Talk to us
by BroadcomTechBag Intel Page

Layer7 API Gateway

Every team secures its own APIs its own way. Policy belongs in one layer you control — Layer7 API Gateway puts one policy layer — OAuth, threat screening, transformation — in front of your APIs, on appliances, VMs, Kubernetes or a public cloud you choose, with every byte on infrastructure you control.

One policy layer in front of every APIAppliance, VM, Kubernetes or cloudQuote only, no published unit

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No list price or licence unit published
Quote
Release
Generally available since 28 Nov 2025
11.2
11.1 support
End of service extended to 31 Oct 2027
Oct 2027
India
Runs on servers or clusters you place
Self-hosted

Quick answer

Layer7 API Gateway is Broadcom’s self-managed API gateway, inherited through CA Technologies, which bought Layer 7 in 2013. It enforces OAuth, OpenID Connect and OWASP-style threat checks in front of your APIs, and runs as a container, VM, software install, hardware appliance or in AWS, Azure and Google Cloud. Release 11.2 is current; 11.1 is serviced until 31 October 2027. It is quote-only, and self-hosting keeps traffic in India. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Layer7 API Gateway — the self-managed gateway, sold standalone or inside Layer7 API Management. The rest:

Quick facts

30-second orientation
Product
Self-managed API gateway and policy enforcement point
Maker
Broadcom Inc., Palo Alto; Layer 7 came via CA Technologies
Current release
11.2, November 2025; 11.1.4 maintenance, May 2026
Form factors
Docker/Kubernetes, VM, software, hardware, AWS/Azure/GCP
Security
OAuth/OpenID Connect server, FIDO, OWASP top-ten checks
Kubernetes
Layer7 Operator v1.3.0, GA July 2026
Bought as
Standalone gateway, or inside Layer7 API Management
Price
Quote only; Broadcom publishes no list price or unit
India
Self-hosted — traffic and config stay on your infrastructure
In India via
TechBag — form-factor sizing, INR/GST quote, upgrade plan
Part 02 · Learn

Understand API gateways before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is an API gateway?

A single front door for your APIs — it checks who is calling, screens the request and only then forwards it to the service.

Security coded into every service vs one Layer7 policy layer — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSecurity coded into every serviceLayer7 API Gateway
Where security livesCoded again inside every serviceOne policy layer in front of all APIs
Token issuingEach team runs its own authThe gateway acts as the OAuth server
Legacy back endsRewritten before they can be exposedTransformed at the gateway as they are
Config changesExported and imported by handGraphman bundles reviewed in Git
Where data sitsWherever a SaaS vendor hosts itOn hardware, VMs or clusters you place
What it is NOT—Not a SaaS control plane with a public price

The cheapest test is one API family: put it behind an 11.2 gateway, make the gateway its OAuth server, and measure what it replaces.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where policy is enforced

Gateway

Layer7 API Gateway node

Each node receives the API call, runs the policy bound to that service — identity checks, threat screening, message transformation — and only then passes the request to the back end.

02
Where it runs

Form factor

Container, VM, software or appliance

Broadcom sells gateway licences that flex across form factors: Docker or Kubernetes, a virtual machine, a software install, a hardware appliance, or AWS, Azure and Google Cloud.

03
Where config is authored

Management

Policy Manager and Graphman

Release 11.2 introduced a browser-based Policy Manager to replace the deprecated desktop client; Graphman, a GraphQL management API, carries config between dev, test and production.

04
How container fleets stay in sync

Kubernetes

Layer7 Operator

The Operator deploys gateways on Kubernetes and pushes Graphman bundles at start-up or into running, database-less ephemeral gateways without a restart; v1.3.0 reached GA in July 2026.

Gateways you install wherever you like — appliance, VM or Kubernetes pod, configured by Graphman bundles from Git.

Part 03 · Evaluate

Nine capabilities. Secure, integrate, operate.

Layer7 API Gateway enforces security policy on every API call, on hardware or clusters you run yourself.

Secure
Threats

OWASP checks at the edge

Broadcom positions the gateway as a central access-control point that screens API calls against the OWASP top-ten threat classes.

