Platform
Secure, manage, and scale every enterprise API
Reference architecture
ForgeCrux Enterprise API Gateway
Pure enterprise API management and traffic orchestration, end to end — from public ingress through the data plane to private backends.
ForgeCrux Enterprise API Gateway
Pure enterprise API management & traffic orchestration architecture (end-to-end)
1. Client & ingress layer
External / public
Mobile Clients
iOS / Android Apps
Web Applications
B2B / Single Page Apps
Third-Party Partners
B2B Integrations
Developer Tools
CLI / SDK / Portals
2. ForgeCrux API Gateway
Enterprise data plane
ForgeCrux API Gateway Engine
Security & Guardrails
OAuth2 / JWT / RBAC / WAF
Traffic Shaping
Rate Limiting & Spike Arrest
Protocol Mediation
REST / gRPC / GraphQL / SOAP
Cache & Performance
Response Caching & Quotas
3. API workload layer
Orchestrated routers
REST & Microservices
OpenAPI / Service Mesh
gRPC & High Throughput
HTTP/2 Protobuf
GraphQL Gateways
Unified Schema Federation
Legacy SOAP / Enterprise
XML Transformation
4. Backend API & data layer
Internal / private
Enterprise Backends
Oracle / Salesforce / SAP
Custom Microservices
Kubernetes / Docker Clusters
Databases & Storage
SQL / NoSQL / Cache Stores
Cloud & Hybrid Endpoints
AWS / GCP / Azure Backends
Full API lifecycle
Design, publish, secure, observe, and retire APIs from one console—proxies, products, apps, and environments included.
Policy-driven security at the edge
Enforce OAuth, quotas, threat protection, CORS, and message validation before traffic reaches backends.
One plane for APIs and AI
Keep API products and traffic patterns while adding AI Gateway, MCP Gateway, and Agent Gateway on the same ForgeCrux plane.
Key Capabilities
Complete API Gateway capabilities
Everything required to publish, secure, mediate, observe, and operate api gateway workloads on ForgeCrux.
Proxy and traffic management
Northbound and southbound control for every API call.
- API proxies with preflow, conditional flows, postflow, and fault rules
- Path, header, query, method, and content-based routing
- Route rules, virtual hosts, host aliases, and base paths
- Target servers, weighted load balancing, and active health checks
- Retry, timeout, circuit breaker, and failover
- Response cache, populate cache, lookup cache, and invalidate cache
- CORS, URL rewrite, header inject/remove, and payload assign
- Spike arrest, concurrent rate limit, and quota buckets by product, app, or developer
- Traffic shadowing, canary, and weighted releases
- HTTP, HTTPS, WebSocket, SOAP, GraphQL, and gRPC passthrough
Products, apps, and developer portal
Package APIs for internal teams, partners, and public consumers.
- API products with quota, scopes, and environment binding
- Developer apps, credentials, secrets, and scheduled key rotation
- Company and developer identity with app approval workflows
- OpenAPI 3 and Swagger import with spec-first proxy generation
- Interactive developer portal, try-it console, and sandbox keys
- Spec store, versioned docs, and Smart documentation from OpenAPI
- Monetization: product catalogs, rate plans, prepaid/postpaid meters
- GraphQL, REST, SOAP, and gRPC product exposure
- Self-service onboarding with email, SSO, and RBAC for developers
- App analytics by product, developer, and credential
Security, identity, and policies
A complete policy library for authentication, authorization, and threat defense.
- OAuth 2.0 authorization code, client credentials, implicit, and password grants
- OIDC, SAML, JWT verify/generate, JWK rotation, and token introspection
- Verify API key, access control lists, and IP allow/deny lists
- JSON and XML threat protection, regex protection, and schema validation
- OAS validation against published OpenAPI contracts
- Message encryption, TLS 1.2/1.3 termination, and mTLS to targets
- Encrypted key-value maps and isolated credential vaults
- JavaScript, Java, and Python callouts; service callouts and flow hooks
- Extract variables, assign message, access entity, and flow variables
- Fault rules, raise-fault, and standardized error payloads
- Bot and abuse protection, anomaly scoring, and geo fencing
- PII masking, data residency controls, and audit-ready access logs
Mediation, integration, and extensions
Connect legacy and modern backends without rewriting consumers.
