Critical Capabilities for API Management

7 October 2025 - ID G00824526 - 42 min read
By Shameen Pillai, John Santoro,  and 2 more
API management tools maximize the value of APIs by enabling discovery, monitoring, security, monetization and life cycle management. Software engineering leaders can use this research to evaluate 17 leading API management solutions against six use cases to identify the best-fit platform for their unique business and technical needs.

Overview


Key Findings

  • The API management market is evolving to support agentic and generative AI use cases. Vendors are driving innovation by introducing features and policies such as AI gateways, Model Context Protocol (MCP) servers and support for other agentic communication protocols.
  • While AI enablement has recently emerged as a prominent use case for API management, products in this market continue to robustly support established use cases — including mobile/web back-end APIs, integration using APIs, internal API management, productizing APIs and distributed API management — all of which remain highly relevant.
  • Software engineers, application developers and, more recently, AI developers are increasing their influence in API management purchasing decisions, requiring vendors to level up their strategies to gain practitioner mind share.

Recommendations

  • Revamp your organization’s API strategy to support new generative AI and agentic AI use cases. Prioritize strong API governance, enhance API discoverability and security, and future-proof your API management strategy and incorporate emerging standards.
  • Adopt API management solutions that seamlessly integrate AI enablement with robust support for traditional use cases, and establish strong governance frameworks to ensure effective oversight and control of your APIs.
  • When selecting API management tools, look beyond marketing hype; prioritize solutions that enhance developer experience and productivity by offering seamless integration with popular IDEs, advanced API testing and linting capabilities, and robust AI gateway features. Conduct evaluations and proofs of concept to ensure the chosen platform meets your organization’s needs.

What You Need to Know


To meet their business objectives, organizations build applications that call APIs to access systems, services, data and partners. They also create APIs to unlock the data and functionality of their applications. API management software enables them to plan, deploy, secure, operate and version those APIs.
We evaluated 17 API management vendor offerings based on 13 critical capabilities:
  • AI mediation and protocol support (new this year)
  • API consumption
  • API design
  • API mediation
  • API monetization
  • API monitoring and analytics
  • API portal
  • API security
  • API testing
  • Deployment flexibility
  • Event-driven and streaming
  • Gateway federation
  • Versioning and API governance
We weighted these critical capabilities in terms of their relative importance to six primary use cases:
  • AI enablement Focuses on creating a secure, governed and efficient environment for AI systems to interact with APIs, facilitating the consumption of external AI services and the exposure of internal enterprise capabilities to AI agents. This year’s assessment emphasizes support for various AI mediation and communication protocols toward implementing agentic AI use cases.
  • Mobile/web back-end APIs — Managing the use of APIs as the back end for mobile and web applications. These APIs require API management and proper security. This use case includes managing the use of APIs in backend for frontend (BFF) patterns.
  • Integration using APIs Managing the use of APIs to integrate applications, services and businesses. Organizations also need the ability to secure, track and rate-limit connections to SaaS APIs, such as from Salesforce, Workday and SAP.
  • Internal API management Managing the discovery, access and use of internal APIs to share data and capabilities across teams within an organization. Discovery of internal APIs typically involves an internal API portal, which may be part of a platform engineering initiative. Organizations must manage and govern APIs to encourage reuse across teams and business boundaries.
  • Productizing APIs — Managing APIs that are shared externally and used outside of a single application. This enables third parties or customers to build and extend applications using the APIs. These API products must be easy for developers to onboard and consume while also providing metrics and reporting for product managers.
  • Distributed API management Managing the use of multiple and often heterogeneous API gateways to support hybrid and multicloud strategies. This requires a modernized API management approach to support API deployment and operations across multiple gateway instances, including lightweight API gateways and third-party gateways to support multivendor and multicloud scenarios.
Software engineering leaders should use this research to understand the key use cases and capabilities of API management products and compare them. Evaluate each vendor’s offering based on its ability to meet your organization’s needs, and assess its product roadmap to ensure alignment with your long-term business strategy and goals (see the companion Magic Quadrant for API Management).

Analysis


Critical Capabilities Use-Case Graphics

Figure 1: Vendors’ Product Scores for Mobile/Web Back-End APIs Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of mobile/web back-end APIs in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.
Figure 2: Vendors’ Product Scores for Integration Using APIs Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of integration using APIs in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.
Figure 3: Vendors’ Product Scores for Internal API Management Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of internal API management in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.
Figure 4: Vendors’ Product Scores for Productizing APIs Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of productizing APIs in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.
Figure 5: Vendors’ Product Scores for Distributed API Management Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of distributed API management in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.
Figure 6: Vendors’ Product Scores for AI Enablement Use Case
Seventeen providers are ranked on a 1 to 5 scale according to how well their offerings meet the needs of AI enablement in API management, as of 23 September 2025. This allows comparison across a set of critical differentiators.

Vendors

Amazon Web Services

Amazon Web Services (AWS) offers Amazon API Gateway for publishing, routing and security, deep integration with AWS Web Application Firewall (WAF) for advanced threat protection, and API monitoring and analytics. AWS offers two distinct, separately priced options for Amazon API Gateway: REST APIs, which includes capabilities like API keys, usage plans and WAF support; and HTTP APIs, a more cost-effective choice with fewer features. AWS also offers a serverless, open-source developer portal. Amazon API Gateway is available exclusively as a SaaS deployment.
Since 2024, AWS has added custom domains for private REST APIs to enable customers to encrypt private API traffic with TLS and simplify API discovery through user-friendly private DNS names, enhancing both security and manageability. It also added additional security features like larger WAF request body inspection and improvements in dynamic routing capabilities.
AWS provides its strongest capabilities in API security, API monitoring and analytics, and event-driven and streaming. Its comprehensive real-time tracking, alerting and traffic analysis capabilities strengthen its support for API monitoring and analytics, while support for AppSync and WebSockets underpins its event-driven and streaming capabilities.
Areas where AWS could improve include its API portal, API testing and gateway federation capabilities. For instance, its API portal lacks advanced customization, community features and comprehensive sign-up workflows.
AWS’ highest use-case scores are in AI enablement and integration using APIs. Its lowest use-case scores are in internal API management and distributed API management.
Axway