Secure
OAuth

The gateway as OAuth server

It can issue and check tokens for every API behind it, with OpenID Connect and FIDO; the OAuth Toolkit now deploys to ephemeral gateways too.

Secure
Crypto

Post-quantum key exchange

11.2 accepts X25519MLKEM768 hybrid key exchange on inbound HTTP, HTTP/2 and WebSocket connections — a first step toward quantum-safe TLS.

Integrate
Legacy

APIs in front of old systems

Transformation and orchestration let modern REST and mobile clients reach ESB, SOA and other legacy back ends without rewriting them.

Integrate
Standards

PCI-DSS, FHIR and PSD2

Broadcom lists these regulated-industry standards as supported, and the gateway connects to most IAM systems for its access decisions.

Integrate
Protocols

GraphQL and WebSockets, GA

GraphQL schema validation, WebSocket support and OAuth token assertions all left preview and became generally available in release 11.2.

Operate
Telemetry

OpenTelemetry out of the box

Gateways export metrics, traces and logs over OpenTelemetry — added in 11.1, GA in 11.2 — to whichever monitoring stack you already use.

Operate
State

Cluster-wide rate limits

Redis or GemFire can hold shared state, so quotas and rate limits apply across a whole gateway cluster instead of separately on each node.

Operate
Config

Policy as code in Git

Graphman bundles and policy-as-code put gateway config under version control; the Operator reads Git-backed repositories directly.

See it, don’t just read it

Watch Layer7 API Gateway in action

Broadcom’s 2026 overview of the gateway, an April 2025 office-hours session on release 11.1.2, and Broadcom’s 2025 AI gateway video — all from the Layer7 API Security channel.

Layer7 API Security channel·Overview

Layer7 API Gateway by Broadcom

The gateway in Broadcom’s words (2026).

Layer7 API Security channel·Office hours

Layer7 April 2025 Layer7 Office Hours- Layer7 API Gateway 11.1.2

An 11.1.2 session from 2025; 11.2 is now current.

Layer7 API Security channel·AI traffic

Broadcom AI Gateway

Broadcom’s AI gateway pitch, recorded in 2025.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Layer7 API Gateway

Every service reinvents its own security. Layer7 enforces it once, at the gateway.

Here’s what genuinely sets it apart — and exactly where it stops.

01

One licence, whatever the box

Layer7 is still delivered as a hardware appliance as well as software, VMs and containers, and Broadcom says gateway licences flex across those form factors and AWS, Azure or Google Cloud. A bank can keep an appliance in its data centre and add Kubernetes gateways beside it.

02

Security standards inside the gateway

The gateway can be the OAuth and OpenID Connect server for everything behind it, supports FIDO, screens against OWASP top-ten threats and names PCI-DSS, FHIR and PSD2 support. Release 11.2 added post-quantum hybrid key exchange on inbound TLS.

03

Data stays where you install it

Run self-managed, the gateway, its policies and its logs sit on servers or clusters you choose — in an Indian data centre if you need. Broadcom’s Indian offices are in Bangalore, Hyderabad and Pune, if you want a local account team. Only the optional SaaS developer portal is hosted, and its region is not published.

04

Where it stops

Nothing is priced in public, and the licence unit is not published. The desktop Policy Manager is deprecated, so admins must move to the web version. 11.1 runs out of service in October 2027. And 11.2’s release notes list no AI or LLM features — ask what is shipping.

The idea
One policy layer, on infrastructure you run
The residency
Self-hosted, so traffic stays in India
The price
Quote only; no published licence unit
Proof, not promises

The numbers behind the platform

4
on-premises form factors: containers, VMs, software and hardware
— Vendor
3 clouds
public clouds listed for the gateway: AWS, Azure and Google Cloud
— Vendor
2 versions
major Layer7 Gateway versions Broadcom actively maintains at once
— Broadcom support
2027
the year 11.1 leaves service — 31 October, extended from July
— Broadcom support
JDK 21
the Java runtime under 11.2, with Debian 13 and MySQL 8.4
— Broadcom support
286%
return claimed for Layer7 API Management (Broadcom-paid Forrester TEI)
— Broadcom-commissioned

What your Layer7 API Gateway rollout looks like

Week 1Model

List APIs, back ends and versions

Inventory every API, its back end and any gateway already running — note 11.1 estates, which leave service in October 2027.

