Every team secures its own APIs its own way. Policy belongs in one layer you control — Layer7 API Gateway puts one policy layer — OAuth, threat screening, transformation — in front of your APIs, on appliances, VMs, Kubernetes or a public cloud you choose, with every byte on infrastructure you control.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Layer7 API Gateway — the self-managed gateway, sold standalone or inside Layer7 API Management. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A single front door for your APIs — it checks who is calling, screens the request and only then forwards it to the service.
What consolidation actually replaces, dimension by dimension.
| Dimension | Security coded into every service | Layer7 API Gateway |
|---|---|---|
| Where security lives | Coded again inside every service | One policy layer in front of all APIs |
| Token issuing | Each team runs its own auth | The gateway acts as the OAuth server |
| Legacy back ends | Rewritten before they can be exposed | Transformed at the gateway as they are |
| Config changes | Exported and imported by hand | Graphman bundles reviewed in Git |
| Where data sits | Wherever a SaaS vendor hosts it | On hardware, VMs or clusters you place |
| What it is NOT | — | Not a SaaS control plane with a public price |
The cheapest test is one API family: put it behind an 11.2 gateway, make the gateway its OAuth server, and measure what it replaces.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Each node receives the API call, runs the policy bound to that service — identity checks, threat screening, message transformation — and only then passes the request to the back end.
Broadcom sells gateway licences that flex across form factors: Docker or Kubernetes, a virtual machine, a software install, a hardware appliance, or AWS, Azure and Google Cloud.
Release 11.2 introduced a browser-based Policy Manager to replace the deprecated desktop client; Graphman, a GraphQL management API, carries config between dev, test and production.
The Operator deploys gateways on Kubernetes and pushes Graphman bundles at start-up or into running, database-less ephemeral gateways without a restart; v1.3.0 reached GA in July 2026.
Gateways you install wherever you like — appliance, VM or Kubernetes pod, configured by Graphman bundles from Git.
Layer7 API Gateway enforces security policy on every API call, on hardware or clusters you run yourself.
Broadcom positions the gateway as a central access-control point that screens API calls against the OWASP top-ten threat classes.
It can issue and check tokens for every API behind it, with OpenID Connect and FIDO; the OAuth Toolkit now deploys to ephemeral gateways too.
11.2 accepts X25519MLKEM768 hybrid key exchange on inbound HTTP, HTTP/2 and WebSocket connections — a first step toward quantum-safe TLS.
Transformation and orchestration let modern REST and mobile clients reach ESB, SOA and other legacy back ends without rewriting them.
Broadcom lists these regulated-industry standards as supported, and the gateway connects to most IAM systems for its access decisions.
GraphQL schema validation, WebSocket support and OAuth token assertions all left preview and became generally available in release 11.2.
Gateways export metrics, traces and logs over OpenTelemetry — added in 11.1, GA in 11.2 — to whichever monitoring stack you already use.
Redis or GemFire can hold shared state, so quotas and rate limits apply across a whole gateway cluster instead of separately on each node.
Graphman bundles and policy-as-code put gateway config under version control; the Operator reads Git-backed repositories directly.
Broadcom’s 2026 overview of the gateway, an April 2025 office-hours session on release 11.1.2, and Broadcom’s 2025 AI gateway video — all from the Layer7 API Security channel.
The gateway in Broadcom’s words (2026).
An 11.1.2 session from 2025; 11.2 is now current.
Broadcom’s AI gateway pitch, recorded in 2025.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Layer7 is still delivered as a hardware appliance as well as software, VMs and containers, and Broadcom says gateway licences flex across those form factors and AWS, Azure or Google Cloud. A bank can keep an appliance in its data centre and add Kubernetes gateways beside it.
The gateway can be the OAuth and OpenID Connect server for everything behind it, supports FIDO, screens against OWASP top-ten threats and names PCI-DSS, FHIR and PSD2 support. Release 11.2 added post-quantum hybrid key exchange on inbound TLS.
Run self-managed, the gateway, its policies and its logs sit on servers or clusters you choose — in an Indian data centre if you need. Broadcom’s Indian offices are in Bangalore, Hyderabad and Pune, if you want a local account team. Only the optional SaaS developer portal is hosted, and its region is not published.
Nothing is priced in public, and the licence unit is not published. The desktop Policy Manager is deprecated, so admins must move to the web version. 11.1 runs out of service in October 2027. And 11.2’s release notes list no AI or LLM features — ask what is shipping.
Inventory every API, its back end and any gateway already running — note 11.1 estates, which leave service in October 2027.
Decide which gateways run as appliances, VMs or Kubernetes pods, and in which Indian data centre or cloud region.
Stand up an 11.2 gateway, ideally through the Operator, put one partner API behind it and make it the OAuth server.
Export policies as Graphman bundles, review changes like code, and send OpenTelemetry data to your existing monitoring.
Move remaining gateways to 11.2, switch admins to the web Policy Manager, and confirm the support terms in the contract.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our core banking APIs sit behind appliance gateways in two data centres. Adding container nodes did not mean a second licence negotiation.”
