Prompt
What should I use for API gateway auth and throttling?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
For API gateway auth + throttling, a solid default is:
Auth
Use the gateway to validate JWTs issued by your identity provider:
- OIDC/OAuth2 with an IdP like Auth0, Okta, Cognito, Azure AD, Keycloak
- Gateway checks:
- signature
- issuer
- audience
- expiry
- scopes/roles as needed
This is usually better than doing auth in every backend service.
Throttling
Use rate limiting at the gateway as a first line of defense:
- per API key
- per user
- per client app
- per IP
- per route/endpoint
- burst + sustained limits
Common patterns:
- Token bucket for bursty traffic
- Leaky bucket / fixed window if you want simpler behavior
- Distributed rate limiting with Redis if you run multiple gateway instances
Good combo
- Auth: JWT/OIDC at the gateway
- Throttling: Redis-backed token bucket or sliding-window limiter
- Extra security: WAF + bot protection + IP reputation if exposed publicly
Product choices
If you’re choosing tooling:
- Kong: strong plugin ecosystem for auth/rate limiting
- NGINX / NGINX Plus: good for auth + limiting, widely used
- AWS API Gateway: easy if you’re in AWS
- Apigee: enterprise-heavy, rich policy support
- Envoy / Istio: good if you’re in a service mesh or want custom control
Rule of thumb
If you want the simplest reliable setup:
- Put an API gateway in front
- Validate JWTs there
- Apply Redis-backed rate limits
- Pass identity claims downstream
- Keep service-to-service auth separate with mTLS or internal JWTs
If you tell me your stack (cloud/provider, gateway choice, language, traffic level), I can recommend a concrete setup.