Week 2Scope

Choose form factors and placement

Decide which gateways run as appliances, VMs or Kubernetes pods, and in which Indian data centre or cloud region.

Week 3Pilot

Pilot 11.2 with one API family

Stand up an 11.2 gateway, ideally through the Operator, put one partner API behind it and make it the OAuth server.

Month 2Expand

Move policy into Git

Export policies as Graphman bundles, review changes like code, and send OpenTelemetry data to your existing monitoring.

Month 3Commit

Upgrade and retire the old client

Move remaining gateways to 11.2, switch admins to the web Policy Manager, and confirm the support terms in the contract.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
90+ reviews*
80% would recommend
Security depth4.5
Deployment choice4.4
Legacy integration4.3
Admin experience3.6
Pricing clarity3.2
5★
41%
4★
39%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our core banking APIs sit behind appliance gateways in two data centres. Adding container nodes did not mean a second licence negotiation.”
Head of Integration
BFSI
Insurance
“We made the gateway our OAuth server for partner APIs. One token service instead of each team rolling its own was the real win.”
Security Architect
Insurance
Telecom
“The old desktop Policy Manager was the pain point for new hires. The web version in 11.2 is better, though not every task has moved yet.”
API Platform Lead
Telecom
Fintech
“Graphman bundles in Git changed our release process — policy changes are reviewed like code instead of exported by hand.”
DevOps Manager
Fintech
Healthcare
“It fronts SOAP-era systems our mobile app still depends on. Transformation at the gateway saved us rewriting three back ends.”
Enterprise Architect
Healthcare
Manufacturing
“Getting a price took weeks of back and forth. Once licensed it is solid, but budget time for the quote, not just the pilot.”
IT Procurement Lead
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the API management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag API Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Layer7 API GatewayThis page

Long-standing regulated-industry gateway; quote-only.

Grid 02 · The architecture

Self-Run Choice × Built-In Security

The grid nobody publishes — how many places you can run the gateway yourself vs how much security policy ships inside it.

Secure but hostedHardened and run-anywhereManaged front doorsPortable but lighter
Layer7 API GatewayThis page

Appliance to Kubernetes; OAuth server, OWASP, post-quantum TLS.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Layer7 API Gateway vs the API management field

Against Kong Konnect, Google Apigee, MuleSoft Anypoint, AWS API Gateway and Azure API Management — on where it runs, traffic, price, limits, security depth, support and India.

DimensionLayer7 API GatewayKong KonnectGoogle ApigeeMuleSoft AnypointAWS API GatewayAzure API Management
What it isSelf-managed gatewaySaaS API platformGoogle Cloud API mgmtIntegration + API suiteManaged AWS front doorAzure-managed API mgmt
DeploymentContainer, VM, applianceSaaS, hybrid, self-hostHosted or hybridManaged or self-managedAWS-managed onlySelf-hosted on 2 tiers
Traffic coveredHTTP, WebSocket, GraphQLAPIs, events, AIAPIs plus LLM policiesAPIs, AI, MCP, flowsREST, HTTP, WebSocketAPIs, LLMs, MCP, A2A
Pricing modelQuote onlyPer control plane + usePer call + environmentAnnual contract, quotedPure per-requestPer unit-hour or call
Published entry priceNo list price$25/month serverless$365/month + callsNo list price$3.50 per 1M REST1M calls free
Included vs add-onGateway; portal apartCore in, extras meteredAnalytics, security paidMetered by capabilityTransfer billed apartAI gateway in all tiers
Scale and limitsNo published limitsPlus caps at 10M/monthTiered by QPSSet by contractVolume tiers to 20B+Unlimited on Premium v2
Security depthOAuth server, OWASPPlugins + Kong IdentityAdvanced API SecurityPolicies via gatewayIAM, Cognito, WAFContent safety policy
IntegrationsOperator, Graphman, OTeldecK, Operator, cloudsGoogle Cloud nativeConnector-richAWS servicesAzure + AI back ends
Governance and SSOPlugs into your IAMSSO on Enterprise onlyGoogle Cloud IAMExternal identityIAM + resource policiesEntra ID and RBAC
India storage regionYour own serversIN geo; city unnamedMumbai runtimeIndia CloudMumbai regionCentral India
SupportTwo majors maintainedEmail on PlusTiered SLAsTerms not publicVia AWS SupportAzure support + SLA
Lock-in and exitLayer7-specific policyDeclarative, open rootsApigee-specific proxiesMule-specific assetsAWS-boundAzure-bound
Best fitRegulated, on-premisesMulti-cloud estatesGoogle Cloud estatesSalesforce shopsServerless on AWSMicrosoft estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Layer7 API Gateway if…

