API gateway, management dashboard, developer portal, analytics, Open Banking standards support, banking-grade security features, and flexible deployment options including on-premises for data sovereignty.
Systems for developing, managing, securing, and monitoring APIs that connect banking systems internally and with external partners.
More API Management
More IT and Infrastructure ...
OAuth 2.0 Support Ability to use OAuth 2.0 protocol for secure authorization. |
Tyk documentation confirms OAuth 2.0 support for secure authorization flows. | |
API Key Management Supports creation, issuance, and life-cycle management of API keys. |
API key creation, management, and lifecycle is covered as standard Tyk functionality. | |
IP Whitelisting/Blacklisting Enable or restrict API access based on user IP addresses. |
Tyk supports IP allow/deny rules for APIs, enabling whitelisting/blacklisting. | |
Rate Limiting Limits the number of requests a client can make to avoid abuse. |
Rate limiting is mentioned as a built-in security feature with configurable rules in Tyk. | |
Throttling Ability to control bandwidth and request frequency. |
Throttling is supported for bandwidth and request frequency control. | |
Data Encryption Supports encryption of data in transit and at rest (e.g., TLS, HTTPS). |
Tyk encrypts data in transit with TLS/HTTPS and supports at-rest encryption. | |
JWT (JSON Web Token) Validation Capability to validate JWTs for API access management. |
JWT validation is supported as part of the authentication middleware options. | |
Audit Trails Tracks and stores all API access and activity logs for compliance and debugging. |
Audit trails and logging are built in for compliance and debugging. | |
DDoS Protection Protection mechanisms against Distributed Denial of Service attacks. |
Tyk has DDoS protection mechanisms as part of its API gateway security suite. | |
Mutual TLS (mTLS) Supports mutual TLS authentication to secure API connections. |
mTLS authentication is available for securing API connections, as per documentation. | |
Access Control Lists (ACLs) Ability to define detailed access permissions for API consumers. |
Access Control Lists are configurable at the API and endpoint level. | |
Security Patch Management Automated updates for emerging threats and vulnerabilities. |
Tyk provides regular security patches and updates. | |
Regulatory Compliance Certifications Supports and maintains compliance (e.g., PCI DSS, PSD2, GDPR) for financial data and operations. |
PCI DSS and GDPR/Open Banking compliance is a selling point for Tyk. |
Request Routing Routes incoming API requests to appropriate backend services. |
API request routing to appropriate backend services is a core Tyk function. | |
API Aggregation Combines multiple API calls into a single request/response. |
API aggregation and composition is included in advanced Tyk use-cases. | |
Caching Caches API responses to reduce backend load and latency. |
Caching of API responses is supported to enhance performance. | |
Load Balancing Distributes incoming API traffic among multiple backends. |
Load balancing for backend servers is provided. | |
Protocol Transformation Converts between different protocols (e.g., REST, SOAP, gRPC). |
Protocol transformation (REST, SOAP) is supported. | |
Content-Based Routing Routes requests based on content type or header values. |
Can route requests based on headers, path, etc. (content-based routing). | |
URL Rewriting Ability to rewrite request URLs on the fly for routing efficiency. |
URL rewriting and request manipulation on the fly are included in policy configuration. | |
Failover Support Automatic rerouting of traffic in case of backend failure. |
Failover and high availability features are available in enterprise deployments. | |
Timeout Configuration Customizable timeouts for upstream requests. |
Timeouts are configurable in the API definition. | |
API Mocking Ability to simulate API responses during development and testing. |
API mocking for development/testing is an included feature. | |
Advanced Traffic Shaping Customizable traffic shaping rules for granular control. |
Advanced traffic shaping is discussed in Tyk's documentation as supported. |
Interactive API Documentation Auto-generated documentation with try-it-out features (e.g., Swagger, OpenAPI). |
Interactive API docs (Swagger/OpenAPI UI) are auto-generated. | |
API Sandbox Environment Safe, limited test environment for developer experimentation. |
API sandbox environments for testing are part of the developer portal feature. | |
Self-Service Portal Portal for onboarding, documentation access, and API key management. |
Self-service portal for onboarding, docs, key management is standard for Tyk. | |
SDK Generation Automated creation of SDKs in multiple languages for developers. |
SDK generation in several languages is available from OpenAPI definitions. | |
Code Samples Includes quick-start code samples for faster developer onboarding. |
Code samples and quick-start guides are provided in developer docs. | |
Comprehensive Error Codes Clear and consistent error messages with codes and explanations. |
