This site is also available in: Deutsch (German)
Today, APIs connect core banking systems with customer portals, make data available to partners, and are increasingly serving as the gateway through which AI agents access enterprise systems. Choosing the right API management platform depends more than ever on the operating model, regulatory requirements, and AI strategy.
We first published this comparison in February 2025. For the 2026 edition, we have thoroughly revised it: We evaluate 14 platforms, categorize them into four groups, and highlight what has changed since the last update. In the coming weeks, we will take a closer look at each technology in a separate article.
What Has Changed Since the Last Issue
- AI agents call APIs on their own: Nearly all platforms now offer a gateway for the Model Context Protocol (MCP).
- 3scale is being phased out: Red Hat has announced the end of 3scale and is positioning Connectivity Link as its successor.
- Kong is restricting the open-source version: As of version 3.10, there are no longer any pre-built open-source images.
- Ingress NGINX is a thing of the past: The project was discontinued in March 2026, and the Kubernetes Gateway API has become the standard.
- New in the comparison: IBM API Connect with webMethods and Envoy Gateway.
- New criteria: Operation on OpenShift, AI and MCP capabilities, federation, and the Swiss regulatory framework.
Why API Management Needs to Be Reevaluated in 2026
The market is growing steadily: Gartner estimates the API management market at just under four billion U.S. dollars, with growth rates remaining in the double digits. More important than the volume, however, is who is using APIs today. In addition to apps, partners, and internal services, AI agents are increasingly accessing APIs—autonomously, at a high frequency, and often outside the scope of existing governance.
With the MCP specification dated July 28, 2026, the protocol has become stateless and can be scaled using standard HTTP infrastructure. For platform teams, this means that MCP traffic belongs in API management—with the same rules for authentication, rate limiting, audit trails, and cost control as any other API.
Swiss banks and insurance companies are subject to additional specific requirements. FINMA Circular 2023/1 requires effective management of operational risks and the resilience of critical functions; Circular 2018/3 governs outsourcing; and the revised Data Protection Act (DSG) applies to all processing of personal data. Many institutions therefore deliberately operate their platforms on-premises or in a private cloud on OpenShift. A SaaS control plane located abroad is not ruled out, but must be clearly justified and documented.
Five Trends Shaping the Market
AI gateways and MCP are becoming standard features
Within a year, virtually all major providers have released MCP support: Gravitee with its own MCP proxy API type, Kong with MCP Registry and Agent Gateway, WSO2 with MCP Gateway and MCP Hub, Tyk with an MCP Gateway in its core product, and the hyperscalers with Apigee API Hub, Azure API Management, and Amazon Bedrock AgentCore Gateway. The differences lie in the details: Does the gateway natively support the MCP protocol, or does it simply forward HTTP requests? Can permissions be assigned on a per-tool basis? Are token costs tracked per team and agent?
Federated API Management Instead of “One Gateway for Everything”
Larger organizations rarely operate just one gateway. This calls for a control plane that centrally catalogs and manages gateways from different vendors. Axway, IBM, WSO2, and Gravitee are specifically focused on this model, and Gartner now classifies distributed API management as a distinct use case.
The Kubernetes Gateway API replaces Ingress
Since the discontinuation of Ingress NGINX in March 2026, the previously most widely used Ingress controller no longer receives security updates. The Kubernetes community recommends the Gateway API as its successor. For API management, this means that policies for authentication, rate limiting, or TLS are increasingly being defined as Kubernetes resources and rolled out via GitOps—an approach on which Red Hat Connectivity Link and Envoy Gateway are built.
Product Life Cycles and Licensing Models Are Undergoing Change
Red Hat is discontinuing 3scale, Kong has restricted the availability of its open-source version, and MuleSoft has renamed Flex Gateway to Omni Gateway and is bundling AI capabilities into Agent Fabric. For sustainable banking architectures, the lesson is clear: exit strategies, open standards such as OpenAPI, AsyncAPI, and Gateway API, as well as portable policies, must be included in the evaluation from the very beginning.
