Apiable

Integrations

Connect Azure API Management

Connect Azure API Management in Apiable with a service principal. Enter the connection name, Client ID, Secret, Tenant Id, Subscription Id, Resource Group and Service ID, then test the connection.

You connect Azure API Management with a service principal. You give the connection a name and enter the service principal's Client ID and Secret, plus your Tenant Id, Subscription Id, Resource Group and Service ID. Then you run the test and save. The core flow works on Azure; some per-key operations are Amazon only.

Where do you connect Azure API Management?

On the Integrations page, choose Set up on the Azure API Gateway card. Or open Integrations → API Gateways, choose + Add Gateway, select Azure API Gateway on Select API Gateway Type, and click Connect new API Gateway.

The guided setup connects Amazon API Gateway only. If you start Run the wizard as an Azure customer, its Gateway step shows Apiable doesn't connect Azure API Gateway yet. Connect Azure from its card first. The guided setup then shows Your gateway is already connected, and you continue to the next step.

What does each Azure field mean?

The connect form asks for a name and six Azure values. Client ID and Secret are write-only, so the form does not show them again after you save.

FieldWhat to enter
NameA label for this connection inside Apiable.
Client ID (write-only)The Application (client) ID of the app registration Apiable authenticates as.
Secret (write-only)A client secret of that app registration.
Tenant IdYour Microsoft Entra ID Directory (tenant) ID.
Subscription IdThe Azure subscription that holds your API Management service.
Resource GroupThe resource group that holds the service.
Service IDThe name of your API Management service.

Apiable uses these to request an Azure access token and call the Azure Resource Manager API for your API Management service.

How do you set up a least-privilege service principal?

Create an app registration in Microsoft Entra ID, add a client secret, and assign it the built-in role API Management Service Contributor scoped to your API Management instance. That gives Apiable access to that one service and nothing wider.

  1. In Microsoft Entra ID, go to App registrations and register a new application. Single tenant is enough, and no redirect URI is needed.
  2. On the app's Overview, copy the Application (client) ID and the Directory (tenant) ID. These are the Client ID and Tenant Id in Apiable.
  3. Under Certificates and secrets, add a new client secret. Copy its value straight away, because Azure shows it only once. This is the Secret in Apiable.
  4. Open your API Management instance, go to Access control (IAM), and add a role assignment.
  5. Assign the built-in role API Management Service Contributor, with the app registration as the member. Scope it to this API Management instance, not the whole subscription.

Apiable authenticates as this service principal, and calls the Azure Resource Manager API for the one API Management service named by Service ID. With the role scoped to that instance, the credentials cannot reach other resources.

How do you test and save the Azure connection?

Fill in the fields, then click the refresh icon labelled test. Apiable lists the APIs on your API Management service to confirm the credentials work. The result reads Connected or Unsuccessful. Then click Save Changes.

  1. Enter Name, Client ID, Secret, Tenant Id, Subscription Id, Resource Group and Service ID. The test becomes available once the first six are filled, but it fails without a correct Service ID.
  2. Click the refresh icon labelled test. Apiable requests a token and lists the APIs on your service.
  3. Read the result: Connected means the test passed; Unsuccessful means it failed.
  4. Click Save Changes. The gateway appears on the API Gateways list.

If Save Changes stays unavailable after the test reads Connected, contact support@apiable.io to finish connecting the gateway. Do not put the Client ID or Secret in the email.

When you edit a saved Azure gateway, enter the Client ID and Secret again before you test or save. The form never shows the saved values.

How do you point the Azure gateway at an Authorization Server?

Open the saved gateway and go to its Authorization tab. Under OAuth handler, choose Gateway-native only or Authorization Server. Picking Authorization Server reveals a picker of your connected servers. Click Save Changes to apply.

The tab also has the Level 0 API Key section and Product-level governance. See API Gateways for what each part does, and Authorization Servers for connecting a server.

Where do your Azure APIs appear after connecting?

In Catalog → API Catalog. When you save the connection, Apiable imports the APIs on your API Management service, so you do not need to synchronize by hand. You then add them to plans.

For each plan, Apiable creates an Azure product and attaches the plan's APIs. When a consumer subscribes, Apiable creates an Azure subscription with primary and secondary keys. See APIs and coupling and Plans.

What does Apiable support on Azure API Management today?

The core flow: connect the gateway, import its APIs, and deploy plans as Azure products and subscriptions as Azure subscriptions. Some per-key operations and gateway reads are available on Amazon API Gateway only.

These are not available on Azure API Management:

  • Enabling or disabling an individual API key.
  • Checking that a plan is set up correctly on the gateway.
  • Reading usage per plan or per key from the gateway.
  • Including only some resources of an API in a plan.
  • Pulling API specifications with Gateway Synchronization.

Secret rotation is not available on standard setups for any gateway. To replace a subscription's keys on Azure, use Regenerate Credentials: Apiable revokes the current credentials and issues new ones. See Credentials.

Troubleshooting

Match what you see to the fix.

What you seeWhat to do
The test control is unavailableOne of Name, Client ID, Secret, Tenant Id, Subscription Id or Resource Group is empty. When editing, enter the Client ID and Secret again.
The test reads UnsuccessfulApiable could not list APIs on your service. Check the Client ID and Secret, that the service principal has the role on the service, and that Subscription Id, Resource Group and Service ID are correct.
Save Changes stays unavailable on a new connectionRun the test first. If it reads Connected and Save Changes is still unavailable, contact support@apiable.io to finish connecting the gateway.
The Client ID and Secret look empty when you reopen the gatewayBoth are write-only, so the form does not show them. Enter them again to test or save.
Apiable doesn't connect Azure API Gateway yet in the guided setupThe guided setup connects Amazon API Gateway only. Connect Azure from its card on the Integrations page.
Banner: Your account does not currently possess a sufficient role or permissions required to manage gateways.Your role cannot manage gateways. Ask an Organisation Admin for a role that can, such as Configuration Owner.
Delete Gateway cannot be confirmedA plan still uses this gateway. Remove the gateway from those plans, then delete it.

Where to next