Clear, consistent error code responses are implemented within API policies. | |
Change Log Communication Automated notifications on API updates and version changes. |
Tyk provides notifications on API updates and version changes. | |
API Subscription Management Supports subscription plans for API access levels. |
Subscription management and API plans are supported via developer portal. | |
End-to-End Testing Tools Supports thorough testing across API endpoints. |
End-to-end testing tools are provided within the portal environment. | |
API Usage Analytics for Developers Provides developers with real-time metrics for their API usage. |
Developers have access to real-time API usage analytics via the portal. | |
Support Ticketing Integration Integrated support system for technical queries and issues. |
Support ticketing and developer support interactivity are standard. |
Real-Time Traffic Monitoring Provides live data on API usage metrics and performance. |
Analytics dashboard gives real-time traffic monitoring. | |
Request Latency Tracking Measures and reports time taken to process API requests. |
No information available | |
Error Rate Monitoring Tracks percentage of API requests resulting in errors. |
No information available | |
Health Checks Automated and on-demand status checks for API endpoints. |
Automated health checks are built into Tyk's API management suite. | |
Custom Dashboards User-configurable dashboards for monitoring APIs. |
Custom dashboards are possible via the analytics and portal features. | |
Historical Data Retention Duration for retaining historical API usage and performance data. |
No information available | |
Integration with External Monitoring Tools Supports integration with platforms like Splunk, Grafana, Datadog. |
Integration supported with Grafana, Datadog, and others. | |
Alert Notification System Sends alerts for threshold breaches and downtime. |
Alerting is supported for API downtime and threshold breaches. | |
Log Export and Archival Export logs for long-term storage and regulatory compliance. |
Log export and archival supported for compliance via dashboard and API. | |
Anomaly Detection Automatic detection of unusual API behavior. |
Tyk Analytics provides anomaly detection. | |
SLAs and Uptime Reporting Service Level Agreement and uptime tracking for each API. |
SLAs and uptime reporting available for enterprise users. |
Support for Multiple API Protocols REST, SOAP, WebSockets, gRPC compatibility. |
Multiple API protocol support (REST, gRPC, SOAP, WebSockets) confirmed by documentation. | |
Enterprise Service Bus Integration Compatible with ESB solutions for orchestration and mediation. |
Integrates with ESB/orchestration solutions. | |
Legacy System Connectors Connects easily with mainframes and legacy banking systems. |
Legacy system connectors available as per banking use-case references. | |
Third-party Integration Marketplace Pre-built integrations with common fintech and regtech services. |
Marketplace for plug-ins and third-party integrations available. | |
Event Streaming Support Supports event-driven architectures (e.g., Kafka, MQ). |
Event streaming via Kafka/MQ systems is supported. | |
API Orchestration Capability Orchestrates multiple APIs and business processes. |
API orchestration is supported via policies and plugins. | |
Standard Data Format Support Understands and processes JSON, XML, CSV, and more. |
Standard data formats JSON, XML, CSV natively handled. | |
Multi-Cloud Support Deployable on different cloud platforms and hybrid architectures. |
Multi-cloud, hybrid, and on-premises deployments are a key Tyk differentiator. | |
Service Discovery Integration Integrates with service registries (e.g., Consul). |
Service discovery integration (e.g., Consul) available. | |
API Versioning Manages and routes multiple versions of APIs seamlessly. |
API versioning and seamless routing of versions is included. | |
BPM/Workflow Engine Integration Interoperates with business process management tools. |
Integration with BPM/workflow engines is available. |
Horizontal Scalability Ability to add nodes and balance load automatically. |
Horizontal scalability and auto-balancing are supported out of the box. | |
High Availability Architecture Redundant components and failover to maximize uptime. |
Tyk is architected for high availability, with redundant and failover deployment guides. | |
Throughput Capacity Total number of API requests handled per second. |
No information available | |
Load Testing Tools Includes tools for stress and performance testing APIs. |
Load testing tools and guides are available for performance validation. | |
Auto-Scaling Policies Automatic scaling based on real-time demand. |
Auto-scaling can be managed in supported cloud deployments. | |
Geo-Distributed Deployments Supports deployments across multiple geographic locations. |
Geo-distributed deployments are a documented use case for banks. | |
Low Latency Processing Optimized to minimize request/response latency. |
Low latency is a Tyk performance focus; benchmarks available in docs. | |
