This site is also available in: Deutsch (German)
Digital customer portals, partner integrations, and automated business processes require reliable interfaces. At the same time, requirements are growing: In addition to traditional API calls, companies must also deliver events from Kafka and other messaging systems in a controlled manner.
With Gravitee and Kong, there are two platforms to choose from, each of which approaches these tasks with a different focus. Which one is a better fit for banks and insurance companies? The key factors are a company’s own system architecture, its operating model, and the features it actually needs.
Two platforms with different areas of focus
Gravitee combines API management with the provision of event data. The platform includes a gateway, a management interface, and a developer portal. APIs can be documented and published; applications are granted regulated access through plans and subscriptions. Gravitee supports both synchronous and asynchronous communication. Gravitee: Introduction and Architecture
Kong offers an extensible gateway with tools for automated operations. Plugins provide additional functionality such as authentication, traffic control, and monitoring. Using decK, Terraform, and the Kubernetes Ingress Controller, the configuration can be integrated into existing development and deployment processes. Konnect complements the centralized management of the gateway infrastructure. Kong: Gateway and Management Tools
Our assessment: Gravitee is particularly worth considering when APIs and event data need to be provided together as usable services. Kong is an obvious choice when a platform team consistently automates its API infrastructure and expands it using specialized components.
A Direct Comparison of Gravitee and Kong
| Kriterium | Gravitee | Kong |
|---|---|---|
| API-Verwaltung | GraviteeManagement-Oberfläche, Pläne, Subscriptions und Portal | KongGateway-Verwaltung; zusätzliche Plattformfunktionen über Konnect |
| Developer Portal | GraviteeBestandteil der APIM-Architektur | KongKonnect Dev Portal für Dokumentation und Self-Service |
| Erweiterbarkeit | GraviteePolicies und Plugins | KongPlugins und Verwaltungswerkzeuge |
| Event-Anbindung | GraviteeProtokollvermittlung zu Messaging-Systemen, abhängig von Edition und Connector | KongEigenständiges Event Gateway für nativen Kafka-Verkehr |
| Betrieb | GraviteeSelf-hosted, hybrid oder SaaS | KongSelf-managed Gateway sowie Konnect mit selbst oder durch Kong betriebenen Data Planes |
| Auswahlfrage | GraviteeWie lassen sich APIs und Events gemeinsam bereitstellen? | KongWie passt die Plattform in unsere automatisierte Gateway-Infrastruktur? |
The table summarizes the documented product features; it is not a comparison of identical license packages. The feature set and operational options must be reviewed for the specific offering. Gravitee Enterprise, Kong Gateway, Kong Dev Portal, Kong Event Gateway
Kafka and Real Time: It All Depends on the Specific Use Case
For example, a bank wants to display status updates for a mortgage application from Kafka in a customer portal. The portal should not require direct access to Kafka to do this.
Gravitee facilitates communication between messaging backends and interfaces such as WebSocket or Server-Sent Events. This allows applications to consume event data using a protocol that suits their needs. The corresponding event functions and connectors are part of the Enterprise offering. Gravitee: Event Management
Kong also offers a solution for Kafka called Event Gateway. It acts as a Kafka proxy between clients and clusters and supports, among other things, virtual clusters, access controls, and message policies. Kong: Event Gateway
For the evaluation, therefore, two requirements must be distinguished: Should a web application receive events via HTTP-based interfaces? Or should existing Kafka clients access Kafka in a controlled manner? This distinction is more meaningful than simply checking a box for “Kafka support.”
Developer Portal: How easy is it for partners to access your APIs?
A gateway alone is not enough to solve the challenge of onboarding new API users. Developers need to be able to find APIs, understand the documentation, and request access.
Gravitee maps this process through its Developer Portal, as well as applications, plans, and subscriptions. The Kong Dev Portal also offers API documentation, access credential management, and self-service features for internal and external developers. Gravitee: Portal and Subscriptions; Kong: Dev Portal
In a real-world test, therefore, the entire process should be examined: from partner registration through approval to the first successful API call. This will reveal how much manual work your team is still required to do.
Open Source and Enterprise: What Are the Operating Costs of the Solution?
Both providers offer an open-source entry point. However, this does not mean that all the platform features described are available for free. Gravitee, for example, assigns audit trails, custom roles, and various event features to the Enterprise Edition. With Kong, it is important to distinguish between the open-source gateway, enterprise features, and Konnect offerings. Gravitee: Enterprise feature set; Kong: Gateway variants
To ensure a reliable cost comparison, both providers should be given the same list of requirements:
- Production, testing, and development environments, including high availability.
- Required security features, portals, and event integrations.
- Expected usage and growth over three years.
- Scope of support, as well as responsibility for updates and troubleshooting.
- Internal costs for operations, integrations, and in-house enhancements.
The relevant figure is the total cost over several years. A lower license fee can be offset by additional operating costs. Conversely, a comprehensive enterprise package is only worthwhile if its features are actually needed.
What should Swiss banks pay particular attention to?
When making architectural decisions, we recommend treating data traffic and administrative data separately: Where are API requests processed? Where are configurations, access logs, and analytics data stored? What external connections are required for operations?
Equally important are integration with the existing identity management system, traceable configuration changes, and how the system behaves in the event of failures. These points should be included in a concrete test setup—together with the people who will operate the platform later on.
A meaningful proof of concept includes a secure REST API, the onboarding of an API user, and a relevant event use case. In addition, a deployment with rollback and the failure of a gateway instance should be tested. This provides a basis for decision-making that goes beyond vendor presentations.
Our Assessment
Gravitee should be on your shortlist if your integration strategy aims to closely integrate traditional APIs and event data and simplify their delivery through shared management processes.
Kong should be on your shortlist if your platform team is looking for a scalable gateway and wants to heavily automate configuration, deployment, and operations.
These are selection criteria, not exclusive capabilities. Which platform is a better fit depends on your use cases and the effort required to implement them in your desired operating model.
Evaluating API Management with ONLU
Would you like to compare Gravitee and Kong for your system landscape? ONLU can assist you with requirements analysis, architecture, and a practical proof of concept. Together, we’ll determine which platform best suits your interfaces, operational processes, and expansion plans.
Talk to us about your API strategy.
Product research as of September 2026. Features and availability depend on the version, edition, and contract.