Prompt
What should I use to enforce authz and rate limits on APIs?
Latest observation
Oct 1, 2026
OpenAI APIWeb search: off
Use an API gateway and/or service mesh, depending on where you want enforcement:
-
API gateway for north-south traffic (clients → APIs):
Best for authentication, authorization, rate limiting, quotas, request validation, logging, and API keys/JWT enforcement at the edge.- Examples: Kong, Apigee, NGINX, Envoy, AWS API Gateway, Azure API Management, GCP API Gateway
-
Service mesh for east-west traffic (service → service inside your network):
Best for enforcing mTLS, service-to-service authorization, and internal rate limits consistently across microservices.- Examples: Istio, Linkerd, Consul
Practical guidance
- If you’re protecting public APIs: start with an API gateway.
- If you need internal microservice policy enforcement: add a service mesh.
- For strong authz, pair them with a centralized policy system like OPA (Open Policy Agent) or built-in policy engines.
Common pattern
- Gateway handles: auth, coarse-grained rate limits, API plans, abuse protection.
- Service mesh handles: fine-grained service authz and internal traffic controls.
- OPA or similar handles: policy-as-code decisions.
If you tell me your stack (cloud/on-prem, REST/gRPC, Kubernetes or not), I can recommend a specific option.