HomeThe ultimate comparison of API management solutionsAPI ManagementThe ultimate comparison of API management solutions

The ultimate comparison of API management solutions

This site is also available in: Deutsch (German)

Today, APIs connect core banking systems with customer portals, make data available to partners, and are increasingly serving as the gateway through which AI agents access enterprise systems. Choosing the right API management platform depends more than ever on the operating model, regulatory requirements, and AI strategy.

We first published this comparison in February 2025. For the 2026 edition, we have thoroughly revised it: We evaluate 14 platforms, categorize them into four groups, and highlight what has changed since the last update. In the coming weeks, we will take a closer look at each technology in a separate article.

What Has Changed Since the Last Issue

  • AI agents call APIs on their own: Nearly all platforms now offer a gateway for the Model Context Protocol (MCP).
  • 3scale is being phased out: Red Hat has announced the end of 3scale and is positioning Connectivity Link as its successor.
  • Kong is restricting the open-source version: As of version 3.10, there are no longer any pre-built open-source images.
  • Ingress NGINX is a thing of the past: The project was discontinued in March 2026, and the Kubernetes Gateway API has become the standard.
  • New in the comparison: IBM API Connect with webMethods and Envoy Gateway.
  • New criteria: Operation on OpenShift, AI and MCP capabilities, federation, and the Swiss regulatory framework.

Why API Management Needs to Be Reevaluated in 2026

The market is growing steadily: Gartner estimates the API management market at just under four billion U.S. dollars, with growth rates remaining in the double digits. More important than the volume, however, is who is using APIs today. In addition to apps, partners, and internal services, AI agents are increasingly accessing APIs—autonomously, at a high frequency, and often outside the scope of existing governance.

With the MCP specification dated July 28, 2026, the protocol has become stateless and can be scaled using standard HTTP infrastructure. For platform teams, this means that MCP traffic belongs in API management—with the same rules for authentication, rate limiting, audit trails, and cost control as any other API.

Swiss banks and insurance companies are subject to additional specific requirements. FINMA Circular 2023/1 requires effective management of operational risks and the resilience of critical functions; Circular 2018/3 governs outsourcing; and the revised Data Protection Act (DSG) applies to all processing of personal data. Many institutions therefore deliberately operate their platforms on-premises or in a private cloud on OpenShift. A SaaS control plane located abroad is not ruled out, but must be clearly justified and documented.

Five Trends Shaping the Market

AI gateways and MCP are becoming standard features

Within a year, virtually all major providers have released MCP support: Gravitee with its own MCP proxy API type, Kong with MCP Registry and Agent Gateway, WSO2 with MCP Gateway and MCP Hub, Tyk with an MCP Gateway in its core product, and the hyperscalers with Apigee API Hub, Azure API Management, and Amazon Bedrock AgentCore Gateway. The differences lie in the details: Does the gateway natively support the MCP protocol, or does it simply forward HTTP requests? Can permissions be assigned on a per-tool basis? Are token costs tracked per team and agent?

Federated API Management Instead of “One Gateway for Everything”

Larger organizations rarely operate just one gateway. This calls for a control plane that centrally catalogs and manages gateways from different vendors. Axway, IBM, WSO2, and Gravitee are specifically focused on this model, and Gartner now classifies distributed API management as a distinct use case.

The Kubernetes Gateway API replaces Ingress

Since the discontinuation of Ingress NGINX in March 2026, the previously most widely used Ingress controller no longer receives security updates. The Kubernetes community recommends the Gateway API as its successor. For API management, this means that policies for authentication, rate limiting, or TLS are increasingly being defined as Kubernetes resources and rolled out via GitOps—an approach on which Red Hat Connectivity Link and Envoy Gateway are built.

Product Life Cycles and Licensing Models Are Undergoing Change

Red Hat is discontinuing 3scale, Kong has restricted the availability of its open-source version, and MuleSoft has renamed Flex Gateway to Omni Gateway and is bundling AI capabilities into Agent Fabric. For sustainable banking architectures, the lesson is clear: exit strategies, open standards such as OpenAPI, AsyncAPI, and Gateway API, as well as portable policies, must be included in the evaluation from the very beginning.

Event-native APIs are becoming mandatory

Real-time data from Kafka, notifications via webhooks, or streams via WebSocket and Server-Sent Events require a gateway that can do more than just handle request-response interactions. Gravitee has been consistently positioned in this space for years, while Kong, Tyk, WSO2, and IBM have significantly expanded their event capabilities.