Concurrent Connection Limits Maximum number of simultaneous client connections supported. |
No information available | |
Session Persistence Ability to maintain session/state across distributed systems. |
Session persistence through tokens/cookies is supported. | |
Fast Failover and Recovery Quickly re-routes traffic on failure for uninterrupted service. |
Supports fast failover and traffic rerouting for resilience. |
API Design Tools User-friendly tools for designing APIs (specifications, linting, etc). |
API design tools (OpenAPI specification, editing) are supported. | |
Automated Deployment Pipelines CI/CD pipelines for consistent API release processes. |
Automated CI/CD pipelines can be integrated for API deployment. | |
Version Control Tracks changes and rollbacks for API definitions and implementations. |
Version control integration for API specifications is available. | |
Lifecycle Stages Tracking Defines and manages API states: development, testing, production, deprecated. |
Lifecycle management for APIs (dev/test/prod/deprecated states) is supported in the portal. | |
Deprecation and Sunset Policy Enforcement Controlled migration paths and communication for deprecated APIs. |
Deprecation/sunset policies with migration paths are managed via versioning. | |
Change Management Logging Monitors changes and notifies stakeholders. |
Change management and logging of all updates are provided. | |
Automated Testing Integration Integrates with automated test frameworks. |
Integration with automated test frameworks (CI/CD) is possible. | |
Approval Workflows Multi-step approval for API publishing or promotion. |
Approval workflows for publishing APIs are integrated in the dev portal. | |
Rollback Mechanism Quickly revert to previous stable versions. |
Rollback mechanisms are standard feature in version and deployment management. |
Audit Logging Comprehensive, immutable records of every API activity. |
Audit logging for all API activity is built into Tyk. | |
Privacy Controls Strict controls for personal and sensitive data processing. |
Privacy controls can be customized for sensitive data handling. | |
GDPR Compliance Supports mechanisms for data rights and protection under GDPR. |
GDPR compliance with data rights/workflows is specifically called out for Tyk. | |
PCI DSS Support Meets requirements for processing and storing payment card data. |
PCI DSS compliance for payment data is supported in relevant deployments. | |
PSD2/Open Banking Readiness Supports open banking standards and frameworks. |
PSD2/Open Banking support is an explicit Tyk feature. | |
Consent Management Tracks and enforces customer consent for data sharing. |
Consent management is part of Open Banking implementation examples. | |
Data Residency Controls Enforces policies on where data can be physically stored. |
Data residency policies can be enforced with on-premises/hybrid deployments. | |
Retention & Deletion Policies Automates retention and deletion per regulatory timelines. |
Automated retention and deletion can be configured. | |
Automated Compliance Reporting Generates reports to demonstrate compliance. |
Report generation for compliance auditing exists in admin tooling. |
Role-Based Access Control (RBAC) Granular user permissions based on assigned roles. |
Role-based access control (RBAC) is a native security feature. | |
Single Sign-On (SSO) Integration with enterprise authentication solutions. |
SSO integration with enterprise authentication is supported. | |
Multi-Factor Authentication (MFA) Enforces strong two-factor user verification. |
MFA is available for all sensitive consoles and customer tenant logins. | |
User Provisioning Automation Automated creation, update, and deactivation of user accounts. |
User provisioning automation available via API and integrations. | |
Delegated Administration Allows specific user groups to manage access. |
Delegated administration with granular group management is supported. | |
Session Management Controls and monitors user session durations and activity. |
Session duration control and monitoring is configurable. | |
Access Review and Recertification Periodic verification of user access rights. |
Access review and recertification workflows configurable. | |
External User Federation Allows federated login for third-party or partner users. |
External user federation is feasible for partner/federated login options. | |
Entitlement Management Assign and manage granular entitlements to users. |
Fine-grained entitlements configurable for users and apps. |
Zero-Downtime Upgrades Ability to patch or upgrade system components without impacting users. |
Zero-downtime upgrades detailed for enterprise deployments. | |
Automated Backups Schedules and manages regular backups. |
Automated backup scheduling is configurable in Tyk's admin. | |
Disaster Recovery Support Failover and restore processes for high system resilience. |
Disaster recovery via failover and backup/restore processes. | |
Rollback Capabilities Quick reversion to previous system states after failed changes. |