Axway offers the Amplify Platform, which can be deployed as on-premises, hybrid or SaaS. Amplify includes Amplify API Management, Amplify Engage (a centralized marketplace and API registry) and Amplify Fusion, an integration platform as a service (iPaaS). Amplify API Management includes an API gateway, API portal and API builder as well as agents for API discovery, subscription management, traceability and analytics. It also supports third-party runtime agents for gateway federation.
Since 2024, Axway has added agents (e.g., for Graylog and Traceable) to surface runtime traffic and the security posture of unmanaged APIs in Amplify, which supports visualization of these APIs and addresses the management of API sprawl. Axway also updated its gateway federation, along with its AI assistant in Engage and Fusion, to assist users in flow creation and API discovery.
Amplify’s capabilities are strongest in gateway federation, API design, API monetization, API portal, and versioning and API governance. The Amplify Marketplace supports the productization of APIs from third-party runtimes and different types of services, and the portal includes an AI assistant for product suggestions.
Areas where Amplify could improve include API testing and AI mediation and protocol support. This is attributed to a lack of significant change or improvement in API testing capabilities and to the full implementation of AI mediation policies and MCP support still being under development or not generally available.
Amplify’s highest use-case scores are in productizing APIs and distributed API management. Its lowest use-case scores are in AI enablement and integration using APIs.
Boomi

Boomi offers API management as part of the Boomi Enterprise Platform, which also includes iPaaS, AI agent management, data management, workflow, data catalog, event streams and low-code development. Boomi’s revamped offering includes acquired capabilities from Mashery for core API management functions, APIIDA for advanced gateway federation and governance, an API portal for developer experience, and AI-powered tools for API design and testing.
Since 2024, Boomi has added several features to its offering, including gateway federation that supports third-party gateways such as AWS, Azure, MuleSoft and others, for managing complex, distributed API landscapes. Boomi also enhanced API consumption for AI and agentic use and integrated API monitoring and analytics.
Boomi’s strongest capabilities are in API consumption and gateway federation, both scoring high due to Boomi’s robust set of connectors and ability to facilitate API consumption by AI and agentic use, which differentiates its API consumption. Strong support for federation across numerous third-party gateways contributed to its gateway federation scores.
Areas where Boomi could improve include its API monetization, API security, API testing, and event-driven and streaming capabilities, all of which score relatively lower.
Boomi’s highest use-case scores are for distributed API management and integration using APIs. Its lowest use-case scores are in mobile/web back-end APIs and productizing APIs.
Google

Google Cloud offers three products: Apigee, Google Cloud API Gateway and Cloud Endpoints. Apigee is offered as both SaaS and hybrid, with gateway instances hosted in customer-run Kubernetes clusters, and it supports AI gateway patterns, including model routing and caching, as part of its core offering. API Gateway and Cloud Endpoints are SaaS-only solutions for managing API calls to Google Cloud services/services hosted in Google Cloud at a lower cost. Apigee Advanced API Security is an add-on for Apigee that provides ML-powered security insights.
In the last year, Google has added limited support for MCP servers, mostly through reverse proxies, to the API gateway. It also added AI gateway support for MCP servers and back-end tools, native AI gateway controls in Apigee and AI assistance across the complete API management process. These new features enhance its ability to compete in traditional API management and in AI and agentic AI-based applications.
Apigee API Management provides its strongest capabilities in API monetization, API security, versioning and governance, and AI mediation and protocol support. It continues to provide enterprise-grade API management capabilities for industries requiring secure, high-performance middleware.
Areas where Apigee API Management could improve include API consumption, event-driven and streaming, and gateway federation. Google continues to bring Apigee closer to the mainstream Google Cloud Platform (GCP) offering and provide roadmaps for both API management and related AI components.
Google’s highest use-case scores are in AI enablement and productizing APIs. Its lowest use-case scores are in distributed API management and integration using APIs.
Gravitee

Gravitee offers the Gravitee platform, which can be deployed as SaaS, on-premises or as a hybrid variation. It includes API design, API access management, alert engine, API developer portal, API gateway and API management.
In 2025, Gravitee added support for A2A to support AI agents in the Gravitee catalog. It also added support for MCP to create and run MCP servers based on cataloged APIs. Gravitee includes purpose-built LLM policies, such as prompt guardrails and token tracking.
Gravitee scored high in several critical capabilities due to its strong coverage of functionality across API design, event-driven and streaming, API mediation, API monitoring and analytics, API portal and API testing. Its graphical design of API specifications and its strong support for event-driven APIs differentiate it from competitors.
Areas where Gravitee could improve include its API consumption and API monetization capabilities.
Gravitee’s highest use-case scores are in mobile/web back-end APIs and internal API management. Its lowest use-case scores are in productizing APIs and distributed API management.
IBM

IBM offers IBM API Connect, available as managed SaaS or as software. IBM API Connect includes an API gateway, API manager, API testing, developer portal and AI gateway. IBM API Connect is part of IBM’s broader middleware portfolio, which includes IBM App Connect, Event Streams and the newly announced IBM webMethods Hybrid Integration. IBM also supports optional integration with Noname Advanced API Security for IBM, an OEM product of Noname Security.
Since 2024, IBM has added an AI gateway that provides a single point of control to LLMs, including prompt management with support for token quotas, semantic caching and content safety policies. It also added an engagement feature to provide an actionable notification framework for visibility into API events, multicloud changes and the overall health of the platform.
IBM scored high in several capabilities, most notably in API design. Among its differentiating capabilities are AI-powered testing and the ability to design APIs without OAS expertise.
Areas where IBM could improve include its AI mediation and protocol support capabilities, which lag competitors in MCP and AI agent support.
IBM’s highest use-case scores are in mobile/web back-end APIs and internal API management. Its lowest use-case score is in AI enablement.
Kong

