an API gateway integration do?
It links Apiable to the gateway that runs your APIs. Apiable imports your APIs from the gateway into the API Catalog, and deploys each subscription back to the gateway so consumers can call your APIs with their credentials.
A gateway integration does two jobs:
- Import your APIs. When you save the connection, Apiable imports the gateway's APIs into Catalog → API Catalog. You pick which of them each plan exposes.
- Deploy subscriptions. When a consumer subscribes to a plan bound to the gateway, Apiable provisions their access on the gateway, including the API key or OAuth client the plan calls for.
Plans come in two kinds. A Gateway-bound plan is tied to one connected gateway, and Apiable deploys its subscriptions there. A Catalog-bound plan draws its APIs from the API Catalog and does not deploy to a gateway, so it has no gateway rate limits or built-in usage analytics. See APIs and coupling.
Which API gateways does Apiable support?
Amazon API Gateway, Azure API Management, Kong and Apigee. Amazon connects through the guided setup; the other three connect through their own connect forms.
| Gateway | Listed as | How you connect |
|---|---|---|
| Amazon API Gateway | Amazon API Gateway | The guided setup, with CloudFormation or the AWS Console. See Connect AWS API Gateway. |
| Azure API Management | Azure API Gateway | The connect form. See Connect Azure API Management. |
| Kong | Kong Community Edition | The connect form. See Connect Kong. |
| Apigee | Apigee | The connect form. See Connect Apigee. |
Amazon API Gateway is a single entry. There is no longer a choice between Basic and Advanced. Select API Gateway Type also lists Kong Enterprise Edition, which does not open a connect form; to connect Kong, choose Kong Community Edition.
How do you connect an API gateway?
Start from the gateway's card on the Integrations page, or from + Add Gateway on the API Gateways page. Amazon then opens the guided setup. Azure, Kong and Apigee open a connect form, where you fill in the fields, test and save.
- Open Integrations → Integrations and choose Set up on the gateway's card. Or open Integrations → API Gateways, choose + Add Gateway, select the gateway on Select API Gateway Type and click Connect new API Gateway.
- For Amazon API Gateway, follow the guided setup in Connect AWS API Gateway.
- For Azure, Kong or Apigee, fill in the connection fields. Each gateway's page lists them.
- Click the refresh icon labelled test. The result reads Connected or Unsuccessful.
- Click Save Changes. If Save Changes stays unavailable on a new connection after the test reads Connected, contact support@apiable.io to finish connecting the gateway. Do not put keys or secrets in the email.
The API Gateways page shows how many gateways your plan includes, under Number of Gateways in your plan. When you have connected that many, + Add Gateway is unavailable; talk to Apiable sales to add more. If you buy Apiable through AWS Marketplace, the page says additional gateways are charged through AWS instead. To connect your first gateway, start from its card on the Integrations page or from Run the wizard.
If your plan does not include a gateway type, choosing it opens Please upgrade to access this feature, and its card on the Integrations page shows Plan upgrade required.
What happens when you save a gateway connection?
Apiable imports the gateway's APIs into Catalog → API Catalog. From there you add them to plans. For a plan to deploy subscriptions to the gateway, make it Gateway-bound to that gateway.
If your APIs do not appear, open Catalog → API Catalog and click Synchronize. Amazon API Gateway imports REST APIs and their stages. Azure API Management, Kong and Apigee import the APIs, services or API proxies the gateway lists.
Which gateway has the deepest support?
Amazon API Gateway. All four gateways support the core flow: import APIs, deploy plans and subscriptions, and issue, regenerate and revoke credentials. Amazon adds the per-key operations and gateway reads the other three do not implement.
| Capability | Amazon | Azure | Kong | Apigee |
|---|---|---|---|---|
| Import APIs into the API Catalog | Yes | Yes | Yes | Yes |
| Deploy plans and subscriptions | Yes | Yes | Yes | Yes |
| Issue, regenerate and revoke subscription credentials | Yes | Yes | Yes | Yes |
| Enable or disable an individual API key | Yes | No | No | No |
| Check that a plan is set up correctly on the gateway | Yes | No | No | No |
| Read usage per plan and per key from the gateway | Yes | No | No | No |
| Include only some resources of an API in a plan | Yes | No | No | No |
| Pull an API specification with Gateway Synchronization | Yes | No | No | No |
Each gateway issues its own kinds of credential. Azure API Management issues subscription keys, Kong issues API keys, OAuth 2.0 apps or JWT credentials, and Apigee issues a developer app's consumer key and secret. Each gateway's page describes what Apiable creates on it.