Event-native APIs are becoming mandatory
Real-time data from Kafka, notifications via webhooks, or streams via WebSocket and Server-Sent Events require a gateway that can do more than just handle request-response interactions. Gravitee has been consistently positioned in this space for years, while Kong, Tyk, WSO2, and IBM have significantly expanded their event capabilities.
A Direct Comparison of the Platforms
The table summarizes the profiles based on the criteria that most often tip the scales in Swiss evaluations. On small screens, you can scroll horizontally through it.
| Platform | Licensing Model | Operation | On-Prem / OpenShift | AI & MCP | Events & Kafka | Developer Portal | Primary Area of Application |
|---|---|---|---|---|---|---|---|
| Apigee | Commercial | SaaS, hybrid | ◐ | ● | ○ | ● | API Products in Google Cloud Environments |
| Azure API Management | Commercial | SaaS, Self-Hosted Gateway | ◐ | ● | ◐ | ● | Microsoft-centric organizations |
| Amazon API Gateway | Commercial | SaaS (serverless) | ○ | ◐ | ◐ | ◐ | Serverless Workloads on AWS |
| MuleSoft | Commercial | SaaS, hybrid, Runtime Fabric | ◐ | ● | ◐ | ● | Integration-Driven Landscapes |
| IBM API Connect / webMethods | Commercial | On-Prem, OpenShift, SaaS | ● | ● | ● | ● | Organizations with IBM or webMethods environments |
| Axway Amplify | Commercial | On-premises, hybrid, SaaS | ● | ◐ | ◐ | ● | Governance Across Multiple Gateways, B2B |
| Gravitee | Open Core | On-premises, hybrid, SaaS | ● | ● | ● | ● | Event-native APIs and AI governance on-premises |
| Kong | Open Core¹ | Konnect, Self-hosted | ● | ● | ● | ◐ | Microservices and Platform Teams |
| WSO2 API Manager | Open Source | On-premises, Kubernetes, SaaS | ● | ● | ◐ | ● | Open Full-Lifecycle APIM |
| Tyk | Open Core | Self-managed, hybrid, cloud | ● | ● | ◐ | ◐ | APIOps, GraphQL, DevOps teams |
| Apiman | Open Source | On-Prem | ● | ○ | ○ | ● | A Lean APIM for Java Environments |
| Red Hat Connectivity Link | Commercial² | OpenShift | ● | ○ | ○ | ◐ | GitOps and Multi-Cluster on OpenShift |
| OpenResty / APISIX | Open Source | On-premises, Kubernetes | ● | ◐ | ◐ | ○ | Performance and Edge Scenarios |
| Envoy Gateway | Open Source | Kubernetes | ● | ◐ | ○ | ○ | Standard-Based Kubernetes Platforms |
● Fully available ◐ Partially available, depending on the edition or with restrictions ○ Not available or only with add-on products
¹ Open-source code, but without prebuilt open-source images since version 3.10. ² Red Hat subscription, based on the open-source Kuadrant project. Simplified assessment by ONLU, as of September 2026. The feature set depends heavily on the edition and version and is evaluated in detail in the deep-dive articles.
14 platforms in four groups
The following profiles summarize each platform’s positioning, strengths, limitations, and key new features. The platforms are grouped according to their operational and business models, as these factors typically have a greater impact on a platform’s suitability in practice than individual features. A separate in-depth article on each platform will be published in the coming weeks.
Hyperscaler platforms
Fully managed services from major cloud providers: get up and running quickly, tightly integrated with the respective ecosystem, with limited options for operation in your own data center.
Google Apigee
SaaS (Apigee X) or hybrid with runtime in your own Kubernetes cluster
Goes well with
Large companies with a Google Cloud strategy and external API products.