A Direct Comparison of the Platforms

The table summarizes the profiles based on the criteria that most often tip the scales in Swiss evaluations. On small screens, you can scroll horizontally through it.

PlatformLicensing ModelOperationOn-Prem / OpenShiftAI & MCPEvents & KafkaDeveloper PortalPrimary Area of Application
ApigeeCommercialSaaS, hybrid◐●○●API Products in Google Cloud Environments
Azure API ManagementCommercialSaaS, Self-Hosted Gateway◐●◐●Microsoft-centric organizations
Amazon API GatewayCommercialSaaS (serverless)○◐◐◐Serverless Workloads on AWS
MuleSoftCommercialSaaS, hybrid, Runtime Fabric◐●◐●Integration-Driven Landscapes
IBM API Connect / webMethodsCommercialOn-Prem, OpenShift, SaaS●●●●Organizations with IBM or webMethods environments
Axway AmplifyCommercialOn-premises, hybrid, SaaS●◐◐●Governance Across Multiple Gateways, B2B
GraviteeOpen CoreOn-premises, hybrid, SaaS●●●●Event-native APIs and AI governance on-premises
KongOpen Core¹Konnect, Self-hosted●●●◐Microservices and Platform Teams
WSO2 API ManagerOpen SourceOn-premises, Kubernetes, SaaS●●◐●Open Full-Lifecycle APIM
TykOpen CoreSelf-managed, hybrid, cloud●●◐◐APIOps, GraphQL, DevOps teams
ApimanOpen SourceOn-Prem●○○●A Lean APIM for Java Environments
Red Hat Connectivity LinkCommercial²OpenShift●○○◐GitOps and Multi-Cluster on OpenShift
OpenResty / APISIXOpen SourceOn-premises, Kubernetes●◐◐○Performance and Edge Scenarios
Envoy GatewayOpen SourceKubernetes●◐○○Standard-Based Kubernetes Platforms

● Fully available ◐ Partially available, depending on the edition or with restrictions ○ Not available or only with add-on products

¹ Open-source code, but without prebuilt open-source images since version 3.10. ² Red Hat subscription, based on the open-source Kuadrant project. Simplified assessment by ONLU, as of September 2026. The feature set depends heavily on the edition and version and is evaluated in detail in the deep-dive articles.

14 platforms in four groups

The following profiles summarize each platform’s positioning, strengths, limitations, and key new features. The platforms are grouped according to their operational and business models, as these factors typically have a greater impact on a platform’s suitability in practice than individual features. A separate in-depth article on each platform will be published in the coming weeks.

Hyperscaler platforms

Fully managed services from major cloud providers: get up and running quickly, tightly integrated with the respective ecosystem, with limited options for operation in your own data center.

Google Apigee

SaaS (Apigee X) or hybrid with runtime in your own Kubernetes cluster

Goes well with

Large companies with a Google Cloud strategy and external API products.

Strengths

  • End-to-end lifecycle management with a sophisticated policy model for security, mediation, and traffic
  • Robust analytics and monetization of API products
  • API hub as a central catalog, including for APIs outside of Apigee

Please note

  • The Management Plane also runs in a hybrid environment on Google Cloud with Apigee—which is relevant for the outsourcing review
  • Complex pricing model; Apigee delivers the greatest value within the Google Cloud ecosystem

New

The MCP server in the API hub has been generally available since July 2026: AI agents can find and manage APIs, MCP Discovery proxies can be deployed directly to the Apigee Runtime, and Model Armor protects tool calls from prompt injection.

Microsoft Azure API Management

SaaS in Classic and v2 tiers, self-hosted gateway for on-premises deployment

Goes well with

Microsoft-centric organizations that are already using Swiss Azure regions.

Deep Dive in the Works

Strengths

  • Seamless integration with Entra ID, Azure Functions, Logic Apps, and Event Grid
  • Self-hosted Gateway as a Container for Hybrid Scenarios
  • Azure API Center as an enterprise-wide registry for APIs and MCP servers

Please note

  • The control plane always runs in Azure; the feature set varies somewhat between classic and v2 tiers
  • Multi-region operation and full network isolation are reserved for the premium tiers

New

REST APIs can be published as MCP servers, and existing MCP servers are secured through API Management—across all tiers. Since August 2026, a dedicated AI Gateway tier has also been available as a public preview, designed for models, MCP servers, and tools.

Amazon API Gateway

Fully managed, serverless service on AWS

Goes well with

Cloud-native, serverless applications on AWS, such as in the Zurich region.