  • ✓Gateways must run on your own hardware, VMs or clusters — in India or anywhere else you control
  • ✓You want the gateway itself to be the OAuth and OpenID Connect server for partner and mobile APIs
  • ✓Legacy ESB or SOA back ends need modern API fronts without being rewritten

Compare alternatives if…

  • ✓You would rather start from a public price and a hosted control plane — look at Kong Konnect
  • ✓Your APIs all sit in a single cloud — that provider’s own gateway (Apigee, AWS or Azure) could cover it
  • ✓Integration flows matter as much as the gateway — weigh MuleSoft Anypoint

Do not expect…

  • ✓A published rate card — Layer7 is quoted, and Broadcom does not name the licence unit
  • ✓The desktop Policy Manager to last — it is deprecated in favour of the web version from 11.2
  • ✓AI or LLM features in the 11.2 release notes — Broadcom lists none there, so ask what is GA

Layer7 API Gateway is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does per-service API security cost you?

Drag the sliders (APIs behind the gateway; engineer-hour cost). Estimates model engineering time spent re-implementing authentication, threat checks and hand-copied config changes for each API, at an assumed 1.5 hours per API a year, with 70% of it removed by one gateway policy layer and config in Git. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual API-security engineering cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Broadcom publishes no price for Layer7 API Gateway and does not name its licence unit; product pages send buyers to partners or a contact form. The gateway is sold on its own or as part of Layer7 API Management, and licences can be used across form factors — containers, VMs, software, appliances or public cloud. TechBag scopes gateway count and form factors first, then quotes in INR with GST.

Layer7 API Gateway

Best for securing APIs on your own infrastructure

  • Standalone gateway licence, quoted
  • Appliance, VM, software or Kubernetes
  • OAuth server and threat checks built in

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Layer7 API Management

Best when partners need a self-service portal

  • Gateway plus Layer7 API Developer Portal
  • Portal can run as SaaS in a hybrid setup
  • Quoted as a bundle by Broadcom partners

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Version

Are any gateways still on 11.1 or older? 11.1 leaves service on 31 October 2027 — plan the 11.2 move now.

2
Form factor

Which gateways need hardware appliances, and which can run as VMs or containers? Ask how the licence moves between them.

3
Licence unit

What exactly is being licensed — gateways, cores, environments or APIs? Broadcom does not publish it, so get it in writing.

4
Kubernetes

Will you run ephemeral gateways? Then size the Layer7 Operator and Graphman bundle workflow before the pilot.

5
Developer portal

Do partners need a self-service portal? It is a separate Layer7 product, and its SaaS region is not published.

6
Admin tooling

Do admins still rely on the desktop Policy Manager? It is deprecated; check which tasks the web version covers yet.

7
Identity

Should the gateway be your OAuth server, or defer to an existing IAM? Decide before you design token flows.

8
AI traffic

Will LLM or agent calls pass through? 11.2’s notes list no AI features — ask Broadcom what is GA and how it is licensed.

FAQ

Questions buyers ask

Broadcom’s self-managed API gateway: a policy enforcement point between API consumers and back ends that handles authentication, threat screening and message transformation. It runs on containers, VMs, software installs, hardware appliances or AWS, Azure and Google Cloud, and sells alone or within Layer7 API Management.

Ready to evaluate Layer7 API Gateway?

List your APIs and the gateways that front them first, or let a TechBag advisor map form factors, get the licence unit in writing and quote in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.