Kong offers Kong Konnect (SaaS), which can be deployed as cloud, multicloud or hybrid models. It also offers Kong Enterprise for self-managed deployments. Its core components are Kong Gateway, a commercial version of its open-source API gateway built on NGINX and OpenResty, and Kong Insomnia, an open-source tool for API design, testing and documentation. Kong also provides an AI gateway, enabling centralized control, observability and security for LLM-powered APIs, a service catalog and a Konnect developer portal. Since 2024, Kong has added the Konnect MCP server and launched serverless gateways in addition to introducing its AI gateway functionality. Kong has also added an event gateway to provide centralized mediation, cost control and security when exposing event brokers as event APIs.
Kong’s strongest capabilities are in API testing, deployment flexibility, and AI mediation and protocol support. In particular, its Insomnia tool is noted as a good tool for API testing and can help test MCP. The AI gateway with native MCP traffic management and advanced LLM features differentiates it from competitors in AI mediation and protocol support.
Areas where Kong could improve include its gateway federation, API monetization and API portal capabilities.
Kong’s highest use-case scores are in AI enablement, integration using APIs and internal API management. Its lowest use-case scores are in productizing APIs and distributed API management.
Microsoft

Microsoft offers Azure API Management (Azure APIM), which allows customers to manage APIs delivered on Microsoft Azure and those hosted on-premises or in private cloud with self-hosted API gateways registered in the APIM control plane. Microsoft also offers Azure API Center, a centralized API catalog for design-time governance, and Microsoft Defender for API Security, which provides a dedicated API threat protection solution that complements Azure APIM.
Since 2024, Microsoft has added AI gateway capabilities integrated with API management, new pricing tiers to better support customers at all consumption levels, AI-powered improvements in APIM, and an API center and MCP support.
Azure APIM provides a good set of features across multiple critical capabilities such as API design, API monitoring and analytics, and AI mediation and protocol support. It continues to deliver capabilities well-suited to those already running in Azure and AI-focused features that will help those building and using APIs in the context of AI and agentic applications.
Areas where Azure APIM could improve include gateway federation, API portal and API monetization.
Azure APIM’s highest use-case scores are in AI enablement, mobile/web back-end APIs and integration using APIs. Its lowest use-case scores are in distributed API management and productizing APIs.
Postman

Postman provides a platform for designing, testing and collaborating on APIs across the full API life cycle as a SaaS-first solution, hosted on AWS, with additional hybrid-compatible options including a lightweight client for local/offline testing. The Postman platform includes key components such as Postman Collections, Postman Workspaces, Postman Flows, Postman Vault, and both public and private API networks. Postman does not provide its own API gateway, but it integrates with and supports publishing API definitions to multiple third-party gateways.
Since 2024, Postman has added several significant product updates, such as features to generate AI tools using MCP and orchestrate multistep workflows via Postman Flows. It also launched a Spec Hub for designing and managing OpenAPI and AsyncAPI specifications.
Postman provides its strongest capabilities for API portal and versioning and API governance. It also scores highly in API design and API testing. In particular, its Spec Hub differentiates it by providing a centralized, governed approach to API specification management, contributing to both design and versioning capabilities. Recently released MCP support enables Postman to generate and validate agent-readable APIs, extending its role in AI workflows.
Areas where Postman could improve include API mediation and API monetization. In particular, Postman is SaaS-first and does not provide a native API gateway, and is generally used alongside third-party gateways.
Postman’s highest use-case scores are in internal API management and mobile/web back-end APIs. Its lowest use-case scores are in integration using APIs and AI enablement.
Salesforce (MuleSoft)

MuleSoft’s API Management offering is part of Anypoint Platform, which includes Anypoint Flex Gateway, Anypoint API Manager, Anypoint API Designer and Anypoint API Governance. It also offers Anypoint API Experience Hub, an API portal, and Anypoint Exchange, a hub for sharing APIs and related integration and automation assets. The Anypoint Platform can be deployed as hybrid models, supporting different runtimes and deployment models, including lightweight API gateways within Docker containers.
Since 2024, MuleSoft has introduced NL-tooling aimed at improving developer productivity, such as Einstein AI in Anypoint Code Builder. It also added policies for MCP in Flex Gateway and released a managed API gateway on CloudHub.
MuleSoft’s strongest capabilities include API design, API mediation, API portal, and versioning and API governance. In particular, its Anypoint Code builder/designer, which includes linting and testing functions, abuse prevention and strong features for proactive versioning, differentiates it from competitors.
Areas where MuleSoft could improve include API monetization, API testing, gateway federation, and AI mediation and protocol support.
MuleSoft’s highest use-case scores are in mobile/web back-end APIs, internal API management and integration using APIs. Its lowest use-case scores are in AI enablement and distributed API management.
SAP

SAP’s API management offering is part of the SAP Integration Suite in the SAP Business Technology Platform (SAP BTP). The SAP Integration Suite includes cloud integration, API management, a developer hub, Edge Integration Cell, SAP Business Accelerator Hub, advanced event mesh, B2B messaging, integration and migration assessment, and open connectors. API management is a SaaS solution, and it supports hybrid deployments of API gateways at the edge of on-premises networks and in private clouds, or hosted by Alibaba Cloud, AWS, Google Cloud Platform, Microsoft Azure and SAP NS2.
Since 2024, SAP has added support for AsyncAPI events in the developer hub and a new “API and Events Edition” of SAP Integration Suite. It also added call prediction for API analytics, OpenAPI spec validation and a new OWASP guide.
SAP Integration Suite’s strongest capabilities are API consumption and event-driven and streaming. In particular, its utility to import APIs from third-party runtimes (like MuleSoft and Azure) and the use of Joule in the SAP Accelerator Hub differentiate its API consumption.
Areas where SAP Integration Suite could improve include API testing.
SAP’s highest use-case score is in integration using APIs. Its lowest use-case scores are in mobile/web back-end APIs and internal API management.
Sensedia

