Skip to content

API Gateways & WAF

An API Gateway is a single entry point for all client requests. Think of it like a reception desk at a company:

  • All visitors (clients) first go to the reception desk
  • The receptionist (gateway) checks who they are, directs them to the right office (service)
  • Some requests are handled right at the desk (authentication, rate limiting)
flowchart TB
subgraph Clients
C1[Web Browser]
C2[Mobile App]
C3[Third Party API]
end
subgraph Gateway[API Gateway]
Auth[Authentication<br/>Verify JWT / API Key]
Rate[Rate Limiting<br/>100 req/min per user]
Route[Routing<br/>Path → Service]
Cache[Response Cache<br/>Frequently accessed data]
Log[Logging & Monitoring<br/>Track all requests]
end
subgraph Services[Backend Services]
S1[Users Service<br/>/api/users/*]
S2[Orders Service<br/>/api/orders/*]
S3[Payments Service<br/>/api/payments/*]
S4[Notifications<br/>/api/notifications/*]
end
C1 --> Gateway
C2 --> Gateway
C3 --> Gateway
Auth --> Rate --> Route --> Cache --> Log
Log --> S1
Log --> S2
Log --> S3
Log --> S4
style Clients fill:#3b82f6,color:#fff
style Gateway fill:#7c3aed,color:#fff
style Services fill:#10b981,color:#fff

FeatureWhat it doesWhy it matters
RoutingDirects requests to the right backend serviceClients only need one URL
AuthenticationVerifies API keys, JWT tokensCentralized security
Rate LimitingLimits requests per user/IPPrevents abuse and DDoS
CachingCaches frequent responsesReduces backend load
SSL TerminationHandles HTTPS encryptionLess work for backend servers
Request/Response TransformModifies headers, formats dataClients and services don’t need to match exactly
MonitoringLogs all API trafficDebugging, analytics, billing

A WAF sits in front of your web application and filters malicious traffic:

flowchart LR
subgraph Internet
Good[Legitimate User]
Bad[Hacker<br/>SQL Injection]
Bot[Bot / Scraper]
end
subgraph WAF[Web Application Firewall]
Rule1[Rule: Block SQL Injection patterns]
Rule2[Rule: Block XSS attempts]
Rule3[Rule: Rate limit per IP]
Rule4[Rule: Block known bot IPs]
end
subgraph Server[Your Web Server]
App[Application<br/>Safe traffic only ✅]
end
Good --> WAF
Bad --> WAF
Bot --> WAF
WAF -->|"✅ Allowed"| App
WAF -->|"❌ Blocked"| Blocked["🚫 Request dropped"]
WAF -->|"❌ Blocked"| Blocked
style Internet fill:#3b82f6,color:#fff
style WAF fill:#f59e0b,color:#fff
style Server fill:#10b981,color:#fff
style Good fill:#10b981,color:#fff
style Bad fill:#ef4444,color:#fff
style Bot fill:#ef4444,color:#fff
style Blocked fill:#991b1b,color:#fff

Common WAF rules:

  • Block SQL injection patterns (' OR 1=1 --)
  • Block XSS attempts (<script>alert('xss')</script>)
  • Block path traversal (../../../etc/passwd)
  • Rate limit — max 1000 requests/minute per IP
  • Geo-blocking — block traffic from unexpected countries
  • IP blacklisting — block known malicious IPs

FeatureLoad BalancerAPI Gateway
LayerL4/L7 (Transport/Application)L7 (Application)
RoutingBy IP + portBy URL path + headers
Auth❌ No✅ Yes
Rate LimitingLimited✅ Deep (per user, per endpoint)
Caching❌ No✅ Yes
Protocol translation❌ No✅ REST → gRPC, etc.
ExampleHAProxy, NginxKong, AWS API Gateway, Apigee

Many modern setups use both: Load balancer → API Gateway → Services.


ToolDescription
KongOpen-source, plugin-based (auth, rate limiting, logging)
AWS API GatewayServerless, integrates with Lambda
ApigeeEnterprise, analytics, monetization
TraefikCloud-native, auto-discovers services
Nginx + LuaCustom gateway logic using Nginx

  • An API Gateway is a single entry point that routes, authenticates, rate-limits, and caches API requests
  • A WAF filters malicious traffic (SQL injection, XSS) before it reaches your server
  • API Gateways understand HTTP (URL paths, headers); Load Balancers work at lower levels (IP, port)
  • Gateways simplify clients — they only need one URL instead of many service URLs
  • Popular gateways: Kong, AWS API Gateway, Traefik