On Amazon API Gateway you can also stream access logs to Apiable for usage-based billing. See Enable usage logs on AWS API Gateway.
Can you rotate a subscription's secret?
Not on standard setups, on any gateway. Rotate Secret appears only for one custom authorization server setup. Everywhere else, a subscription offers Regenerate Credentials, which revokes the current credentials and issues new ones. Regenerate works on all four gateways.
Regenerating invalidates the old credentials, so applications using them stop working until they switch to the new ones. The new credentials are shown once. See Credentials for how Regenerate and Rotate Secret differ.
How does a gateway connect to an Authorization Server?
Open the saved gateway and go to its Authorization tab. In the Level 1+ OAuth 2.0 section, the OAuth handler answers What handles OAuth flows?: Gateway-native only or Authorization Server.
- Gateway-native only is limited to Client Credentials, with no user flows.
- Authorization Server enables Client Credentials, Auth Code, PKCE and JWT validation. Picking it reveals a picker of your connected servers, and + Add new Authorization Server.
The tab also shows the Level 0 API Key section, provided by the gateway and always available, and Product-level governance, where Plan governance is Free choice or Locked to this pairing. Click Save Changes to apply.
The Authorization tab is available once the gateway is saved. For an Amazon API Gateway connected through the guided setup, its Authorization step, Choose your authorization enforcement model, sets how authorization is enforced. See Authorization Servers.
How do you delete a gateway?
Open Integrations → API Gateways, open the gateway's row menu and choose Delete. Delete Gateway asks you to confirm. You cannot confirm while a plan still uses the gateway.
Deleting a gateway also removes its APIs from the API Catalog, and cannot be undone. Remove the gateway from your plans first. Read-only gateways, marked read only in the list, cannot be deleted.
Troubleshooting
Match what you see to the fix.
| What you see | What to do |
|---|---|
| + Add Gateway is unavailable | You have connected as many gateways as your plan includes, or your role cannot add gateways. For your first gateway, start from its card on Integrations → Integrations or from Run the wizard. |
| Please upgrade to access this feature when you pick a gateway type | Your plan does not include that gateway type. Talk to Apiable sales. |
| Sorry, this gateway is not included in your plan. | You opened a connect address for a gateway type your plan does not include. |
| Save Changes stays unavailable on a new Azure, Kong or Apigee connection | Run the test first. If it reads Connected and Save Changes is still unavailable, contact support@apiable.io to finish connecting the gateway. |
| Banner: Your account does not currently possess a sufficient role or permissions required to manage gateways. | Your role cannot manage gateways. Ask an Organisation Admin to give you a role that can, such as Configuration Owner. |
| Your APIs are missing from the API Catalog | Open Catalog → API Catalog and click Synchronize. |
| Delete Gateway cannot be confirmed | A plan still uses this gateway. Remove the gateway from those plans, then delete it. |
| Apiable doesn't connect Azure API Gateway yet (or Kong or Apigee) in the guided setup | The guided setup connects Amazon API Gateway only. Connect this gateway from its card on the Integrations page. |
Where to next
Connect AWS API Gateway
The guided setup for Amazon API Gateway, screen by screen.
Connect Azure API Management
Connect an Azure API Management service with a service principal.
Connect Kong
Connect a Kong gateway through its Admin API.
Connect Apigee
Connect Apigee with a Google Cloud service account key.
Authorization Servers
Connect Keycloak, Auth0 or Duende to issue the OAuth 2.0 tokens your gateway validates.
APIs and coupling
Choose which APIs a plan exposes, and whether it is Gateway-bound or Catalog-bound.
Integrations
Every system Apiable connects to, and the Integrations page.