NETWORKING / A CONCEPT NOTE

API Gateway

a single front door for all your backend services

~85 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

An API Gateway sits between clients and your microservices, handling authentication, rate limiting, request routing, response transformation, and API versioning — so your backend services don't have to. Common implementations: AWS API Gateway, Kong, NGINX, Envoy, and Zuul.

02 / FOLLOW THE MECHANISM

How an API gateway processes a request

  1. Client

    sends a request to the gateway's endpoint (e.g., https://api.example.com/orders).

  2. Gateway auth

    validates the API key, JWT, or OAuth token before the request reaches any backend.

  3. Rate limiter

    checks the client's usage against its quota. If exceeded, returns 429 Too Many Requests.

  4. Router

    maps the path /orders to the Orders microservice and proxies the request.

  5. Response pipeline

    the gateway can transform, cache, or aggregate responses before sending them back.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

check gateway health status

curl -s -o /dev/null -w "%{http_code}" https://api.example.com/health

EXAMPLE 02 · REFERENCE

list API keys for a usage plan

aws apigateway get-usage-plan-keys --usage-plan-id PLAN_ID

Explore command anatomy in the CLI lab