CA Technologies API Gateway is a security appliance that is typically placed between a web server a web server, and then routes requests to an internal application server (JBoss, Tomcat, WebSphere), or routes requests to an external vendor. The API Gateway contains controls that are used to either allow the request to be passed onto the internal application server or vendor, or to deny the request. Some common examples of controls in the API Gateway are to check to see if the request has permission to use an operation in a WSDL, to check if a request is using an appropriate authentication mechanism (username / password, SAML), or to check if the request is using HTTPS instead of HTTP.


A free trial of CA Technologies API Gateway can be downloaded from