- SOAP-to-REST and REST-to-SOAP transformation
- XML/JSON, XSLT, and JSONPath/XPath extraction
- GraphQL gateway with query depth and complexity limits
- gRPC transcoding and protocol bridging
- Service callouts to internal and third-party APIs
- Message logging, syslog, and streaming export
- Connectors for databases, queues, SaaS, and cloud services
- Hosted targets and sidecar runtimes next to existing services
- Webhooks, async callbacks, and retry-on-failure delivery
- Custom extensions and shared policy packs
Analytics, trace, and operations
Day-2 visibility from proxy hop to business product.
- Traffic, latency, error rate, throughput, and cache hit ratio
- Custom reports by proxy, product, developer, app, and status code
- Geo, device, and consumer analytics
- Debug and trace sessions with policy-by-policy timing
- Statistics collectors and custom dimensions
- Alerts on SLA, error budget, quota exhaustion, and latency
- Audit logs for config, credential, and environment changes
- OpenTelemetry, Prometheus, Grafana, and Datadog export
Lifecycle, runtime, and environments
Promote safely from development to production on any footprint.
- Organizations, environments, and environment groups
- Proxy revisions, deployments, and instant rollback
- Config as code: Git, Terraform, and CI/CD promotion
- Zero-downtime deployments and dual-run validation
- Public cloud, VPC, private Kubernetes, on-prem, and air-gapped
- Multi-region active-active and disaster recovery
- RBAC, custom roles, SSO, and separation of duties
- High availability, horizontal scale, and traffic shaping
How teams run API Gateway on ForgeCrux
Design and publish
Import OpenAPI, generate proxies, bind products, and publish to the developer portal with sandbox and production keys.
Secure and mediate
Attach OAuth, quota, threat protection, caching, and transformation policies as shared flows reused across proxies.
Promote across environments
Move revisions from development to test to production with the same host aliases, target servers, and product quotas.
Observe and optimize
Use traces, custom reports, and alerts to tune latency, errors, cache hit ratio, and quota consumption.
Monetize and partner
Package APIs for partners with rate plans, usage meters, app approval, and branded portal experiences.
Run anywhere
Deploy the data plane in cloud, VPC, Kubernetes, on-prem, or air-gapped sites while the control plane stays unified.
Related Products
AI Gateway
ForgeCrux AI Gateway is the single endpoint for multi-model access, intelligent routing, prompt control, guardrails, token and cost management, evaluation, and LLM observability—across OpenAI, Anthropic, Gemini, Bedrock, Azure OpenAI, and self-hosted models.
Control Plane
ForgeCrux One is the enterprise control plane for APIs, AI models, MCP tools, and agents. Platform, security, and SRE teams use it to install, configure, govern, and operate every gateway from one catalog, one policy engine, and one audit trail—across SaaS, hybrid, and air-gapped footprints.
Observability
ForgeCrux One Observability is the telemetry plane for APIs, LLMs, MCP tools, and agents. Platform, SRE, security, and FinOps teams ingest logs, metrics, and traces from every gateway hop, then act from one dashboard—maps, alerts, incident tools, and audit replay included.
API Modernization
ForgeCrux migrates proxies, products, policies, developer apps, and traffic from legacy API management onto a unified control plane—then extends the same estate to AI, MCP, and agents. Discovery, dependency analysis, policy translation, dual-run, cutover, and rollback are first-class.
Ready to get started with API Gateway?
Talk to our team about deploying API Gateway in your enterprise environment.