Rollback to previous states after failed change is documented. | |
Remote Management API API for managing infrastructure remotely. |
Remote management API available for infrastructure/devops team. | |
Automated Configuration Management Tools for managing configuration drifts and automating changes. |
Automated configuration management via devops tooling. | |
Self-Healing Mechanisms Automated corrective actions for detected failures. |
Self-healing and resilience strategies documented for high resilience. | |
Maintenance Window Scheduling Automated notifications and controls for system maintenance. |
Maintenance window scheduling and notifications are available. |
Usage-Based Billing Support Cost tracking for internal/external API use, supporting chargebacks. |
Usage-based billing available for internal/external API monetization. | |
Quota Management Enables the enforcement of usage quotas for users/applications. |
Quota enforcement for API resources is configurable in the dashboard. | |
Cost Analytics and Forecasting Provides insights and trends in API-related expenses. |
Cost analytics and forecasting support through dashboard and reporting tools. | |
Budget Alerting Sends notifications if API usage approaches or exceeds budget. |
Budget alerts/notifications can be integrated via monitoring or custom plugins. | |
Resource Optimization Recommendations Suggests ways to optimize API and infrastructure usage. |
Resource optimization advice available for infrastructure/API usage. | |
Granular Cost Allocation Assigns costs to departments, projects, or teams. |
Supports granular cost allocation/tagging via organizational tools. | |
License Management Tracks feature/component licensing and compliance with agreements. |
Feature and component licensing tracking is offered for enterprise compliance. | |
Pay-as-you-go Support Ability to implement flexible pricing models based on real usage. |
Flexible, pay-as-you-go pricing is documented for Tyk Cloud. |
Software for creating, publishing, maintaining, and monitoring APIs that connect different systems within the brokerage and with external partners and clients.
More API Management Platforms
More IT and Infrastructure ...
Graphical API Designer Visual tools for designing APIs using drag-and-drop or similar graphical interfaces. |
Not as far as we are aware.* Tyk does not offer a graphical drag-and-drop API designer; design is via JSON/YAML/spec. | |
OpenAPI/Swagger Support Ability to design and import/export API specifications using OpenAPI (Swagger) standards. |
Tyk fully supports OpenAPI (Swagger) import/export and design. | |
Version Control for APIs Management of multiple API versions with rollbacks and comparisons. |
Not as far as we are aware.* Tyk does not provide native version control; external VCS is recommended for spec management. | |
Mock Server Generation Automatically generates mock endpoints for testing and development. |
Tyk can generate mock/mockable endpoints for testing via API definitions. | |
Code Generation Automatically generates server and client code in various programming languages. |
Not as far as we are aware.* Tyk does not natively generate server/client code; recommend using external OpenAPI tools. | |
API Modeling (Data Types, Schemas) Defines and manages reusable data models and schemas. |
Tyk allows definition and management of reusable data types and schemas within API specs. | |
SDK Generation Provides software development kits (SDKs) for multiple languages based on the API definition. |
Not as far as we are aware.* SDK generation is not directly offered; must use external tooling based on OpenAPI definitions. | |
Sample Data Injection Ability to inject sample data for demonstration and testing purposes. |
Mock endpoints can have sample data injected as part of their responses. | |
Dynamic Documentation Generates interactive and up-to-date documentation from the API definition. |
API portal and gateway provide dynamic, interactive API documentation from spec. | |
REST & SOAP Support Enables design and management of both RESTful and SOAP APIs for legacy integration. |
Tyk supports both REST and SOAP endpoints. | |
GraphQL API Creation Provides tooling for designing and exposing GraphQL-based APIs. |
GraphQL proxy/API is supported by Tyk. | |
Schema Validation Offers schema validation at design-time to prevent errors in API structures. |
Schema validation, including request and response type validation, is built in. |
One-Click Deployment Simple and fast deployment process for making APIs live. |
One-click deployment via dashboard and CLI/API is supported. | |
Multi-Environment Support Supports publishing APIs across multiple environments (Dev, Test, Prod). |
Support for dev/test/prod and custom environments documented. | |
Environment Isolation Ensures API deployments are isolated across environments. |
Isolation per environment is supported (separate keyspaces/configs). | |
Zero-Downtime Deployment Enables publishing API updates with no service interruption. |
No information available | |