Deep Dive in the Works

Strengths

  • Pay-per-use and automatic scaling without having to manage the infrastructure yourself
  • Tight integration with Lambda, IAM, AWS WAF, and CloudWatch
  • Global Delivery via CloudFront

Please note

  • Operation outside of AWS is not possible
  • More of a gateway than a full APIM suite: The developer portal and cross-account governance require additional effort

New

Amazon Bedrock AgentCore Gateway makes REST APIs from API Gateway available as MCP tools without any modifications and, as of July 2026, supports the new MCP specification (2026-07-28) alongside older versions.

Enterprise Integration Suites

Platforms that combine API management with application integration, B2B, and file transfer—effective in heterogeneous environments, and correspondingly complex in terms of operations and licensing.

MuleSoft Anypoint Platform

Salesforce integration suite; CloudHub, Runtime Fabric, or hybrid

Goes well with

Organizations where system integration and API management are considered together, particularly in Salesforce environments.

Deep Dive in the Works

Strengths

  • API-led connectivity with a very large library of connectors, such as for SAP, Salesforce, and Workday
  • Anypoint Exchange as a central catalog for APIs, agents, and MCP servers
  • Agent Fabric with registry, broker, visualization, and governance for MCP and agent-to-agent traffic

Please note

  • High licensing and operating costs; in practice, we are seeing an increasing number of evaluations aimed at replacing the system
  • The roadmap is closely aligned with Salesforce’s strategy

New

Agent Fabric automatically detects agents on Amazon Bedrock, Google Vertex AI, and Microsoft Copilot Studio using Agent Scanners. Flex Gateway is now called Omni Gateway.

New in Comparison

IBM API Connect and webMethods

On-premises, on OpenShift, or as SaaS; webMethods has been part of IBM since 2024

Goes well with

Banks and insurance companies with existing IBM, DataPower, or webMethods environments.

Deep Dive in the Works

Strengths

  • A DataPower-based gateway that is already in use at many financial institutions
  • webMethods Hybrid Integration combines application integration, API management, B2B, managed file transfer, and event endpoint management
  • Federated API Management: Controlling Gateways from Multiple Vendors via a Hybrid Control Plane

Please note

  • A broad portfolio comprising API Connect, DataPower, and webMethods—the right combination of products must be chosen carefully
  • Licensing and operation are challenging

New

webMethods supports MCP with a gateway and registry that expose REST APIs as MCP endpoints; API Connect includes an AI gateway and an API agent. Red Hat also cites IBM API Connect as an alternative for existing 3scale installations.

Axway Amplify API Management

On-premises, hybrid, or SaaS; Axway is part of the 74Software Group

Goes well with

Financial institutions with numerous gateways, significant governance needs, and B2B requirements.

Deep Dive in the Works

Strengths

  • Federated, multi-vendor API management across various gateways
  • Over 200 preconfigured security policies and robust governance features
  • Extensive experience in B2B integration and managed file transfer

Please note

  • Comprehensive platform with associated implementation and operational costs
  • Often too large for smaller teams

New

Ranked as a Leader for the tenth time in the 2025 Gartner Magic Quadrant, with the highest rating for distributed API management; also positioned as a Leader in the 2026 IDC MarketScape.

Open-source and open-core platforms

Open-source code, commercial enterprise editions, and complete freedom in where to run the application: often the top choice when data sovereignty and running on OpenShift are priorities.

Gravitee

Open Core from a European vendor; on-premises, hybrid, or SaaS

Goes well with

Environments with on-premises or OpenShift requirements, event streaming, and the goal of integrating AI agents in a controlled manner.

Strengths

  • Event-Native Gateway for Kafka, MQTT, WebSocket, Webhooks, and Server-Sent Events
  • Integrated Access Management and Federation of Third-Party Gateways
  • Proven operation on Kubernetes and OpenShift

Please note

  • Core features such as the Kafka gateway and AI agent management are exclusive to the Enterprise Edition
  • A smaller partner and plugin ecosystem than Kong’s

New

Version 4.10 introduces a dedicated MCP proxy API type, a token-based rate-limit policy for LLM traffic, MCP server applications with OAuth and scope validation per tool, as well as Redis-based synchronization that keeps gateways operational even when the control plane is unreachable. Version 4.11 adds analytics dashboards for MCP.

Kong

Open Core; Konnect as a SaaS control plane with self-managed data planes or Kong Enterprise on-premises

Goes well with

Microservice-oriented architectures and platform teams seeking maximum extensibility.