Sensedia’s API management offering is the Sensedia API Platform, which provides API design tools, an API portal, monitoring and other features to support the full life cycle of APIs. It is offered as a managed SaaS predominantly on AWS, but it supports hybrid deployment with the data plane fully managed by Sensedia on AWS, GCP and Oracle Cloud Infrastructure (OCI), and on-premises.
Since 2024, Sensedia has added an AI gateway for LLM routing and AI-specific policy enforcement and mediation. It also added MCP support by generating and hosting MCP servers.
Sensedia provides its strongest capabilities for API design and versioning and governance. Its adaptive governance generates a maturity score and automates design-time validation to identify and resolve compliance issues.
Areas where Sensedia could improve include deployment flexibility and API testing. Its SaaS-only control plane limits deployment flexibility, and it falls behind in advanced capabilities like AI-assisted testing.
Sensedia’s highest use-case scores are in mobile/web back-end APIs and distributed API management. Its lowest use-case scores are in integration using APIs and AI enablement.
SmartBear

SmartBear offers SmartBear API Hub, which includes multiple API management capabilities: API design, functional test, explore, portal and contract testing. In addition, SmartBear also offers ReadyAPI for API testing and Stoplight for API design and design governance. SmartBear does not provide an API gateway; instead, it offers connectors for API gateways from other vendors.
Since 2024, SmartBear has added AI-powered API testing to its API hub, aimed at consolidating tooling. It also added Halo AI support for generating consumer contract testing.
SmartBear provides its strongest capabilities for API design and API testing due to its strong API editor and integrated testing capabilities. Swagger, its open source tool, is widely used and offers a user-friendly API design experience with side-by-side views of the specification and a human-readable preview that has been widely copied.
Areas where SmartBear could improve include AI mediation and protocol support. It also scored lower in capabilities like API mediation and API monitoring and analytics because of its lack of an API gateway.
SmartBear’s highest use-case scores are in internal API management and mobile/web back-end APIs. Its lowest use-case scores are in distributed API management, AI enablement and productizing APIs.
Solo.io

Solo.io offers Gloo Gateway, an Envoy-based API gateway (which it donated to the CNCF as an open-source project kgateway in January 2025), and Gloo Mesh, an enterprise service mesh. It provides plugins for Backstage, an open-source API developer portal from Spotify, to support internal developer portals.
Since 2024, Solo.io has introduced the Gloo AI gateway, aimed at providing security and prompt management in support of AI initiatives.
Solo.io’s strongest capabilities are in API monitoring and analytics and deployment flexibility, due to its support of SaaS and multiple Kubernetes environments.
Areas where Solo.io could improve include gateway federation, as it falls short in supporting federation with other vendors’ gateways.
Solo.io’s highest use-case scores are in internal API management and AI enablement. Its lowest use-case score is in distributed API management.
Solo declined requests for supplemental information. Gartner’s analysis is therefore based on other credible sources.
Tyk

Tyk offers the Tyk platform, which can be deployed as on-premises, hybrid or SaaS. It includes Tyk Gateway (an open-source API gateway), Tyk Developer Portal, Tyk Dashboard and the Tyk console (an infrastructure management tool), alongside its Universal Data Graph (a GraphQL interface).
Since 2024, Tyk has improved its federated API governance capabilities to provide a unified catalog of all APIs across the organization, automated policy enforcement and comprehensive compliance monitoring. It also introduced features to provide an AI gateway, AI governance controls and monitoring of AI interactions, along with MCP support through a stand-alone server and the Tyk AI Studio chat interface.
Tyk provides its strongest capabilities for event-driven and streaming, versioning and API governance, and deployment flexibility. In particular, its Tyk Streams for real-time data processing and Tyk Federated API Governance for a unified catalog and policy enforcement differentiate it from competitors.
Areas where Tyk could improve include its API consumption and API monetization capabilities, with several AI mediation and protocol support features on its roadmap at the time of assessment.
Tyk’s highest use-case scores are in mobile/web back-end APIs and internal API management. Its lowest use-case scores are in integration using APIs, productizing APIs and AI enablement.
Workato

Workato offers the Workato API Management Platform, which contains an API gateway, an AI gateway, a developer portal and insights for monitoring and performance tracking. Well-integrated into its iPaaS offering, the Workato API Management Platform can also expose Workato recipes as APIs. Deployed cloud-first, customers can choose managed deployments with virtual private Workato. It offers a design-time AI assistant for helping to design and deploy APIs and MCP support.
Workato is a new entrant in this Critical Capabilities research and has added capabilities to support its AI gateway to manage traffic to and from LLMs, AI assistants to help with the design and maintenance of APIs, and improvements to its API portal. It is an option worth considering if you are already using Workato’s integration capabilities and want to expose them as APIs internally.
Workato’s strongest capabilities are in AI mediation and protocol support, versioning and API governance, and API monitoring and analytics. However, Workato received moderate scores outside of its strongest capabilities and lacks features in gateway federation and API portals.
Workato’s highest use-case scores are in AI enablement, integration using APIs and internal API management. Its lowest use-case scores are in distributed API management and productizing APIs.
WSO2

WSO2 offers WSO2 API Manager, an open-source solution, and Bijira (formerly Choreo for API Management), its cloud offering, with both featuring a central control plane. WSO2 API Manager supports universal Kubernetes and immutable gateways and third parties like AWS and Solace. Both products combine integration and API management capabilities and also act as API platforms, including the use of Kubernetes for hosting services that are exposed as APIs. They also include an AI gateway to manage outgoing traffic to LLMs and provide support for MCP. It acquired Moesif in late Spring 2025 to augment its monetization capabilities, but this missed the cutoff date for this assessment.
With its strong commitment to open source first, and new central control plane capabilities to both WSO2 API Manager and Bijira, WSO2 provides options for different deployment methods, including support for hybrid environments.
Since 2024, WSO2 has added a new central control plane to both WSO2 API Manager and Bijira with added AI capabilities, natural language-based API design and testing, AI gateway capabilities and MCP support.
WSO2 API Manager provides its strongest capabilities for API portal, event-driven and streaming, versioning and API governance, and API security.
Areas where WSO2 API Manager could improve include API monetization (this will change with the acquisition of Moesif) and gateway federation.
WSO2’s highest use-case scores are in mobile/web back-end APIs and internal API management. Its lowest use-case scores are in distributed API management and productizing APIs.