Strengths
- End-to-end lifecycle management with a sophisticated policy model for security, mediation, and traffic
- Robust analytics and monetization of API products
- API hub as a central catalog, including for APIs outside of Apigee
Please note
- The Management Plane also runs in a hybrid environment on Google Cloud with Apigee—which is relevant for the outsourcing review
- Complex pricing model; Apigee delivers the greatest value within the Google Cloud ecosystem
New
The MCP server in the API hub has been generally available since July 2026: AI agents can find and manage APIs, MCP Discovery proxies can be deployed directly to the Apigee Runtime, and Model Armor protects tool calls from prompt injection.
Microsoft Azure API Management
SaaS in Classic and v2 tiers, self-hosted gateway for on-premises deployment
Goes well with
Microsoft-centric organizations that are already using Swiss Azure regions.
Deep Dive in the Works
Strengths
- Seamless integration with Entra ID, Azure Functions, Logic Apps, and Event Grid
- Self-hosted Gateway as a Container for Hybrid Scenarios
- Azure API Center as an enterprise-wide registry for APIs and MCP servers
Please note
- The control plane always runs in Azure; the feature set varies somewhat between classic and v2 tiers
- Multi-region operation and full network isolation are reserved for the premium tiers
New
REST APIs can be published as MCP servers, and existing MCP servers are secured through API Management—across all tiers. Since August 2026, a dedicated AI Gateway tier has also been available as a public preview, designed for models, MCP servers, and tools.
Amazon API Gateway
Fully managed, serverless service on AWS
Goes well with
Cloud-native, serverless applications on AWS, such as in the Zurich region.
Deep Dive in the Works
Strengths
- Pay-per-use and automatic scaling without having to manage the infrastructure yourself
- Tight integration with Lambda, IAM, AWS WAF, and CloudWatch
- Global Delivery via CloudFront
Please note
- Operation outside of AWS is not possible
- More of a gateway than a full APIM suite: The developer portal and cross-account governance require additional effort
New
Amazon Bedrock AgentCore Gateway makes REST APIs from API Gateway available as MCP tools without any modifications and, as of July 2026, supports the new MCP specification (2026-07-28) alongside older versions.
Enterprise Integration Suites
Platforms that combine API management with application integration, B2B, and file transfer—effective in heterogeneous environments, and correspondingly complex in terms of operations and licensing.
MuleSoft Anypoint Platform
Salesforce integration suite; CloudHub, Runtime Fabric, or hybrid
Goes well with
Organizations where system integration and API management are considered together, particularly in Salesforce environments.
Deep Dive in the Works
Strengths
- API-led connectivity with a very large library of connectors, such as for SAP, Salesforce, and Workday
- Anypoint Exchange as a central catalog for APIs, agents, and MCP servers
- Agent Fabric with registry, broker, visualization, and governance for MCP and agent-to-agent traffic
Please note
- High licensing and operating costs; in practice, we are seeing an increasing number of evaluations aimed at replacing the system
- The roadmap is closely aligned with Salesforce’s strategy
New
Agent Fabric automatically detects agents on Amazon Bedrock, Google Vertex AI, and Microsoft Copilot Studio using Agent Scanners. Flex Gateway is now called Omni Gateway.
New in Comparison
IBM API Connect and webMethods
On-premises, on OpenShift, or as SaaS; webMethods has been part of IBM since 2024
Goes well with
Banks and insurance companies with existing IBM, DataPower, or webMethods environments.
Deep Dive in the Works
Strengths
- A DataPower-based gateway that is already in use at many financial institutions
- webMethods Hybrid Integration combines application integration, API management, B2B, managed file transfer, and event endpoint management
- Federated API Management: Controlling Gateways from Multiple Vendors via a Hybrid Control Plane
Please note
- A broad portfolio comprising API Connect, DataPower, and webMethods—the right combination of products must be chosen carefully
- Licensing and operation are challenging
New
webMethods supports MCP with a gateway and registry that expose REST APIs as MCP endpoints; API Connect includes an AI gateway and an API agent. Red Hat also cites IBM API Connect as an alternative for existing 3scale installations.