Strengths

  • Very high performance and a large plugin ecosystem in Lua, Go, and JavaScript
  • Broad portfolio: API, AI, MCP, and event gateways; ingress controllers; and service mesh
  • Metering and Billing for API and AI Products Directly in Konnect

Please note

  • Starting with version 3.10 (2025), there are no longer any pre-built open-source images or Free Mode—in practice, productive use is only possible with an Enterprise license or Konnect
  • Many AI and MCP features are included in paid editions

New

The MCP Registry in the Konnect catalog (February 2026) and the Agent Gateway for agent-to-agent traffic in Gateway 3.14 extend governance to agents. With AI Gateway 2.x, AI control gains its own control plane in Konnect, which manages providers, models, MCP servers, and agents as independent objects.

WSO2 API Manager

Open source (Apache 2.0) with a commercial subscription; on-premises, Kubernetes, private cloud, or SaaS (Bijira)

Goes well with

Organizations looking for a fully open APIM with a high degree of deployment flexibility and federation capabilities.

Deep Dive in the Works

Strengths

  • Complete APIM with a developer portal, analytics, and monetization
  • REST, GraphQL, and SOAP, as well as streaming APIs via WebSocket, WebSub, and Server-Sent Events
  • Federation of gateways from other providers, such as AWS, Azure, and Kong

Please note

  • Java-based and operationally demanding; upgrades require planning
  • Ongoing updates and security patches for production use are included with the subscription

New

Version 4.6 (November 2025) introduces an MCP gateway that exposes existing APIs as MCP servers and secures external MCP servers, an MCP hub for cross-team reuse, and integration with multiple AI providers featuring guardrails and semantic caching.

Tyk

Open Core from a British vendor; self-managed, hybrid, or Tyk Cloud

Goes well with

DevOps-oriented teams looking for a lean, fully automatable gateway.

Deep Dive in the Works

Strengths

  • A lean, high-performance gateway written in Go under an open-source license (MPL)
  • Strong in GraphQL, APIOps, and Infrastructure as Code
  • Complete OpenTelemetry stack for traces and metrics

Please note

  • The dashboard, developer portal, and many governance features are available for a fee
  • Identity management through external providers such as Keycloak, Entra ID, or Okta

New

Tyk 5.13 (May 2026) integrates an MCP gateway with its own authorization model, tool-based access control, and rate limits per MCP primitive. The AI governance solution Tyk AI Studio has been open source since March 2026.

Apiman

Java-based open source (Apache 2.0); commercial support through partners such as Scheer PAS

Goes well with

SMEs and public organizations using the Java stack that are looking for a lean, open API without AI requirements.

Deep Dive in the Works

Strengths

  • Robust core APIM features: Policy Engine, API Manager, and Developer Portal
  • Can be embedded in existing Java platforms; integrates with Keycloak
  • Commercial support available in the DACH region

Please note

  • Small community; further development depends heavily on sponsors
  • Very few features for AI agents, MCP, or event streaming

New

The third generation publishes technical events as versioned events in the CloudEvents format, thereby simplifying integration with peripheral systems.

Kubernetes-Native Gateways and Toolkits

Building blocks for platform teams that manage API traffic as part of their Kubernetes platform and specifically supplement missing APIM features.

Red Hat Connectivity Link

A Kubernetes-native solution for OpenShift, based on the Gateway API and the open-source project Kuadrant; successor to 3scale

Goes well with

OpenShift operators with a platform team, as well as those with existing 3scale installations who are now planning their migration.

Strengths

  • Policies for authentication, rate limiting, TLS, and DNS as Kubernetes resources—ideal for GitOps
  • Multi-cluster operation with global load balancing
  • Seamless integration with OpenShift and the Red Hat subscription

Please note

  • Not a traditional full-lifecycle APIM: The developer portal, monetization, and analytics are more streamlined than with 3scale
  • Short release cycles of about four months, with approximately twelve months of support for each minor version

New: Schedule for 3scale

3scale will no longer receive new major versions. Maintenance and managed services will end on June 30, 2027; for self-hosted installations, Extended Life Cycle Support will be available through June 30, 2029. Red Hat recommends Connectivity Link, IBM API Connect, and partner solutions.

OpenResty and Apache APISIX

Open-source toolkit and gateway based on NGINX and LuaJIT; on-premises or on Kubernetes

Goes well with

Teams focused on performance and edge computing with in-depth NGINX expertise.

Deep Dive in the Works

Strengths

  • Extremely high performance with minimal overhead
  • Full control over request processing via Lua
  • Apache APISIX adds dynamic configuration, plugins, and a dashboard

Please note

  • OpenResty alone is not an API management solution: it lacks a portal, analytics, and lifecycle management
  • Requires in-depth knowledge of NGINX and Lua

Classification 2026

OpenResty remains an important core technology—Kong is also built on it. Anyone running NGINX-based setups on Kubernetes should plan to migrate to the Gateway API following the discontinuation of Ingress NGINX.