Context

API management is a foundational capability, allowing digital enterprises that share APIs internally, expose APIs externally to customers and partners, and use third-party APIs in applications to catalog, monitor, secure and control those APIs.
Innovation in this market has focused most recently on enabling customers’ AI use and incorporating AI-based capabilities to improve customer productivity around API search, design, testing and governance. Supporting multivendor API management deployment, multicloud computing strategies and hybrid deployment models has continued and expanded more widely across API management solutions.
The product changes associated with these trends may make it more difficult for software engineering leaders to identify the best solution for their organization’s needs. They should use the major use cases and critical capabilities outlined in this research to select the right API management technologies for their needs.

Market Definition

Gartner defines the application programming interface (API) management market as the market for software to manage, govern and secure APIs.
APIs modernize IT architectures. They provide context, tools and resources to generative and agentic AI programs and provide access to systems, services, partners and data services. API management tools enable organizations to plan, deploy, secure, operate, version control and retire APIs, regardless of their size, region or industry.

Mandatory Features

  • API portal: Provides a self-service interface for API consumers to discover and try APIs. An API catalog is necessary for the registration of APIs.
  • API gateway: Provides, or integrates with, gateways for runtime management, security, policy enforcement, throttling, operational control and usage monitoring for APIs.
  • Policy management: Provides style enforcement, API mediation, usage limits, throttling and security configurations.
  • Governance: Manages API versions, access control, publication and operation.

Common Features

  • API design: These capabilities deliver a meaningful developer experience and tools to design APIs and enable API usage for existing systems.
  • API testing: Provides a range of testing capabilities, from basic mock testing to advanced functional, performance and security testing of APIs.
  • Monitoring and analytics: Ability to produce, collect and report operational metrics and meaningful statistics for API consumption.
  • Security: Ability to protect APIs from malicious activity and integrate with existing security infrastructure; enforce identity and access management rules; enforce design time and operational security.
  • AI gateway support: Provide security, mediation and traffic management for AI access to enterprise data and resources.
  • AI protocol support: Support implementations of emerging protocols like the Model Context Protocol (MCP) and Agent2Agent (A2A).
  • AI-enabled productivity: Aimed at improving developer experience, productivity and operational rigor (when generating API specifications, documenting APIs, obtaining usage analytics or optimizing traffic, for example).
  • Gateway federation: The ability to manage multiple instances and form factors of gateways, including third-party API gateways.
  • API mediation: Features to implement composite services, service mediation, and protocol mapping and translation.
  • Service mesh: Ability to integrate with or mediate traffic to and from service mesh solutions.
  • Monetization: The ability to implement pricing models, billing strategies, chargeback methods as well as to commercialize and market API products.

Product/Service Trends

The API management market is undergoing swift transformation, driven by the rise of AI and evolving enterprise needs. Vendors are innovating capabilities to address new challenges in security, scalability and developer experience. Key trends shaping the market since 2024 include:
  • Rapid AI integration: Platforms support mainstream AI and agentic AI use cases, with new protocols and specialized AI gateways for security, cost tracking and prompt management.
  • Evolving user base: More AI engineers and automation developers are adopting API management tools, driving enhanced developer productivity and AI-powered assistance features.
  • Distributed management: Vendors offer unified control planes and federated management for multicloud and hybrid environments, supporting multiple API gateways.
  • Advanced security and governance: Focus on robust protection against traditional and AI-specific threats, centralized policy enforcement and AI safety is increasing.
  • Cost optimization: Shift toward consumption/value-based pricing and automation reduces operational overhead and improves efficiency.

Critical Capabilities Definition

API Consumption

The ability to manage how third-party APIs are consumed, including Github APIs, logistics APIs such as Shippo, payments APIs such as Stripe and communications APIs such as Twilio.
API consumption capabilities include SLAs, monitoring and API key management. API consumption should also include support for AI consumers and agentic automation programs. A comprehensive set of adapters and connectors, mapping and translation capabilities, and industry-specific mapping and transformation features are often required to support effective use of third-party APIs.
API Design

The ability to create new APIs or new versions of APIs using generation tools or a design tool. This includes the ability to design APIs from scratch, to design APIs that virtualize existing APIs and to support linting (syntax checking, including checking for consistency against an API style guide).
At a basic level, this capability covers design requirements and effective API specifications to meet business needs and the iterative and collaborative creation of those specifications. Organizations may routinely use API design tools that support OpenAPI Specification (OAS), GraphQL or other specifications. Desirable features include the ability to use, manage and apply design guidelines, style guides, naming conventions and domain models. This includes support for alternative approaches to REST APIs, including GraphQL, gRPC and OData.
API Mediation

The ability to provide a mediation layer between an API consumer and API service implementation. A mediation layer provides protocol and message transformation, and it can protect and manage APIs through the enforcement of policies for security and traffic.
API mediation often involves protocol translation (for example, from SOAP to REST) or a modification to the message payload for consistency. This helps users to create multiple experiences for API consumers.
API Monetization

The ability to monetize APIs. This includes not just a selection of billing options, but also the ability to manage subscription usage plans and a variety of pricing models that are potentially different for various consumers of the same API.
API monetization is important in scenarios where APIs are productized, deliver access to valuable data (data-as-a-service APIs) or provide access to algorithms. Monetization builds on features such as fine-grained tracking and access control, and adds the ability to create usage plans. In these cases, API management vendors must provide support for a wide variety of API pricing models, such as subscription and pay-as-you-go. This should include the ability to change the pricing model for an API and to perform billing.
API Monitoring and Analytics