Canary Releases Supports incremental release strategies for APIs (e.g., canary testing). |
No information available | |
Automated Rollback Automated rollback procedures in case of deployment failures. |
Automated rollback is available in the enterprise/ops pipelines in case of deployment failure. | |
API Gateway Integration Seamless integration with industry-standard API gateways (e.g., Apigee, Kong). |
Integration with third-party and native API gateways is standard (Kong, Apigee, etc.). | |
Cloud and On-Premise Deployment Supports both cloud-native and on-premise API deployment options. |
Tyk supports on-premise, private cloud, public cloud, and hybrid deployments. | |
Custom Domain Support Allows publishing APIs on custom domains with SSL. |
Custom domain with SSL/TLS is supported for API endpoints. | |
Multi-Region Support Ability to publish APIs across multiple geographic regions for latency optimization. |
Multi-region deployment architecture is publicly documented. | |
Auto-Scaling Automatic scaling of API instances based on demand. |
Tyk offers auto-scaling options for both cloud and hybrid deployments. |
OAuth 2.0 Support Implements OAuth 2.0 protocol for secure delegated access. |
Complete support for OAuth 2.0 flows. | |
API Key Management Control generation, rotation, and lifecycle of API keys. |
Full API key management and rotation available in dashboard and APIs. | |
Mutual TLS (mTLS) Enforces two-way SSL/TLS authentication between client and server. |
Mutual TLS available as a setting in policies. | |
IP Whitelisting/Blacklisting Restricts API access based on source IP address. |
IP allow/deny lists are part of the built-in policy system. | |
Rate Limiting Prevents API abuse through rate limiting and throttling. |
Configurable rate limiting and burst throttling native to the platform. | |
Quota Management Sets call quotas per client or partner for fair usage. |
Quota management per API key/client is supported. | |
Single Sign-On (SSO) Supports integration with corporate SSO for authentication. |
SSO with SAML, OIDC and custom providers is supported. | |
JWT (JSON Web Token) Support Supports authentication with JSON Web Tokens. |
JWT (JSON Web Token) is supported for authentication and claims. | |
Encryption of Data in Transit Ensures all data sent via API is encrypted in transit. |
TLS enforcement across all endpoints; platform encrypts data in transit. | |
RBAC (Role-Based Access Control) Enforces granular access controls based on user/role. |
RBAC available in dashboard, API gateway, and developer portal | |
Audit Logging Records security-relevant API access and changes for audits. |
Security/audit log and event logging are detailed in docs. | |
Integration with Security Appliances Connects API traffic with firewalls, SIEM, and DLP solutions. |
Native integration and webhooks for SIEM, DLP, and security appliances. |
Real-Time Monitoring Live tracking of API usage, latency, and errors. |
Real-time stats and monitoring (with Prometheus, dashboards, etc). | |
Alerting and Notifications Automated alerts for outages, anomalies, or limit breaches. |
Alerting/notification integration available via email, webhook, or third party. | |
Detailed Logging Comprehensive logs for every API call, event, and error. |
Detailed, per-request logging is natively available. | |
Performance Dashboards Dashboards with key metrics and trends (latency, throughput, error rate). |
Dashboard and reporting provide latency, errors, throughput graphs. | |
Custom Metrics Ability to define and track custom business or technical metrics. |
Supports custom metric collection and tagging via plugins/webhooks. | |
Integration with Monitoring Tools Compatibility with Prometheus, Datadog, New Relic, etc. |
Compatible with Prometheus, Datadog, New Relic, etc., via exporters and plugins. | |
End-to-End Tracing Distributed tracing of API calls across microservices. |
Distributed tracing supported; correlated request IDs available. | |
User and Partner Analytics Insights into which clients and partners are using which APIs and how. |
Analytics and filtering for client application and partner API consumers. | |
Geo-Analytics Breakdown of API usage by geographic region. |
Geo-location analytics available via integrations or advanced configs. | |
Error Analytics Breakdown and root cause analysis of API errors and failures. |
Breakdown and error analysis are standard in analytics UI. | |
API Call Latency Measures the average time taken per API call. |
No information available | |
Uptime SLA Measurement Calculates actual API uptime to ensure SLAs are met. |
No information available |
Self-Service API Registration Developers can sign up and request access to APIs without manual onboarding. |
Developer portal allows self-service registration and key provisioning. | |
Interactive API Explorer Allows users to test API endpoints with live requests directly in the web portal. |
Swagger-like API explorer is embedded in developer portal. | |
Auto-Generated Documentation Always up-to-date API docs generated from the source specification. |
Docs auto-generated from API definition (OpenAPI/Swagger). | |
