Your APIs sit behind BIG-IP, NGINX and a cloud gateway, and nobody has the full list. Attackers only need the endpoint you forgot — F5 API Security lists your APIs from code, traffic and client-side crawling and blocks OWASP API Top 10 attacks inline — as Distributed Cloud SaaS or hybrid, or as an on-premises Local Edition that can run air-gapped.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers F5 API Security — Distributed Cloud API Security and the on-premises Local Edition. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It keeps an up-to-date list of your APIs and stops attacks aimed at them, which page-focused WAF rules often miss.
What consolidation actually replaces, dimension by dimension.
| Dimension | Gateway lists and WAF alerts | F5 API Security |
|---|---|---|
| Where the API list comes from | Whatever each gateway team registered | Code, live traffic and client-side crawling |
| Who stops a live attack | A ticket raised after the alert | An inline block on the OWASP API Top 10 |
| Contract drift | Found when a partner integration breaks | Requests checked against the OpenAPI schema |
| Air-gapped sites | Left out of cloud API tools | Covered by the on-premises Local Edition |
| Personal data in responses | Noticed during an audit | Detected and masked (Enterprise package) |
| What it is NOT | — | A CI/CD test suite, or an MCP inventory |
The cheapest test is metered: run API Discovery on one load balancer through AWS pay-as-you-go for a month and count what it finds.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Discovery reads code repositories, watches the traffic flowing to your APIs and crawls the client side of web apps, then merges all three into one list of endpoints.
The Distributed Cloud service keeps the inventory and runs the runtime analysis, bought as SaaS or deployed in a hybrid model for estates that span public clouds and data centres.
Runtime checks for the OWASP API Top 10 can drop a request inline, and F5 connects the service to BIG-IP, NGINX and API gateways from other vendors for that job.
Local Edition installs inside your own data centre for estates that cannot send API traffic to a cloud service, including air-gapped networks with no outside link.
Code, traffic and a client-side crawl build the inventory — blocking runs inline, in F5’s cloud or on a Local Edition.
F5 API Security finds every API from three directions and can stop attacks on them in line.
Repositories show APIs before release, traffic shows what is live, and crawling shows what web front ends call.
Connects to BIG-IP and NGINX deployments and to third-party API gateways, so non-F5 estates are covered too.
Live requests are checked against the OWASP API Security Top 10, from broken object-level authorisation to resource abuse.
With the WAAP Enterprise package, responses carrying sensitive data are detected and the values can be masked.
Requests that match an attack can be stopped in the path, so the API owner is not waiting on a ticket to act.
The WAAP Enterprise package validates requests against your OpenAPI schema and refuses calls that break it.
F5’s 2024 explainer on API sprawl, plus two 2025 partner videos with Google Cloud and AWS on protecting the APIs behind AI applications. All from F5’s official channel.
F5’s 2024 framing of why API estates outgrow manual inventories and per-gateway rules.
F5 and Google Cloud on finding and protecting the APIs that AI applications depend on.
The AWS angle: F5’s API security pitched for AI workloads running on Amazon’s cloud.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Gateway logs only show APIs someone registered. F5 combines code-repository analysis, observed traffic and client-side web crawling, so an endpoint surfaces before it ships, once it carries calls, or because a browser page quietly calls it.
Many API tools watch a copy of traffic and leave the block to something else. F5 detects OWASP API Top 10 attacks at runtime and can drop the request inline, and if BIG-IP or NGINX already fronts your APIs, that is gear your team runs today.
Distributed Cloud API Security runs as SaaS or hybrid; the Local Edition installs on premises for networks that cannot reach a cloud. Banks and public bodies that keep API traffic in-house get that option without changing vendor. KuppingerCole named F5 a WAAP Leader in August 2025.
f5.com prints no price; the AWS meters sit on a $3.704-an-hour base package. There is no pipeline testing (Web App Scanning is sold apart) and no documented MCP discovery. Schema validation and masking need the WAAP Enterprise package, and a BIG-IP enforcer brings its patch duty.
Decide which APIs may be analysed in Distributed Cloud and which must stay on site under the Local Edition.
List where each API is fronted today — BIG-IP, NGINX, a cloud gateway or another vendor — and pick where blocks happen.
Connect a repository, the traffic for one product line and a client-side crawl, then compare the result to the gateway list.
Leave OWASP API Top 10 rules in monitoring for a few weeks, tune false hits with API owners, then switch them to block.
Upload OpenAPI files for the riskiest APIs, turn on schema validation and masking, and agree who approves new rules.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our NGINX tier already fronted the payment APIs, so blocking a BOLA probe happened where traffic was flowing anyway.”
“The client-side crawl surfaced endpoints our mobile web pages called that no gateway team had ever been asked about.”
“Regulators wanted no API payloads leaving our network, so Local Edition was the only reason the project got approved.”
“Schema validation caught a partner sending fields our OpenAPI file never allowed. We had to buy the Enterprise package for it.”
