Apiable

Platform · Architecture

Built on open standards.

OpenAPI 3.1, OAuth 2.0, and OpenID Connect — the protocols your platform team already runs in production. Apiable plugs in as a thin layer on top of your existing stack. We don't proxy your API traffic, and we don't ask your engineers to learn a proprietary auth model.

How Apiable works A diagram showing API consumer onboarding through Apiable, then runtime API calls bypassing Apiable entirely. Apiable provisions and observes but never sits in the request path. ◆ APIABLE ◇ YOUR INFRASTRUCTURE Portal Branded developer hub Backend Provisioning & analytics IdP Your identity provider API Gateway API Consumer Your technology partner building against your APIs 1 2 2 3 4 4 Apiable provisions and observes — but is never in the runtime request path. NO REPLATFORMING · NO PROXY · OPEN STANDARDS
① Onboarding

Consumer signs up

A developer or partner discovers your API and registers through your branded portal.

② Subscription

Backend provisions access

Apiable creates an OAuth client in your IdP through DCR and registers a key in your API gateway.

③ Credentials

Delivered to the consumer

Scoped credentials surface in the portal. The consumer is ready to make their first API call.

④ Runtime

API calls bypass Apiable

At runtime, traffic flows directly from the API consumer to your IdP and gateway.

How it fits

Three layers, one principle.

Your gateway and IdP keep doing what they're already doing. Apiable adds onboarding, plans, quotas, billing, and a self-serve developer portal on top — and talks to the layers below through open standards wherever they exist (OpenAPI, OAuth 2.0, OIDC). Where a gateway exposes only a vendor API, we integrate against that — but the protocols your developers and partners touch stay open.

Standards

Three protocols do all the work.

Same protocols your platform team already runs in production.

RFC · OpenAPI 3.x OAS

OpenAPI 3.0 & 3.1

We sync your API catalog from your gateway using your existing OpenAPI specs.

Specs can be pulled from your gateway, uploaded manually, or synchronized through your CI/CD pipeline. We store and version the spec — when it changes, the portal catalog updates.

Read the API Gateway sync page
RFC 6749 OAuth

OAuth 2.0

Standard token flows, scopes, and grant types. No proprietary auth.

Authorization code, client credentials, and refresh-token grants. Scope-based access control mapped to plans and products. Your engineers don't learn a new auth model.

Read the API Security page
OIDC core 1.0 OIDC

OpenID Connect

Federated authentication with your existing OIDC-compliant provider.

Partner onboarding via DCR (RFC 7591) — Apiable provisions OAuth clients in Cognito, Keycloak, Auth0, or Duende. No custom adapter, no proprietary protocol.

Read the API Security page

API gateways

Four supported out of the box. More on demand.

KNG

Kong Gateway self-managed

Consumer provisioning via Kong Admin API. Rate-limiting & ACL plugin for plan access control.

Reference architecture

More gateways available on demand. Talk to us.

Identity providers

Three named integrations, plus any OIDC-compliant provider.

CGN

AWS Cognito

Most common deployment. One Cognito user pool per Customer.

Recommended on AWS
MS

Microsoft Entra ID

Enterprise path; common in larger organization stacks where compliance is paramount.

A0

Auth0

Federation pattern for orgs already standardized on Auth0 — including custom rules and post-login actions.

+

Any OIDC-compliant provider

If your IdP speaks OIDC, Apiable can federate. Okta, Entra ID, Ping, ForgeRock — talk to us about edge cases.

Does Apiable proxy my API traffic?

No.

Apiable does not sit in your API request path.

Traffic between your developers and your gateway never passes through Apiable's infrastructure. Onboarding, plans, quotas, and billing happen in Apiable; the API calls themselves do not.

Optionally, Apiable retrospectively reads your gateway's log files to track usage, generate insights, and drive billing. Log access is read-only and runs on your schedule, not in the request path.

"If Apiable required network traffic to pass through their data center, that would be a dead route."

— security architect, Convera
Read the security and data-flow page

Hosting

Where is Apiable hosted?

eu-central-1 Frankfurt · AWS

Customer data and configuration are stored in Frankfurt. Additional regions are available for enterprise customers — talk to us if you need US, APAC, or another EU region.

Read the security page

Implementation timeline

Three honest scenarios. Your timeline lands inside one of them.

Standard
1 wk

Existing AWS API Gateway + Cognito.

Simple plan model, default branding, single gateway. The fastest path — and the most common one for AWS-native programs.

Customized
4 wks

Multi-gateway or multi-IdP, custom branding, custom plans.

Most teams with an existing API program land here — multiple gateways, federated identity, plan model tied to existing pricing tiers.

Enterprise
12 wks

Complex enterprise integration.

Regulated industry, custom auth federation, contractual approvals workflow, security reviews.

The variables: gateway count, IdP federation depth, billing-model complexity. Everything else is consistent.

Talk to us about your timeline

Is Apiable a fit?

We'd rather tell you on the first call than burn three months.

Built for you if

  • You already run an API gateway (AWS, Apigee, Kong, …)
  • Your APIs are REST, with OpenAPI specs maintained somewhere
  • You want partners to onboard themselves, not via support tickets
  • Monetization, plans, or quotas are on your roadmap

× Probably not for you if

  • Your program is GraphQL-only
  • Deployment must be fully on-premise with no SaaS plane
  • You don't have an API gateway today (start with one first)

If that's you, we'll tell you on the first call rather than burn three months of evaluation. See the full fit checklist

Explore more of the Apiable Platform

All the tools you need to manage your entire API Ecosystem.

API Portal as a Service

Innovate and grow fast with an API Portal built for API Consumers, API Product Managers, API Products, and Multiple API gateways.

Explore API Portal
Apiable API Portal dashboard showing developer onboarding

Talk to us

See your stack inside Apiable in a 45-minute call.

Request a Demo

Want to read the security & compliance details first? Go there →