“We made the gateway our OAuth server for partner APIs. One token service instead of each team rolling its own was the real win.”
“The old desktop Policy Manager was the pain point for new hires. The web version in 11.2 is better, though not every task has moved yet.”
“Graphman bundles in Git changed our release process — policy changes are reviewed like code instead of exported by hand.”
“It fronts SOAP-era systems our mobile app still depends on. Transformation at the gateway saved us rewriting three back ends.”
“Getting a price took weeks of back and forth. Once licensed it is solid, but budget time for the quote, not just the pilot.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the API management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Long-standing regulated-industry gateway; quote-only.
The grid nobody publishes — how many places you can run the gateway yourself vs how much security policy ships inside it.
Appliance to Kubernetes; OAuth server, OWASP, post-quantum TLS.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Kong Konnect, Google Apigee, MuleSoft Anypoint, AWS API Gateway and Azure API Management — on where it runs, traffic, price, limits, security depth, support and India.
| Dimension | Layer7 API Gateway | Kong Konnect | Google Apigee | MuleSoft Anypoint | AWS API Gateway | Azure API Management |
|---|---|---|---|---|---|---|
| What it is | Self-managed gateway | SaaS API platform | Google Cloud API mgmt | Integration + API suite | Managed AWS front door | Azure-managed API mgmt |
| Deployment | Container, VM, appliance | SaaS, hybrid, self-host | Hosted or hybrid | Managed or self-managed | AWS-managed only | Self-hosted on 2 tiers |
| Traffic covered | HTTP, WebSocket, GraphQL | APIs, events, AI | APIs plus LLM policies | APIs, AI, MCP, flows | REST, HTTP, WebSocket | APIs, LLMs, MCP, A2A |
| Pricing model | Quote only | Per control plane + use | Per call + environment | Annual contract, quoted | Pure per-request | Per unit-hour or call |
| Published entry price | No list price | $25/month serverless | $365/month + calls | No list price | $3.50 per 1M REST | 1M calls free |
| Included vs add-on | Gateway; portal apart | Core in, extras metered | Analytics, security paid | Metered by capability | Transfer billed apart | AI gateway in all tiers |
| Scale and limits | No published limits | Plus caps at 10M/month | Tiered by QPS | Set by contract | Volume tiers to 20B+ | Unlimited on Premium v2 |
| Security depth | OAuth server, OWASP | Plugins + Kong Identity | Advanced API Security | Policies via gateway | IAM, Cognito, WAF | Content safety policy |
| Integrations | Operator, Graphman, OTel | decK, Operator, clouds | Google Cloud native | Connector-rich | AWS services | Azure + AI back ends |
| Governance and SSO | Plugs into your IAM | SSO on Enterprise only | Google Cloud IAM | External identity | IAM + resource policies | Entra ID and RBAC |
| India storage region | Your own servers | IN geo; city unnamed | Mumbai runtime | India Cloud | Mumbai region | Central India |
| Support | Two majors maintained | Email on Plus | Tiered SLAs | Terms not public | Via AWS Support | Azure support + SLA |
| Lock-in and exit | Layer7-specific policy | Declarative, open roots | Apigee-specific proxies | Mule-specific assets | AWS-bound | Azure-bound |
| Best fit | Regulated, on-premises | Multi-cloud estates | Google Cloud estates | Salesforce shops | Serverless on AWS | Microsoft estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Layer7 API Gateway is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (APIs behind the gateway; engineer-hour cost). Estimates model engineering time spent re-implementing authentication, threat checks and hand-copied config changes for each API, at an assumed 1.5 hours per API a year, with 70% of it removed by one gateway policy layer and config in Git. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Broadcom publishes no price for Layer7 API Gateway and does not name its licence unit; product pages send buyers to partners or a contact form. The gateway is sold on its own or as part of Layer7 API Management, and licences can be used across form factors — containers, VMs, software, appliances or public cloud. TechBag scopes gateway count and form factors first, then quotes in INR with GST.
Best for securing APIs on your own infrastructure
Best for a broader rollout
Best when partners need a self-service portal
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are any gateways still on 11.1 or older? 11.1 leaves service on 31 October 2027 — plan the 11.2 move now.
Which gateways need hardware appliances, and which can run as VMs or containers? Ask how the licence moves between them.
What exactly is being licensed — gateways, cores, environments or APIs? Broadcom does not publish it, so get it in writing.
Will you run ephemeral gateways? Then size the Layer7 Operator and Graphman bundle workflow before the pilot.
Do partners need a self-service portal? It is a separate Layer7 product, and its SaaS region is not published.
Do admins still rely on the desktop Policy Manager? It is deprecated; check which tasks the web version covers yet.
Should the gateway be your OAuth server, or defer to an existing IAM? Decide before you design token flows.
Will LLM or agent calls pass through? 11.2’s notes list no AI features — ask Broadcom what is GA and how it is licensed.
List your APIs and the gateways that front them first, or let a TechBag advisor map form factors, get the licence unit in writing and quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.