“Hourly AWS metering made the pilot easy to start, but forecasting the per-request charge took a month of real data.”
“We still run a separate API test tool in CI. This covers inventory and runtime; it was never sold to us as a scanner.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the API security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
KuppingerCole WAAP Leader 2025; metered on AWS.
The grid nobody publishes — how many places the tool can run while keeping API data on your side vs how much of discover, test and block it covers.
SaaS, hybrid or air-gapped; finds and blocks, no CI tests.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Set beside Akamai API Security, Salt Security, Traceable by Harness, Cloudflare API Shield and Levo.ai — on deployment, discovery, testing, blocking, price, India data and exit.
| Dimension | F5 API Security | Akamai API Security | Salt Security | Traceable by Harness | Cloudflare API Shield | Levo.ai |
|---|---|---|---|---|---|---|
| What it is | SaaS plus Local Edition | Ex-Noname lifecycle tool | Runtime-first, AI agents | Part of Harness | Edge add-on suite | Young, test-led vendor |
| Where it runs | SaaS, hybrid, air-gapped | SaaS, hybrid or on-prem | Cloud or Hybrid Server | SaaS agent or on-prem | Cloudflare proxy only | eBPF sensors on site |
| How APIs are found | Code, traffic, crawling | 40+ feeds plus code | Mirrored traffic | Five API styles | Proxied traffic only | eBPF + OpenAPI output |
| Posture and schema | Schema + sensitive data | Seven framework maps | EU AI Act, SOC 2 checks | Data to parameter | OpenAPI checks, mTLS | Maps to India’s DPDPA |
| Testing before release | Not in this product | 200+ pipeline tests | Policy in AI coders | XAST and DAST in CI | No pipeline testing | Exploit-aware DAST |
| Blocking in production | Inline blocking | Detects; others block | Out of band, no lag | Policy in-platform | Inline at the edge | Newer runtime layer |
| AI-linked APIs | AI apps; MCP not listed | MCP and LLM endpoints | Agents, MCP, models | Not documented | Firewall for AI apart | Added in 2025 |
| How it is priced | Package or metered | Quote, unit unknown | By monthly API calls | Quote only | Enterprise add-on | Free tier, then quote |
| Public price | $1.079/LB-hour on AWS | Free assessment only | $100,000 a year | Not published | Not published | Free testing tier |
| Scale figures | Not published | 6B calls a month | $250,000 for 100M | Sized by sales | ~500 Tbps network | Small supplier |
| Integrations | BIG-IP, NGINX, others | SIEM through CMDB | Gateways incl. F5 | WAFs, ITSM, Wiz | Cloudflare console | CI/CD pipelines |
| India data | Local Edition, or PoPs | Hybrid or on-prem | Payloads stay local | Redact or self-host | Localization Suite | india-1 region |
| Exit and lock-in | Distributed Cloud tie | No Akamai edge needed | Vendor-neutral feeds | Inside Harness | Tied to the proxy | Continuity question |
| Best fit | BIG-IP and NGINX estates | Multi-CDN API estates | Runtime and AI agents | Harness CI/CD users | Cloudflare Enterprise | Shift-left, India region |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no API security guide yet, so F5 API Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (APIs in your estate; AppSec hour cost). Estimates model engineering time spent listing APIs by hand, chasing undocumented endpoints and triaging attack alerts at an assumed 1.5 hours per API a year, with 70% of it removed by automatic discovery and inline blocking. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
f5.com publishes no price for F5 API Security. On AWS Marketplace pay-as-you-go (effective 1 January 2025), API Discovery is $1.079 per load balancer per hour and API Protection $0.328 per 1,000 requests, billed on top of the $3.704-an-hour Distributed Cloud base package; these are marketplace software fees, not a list price. Annual subscriptions, private offers and the Local Edition are quoted. TechBag estimates your request volume first, then quotes in INR with GST.
Best for APIs already in the cloud
Best for a broader rollout
Best for sites that keep traffic in-house
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which API traffic may be analysed in F5’s cloud, and which must stay inside your walls on the Local Edition?
Do BIG-IP, NGINX or a third-party gateway front each API, and which of them will drop a blocked request?
Do you need schema validation and data masking? Those sit in the WAAP Enterprise package, not Essentials.
Can F5 read the code repositories, and which web apps should the client-side crawler be allowed to visit?
Which tool will test APIs in CI/CD, since this product does not, and is Web App Scanning part of the plan?
Do teams run MCP servers or agent-facing APIs that need inventorying, and how will you find them here?
If BIG-IP enforces, is it on 17.1, 17.5 or 21.x? Versions 15.1 and 16.1 are past end of support.
Subscription, private offer or AWS pay-as-you-go? Ask TechBag for INR with GST and an estimate of request volume.
Estimate your request volume and pick the edition first, or let a TechBag advisor run discovery on one product line and compare it with your gateway list.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.