{"id":1184,"date":"2026-09-11T10:41:45","date_gmt":"2026-09-11T10:41:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1184"},"modified":"2026-09-11T10:41:45","modified_gmt":"2026-09-11T10:41:45","slug":"api-gateway","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/api-gateway\/","title":{"rendered":"API Gateway"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: API GATEWAY\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">An API gateway is infrastructure that happens to enforce security, not a security product. Treating it as one is how teams end up with a hardened front door and an unlocked side entrance.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>An API gateway is a single entry point that sits in front of backend services. It routes requests, enforces authentication, applies rate limits, transforms payloads, manages versions and produces logs. It centralises concerns that would otherwise be duplicated in every service, which is a strong architectural reason to run one and a weak reason to consider your APIs protected.<\/p>\n<\/div>\n\n<p>The distinction matters because the gateway only sees traffic that goes through it, and it only checks the things it was told to check.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#functions\">The six API gateway functions<\/a><\/li>\n    <li><a href=\"#path\">What an API gateway does to a request<\/a><\/li>\n    <li><a href=\"#misses\">What an API gateway does not catch<\/a><\/li>\n    <li><a href=\"#versus\">API gateway, WAF and API security<\/a><\/li>\n    <li><a href=\"#osto\">How Osto approaches API gateway gaps<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"functions\">The six API gateway functions<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Function<\/th><th>What it does<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Routing<\/td><td>Directs a request to the right backend service, hiding internal topology from clients<\/td><\/tr>\n    <tr><td>Authentication<\/td><td>Validates tokens, keys or certificates once, so each service does not reimplement it<\/td><\/tr>\n    <tr><td>Rate limiting and quotas<\/td><td>Caps request volume per client, protecting backends from overload and abuse<\/td><\/tr>\n    <tr><td>Transformation<\/td><td>Reshapes requests and responses between what clients send and what services expect<\/td><\/tr>\n    <tr><td>Versioning<\/td><td>Runs multiple API versions side by side so consumers migrate on their own schedule<\/td><\/tr>\n    <tr><td>Observability<\/td><td>Produces a consistent log and metric stream, which is what makes <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlation<\/a> possible later<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"path\" class=\"c-sage\">What an API gateway does to a request<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 178\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Request path through an API gateway: client, authentication, rate limit, routing, then backend service.\">\n  <defs><marker id=\"ag\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"42\" width=\"112\" height=\"60\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"68\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Client<\/text>\n  <text x=\"68\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#0f1538\">App, partner, bot<\/text>\n  <line x1=\"128\" y1=\"72\" x2=\"146\" y2=\"72\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ag)\"\/>\n\n  <rect x=\"152\" y=\"26\" width=\"386\" height=\"92\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"345\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#8f9ad4\">GATEWAY<\/text>\n\n  <rect x=\"168\" y=\"58\" width=\"112\" height=\"44\" rx=\"10\" fill=\"#3f4796\"\/>\n  <text x=\"224\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#ffffff\">Authenticate<\/text>\n  <text x=\"224\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9\" fill=\"#c7cceb\">Who is calling?<\/text>\n\n  <rect x=\"288\" y=\"58\" width=\"112\" height=\"44\" rx=\"10\" fill=\"#3f4796\"\/>\n  <text x=\"344\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#ffffff\">Rate limit<\/text>\n  <text x=\"344\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9\" fill=\"#c7cceb\">How often?<\/text>\n\n  <rect x=\"408\" y=\"58\" width=\"114\" height=\"44\" rx=\"10\" fill=\"#3f4796\"\/>\n  <text x=\"465\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#ffffff\">Route<\/text>\n  <text x=\"465\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9\" fill=\"#c7cceb\">Which service?<\/text>\n\n  <line x1=\"542\" y1=\"72\" x2=\"560\" y2=\"72\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ag)\"\/>\n  <rect x=\"566\" y=\"42\" width=\"182\" height=\"60\" rx=\"12\" fill=\"#3a6f5d\"\/>\n  <text x=\"657\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#ffffff\">Backend service<\/text>\n  <text x=\"657\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#c9e5d8\">Decides what you may see<\/text>\n\n  <rect x=\"12\" y=\"130\" width=\"736\" height=\"38\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"154\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">The gateway confirms who is calling. Only the service knows whether that caller should see this particular record.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"misses\" class=\"c-plum\">What an API gateway does not catch<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Gap<\/th><th>Why the gateway misses it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Shadow and undocumented APIs<\/td><td>Endpoints deployed outside the API gateway are invisible to it, which is why <a href=\"https:\/\/www.osto.one\/resources\/glossary\/easm\/\">external discovery<\/a> keeps finding them<\/td><\/tr>\n    <tr><td>Broken object level authorisation<\/td><td>A valid token requesting someone else&#8217;s record looks like a legitimate request. Only the service knows it is not<\/td><\/tr>\n    <tr><td>Excessive data exposure<\/td><td>An endpoint returning more fields than the client needs passes through untouched<\/td><\/tr>\n    <tr><td>Business logic abuse<\/td><td>Sequences of individually permitted calls that add up to something the design never intended<\/td><\/tr>\n    <tr><td>Internal service traffic<\/td><td>Service to service calls that never traverse the gateway carry none of its policy<\/td><\/tr>\n    <tr><td>Schema drift<\/td><td>A new parameter shipped on Friday is not in the gateway&#8217;s definition until someone updates it<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Authentication is not authorisation<\/p>\n  <p>Nearly every serious API breach of recent years turns on this. The gateway confirmed a valid token, then a service returned data belonging to a different customer because the object level check was missing. Broken object level authorisation sits at the top of the OWASP API Security Top 10 precisely because it is invisible at the edge. A gateway cannot fix it, and a gateway vendor cannot claim to.