Apiable

Platform

The no-proxy model

Apiable does not sit in your API request path. Your traffic runs on your own gateway; Apiable configures the gateway ahead of time. The one exception is prepaid plans with Apiable-managed credits, where the authorizer checks credit with Apiable on each call.

Apiable is not a proxy. Your API traffic runs on your own gateway, the same way it runs without Apiable. Apiable configures your gateway through its management API and stays out of the request path, with one exception for prepaid plans that use Apiable-managed credits.

Does Apiable proxy my API traffic?

No. Apiable does not sit between your consumers and your gateway. A consumer calls your gateway directly, your gateway validates the credential or token, and your backend responds. Apiable set that gateway up ahead of time.

The request path with Apiable is the path you already have:

  1. Your consumer sends a request to your gateway with their API key or OAuth token.
  2. Your gateway validates the credential and enforces the plan's limits and scopes.
  3. Your gateway forwards the request to your backend.
  4. Your backend responds through your gateway to the consumer.

Apiable is not a step in that list, except in the prepaid case below. It configured the gateway ahead of time and it runs the portal where the consumer got their credentials.

When does Apiable take part in a request?

On prepaid plans whose Bill Processing is Apiable - Credits. Your gateway's Apiable authorizer checks the subscriber's credit with your Apiable portal, and draws it down, as it authorizes each call. If Apiable cannot be reached, the call is refused.

This applies only to those plans, which run on Amazon API Gateway with the Apiable authorizer. The dashboard says so when you choose the option: Apiable-managed credits require Apiable to act as middleware for the applicable calls, which may add latency and makes them depend on your portal's availability.

PlanDoes a call reach Apiable?
Any plan without Apiable-managed creditsNo. The gateway authorizes and serves the call on its own.
Prepaid plan with Apiable - CreditsYes. The authorizer checks and draws credit through your portal before it allows the call.

See Monetization for how prepaid credits work.

What does Apiable do if it is not in the request path?

It configures your gateway out of band. Apiable calls your gateway's management API to read your APIs, create plans, and provision each subscriber's API key or OAuth client. Those are control-plane operations, separate from live API traffic.

On Amazon API Gateway, for example, Apiable uses the AWS API Gateway management client against your own AWS account to list your REST APIs and stages, deploy plans, rotate a subscription secret, enable or disable a key, and read usage. The same pattern applies to each gateway through a gateway-specific adapter.

What is the difference between gateway-bound and catalog-bound for data flow?

A plan is either gateway-bound or catalog-bound. Gateway-bound plans provision credentials on one gateway and run traffic there. Catalog-bound plans never push to a gateway: they group catalog APIs in your portal and rely on scopes for access.

CouplingWhere APIs come fromProvisioning on a gatewayHow access is secured
Gateway-boundOne API gatewayYes, the API key or OAuth client is created on that gatewayGateway limits and credentials, plus scopes when an authorization server is configured
Catalog-boundThe API Catalog, across one or more gatewaysNo, catalog APIs are never pushed to a gatewayScope-based access through your authorization server, when one is configured

A gateway-bound plan binds to a single gateway and creates credentials on it. A catalog-bound plan has no gateway binding and no rate limit. See APIs and coupling for how you choose between them on a plan.

Where does Apiable create my API keys and OAuth clients?

On your own gateway and your own authorization server. For a gateway-bound plan, Apiable provisions the subscriber's API key or OAuth client on the gateway. For scope-based access, it registers an OAuth client per subscription on your authorization server through Dynamic Client Registration.

A gateway resolves OAuth one of two ways. It issues and validates tokens natively, or it binds an external Authorization Server, such as Keycloak, Auth0 or Duende, that issues the tokens. Either way, your gateway validates the token at request time. See Authorization Servers and Scopes.

What does no-proxy mean for data residency and latency?

Your request and response payloads stay on your infrastructure, and your calls take the same network path they take without Apiable. Apiable exchanges configuration and management calls with your gateway, not your payloads.

Two things do reach Apiable. If you connect gateway access logs for usage billing or analytics, Apiable receives a per-request log record, with the fields in the log format and no bodies; see Enable usage logs on AWS API Gateway. And on prepaid plans with Apiable-managed credits, the credit check adds a round trip to Apiable on each authorized call.

For where Apiable's own dashboard and API Portal run, see Hosting and infrastructure.

Where to next