New in Comparison

Envoy Gateway

Kubernetes-native open-source gateway from the CNCF Envoy project

Goes well with

Platform teams that rely on open standards and build APIM features in a modular way.

Deep Dive in the Works

Strengths

  • Vendor-neutral implementation of the Kubernetes Gateway API
  • Envoy Proxy as a proven, high-performance foundation for numerous commercial products
  • Extensible, with the sister project Envoy AI Gateway for LLM traffic

Please note

  • Gateway, not a complete APIM: The catalog, portal, and monetization features need to be added
  • Requires a solid understanding of the Kubernetes platform

Classification 2026

For teams switching to the Gateway API following the discontinuation of Ingress NGINX, Envoy Gateway is an obvious choice—as well as a destination for migrations away from Kong OSS.

Which platform is best suited for which scenario?

The following scenarios are the ones we encounter most frequently in projects. They are not a substitute for an evaluation, but they do help keep the shortlist realistic.

On-premises or on OpenShift, strict data sovereignty

Gravitee, WSO2, Kong Enterprise, IBM API Connect, or Red Hat Connectivity Link. The key factors are the location of the control plane and the availability of expertise for operations in Switzerland.

A Clear Cloud Strategy for a Hyperscaler

Typically, the platform of the existing cloud provider: Apigee, Azure API Management, or Amazon API Gateway. Assess your dependency on the control plane and define an exit strategy.

Integration is a top priority: core banking system, SAP, Salesforce, B2B

MuleSoft, IBM webMethods, or Axway. Those who primarily need API governance often combine a leaner APIM with an existing integration platform.

AI agents should be allowed to access core systems in a controlled manner

Platforms with a protocol-native MCP proxy and tool-specific permissions—such as Gravitee, Kong, WSO2, Tyk, and the hyperscalers. Ensure a complete audit trail and cost control for each agent.

Many gateways, many teams, one governance model

Federated approaches from Axway, IBM, WSO2, or Gravitee that integrate with existing gateways rather than replacing them.

Replacement for 3scale or MuleSoft

First, inventory and policy mapping; then, the target platform: Connectivity Link for OpenShift-centric platform teams, Gravitee or Kong for a full-fledged APIM, or IBM API Connect for existing IBM environments.

Here's how to conduct the evaluation

  1. Clarify requirements and the operating model: on-premises, private cloud, or SaaS—based on FINMA Circulars 2023/1 and 2018/3, the DSG, and your cloud strategy.
  2. Take stock of the API landscape: existing gateways, policies, consumers, and protocols—from REST and SOAP to events and MCP.
  3. Create a shortlist and weight the criteria: three candidates, evaluated based on IAM integration, AI and MCP capabilities, event support, federation, licensing model, as well as partners and support in Switzerland.
  4. Proof of Concept with real-world use cases: for example, a customer API, a Kafka topic, and an MCP tool, including load and security testing on the target infrastructure.
  5. Evaluate total costs and exit strategy: licenses, operations, and skills over five years, as well as the portability of policies and specifications.

What's Next: The Deep Dive Series

This comparison is the starting point for a series. In the coming weeks, we’ll analyze each platform in detail—covering architecture, licensing models, operation on OpenShift, AI and MCP features, and insights from our projects in the Swiss financial sector. Articles on Apigee, Red Hat Connectivity Link, and Gravitee have already been published, as well as a direct comparison of Gravitee vs. Kong.

Conclusion: The right platform stems from the business model and strategy

There is no single “best” API management solution. Hyperscaler platforms are a good fit when the cloud strategy is clear. Integration suites really shine in heterogeneous environments. Open-source and open-core platforms offer the greatest operational flexibility and are therefore the natural choice for many Swiss financial institutions. Kubernetes-native gateways are ideal for platform teams, but they are no substitute for a comprehensive API management solution.

What’s new is that every platform decision today is also an AI decision: Whoever manages APIs will also manage access by AI agents in the future. Therefore, don’t just evaluate your platform based on today’s requirements—also assess whether it can manage MCP and agent traffic securely, transparently, and cost-effectively.

Are you evaluating an API management platform or planning a migration?

ONLU supports banks and insurance companies every step of the way—from requirements analysis through proof of concept to deployment on OpenShift. Talk to our experts.


Leave a Reply

Your email address will not be published. Required fields are marked *