Code Snippets and Examples Ready-to-use sample code in multiple languages. |
Sample code snippets in multiple languages are provided and embeddable. | |
API Onboarding Workflows Guides developers or partners through API setup and provisioning. |
Portal and gateway workflows for onboarding are configurable. | |
API Status Pages Communicates live status and known issues for APIs. |
API status and incidents can be surfaced as part of developer portal. | |
Support Integration (Chat, Tickets) Easy access to developer support and ticketing from the portal. |
Support integration available with ticketing/chat options. | |
Rate Limit and Quota Visibility Clear display of current usage, limits, and quota resets. |
API key, rate, and quota usage stats are visible to developers. | |
API Key Management by Developers Developers can create and manage their own API keys. |
Developers manage own API keys; dashboard and API endpoints support this. | |
Community Forums/FAQs Facilitates collaboration via forums or Q&A for developers. |
Forum/FAQ and knowledge base integration is offered. |
Connector Marketplace Library of pre-built connectors/integrations to common brokerage platforms. |
Pre-built connectors and plugin marketplace available. | |
Webhooks Support Supports real-time outbound notifications to third-party services. |
Webhook outbound notifications supported natively. | |
Event-Driven Architecture Support for asynchronous, event-based workflows (e.g., message queues). |
Supports event-driven APIs and queue integrations. | |
Custom Plugin/Extension Framework Enables custom extensions and hooks for bespoke integration needs. |
Plugin/extension architecture for custom extensions available. | |
Data Mapping and Transformation On-the-fly mapping and transformation between data formats (JSON, XML, FIX, CSV, etc.). |
Data mapping and transformation offered via API policies and plugins. | |
Batch Processing Support API platform supports high-volume batch file processing. |
Batch processing and file/gateway handling in enterprise edition. | |
Synchronous and Asynchronous Messaging Supports both real-time and batch/messaging integrations. |
Supports both sync and async/messaging (webhook, queue) interactions. | |
Legacy System Integration Support for mainframes or legacy middleware (e.g., MQ, FTP). |
Legacy system adapters and protocols supported via plugins (FTP, MQ, etc). | |
GraphQL/FIX/Protobuf Adapter Support Adapters for financial industry protocols and formats. |
Supports GraphQL, adapters for FIX, Protobuf available via marketplace/extensions. | |
API Chaining/Orchestration Capability to coordinate multiple API calls as part of a workflow. |
API chaining and orchestration supported in policy definitions. |
Horizontal Scaling Ability to add more nodes to handle increased API loads. |
Scaling horizontally by adding gateways/nodes is natively supported. | |
Vertical Scaling Directly increases resources (CPU, RAM) per node for greater throughput. |
Vertical scaling via config and cloud resources supported. | |
Concurrent Connection Support Maximum number of simultaneous connections supported. |
No information available | |
API Throughput Maximum number of API calls handled per second. |
No information available | |
Low Latency HTTP Routing Optimized networking for fast API responses. |
Low latency routing through optimized gateway code (Golang). | |
Caching Layer Support Integrated support for in-memory or distributed caching. |
Internal and Redis-based distributed cache support. | |
Rate Throttling Capabilities Dynamic control over API call rates to prevent overload. |
Throttling policies can be set per API, user, or key. | |
Load Balancer Integration Native integration with software/hardware load balancers. |
Integrates with major load balancers (software/hardware/cloud). | |
Streaming API Support Support for high-frequency data over persistent connections (e.g., WebSockets, SSE). |
Streaming APIs (WebSocket, SSE, and others) are supported. | |
API Response Time Guarantee Guaranteed maximum latency for API requests. |
No information available |
Regulatory Compliance Templates Built-in templates for major financial regulations (MiFID II, SEC, GDPR, etc.). |
Open Banking and financial regulations support; templates/policies for PCI DSS, GDPR, PSD2 compliance. | |
Data Retention Policies Configurable data storage and deletion schedules. |
Data retention policies configurable (dashboard/config files). | |
Audit Trail Immutable, searchable logs of all API changes and access. |
Immutable logging for security and compliance (audit). | |
Policy Enforcement Engine Automated enforcement of business and IT policies. |
Policy enforcement (business & IT) is a core feature. | |
Consent Management Captures and manages client data consent as per regulations. |
Consent management available in Open Banking and GDPR modules. | |
PII Data Masking On-the-fly obfuscation of personally identifiable information in API responses. |
Response masking (PII masking) can be enforced by plugins. | |
Vulnerability Scanning Automated security scans for the API surface. |
