Platform
Platform overview
How Apiable fits together: a dashboard control plane and a branded API Portal that configure your own API gateways and authorization servers. Your API traffic runs on your gateway, not through Apiable.
Apiable is a control plane and a branded API Portal that sit on top of the infrastructure you already run. You connect your API gateways and authorization servers once, and Apiable configures them and runs the portal your consumers use. Your API traffic stays on your own gateway.
What is Apiable's architecture?
A control plane plus a branded API Portal. The dashboard configures your own API gateways and authorization servers. The API Portal is the site your consumers use to discover APIs, subscribe to plans, and manage their access and credentials.
Four parts work together:
| Part | What it is | Who hosts it |
|---|---|---|
| Dashboard | Where you connect gateways, build products and plans, and manage consumers. | Apiable, on AWS |
| API Portal | Your branded site where consumers subscribe and get credentials. | Apiable, on AWS |
| Your API gateways | The gateways that run your APIs and serve live traffic. | You |
| Your authorization servers | The OAuth2 layer that issues and validates tokens. | You |
Apiable hosts the first two. The last two are yours: Apiable connects to them and configures them, but does not replace them. See Hosting and infrastructure for where each part runs.
Does my API traffic flow through Apiable?
No, apart from one case. A consumer's request goes from the consumer to your gateway to your backend. The exception is prepaid plans that use Apiable-managed credits, where your gateway's Apiable authorizer checks credit with Apiable as it authorizes each call.
This is the no-proxy model. Apiable creates plans, API keys and OAuth clients on your gateway and authorization server ahead of time, then stays out of the request path. See The no-proxy model for how data flows, what the prepaid exception means, and what it means for latency.
Which API gateways does Apiable work with?
Amazon API Gateway, Azure API Gateway, Kong and Apigee. Apiable uses a dedicated adapter for each gateway type, so you connect the gateway that already runs your APIs rather than moving to a new one.
What each gateway supports differs. See API Gateways before you choose.
How does Apiable secure access without holding your traffic?
It configures access on your own gateway and authorization server. Your authorization server issues tokens carrying the granted scopes, and your gateway checks the credential or token before a request reaches your backend.
A gateway resolves OAuth natively, or binds an external Authorization Server: Keycloak, Auth0 or Duende. Apiable registers an OAuth client per subscription on the Authorization Server through Dynamic Client Registration. With Duende, a client's scopes are set when it is registered, and Apiable cannot change them afterwards. Amazon Cognito and Okta show as Coming Soon.
See Authorization Servers and Access control for how scopes are assigned and enforced, and Security and compliance for the platform's security mechanisms.
Where to next
The no-proxy model
Why your API traffic stays on your gateway, and the one exception.
Security and compliance
The security mechanisms in the product, and where to get compliance documentation.
Hosting and infrastructure
Where the dashboard, the API Portal and the Platform API run.
Platform positioning
The product view of what Apiable does and the problems it solves.