Axway Amplify API Management
On-premises, hybrid, or SaaS; Axway is part of the 74Software Group
Goes well with
Financial institutions with numerous gateways, significant governance needs, and B2B requirements.
Deep Dive in the Works
Strengths
- Federated, multi-vendor API management across various gateways
- Over 200 preconfigured security policies and robust governance features
- Extensive experience in B2B integration and managed file transfer
Please note
- Comprehensive platform with associated implementation and operational costs
- Often too large for smaller teams
New
Ranked as a Leader for the tenth time in the 2025 Gartner Magic Quadrant, with the highest rating for distributed API management; also positioned as a Leader in the 2026 IDC MarketScape.
Open-source and open-core platforms
Open-source code, commercial enterprise editions, and complete freedom in where to run the application: often the top choice when data sovereignty and running on OpenShift are priorities.
Gravitee
Open Core from a European vendor; on-premises, hybrid, or SaaS
Goes well with
Environments with on-premises or OpenShift requirements, event streaming, and the goal of integrating AI agents in a controlled manner.
Strengths
- Event-Native Gateway for Kafka, MQTT, WebSocket, Webhooks, and Server-Sent Events
- Integrated Access Management and Federation of Third-Party Gateways
- Proven operation on Kubernetes and OpenShift
Please note
- Core features such as the Kafka gateway and AI agent management are exclusive to the Enterprise Edition
- A smaller partner and plugin ecosystem than Kong’s
New
Version 4.10 introduces a dedicated MCP proxy API type, a token-based rate-limit policy for LLM traffic, MCP server applications with OAuth and scope validation per tool, as well as Redis-based synchronization that keeps gateways operational even when the control plane is unreachable. Version 4.11 adds analytics dashboards for MCP.
Kong
Open Core; Konnect as a SaaS control plane with self-managed data planes or Kong Enterprise on-premises
Goes well with
Microservice-oriented architectures and platform teams seeking maximum extensibility.
Strengths
- Very high performance and a large plugin ecosystem in Lua, Go, and JavaScript
- Broad portfolio: API, AI, MCP, and event gateways; ingress controllers; and service mesh
- Metering and Billing for API and AI Products Directly in Konnect
Please note
- Starting with version 3.10 (2025), there are no longer any pre-built open-source images or Free Mode—in practice, productive use is only possible with an Enterprise license or Konnect
- Many AI and MCP features are included in paid editions
New
The MCP Registry in the Konnect catalog (February 2026) and the Agent Gateway for agent-to-agent traffic in Gateway 3.14 extend governance to agents. With AI Gateway 2.x, AI control gains its own control plane in Konnect, which manages providers, models, MCP servers, and agents as independent objects.
WSO2 API Manager
Open source (Apache 2.0) with a commercial subscription; on-premises, Kubernetes, private cloud, or SaaS (Bijira)
Goes well with
Organizations looking for a fully open APIM with a high degree of deployment flexibility and federation capabilities.
Deep Dive in the Works
Strengths
- Complete APIM with a developer portal, analytics, and monetization
- REST, GraphQL, and SOAP, as well as streaming APIs via WebSocket, WebSub, and Server-Sent Events
- Federation of gateways from other providers, such as AWS, Azure, and Kong
Please note
- Java-based and operationally demanding; upgrades require planning
- Ongoing updates and security patches for production use are included with the subscription
New
Version 4.6 (November 2025) introduces an MCP gateway that exposes existing APIs as MCP servers and secures external MCP servers, an MCP hub for cross-team reuse, and integration with multiple AI providers featuring guardrails and semantic caching.
Tyk
Open Core from a British vendor; self-managed, hybrid, or Tyk Cloud
Goes well with
DevOps-oriented teams looking for a lean, fully automatable gateway.