The ability to assess the availability and performance of APIs. This includes providing real-time tracking of the service level that API consumers are experiencing and triggering alerts when intervention is needed.
API monitoring also includes API traffic analysis for API usage insights and provides a security measure
by detecting suspicious patterns. API monitoring is used in preproduction environments to identify
performance issues early in the API development process. This also includes the ability to measure and
report the business value of APIs by providing features empowering API product managers and other
stakeholders to define, develop and measure meaningful business KPIs related to APIs.
API Portal

The ability to customize a developer portal based on developer experience, look and feel, community and sign-up workflows. With further customization and extensibility, API portals may also be used as the basis for creating API marketplaces.
Basic API portals provide API documentation (usually in Swagger/OAS). Organizations typically wish to customize API portals for their specific needs. Customization of the portal initially focuses on look and feel, then extends to adapting the workflow (for example, adapting the developer sign-up and approval process). In addition, features may be added to support and engage developers in order to develop a community and encourage innovation. API developer portals provided by vendors are typically built on top of a content management system such as WordPress or Drupal. In a hybrid model, API developer portals may be provided in the cloud, while API gateways may be provided on-premises by the same vendor.
API Testing

The ability to support a broad range of API testing scenarios, including (but not limited to) automated, functional, A/B testing scenarios and CI/CD pipelines.
This means testing for reliability, availability, performance, functional and nonfunctional requirements.
It also involves support for CI/CD automation and continuous quality testing of APIs. Security testing and support for broader API testing tools are also evaluated within this capability. The API testing capability also assesses vendor support for versioning, staging and quality-controlled deployments through its own offering or through partnerships. It also includes the use of AI techniques and features to optimize API testing, such as AI to generate synthetic data for API testing.
API Security

The ability to control API access with authentication and authorization standards, such as OAuth 2.0 and OpenID Connect, and to integrate with identity infrastructures such as identity providers (IdPs).
This also includes support for the OWASP API Security Top 10, scanning APIs and detecting suspicious
API usage, and defense against attacks on APIs. Additionally, it includes the ability to provide identity, access management and security for AI applications and agentic API consumers.
Deployment Flexibility

The ability to manage APIs in the cloud, on-premises or both. This includes support for common hybrid deployment patterns, such as on-premises API gateways with cloud-based management and reporting, and the ability to deploy lightweight API gateways in environments like Docker containers.
Many organizations expose API endpoints in the cloud to access services that are hosted on-premises or to provide on-premises gateways with reporting and management hosted in the cloud. Containerized deployments and cloud elasticity are especially important for APIs that are used in industry verticals with sporadic or seasonal spikes in demand. Organizations are increasingly looking for multicloud support and the flexibility to deploy APIs in a wide variety of runtimes (occasionally from different vendors). Organizations that use microservices, service mesh and east-west service patterns have additional requirements.
Event-Driven and Streaming

The ability to support event-driven APIs and streaming APIs through protocols such as Webhooks, WebSockets, AsyncAPI and server-sent events. This includes the ability to publish event-driven APIs in an API catalog.
This support should include the ability to apply policies to event-driven and streaming APIs. Currently, many API management products focus on synchronous request-response APIs. To support event-driven and streaming APIs, API management vendors must enable API usage to be managed at runtime through API gateways, while also enabling these types of APIs to be registered and consumed through an API developer portal.
Gateway Federation

The ability to support a federated API gateway architecture to manage APIs that are deployed in federated API gateway instances, including third-party gateways. This includes control plane support for policy management, administration and enforcement in a federated gateway environment.
Built-in support for a variety of cloud-provided gateways (that is, API gateways natively provided by major cloud vendors), container-hosted API gateways and third-party runtimes are increasingly in use
by organizations using a multicloud or multiproduct strategy. Support for cataloging and managing
APIs across multiple gateways, along with the ability to operationally control and govern such APIs, is an essential part of this capability.
Versioning and API Governance

The ability to version an API protects users against breaking changes while supporting governance for the product life cycle of an API.
API management products can be used by API providers to support a release notification, versioning and API deprecation strategy. Features to support proactive notifications of upcoming retirements and the ability to understand dependencies are necessary to support a mature governance practice.
AI Mediation and Protocol Support

The ability to mediate AI traffic, traffic between LLMs and built-in support for various emerging protocols like MCP and A2A.
This includes the ability to surface existing APIs to be provided as tools, resources and context to AI programs and other agentic applications, as well as support for diverse AI models and AI development tools. Effective mechanisms for cost management, traffic optimization and secrets management for LLMs and other AI consumption of APIs are also included. API management solutions should facilitate building an effective ecosystem of AI agents and AI applications using enterprise data and resources in a safe and secure manner via APIs.

Use Cases

AI Enablement

Organizations use API management to support AI initiatives, including managing the consumption and generation of AI APIs.
Managing AI APIs includes functionality to publish, rate-limit, mediate, secure and monitor API access to expensive AI-related resources like LLMs.
The AI enablement use case requires API management vendors to provide:
  • The ability to import AI API specifications, such as those from OpenAI or Mistral, so that usage of these APIs can be managed by the solution.
  • Management of API access by LLMs.
  • Cost optimization of AI APIs that are valuable to consumers or may be particularly resource-intensive.
  • Support for emerging trends, protocols and tools in AI engineering.
Mobile/Web Back-End APIs

Organizations use APIs as the back end for mobile and web apps. These APIs need to be managed and secured, including APIs in BFF patterns.
The mobile/web back-end APIs use case requires API management vendors to provide:
  • Support for frameworks used for web and mobile, such as React and Angular.
  • Client software development kits (SDKs) that may be used in mobile apps to manage API keys at the client side.
  • Support for authentication and authorization of web and mobile apps, using API keys, OAuth, OpenID Connect (OIDC) and other relevant standards.
  • Discovery of APIs used by mobile apps.
Integration Using APIs

