WSO2 API Manager, Set Up the Right Way
WSO2 API Manager covers the whole API lifecycle: gateway, publisher, developer portal, key manager, rate limiting and analytics. Newer releases add an AI gateway for LLM traffic and let you expose APIs to AI agents over MCP. Host it yourself, on Kubernetes, or use Bijira, the SaaS version.
If you’re comparing it with Kong, Apigee, or Azure API Management, we’ll test it on your own APIs before you commit. If it’s already live, we take on the work that piles up: new APIs, upgrades, gateway tuning and 24×7 support.
Why Teams Pick WSO2 API Manager
WSO2 API Manager Services
What we do on WSO2 API Manager projects, for new platforms and ones that have been live for years.
Evaluate and Design
Platform Comparison:
WSO2 against Kong, Apigee or Azure API Management, scored on your own requirements.
API Standards:
Naming, versioning and security rules every team follows from the first API.
Reference Architecture:
Self-hosted, Kubernetes, hybrid or Bijira, sized for the traffic you expect.
Proof of Concept:
Gateway, portal and security policies running on your own APIs within weeks.
Subscription Sizing:
A realistic view of the WSO2 subscription you need, and what it will cost.
API-First Design:
OpenAPI definitions and mock endpoints, so consumers give feedback before you build.
Build and Publish
Installation and Setup:
API Manager installed and configured across dev, test and production.
API Development:
REST, SOAP, GraphQL, WebSocket and async APIs, with mediation and protocol transformation.
Developer Portal:
A branded portal where internal teams and partners find, test, and subscribe to APIs.
API Products:
APIs bundled into products with subscription tiers and, if needed, monetisation.
Multi-Gateway Setup:
Govern APIs that also run on Kong, AWS API Gateway or Azure API Management.
CI/CD for APIs:
Automated deployment and promotion of APIs through existing pipelines.
Secure and Govern
Access Control:
OAuth2, JWT, API Keys and mutual TLS, tied to your identity provider
Threat Protection:
Payload validation and attack blocking before requests reach your backends.
Visibility Rules:
Control who can see, subscribe to and call each API, down to each operation.
Governance Checks:
API definitions checked against your design and security rules before publishing.
AI Gateway Policies:
Rate limits, security and cost controls on traffic to LLM providers.
Audit Trails:
The logs and reports your security and compliance teams will ask for.
Scale and Support
Gateway Tuning:
We find what’s slowing the gateway, from thread pools to backend timeouts, and fix it.
High Availability:
Clustered, multi-region and Kubernetes deployments that hold up under traffic spikes.
Version Upgrades:
Tested upgrades covering databases, key manager and gateways, so consumers keep working.
Throttling and Caching:
Throttling tiers and response caching tuned to how your APIs are really used.
Team Extension:
WSO2 API developers who join your sprints for as long as you need them.
24×7 Support:
Monitoring, patching, and incident response under an agreed SLA.
Impact Stories
Featured Work
Explore More
Talk to a WSO2 API Manager Expert
Tell us what you're working on. An API architect will reply within one business day.
WSO2 API Manager FAQs
Is WSO2 API Manager free to use?
The software is Apache 2.0 licensed, so there’s no fee to download and run it. For production, most teams buy a WSO2 subscription for tested updates, security patches and support. WSO2 prices it on usage, for example the number of APIs or transactions.
How long does an API Manager implementation take?
A focused first release, with the gateway, developer portal, security and a handful of APIs, usually takes 10 to 12 weeks. Programmes with many teams, environments or a migration from another gateway take longer. We’ll give you a firm plan once we’ve seen the scope.
How does WSO2 API Manager compare with Kong and Apigee?
All three will secure and publish your APIs. WSO2’s strengths are the open-source licence, full lifecycle tooling in one product and freedom to deploy anywhere. Kong is popular for lightweight, gateway-first setups. Apigee makes most sense if you’re committed to Google Cloud. The real answer comes from testing against your own requirements.
Can WSO2 API Manager run on Kubernetes?
Yes. WSO2 publishes Helm charts, and we run API Manager on EKS, AKS, GKE, OpenShift and on-premise Kubernetes clusters.
Does WSO2 API Manager support MCP and AI agents?
Yes. Recent releases include an AI gateway that applies security, rate limits and cost controls to LLM traffic, plus tooling to expose your existing APIs to AI agents through the Model Context Protocol.
Can WSO2 govern APIs running on other gateways?
Yes. WSO2’s API platform can federate with Kong, AWS API Gateway and Azure API Management, so you manage policies in one place.
Can you upgrade our current API Manager version?
Yes. In our experience the gateway is rarely the hard part. The database migration, key manager and custom extensions need the most care, so we test those in a separate environment first.
Self-hosted API Manager or Bijira?
Self-host if you need full control over hosting, data location or custom extensions. Bijira, WSO2’s SaaS option, makes sense if you’d rather not run infrastructure at all.