Deep Dive in the Works
Strengths
- A lean, high-performance gateway written in Go under an open-source license (MPL)
- Strong in GraphQL, APIOps, and Infrastructure as Code
- Complete OpenTelemetry stack for traces and metrics
Please note
- The dashboard, developer portal, and many governance features are available for a fee
- Identity management through external providers such as Keycloak, Entra ID, or Okta
New
Tyk 5.13 (May 2026) integrates an MCP gateway with its own authorization model, tool-based access control, and rate limits per MCP primitive. The AI governance solution Tyk AI Studio has been open source since March 2026.
Apiman
Java-based open source (Apache 2.0); commercial support through partners such as Scheer PAS
Goes well with
SMEs and public organizations using the Java stack that are looking for a lean, open API without AI requirements.
Deep Dive in the Works
Strengths
- Robust core APIM features: Policy Engine, API Manager, and Developer Portal
- Can be embedded in existing Java platforms; integrates with Keycloak
- Commercial support available in the DACH region
Please note
- Small community; further development depends heavily on sponsors
- Very few features for AI agents, MCP, or event streaming
New
The third generation publishes technical events as versioned events in the CloudEvents format, thereby simplifying integration with peripheral systems.
Kubernetes-Native Gateways and Toolkits
Building blocks for platform teams that manage API traffic as part of their Kubernetes platform and specifically supplement missing APIM features.
Red Hat Connectivity Link
A Kubernetes-native solution for OpenShift, based on the Gateway API and the open-source project Kuadrant; successor to 3scale
Goes well with
OpenShift operators with a platform team, as well as those with existing 3scale installations who are now planning their migration.
Strengths
- Policies for authentication, rate limiting, TLS, and DNS as Kubernetes resources—ideal for GitOps
- Multi-cluster operation with global load balancing
- Seamless integration with OpenShift and the Red Hat subscription
Please note
- Not a traditional full-lifecycle APIM: The developer portal, monetization, and analytics are more streamlined than with 3scale
- Short release cycles of about four months, with approximately twelve months of support for each minor version
New: Schedule for 3scale
3scale will no longer receive new major versions. Maintenance and managed services will end on June 30, 2027; for self-hosted installations, Extended Life Cycle Support will be available through June 30, 2029. Red Hat recommends Connectivity Link, IBM API Connect, and partner solutions.
OpenResty and Apache APISIX
Open-source toolkit and gateway based on NGINX and LuaJIT; on-premises or on Kubernetes
Goes well with
Teams focused on performance and edge computing with in-depth NGINX expertise.
Deep Dive in the Works
Strengths
- Extremely high performance with minimal overhead
- Full control over request processing via Lua
- Apache APISIX adds dynamic configuration, plugins, and a dashboard
Please note
- OpenResty alone is not an API management solution: it lacks a portal, analytics, and lifecycle management
- Requires in-depth knowledge of NGINX and Lua
Classification 2026
OpenResty remains an important core technology—Kong is also built on it. Anyone running NGINX-based setups on Kubernetes should plan to migrate to the Gateway API following the discontinuation of Ingress NGINX.
New in Comparison
Envoy Gateway
Kubernetes-native open-source gateway from the CNCF Envoy project
Goes well with
Platform teams that rely on open standards and build APIM features in a modular way.
Deep Dive in the Works
Strengths
- Vendor-neutral implementation of the Kubernetes Gateway API
- Envoy Proxy as a proven, high-performance foundation for numerous commercial products
- Extensible, with the sister project Envoy AI Gateway for LLM traffic
Please note
- Gateway, not a complete APIM: The catalog, portal, and monetization features need to be added
- Requires a solid understanding of the Kubernetes platform
Classification 2026
For teams switching to the Gateway API following the discontinuation of Ingress NGINX, Envoy Gateway is an obvious choice—as well as a destination for migrations away from Kong OSS.
Which platform is best suited for which scenario?
The following scenarios are the ones we encounter most frequently in projects. They are not a substitute for an evaluation, but they do help keep the shortlist realistic.
On-premises or on OpenShift, strict data sovereignty
Gravitee, WSO2, Kong Enterprise, IBM API Connect, or Red Hat Connectivity Link. The key factors are the location of the control plane and the availability of expertise for operations in Switzerland.