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-sky\">API gateway, WAF and API security<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>API gateway<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a><\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Primary job<\/td><td>Manage and route traffic<\/td><td>Block known attack patterns<\/td><td>Understand the API and how it is being used<\/td><\/tr>\n    <tr><td>Knows your endpoints<\/td><td>Only those registered with it<\/td><td>Only those behind it<\/td><td>Discovers them, including unregistered ones<\/td><\/tr>\n    <tr><td>Checks payload validity<\/td><td>Schema, if configured<\/td><td>Against attack signatures<\/td><td>Against learned normal behaviour<\/td><\/tr>\n    <tr><td>Catches logic abuse<\/td><td>No<\/td><td>Rarely<\/td><td>This is the point of it<\/td><\/tr>\n    <tr><td>You need it because<\/td><td>Architecture<\/td><td>Volume of generic attacks<\/td><td>The gaps the other two leave<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>They stack rather than compete. Run an API gateway because managing routing, auth and rate limits in one place is good engineering. Add protection layers because the gateway was never designed to answer the question of whether a well-formed, authenticated request is legitimate.<\/p>\n\n<h2 id=\"osto\">How Osto approaches API gateway gaps<\/h2>\n\n<p>Osto is not an API gateway and does not replace one. Keep whichever you run. What Osto adds is the layer the gateway leaves uncovered.<\/p>\n\n<p>Applications and APIs are discovered automatically, which matters most for endpoints that were never registered with a gateway in the first place. The engine learns URLs, parameters and HTTP methods for each application and generates a positive security policy from observed behaviour, so validation reflects what the API actually does rather than what a specification claims. Input validation, parameter type enforcement, cookie and session protection, file upload checks and protection against parameter pollution and forced browsing all apply to traffic the gateway would have passed on. Policy recommendations continue as the application changes, which addresses the schema drift row above. Requests correlate in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as identity and endpoint events, so an unusual API call pattern can be read alongside the login that preceded it.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Including the endpoints nobody registered<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Automatic API discovery with a positive security policy generated from observed behaviour, not from a spec that drifted. Keep your gateway. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Auto-discovery, auto-protection &middot; No hand-written rules &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is an API gateway?<\/summary>\n  <p>A single entry point in front of backend services that routes requests, enforces authentication, applies rate limits, transforms payloads, handles versioning and centralises logging. It removes the need for every service to implement those concerns separately.<\/p>\n<\/details>\n\n<details>\n  <summary>Is an API gateway a security tool?<\/summary>\n  <p>Partly. It enforces authentication and rate limiting, which are security functions, but it is designed as traffic infrastructure. It cannot see endpoints deployed outside it and cannot judge whether an authenticated request should be allowed to access a particular record.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between an API gateway and a WAF?<\/summary>\n  <p>A gateway manages and routes API traffic. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> inspects traffic for attack patterns and blocks them. They address different problems and are commonly deployed together, often with the WAF in front.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we still need API security if we have a gateway?<\/summary>\n  <p>Yes. The most damaging API failures are broken object level authorisation, excessive data exposure and business logic abuse, none of which a gateway detects. Shadow endpoints outside the gateway are also a frequent finding.<\/p>\n<\/details>\n\n<details>\n  <summary>Which API gateway should we use?<\/summary>\n  <p>It is an architecture decision rather than a security one, driven by your cloud provider, traffic profile and how much routing logic you want to centralise. Whichever you choose, the coverage gaps described above are the same.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/easm\/\">EASM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An API gateway is infrastructure that happens to enforce security, not a security product. Treating it as one is how\u2026<\/p>\n","protected":false},"author":8,"featured_media":1185,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[580,581,582],"class_list":["post-1184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-api-gateway","tag-api-gateway-security","tag-api-gateway-vs-waf"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1184"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1184\/revisions"}],"predecessor-version":[{"id":1186,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1184\/revisions\/1186"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1185"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}