Organizations use APIs to integrate applications, services and businesses. These APIs need to be managed by API management solutions.
The integration using APIs use case requires API management vendors to provide:
  • The ability to create and manage APIs for integration with common enterprise applications.
  • Multiprotocol support beyond REST, including event-based APIs and GraphQL.
  • Mapping and transformation support.
  • A hybrid model that enables the solution to be used behind the firewall and in the cloud, in order to support integration of on-premises applications and cloud-based applications.
Internal API Management

Organizations use APIs to share data and capabilities across teams. The discovery, access and usage of internal APIs must be managed and governed.
Discovery of internal APIs typically involves an internal developer portal, which may be part of a platform engineering initiative. Organizations must manage and govern APIs to encourage reuse across teams and business boundaries.
The internal API consumption use case requires API management vendors to provide:
  • A customizable API portal that matches internal business needs and can be a part of a wider internal developer portal or platform, such as Spotify Backstage.
  • Support for consumption and internal chargeback mechanisms between different teams.
  • Support for governing and versioning internal APIs.
  • Use of lightweight developer-friendly API gateways suitable for internal API usage.
  • Support for DevOps approaches, including CI/CD, automated functional testing and automated security testing.
Productizing APIs

Organizations use APIs outside of a single app or share them externally. These APIs must be treated as products so that third parties and customers can build and extend apps.
API products must be easy for developers to onboard and consume, while also providing metrics and reporting for product managers.
The productizing APIs use case requires API management vendors to provide:
  • Ability to create API products (for example, by grouping APIs and other resources together by business domain).
  • Features that support the API product manager.
  • API monetization and API consumption plans, such as subscription-based plans.
  • Business value reporting.
  • An API portal for ease of onboarding and ongoing support of new and existing customers.
  • Versioning and API governance to support new releases, updates and retirement of API products.
Distributed API Management

Organizations use multiple API gateways to support hybrid and multicloud strategies, thus requiring them to deploy and operate APIs across multiple gateway instances.
The distributed API management use case requires API management vendors to provide:
  • The ability to manage multiple gateway instances, including microgateways.
  • A central control plane for operational visibility and control.
  • The ability to collect statistics and metrics across gateway instances.
  • The ability to catalog APIs deployed across multiple gateways.
  • API portal support to search and discover APIs.
  • Built-in support for a variety of cloud gateways, lightweight API gateways and third-party gateways.
  • The ability to create and manage policies in a structured or hierarchical way across multiple API gateways.
  • Operational control of third-party gateways.

Vendors Added and Dropped

We review and adjust our inclusion criteria for Critical Capabilities as markets change. As a result of these adjustments, the mix of vendors in any Critical Capability may change over time. A vendor’s appearance in a Critical Capability one year and not the next does not necessarily indicate that we have changed our opinion of that vendor. It may be a reflection of a change in the market and, therefore, changed inclusion criteria, or of a change of focus by that vendor.

Added

  • Workato

Dropped

  • Software AG: In July 2024, IBM acquired Software AG’s API management product, webMethods.

Inclusion Criteria


To qualify for inclusion, providers need to:
  • Actively market, sell and support products that provide the capabilities defined in the Market Definition for API Management.
  • Have made the qualifying offering generally available as of June 2024.
  • Have a comprehensive, general-purpose offering not specific to one industry or limited to an adjacent market (such as iPaaS or application security). This offering has to be available either directly from the vendor or via publicly announced agreements with partners.
  • Have generated revenue of at least $50 million (constant currency) from API management in 2024. Vendors of an open-source or open-core product had to have generated at least $6 million in revenue (constant currency) per year from API management. No more than 90% of this revenue should have come from one geographic region.
  • Have had at least 150 paying customers for API management in 2024.

Weighting for Critical Capabilities in Use Cases

Critical CapabilitiesMobile/Web Back-End APIsIntegration Using APIsInternal API ManagementProductizing APIsDistributed API ManagementAI Enablement
API Consumption
0%
30%
0%
0%
0%
10%
API Design
15%
0%
20%
0%
0%
0%
API Mediation
20%
20%
0%
0%
0%
10%
API Monetization
0%
0%
0%
25%
0%
0%
API Monitoring and Analytics
0%
0%
0%
10%
10%
10%
API Portal
20%
0%
20%
30%
10%
10%
API Security
10%
10%
0%
10%
10%
10%
API Testing
15%
0%
20%
0%
0%
0%
Deployment Flexibility
0%
0%
10%
0%
20%
0%
Event-Driven and Streaming
0%
10%
0%
0%
0%
0%
Gateway Federation
0%
0%
0%
10%
40%
0%
Versioning and API Governance
20%
10%
20%
15%
10%
0%
AI Mediation and Protocol Support
0%
20%
10%
0%
0%
50%
As of 3 October 2025
Source: Gartner (October 2025)
This methodology requires analysts to identify the critical capabilities for a class of products/services. Each capability is then weighted in terms of its relative importance for specific product/service use cases.

Critical Capabilities Rating

Each of the products/services that meet our inclusion criteria has been evaluated on the critical capabilities on a scale from 1.0 to 5.0.