A Clear Cloud Strategy for a Hyperscaler
Typically, the platform of the existing cloud provider: Apigee, Azure API Management, or Amazon API Gateway. Assess your dependency on the control plane and define an exit strategy.
Integration is a top priority: core banking system, SAP, Salesforce, B2B
MuleSoft, IBM webMethods, or Axway. Those who primarily need API governance often combine a leaner APIM with an existing integration platform.
AI agents should be allowed to access core systems in a controlled manner
Platforms with a protocol-native MCP proxy and tool-specific permissions—such as Gravitee, Kong, WSO2, Tyk, and the hyperscalers. Ensure a complete audit trail and cost control for each agent.
Many gateways, many teams, one governance model
Federated approaches from Axway, IBM, WSO2, or Gravitee that integrate with existing gateways rather than replacing them.
Replacement for 3scale or MuleSoft
First, inventory and policy mapping; then, the target platform: Connectivity Link for OpenShift-centric platform teams, Gravitee or Kong for a full-fledged APIM, or IBM API Connect for existing IBM environments.
Here's how to conduct the evaluation
- Clarify requirements and the operating model: on-premises, private cloud, or SaaS—based on FINMA Circulars 2023/1 and 2018/3, the DSG, and your cloud strategy.
- Take stock of the API landscape: existing gateways, policies, consumers, and protocols—from REST and SOAP to events and MCP.
- Create a shortlist and weight the criteria: three candidates, evaluated based on IAM integration, AI and MCP capabilities, event support, federation, licensing model, as well as partners and support in Switzerland.
- Proof of Concept with real-world use cases: for example, a customer API, a Kafka topic, and an MCP tool, including load and security testing on the target infrastructure.
- Evaluate total costs and exit strategy: licenses, operations, and skills over five years, as well as the portability of policies and specifications.
What's Next: The Deep Dive Series
This comparison is the starting point for a series. In the coming weeks, we’ll analyze each platform in detail—covering architecture, licensing models, operation on OpenShift, AI and MCP features, and insights from our projects in the Swiss financial sector. Articles on Apigee, Red Hat Connectivity Link, and Gravitee have already been published, as well as a direct comparison of Gravitee vs. Kong.
Conclusion: The right platform stems from the business model and strategy
There is no single “best” API management solution. Hyperscaler platforms are a good fit when the cloud strategy is clear. Integration suites really shine in heterogeneous environments. Open-source and open-core platforms offer the greatest operational flexibility and are therefore the natural choice for many Swiss financial institutions. Kubernetes-native gateways are ideal for platform teams, but they are no substitute for a comprehensive API management solution.
What’s new is that every platform decision today is also an AI decision: Whoever manages APIs will also manage access by AI agents in the future. Therefore, don’t just evaluate your platform based on today’s requirements—also assess whether it can manage MCP and agent traffic securely, transparently, and cost-effectively.
Are you evaluating an API management platform or planning a migration?
ONLU supports banks and insurance companies every step of the way—from requirements analysis through proof of concept to deployment on OpenShift. Talk to our experts.
Sources and Status
As of September 2026. Product specifications based on manufacturer documentation; estimates by ONLU.
- Red Hat: 3scale API Management End-of-Life Update
- Kubernetes Blog: Retirement of NGINX Ingress
- AWS Machine Learning Blog: AgentCore Gateway and the MCP Specification July 28, 2026
- Google Cloud: Apigee Release Notes
- Microsoft Learn: MCP Servers in Azure API Management
- InfoQ: Azure API Management Adds a Dedicated AI Gateway Tier
- Gravitee Community: Introducing Gravitee 4.10
- Kong: Kong Introduces MCP Registry in Kong Konnect
- WSO2: API Manager 4.6.0, About This Release
- MuleSoft: Agent Fabric Release Notes
- Business Wire: Axway in the IDC MarketScape: API Management 2026