API gateways

A gateway enforces policy where traffic passes through it, and only there.

Authentication, rate limiting, logging and schema validation in one place is a genuine win. It also means anything reaching the service by another route, internal callers, a direct address, a legacy path, bypasses all of it. The control is only as good as the certainty that there is no way round.

Checked against the primary source.

More on API security