Talk to us
by F5TechBag Intel Page

F5 API Security

Your APIs sit behind BIG-IP, NGINX and a cloud gateway, and nobody has the full list. Attackers only need the endpoint you forgot — F5 API Security lists your APIs from code, traffic and client-side crawling and blocks OWASP API Top 10 attacks inline — as Distributed Cloud SaaS or hybrid, or as an on-premises Local Edition that can run air-gapped.

Find from code, traffic and crawlingInline OWASP API Top 10 blockingSaaS, hybrid or air-gapped

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No price on f5.com; AWS Marketplace lists metered pay-as-you-go rates for discovery and protection
Quote or PAYG
Analysts
KuppingerCole’s Leadership Compass for Web Application and API Security, August 2025
WAAP Leader
Editions
Distributed Cloud API Security as SaaS or hybrid; Local Edition for sites with no internet link
SaaS + on-prem
India
Mumbai and Chennai Distributed Cloud PoPs announced in December 2022; Local Edition stays in your DC
Two PoPs (2022)

Quick answer

F5 API Security comes in two forms: Distributed Cloud API Security, run as SaaS or hybrid, and the on-premises Local Edition for air-gapped sites. It builds an API inventory from code repositories, live traffic and client-side web crawling, spots OWASP API Top 10 attacks at runtime and can block them inline, alongside BIG-IP, NGINX or a third-party gateway. f5.com prints no price; AWS Marketplace meters it by the hour and request. Read more ↓ Show less ↑
Part 01 · Orient

The F5 platform family

This page covers F5 API Security — Distributed Cloud API Security and the on-premises Local Edition. The rest:

Quick facts

30-second orientation
Product
API discovery, runtime attack detection and inline blocking, as SaaS or an on-prem edition
Maker
F5, Inc.; Chairman, President and CEO François Locoh-Donou; Q3 FY26 revenue $865M
Editions
Distributed Cloud API Security (SaaS or hybrid) and F5 API Security Local Edition (on-prem)
Discovery
Code-repository analysis combined with traffic and client-side web crawling
Runtime
OWASP API Top 10 detection, with offending requests blocked inline
Price
None on f5.com; AWS Marketplace pay-as-you-go meters API Discovery and API Protection
Works with
BIG-IP, NGINX and third-party API gateways, per F5’s API Security page
Analysts
Leader, KuppingerCole Leadership Compass for Web Application and API Security (Aug 2025)
India
Distributed Cloud PoPs in Mumbai and Chennai since Dec 2022; Local Edition runs on your site
In India via
TechBag — edition choice, gateway mapping, quote in INR with GST
Part 02 · Learn

Understand API security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is API security?

It keeps an up-to-date list of your APIs and stops attacks aimed at them, which page-focused WAF rules often miss.

Gateway lists and WAF alerts vs F5 API Security — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionGateway lists and WAF alertsF5 API Security
Where the API list comes fromWhatever each gateway team registeredCode, live traffic and client-side crawling
Who stops a live attackA ticket raised after the alertAn inline block on the OWASP API Top 10
Contract driftFound when a partner integration breaksRequests checked against the OpenAPI schema
Air-gapped sitesLeft out of cloud API toolsCovered by the on-premises Local Edition
Personal data in responsesNoticed during an auditDetected and masked (Enterprise package)
What it is NOT—A CI/CD test suite, or an MCP inventory

The cheapest test is metered: run API Discovery on one load balancer through AWS pay-as-you-go for a month and count what it finds.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How the API inventory is assembled

Inputs

Code, traffic and crawl

Discovery reads code repositories, watches the traffic flowing to your APIs and crawls the client side of web apps, then merges all three into one list of endpoints.

02
The SaaS or hybrid edition

Cloud

Distributed Cloud API Security

The Distributed Cloud service keeps the inventory and runs the runtime analysis, bought as SaaS or deployed in a hybrid model for estates that span public clouds and data centres.

03
Where a bad request is stopped

Enforce

Inline enforcement points

Runtime checks for the OWASP API Top 10 can drop a request inline, and F5 connects the service to BIG-IP, NGINX and API gateways from other vendors for that job.

04
The on-premises edition

Local

F5 API Security Local Edition

Local Edition installs inside your own data centre for estates that cannot send API traffic to a cloud service, including air-gapped networks with no outside link.

Code, traffic and a client-side crawl build the inventory — blocking runs inline, in F5’s cloud or on a Local Edition.

Part 03 · Evaluate

Six capabilities. Find, detect, enforce.

F5 API Security finds every API from three directions and can stop attacks on them in line.

Find
Three inputs

Code, traffic and crawling

Repositories show APIs before release, traffic shows what is live, and crawling shows what web front ends call.

Find
Gateways

Fed by F5 and others

Connects to BIG-IP and NGINX deployments and to third-party API gateways, so non-F5 estates are covered too.

Detect
OWASP API

Top 10 attacks at runtime

Live requests are checked against the OWASP API Security Top 10, from broken object-level authorisation to resource abuse.

Detect
Sensitive data

Spot and mask personal data

With the WAAP Enterprise package, responses carrying sensitive data are detected and the values can be masked.

Enforce
Inline

Block, not just alert

Requests that match an attack can be stopped in the path, so the API owner is not waiting on a ticket to act.

Enforce
Schema

Hold calls to the OpenAPI file

The WAAP Enterprise package validates requests against your OpenAPI schema and refuses calls that break it.

