SELF-HOSTED API GATEWAY & SECURITY

You Make the Rules.

apiRuler is a self-hosted API gateway and security platform. Centralize authentication, rate limiting, observability and AI proxying — all from a single visual console.

ON‑PREMISE  •  GRAFANA + ELK  •  WAF‑COMPATIBLE

Total API Control

Three pillars that put you back in charge of every API call.

Centralized Control

Manage all your APIs from one panel — services, routes, consumers and certificates under a single roof. Scattered configs become history.

Full Visibility

Grafana dashboards, Prometheus metrics and Kibana log analysis. Watch every call in real time — from P95/P99 latency to 5xx error detection.

Unlimited Customization

Authentication, rate limiting, bot detection, AI proxy and more. A plugin architecture that adapts to any requirement you throw at it.

Capabilities

Everything a modern gateway needs, organized into six domains.

Authentication

JWT • OAuth 2.0 • API Key • HMAC • Basic Auth • LDAP

Artificial Intelligence

AI Proxy • Prompt Templates • Prompt Guard • Request/Response Transformer

Security

CORS • IP Restriction • Bot Detection • Let’s Encrypt • SNI / TLS

Traffic Control

ACL • Rate Limiting • Request Size Filter • Proxy Cache • Load Balancing

Monitoring & Logging

Grafana Dashboards • Prometheus Metrics • Kibana Log Analysis • Real-time Alerts

Management

Visual Editor • Quick Setup • Service & Route Management • Upstream & Certificate Management

Total Control From a Single Screen

Live dashboards, deep latency analysis and visual plugin management.

Grafana monitoring and ELK logging

Gateway Monitoring

P90/P95/P99 latency graphs and Prometheus metrics.

Developer working with API code interface

Real-time Logging

Request/response detail and Kibana-powered log analysis.

API gateway plugin customization

Visual Editor & Plugins

Auth, AI, security and traffic plugins managed visually.

apiRuler & WAF — Complementary Layers

A WAF is your security shield, blocking attacks like SQLi, XSS and DDoS. apiRuler is your API management engine — handling authentication, routing, rate limiting and observability. They complement each other; they don’t compete.

Use Cases

Where teams put apiRuler to work.

01  Microservice Orchestration

Manage dozens of internal services from one point.

Per-service auth, rate limiting and monitoring. Upstream health checks and automatic load balancing.

02  AI API Security & Cost Control

Bring OpenAI / Anthropic calls under control.

Prompt-injection protection, token quotas and per-user cost tracking. Flexibility to switch models.

03  Third-Party API Hub

Centralize your external dependencies.

Single-point key management, fallback strategy, SLA monitoring and automatic retry.

04  Certificate & TLS Automation

Zero manual certificate work with Let’s Encrypt.

Multi-domain via SNI, automatic renewal and a central certificate store.

Ready to set the rules?

Bring your APIs under one roof — secure, observable and fully under your control.