New

Announcing AISIX: The AI-Native AI Gateway for LLMs and AI AgentsLearn More

Learn More

All posts tagged

"API Gateway Security"

API Gateway and WAF Reference Architecture: Ownership, Header Trust, and Failure Modes

API Gateway Guide

September 11, 2026

API Gateway and WAF Reference Architecture: Ownership, Header Trust, and Failure Modes

Design an API gateway and WAF integration with explicit control ownership, trusted client context, bypass prevention, and tested failure behavior.

API Access Log Auditing: Evidence, Integrity, Retention, and Review

API Gateway Guide

September 10, 2026

API Access Log Auditing: Evidence, Integrity, Retention, and Review

Design gateway audit evidence that identifies actors, actions, resources, and outcomes while protecting sensitive log data.

Preventing API Scraping and Abuse: Identity, Behavioral Signals, and Rate Controls

API Gateway Guide

September 10, 2026

Preventing API Scraping and Abuse: Identity, Behavioral Signals, and Rate Controls

Reduce abusive automation with identity-aware quotas, behavioral signals, graduated responses, and tested ownership across gateway and application layers.

API Gateway mTLS: Client Identity, Certificate Rotation, and APISIX Configuration

API Gateway Guide

September 10, 2026

API Gateway mTLS: Client Identity, Certificate Rotation, and APISIX Configuration

Deploy client-to-gateway mTLS with explicit trust anchors, safe identity mapping, certificate rotation, and tested failure behavior.

Fine-Grained API Gateway Authorization: RBAC, ABAC, and External Policy Decisions

API Gateway Guide

September 10, 2026

Fine-Grained API Gateway Authorization: RBAC, ABAC, and External Policy Decisions

Design gateway authorization with explicit policy inputs, external decisions, fail-closed behavior, and application-owned object checks.

Distributed API Gateway Rate Limiting: Local vs Redis Counters and Accuracy Trade-offs

API Gateway Guide

September 9, 2026

Distributed API Gateway Rate Limiting: Local vs Redis Counters and Accuracy Trade-offs

Choose local or shared Redis rate-limit counters by balancing fleet-wide accuracy, latency, dependency risk, and failure behavior.

API Gateway IP Allowlist and Denylist Management: Trust, Proxies, and Operations

API Gateway Guide

September 9, 2026

API Gateway IP Allowlist and Denylist Management: Trust, Proxies, and Operations

Build dependable API gateway IP policies by establishing a trusted client address, choosing the right list, and operating changes safely.

API Gateway Security Scanning: What to Test and How to Operationalize Findings

API Gateway Guide

September 9, 2026

API Gateway Security Scanning: What to Test and How to Operationalize Findings

Build a repeatable API gateway security scanning program across software, configuration, control-plane exposure, and API behavior.

SQL Injection and XSS at the API Gateway: Detection Limits and Defense in Depth

API Gateway Guide

September 9, 2026

SQL Injection and XSS at the API Gateway: Detection Limits and Defense in Depth

Use API gateway validation and WAF controls without mistaking them for application-level fixes for SQL injection or cross-site scripting.

DDoS Defense at the API Gateway: Layered Controls and Failure Planning

API Gateway Guide

September 8, 2026

DDoS Defense at the API Gateway: Layered Controls and Failure Planning

Place API gateway controls in a layered DDoS defense with upstream mitigation, origin protection, resource limits, observability, and response drills.