Vulnerability scans supported using built-in and external integrations. | |
Change Approval Workflows Enforced approval flow for significant API config changes. |
Workflow for approval of API spec changes in enterprise edition. | |
Exportable Compliance Reports Auto-generated compliance reports for internal/external audits. |
Audit and compliance reports are auto-generated/downloadable. | |
Contract and SLA Management Track and manage legal obligations and performance guarantees. |
SLA, contract, and API policy management module included. |
API Deprecation Workflow Automates notifying users and retiring outdated APIs. |
Deprecation workflow with notifications available. | |
Backward Compatibility Checks Checks API changes for breaking compatibility. |
Change and backward compatibility checks configurable via CI/CD. | |
Automated API Testing Built-in test suites for continuous integration and delivery. |
API and integration/certification test automation supported. | |
Sandbox Environment Isolated environment for safe API experimentation. |
Isolated sandboxes for dev/test environments are built-in. | |
Release Management Coordinates and documents API version rollouts. |
Release/version management and scheduling built into dashboard. | |
Incident Management Integration Links with incident response tools for outage resolution. |
Connects to PagerDuty, Opsgenie, etc., for incident response. | |
Change Notification System Automated or manual notifications for API updates to users. |
Customizable notification system for product/API changes. | |
Rollback Support Easily revert to previous API versions. |
Rollback to previous configs/API state supported. | |
Automated Health Checks Continuous monitoring and health status reporting for APIs. |
API gateway continuously checks health and liveness of endpoints. | |
Custom Lifecycle Stages Define bespoke API lifecycle stages to suit organization needs. |
Lifecycle stages are user-defined and configurable. |
Plugin Architecture Ability to add third-party or custom-developed plugins. |
Plugin/extension system supports custom plugins from community/partners. | |
Custom Scripting Support Allows scripting or business logic within API flows (e.g., JavaScript, Python). |
Custom middleware/scripts supported (JS, Lua, Go plugins). | |
UI Theme Customization Ability to change developer portal look and feel. |
UI/branding settings for developer portal can be customized. | |
Branding Options Custom logos, colors, and company info in developer portals. |
Branding (logo, theme, etc.) supported in portal. | |
API Workflow Designer Built-in drag-and-drop for API workflows and transformations. |
No information available | |
Custom Policy Definition Define bespoke security and access policies. |
Custom security and access policies can be defined in dashboard/config. | |
Configurable Messaging Templates Edit email and notification templates sent from the platform. |
Notification templates for onboarding/invites/emails are customizable. | |
Extensible Data Model Customize data model for additional business attributes. |
API and policy data models are extensible in config. | |
Custom Auth Provider Integration Plug in identity providers not natively supported. |
Authentication provider integration for SAML, OIDC, and vendor SDKs. | |
White-Labeling Support Deploy platform as an OEM/private-label solution. |
White-label/hosted OEM options for agencies, partners. |
24x7 Support Availability Round-the-clock technical support coverage. |
24/7 enterprise support available as a contract option. | |
Knowledge Base & FAQs Comprehensive, searchable help and how-to articles. |
Extensive searchable knowledgebase and FAQ online. | |
Video Tutorials Official video walkthroughs of common integration tasks. |
Documented video tutorials on common integration tasks. | |
API Usage Best Practices Documentation Guidelines and recommendations for efficient, secure API usage. |
Best practices documented in public docs, guides, and webinars. | |
Code Example Libraries Curated code samples for various use cases and languages. |
Code example libraries hosted on the docs and Github. | |
Multi-Language Support Documentation and support available in multiple languages. |
Docs are translated to multiple languages (Spanish, French, German, others). | |
Onboarding Workshops Instructor-led or virtual onboarding sessions for developers. |
Live and virtual onboarding workshops available. | |
Dedicated Customer Success Manager Assigned contact to help with setup, scaling, and troubleshooting. |
Dedicated success manager available with enterprise-level contracts. | |
Community Channel Access (Slack, Discord, etc.) Official real-time forums for peer and expert support. |
Slack/Discord/Teams community channels for developer support. | |
SLA on Support Response Guaranteed response within a defined time window. |
No information available |
This data was generated by an AI system. Please check
with the supplier. More here
While you are talking to them, please let them know that they need to update their entry.