Product/Service Rating on Critical Capabilities

Critical CapabilitiesAmazon Web ServicesAxwayBoomiGoogleGraviteeIBMKongMicrosoftPostmanSalesforce (MuleSoft)SAPSensediaSmartBearSolo.ioTykWorkatoWSO2
API Consumption
2.0
4.0
4.0
2.0
3.0
4.0
3.0
2.0
2.0
3.0
4.0
3.0
4.0
2.0
2.0
2.0
3.0
API Design
2.0
4.0
3.0
3.0
5.0
5.0
3.0
3.0
4.0
4.0
3.0
4.0
5.0
2.0
3.0
2.0
4.0
API Mediation
2.0
3.0
3.0
3.0
4.0
4.0
3.0
3.0
1.0
4.0
3.0
3.0
1.0
2.0
3.0
2.0
4.0
API Monetization
2.0
4.0
2.0
4.0
2.0
4.0
2.0
2.0
1.0
2.0
3.0
2.0
1.0
2.0
2.0
2.0
2.0
API Monitoring and Analytics
3.0
3.0
3.0
3.0
4.0
4.0
3.0
3.0
2.0
3.0
3.0
4.0
1.0
3.0
3.0
3.0
3.0
API Portal
1.0
4.0
3.0
3.0
4.0
4.0
2.0
2.0
5.0
4.0
3.0
4.0
3.0
2.0
3.0
2.0
4.0
API Security
3.0
3.0
2.0
4.0
4.0
4.0
3.0
3.0
2.0
3.0
3.0
3.0
2.0
2.0
3.0
3.0
4.0
API Testing
1.0
2.0
2.0
3.0
4.0
4.0
4.0
2.0
4.0
2.0
2.0
2.0
5.0
2.0
3.0
3.0
3.0
Deployment Flexibility
1.0
3.0
3.0
3.0
3.0
4.0
4.0
2.0
2.0
3.0
3.0
2.0
2.0
3.0
3.0
2.0
4.0
Event-Driven and Streaming
3.0
3.0
2.0
2.0
5.0
4.0
3.0
2.0
2.0
3.0
4.0
3.0
2.0
2.0
4.0
2.0
4.0
Gateway Federation
1.0
4.0
4.0
2.0
3.0
3.0
2.0
1.0
2.0
2.0
3.0
4.0
2.0
1.0
3.0
1.0
2.0
Versioning and API Governance
2.0
4.0
3.0
4.0
3.0
4.0
3.0
3.0
5.0
4.0
3.0
5.0
4.0
2.0
4.0
3.0
4.0
AI Mediation and Protocol Support
2.0
2.0
3.0
4.0
3.0
2.0
4.0
3.0
2.0
2.0
3.0
3.0
1.0
2.0
3.0
4.0
3.0
As of 3 October 2025
Source: Gartner (October 2025)
Table 3 shows the product/service scores for each use case. The scores, which are generated by multiplying the use-case weightings by the product/service ratings, summarize how well the critical capabilities are met for each use case.

Product Score in Use Cases

Use CasesAmazon Web ServicesAxwayBoomiGoogleGraviteeIBMKongMicrosoftPostmanSalesforce (MuleSoft)SAPSensediaSmartBearSolo.ioTykWorkatoWSO2
Mobile/Web Back-End APIs
1.75
3.40
2.75
3.30
3.95
4.15
2.95
2.65
3.60
3.60
2.85
3.60
3.30
2.00
3.20
2.45
3.85
Integration Using APIs
2.20
3.20
3.10
3.00
3.50
3.60
3.20
2.60
2.10
3.10
3.40
3.20
2.40
2.00
2.90
2.60
3.50
Internal API Management
1.50
3.30
2.80
3.30
3.80
4.00
3.20
2.50
4.00
3.30
2.80
3.50
3.70
2.10
3.20
2.60
3.70
Productizing APIs
1.80
3.80
2.75
3.40
3.25
3.90
2.35
2.25
3.10
3.10
3.00
3.55
2.25
2.00
2.90
2.25
3.20
Distributed API Management
1.50
3.60
3.30
2.80
3.30
3.60
2.70
1.90
2.60
2.80
3.00
3.60
2.20
1.90
3.10
1.90
3.10
AI Enablement
2.10
2.70
3.00
3.50
3.40
3.00
3.40
2.80
2.20
2.70
3.10
3.20
1.60
2.10
2.90
3.20
3.30
As of 3 October 2025
Source: Gartner (October 2025)
To determine an overall score for each product/service in the use cases, multiply the ratings in Table 2 by the weightings shown in Table 1.

Evidence


Our analysis is based on each vendor’s response to our evaluation questionnaire, as well as customer feedback from inquiries and Gartner Peer Insights reviews.

Critical Capabilities Methodology


This methodology requires analysts to identify the critical capabilities for a class of products or services. Each capability is then weighted in terms of its relative importance for specific product or service use cases. Next, products/services are rated in terms of how well they achieve each of the critical capabilities. A score that summarizes how well they meet the critical capabilities for each use case is then calculated for each product/service.
"Critical capabilities" are attributes that differentiate products/services in a class in terms of their quality and performance. Gartner recommends that users consider the set of critical capabilities as some of the most important criteria for acquisition decisions.
In defining the product/service category for evaluation, the analyst first identifies the leading uses for the products/services in this market. What needs are end-users looking to fulfill, when considering products/services in this market? Use cases should match common client deployment scenarios. These distinct client scenarios define the Use Cases.
The analyst then identifies the critical capabilities. These capabilities are generalized groups of features commonly required by this class of products/services. Each capability is assigned a level of importance in fulfilling that particular need; some sets of features are more important than others, depending on the use case being evaluated.
Each vendor’s product or service is evaluated in terms of how well it delivers each capability, on a five-point scale. These ratings are displayed side-by-side for all vendors, allowing easy comparisons between the different sets of features.
Ratings and summary scores range from 1.0 to 5.0:
1 = Poor or Absent: most or all defined requirements for a capability are not achieved
2 = Fair: some requirements are not achieved
3 = Good: meets requirements
4 = Excellent: meets or exceeds some requirements
5 = Outstanding: significantly exceeds requirements
To determine an overall score for each product in the use cases, the product ratings are multiplied by the weightings to come up with the product score in use cases.
The critical capabilities Gartner has selected do not represent all capabilities for any product; therefore, may not represent those most important for a specific use situation or business objective. Clients should use a critical capabilities analysis as one of several sources of input about a product before making a product/service decision.