Prompt
I'm building an API layer for internal services and partner access, what should I use?
Latest observation
For an API layer serving internal services + external/partner access, the usual best choice is an API Gateway in front of your services, often combined with an identity layer and sometimes a service mesh internally.
Short answer
Use:
-
API Gateway for:
- authentication/authorization
- rate limiting / quotas
- request routing and versioning
- logging / analytics
- partner-specific policies
-
OAuth 2.0 / OpenID Connect (OIDC) for identity and access control
-
mTLS + service mesh only if you have substantial internal service-to-service traffic and need stronger zero-trust controls
Good architecture pattern
-
External/partner traffic
- Partner API client
- API Gateway
- Auth provider (OIDC/OAuth2)
- Backend services
-
Internal traffic
- Internal clients/services
- API Gateway or internal ingress
- Service mesh optional
- Backend services
What to choose by need
If you want a managed solution
Good if you want less ops:
- AWS: API Gateway, ALB + WAF, Cognito, Lambda
- Azure: API Management
- GCP: API Gateway / Apigee
- Cloudflare: API Gateway / Zero Trust tools
- Kong / Tyk / Apigee as managed or self-managed options
If you want self-hosted and flexible
Strong options:
- Kong Gateway
- Tyk
- NGINX Plus
- KrakenD for lightweight aggregation
- Traefik if you also want ingress simplicity
If you need enterprise partner management
Look for:
- API keys + OAuth2
- developer portal
- quotas, billing/plan support
- schema validation
- transformation/mapping
- audit logs
- API version lifecycle management
That points toward:
- Apigee
- Kong Enterprise
- Tyk
- MuleSoft if your org is already in that ecosystem
Recommendation by scenario
1) Early stage / simple internal + partner APIs
- Kong or Tyk
- OIDC provider like Auth0, Keycloak, Okta, Azure AD
- Add WAF if exposed publicly
2) Cloud-native on AWS
- API Gateway for public APIs
- ALB / Ingress for internal routes
- Cognito or external OIDC
- WAF
- EKS service mesh only if needed
3) Large enterprise with many partners
- Apigee or Kong Enterprise
- Strong portal, analytics, quotas, policy controls
Practical recommendation
If you’re starting from scratch and want a balanced choice:
Use an API Gateway + OAuth2/OIDC, and add a service mesh only if internal complexity grows.
If you want a concrete default:
- Kong Gateway
- OIDC provider: Keycloak / Okta / Auth0 / Azure AD
- WAF in front
- OpenAPI specs for contract-first design
Important design tips
- Separate internal and partner API policies
- Use scopes/claims instead of only API keys for sensitive access
- Version your APIs from day one
- Add request/response validation
- Log with correlation IDs
- Plan for quotas and tenant isolation if partners vary
If you want, I can recommend a specific stack based on:
- your cloud provider
- expected traffic
- internal vs partner ratio
- whether you want managed or self-hosted