See it, don’t just read it

Watch F5 API Security in action

F5’s 2024 explainer on API sprawl, plus two 2025 partner videos with Google Cloud and AWS on protecting the APIs behind AI applications. All from F5’s official channel.

F5 (official)·Explainer, 2024

Staying Ahead of API Security Complexity

F5’s 2024 framing of why API estates outgrow manual inventories and per-gateway rules.

F5 (official)·Partner video, 2025

Discover, protect, and optimize APIs powering your AI applications at scale with F5 and Google Cloud

F5 and Google Cloud on finding and protecting the APIs that AI applications depend on.

F5 (official)·Partner video, 2025

Fortify Your AI Investments with API Security from F5 and AWS | AI

The AWS angle: F5’s API security pitched for AI workloads running on Amazon’s cloud.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why F5 API Security

APIs multiply faster than anyone can list them. F5 finds them from three directions and blocks attacks in line.

Here’s what genuinely sets it apart — and exactly where it stops.

01

An inventory from three directions

Gateway logs only show APIs someone registered. F5 combines code-repository analysis, observed traffic and client-side web crawling, so an endpoint surfaces before it ships, once it carries calls, or because a browser page quietly calls it.

02

It can stop the request itself

Many API tools watch a copy of traffic and leave the block to something else. F5 detects OWASP API Top 10 attacks at runtime and can drop the request inline, and if BIG-IP or NGINX already fronts your APIs, that is gear your team runs today.

03

A cloud edition and an air-gapped one

Distributed Cloud API Security runs as SaaS or hybrid; the Local Edition installs on premises for networks that cannot reach a cloud. Banks and public bodies that keep API traffic in-house get that option without changing vendor. KuppingerCole named F5 a WAAP Leader in August 2025.

04

Where it stops

f5.com prints no price; the AWS meters sit on a $3.704-an-hour base package. There is no pipeline testing (Web App Scanning is sold apart) and no documented MCP discovery. Schema validation and masking need the WAAP Enterprise package, and a BIG-IP enforcer brings its patch duty.

The idea
Find from three inputs, block inline
The editions
Distributed Cloud, or on-prem Local
The price
Quoted, or metered on AWS Marketplace
Proof, not promises

The numbers behind the platform

3 inputs
code repositories, live traffic and client-side web crawling, merged for API discovery
— Vendor
OWASP Top 10
the API attack categories F5 detects at runtime, with inline blocking available
— Vendor
$1.079/LB-hour
API Discovery on AWS Marketplace pay-as-you-go, per load balancer, from 1 Jan 2025
— AWS Marketplace
$0.328 per 1,000
requests under API Protection on the same AWS listing, billed above the base package
— AWS Marketplace
2 Indian PoPs
Mumbai and Chennai, announced for Distributed Cloud in December 2022
— Vendor (2022)
2025
the year KuppingerCole named F5 a Leader for Web Application and API Security
— Analyst

What your F5 API Security rollout looks like

Week 1Model

Choose the edition

Decide which APIs may be analysed in Distributed Cloud and which must stay on site under the Local Edition.

Week 2Decide

Map enforcement points

List where each API is fronted today — BIG-IP, NGINX, a cloud gateway or another vendor — and pick where blocks happen.

Week 3Pilot

Run discovery on one domain

Connect a repository, the traffic for one product line and a client-side crawl, then compare the result to the gateway list.

Month 2Prove

Detect before you block

Leave OWASP API Top 10 rules in monitoring for a few weeks, tune false hits with API owners, then switch them to block.

Month 3Commit

Add schemas and masking

Upload OpenAPI files for the riskiest APIs, turn on schema validation and masking, and agree who approves new rules.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
36+ reviews*
80% would recommend
API discovery4.2
Runtime blocking4.3
Deployment choice4.4
Ease of rollout3.8
Value for money3.6
5★
41%
4★
37%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Fintech
“Our NGINX tier already fronted the payment APIs, so blocking a BOLA probe happened where traffic was flowing anyway.”
Platform Engineer
Fintech
E-commerce
“The client-side crawl surfaced endpoints our mobile web pages called that no gateway team had ever been asked about.”
AppSec Lead
E-commerce
Public-sector BFSI
“Regulators wanted no API payloads leaving our network, so Local Edition was the only reason the project got approved.”
CISO
Public-sector BFSI
Insurance
“Schema validation caught a partner sending fields our OpenAPI file never allowed. We had to buy the Enterprise package for it.”
Integration Architect
Insurance
SaaS
“Hourly AWS metering made the pilot easy to start, but forecasting the per-request charge took a month of real data.”
Cloud FinOps Analyst
SaaS
Telecom
“We still run a separate API test tool in CI. This covers inventory and runtime; it was never sold to us as a scanner.”
DevSecOps Engineer
Telecom
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the API security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag API Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
F5 API SecurityThis page

KuppingerCole WAAP Leader 2025; metered on AWS.

Grid 02 · The architecture

Deployment Reach × Lifecycle Coverage

The grid nobody publishes — how many places the tool can run while keeping API data on your side vs how much of discover, test and block it covers.

Broad but edge-boundFull cover, runs anywhereEdge-only add-onsPortable, narrower tools
F5 API SecurityThis page

SaaS, hybrid or air-gapped; finds and blocks, no CI tests.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

F5 API Security vs the API security field

Set beside Akamai API Security, Salt Security, Traceable by Harness, Cloudflare API Shield and Levo.ai — on deployment, discovery, testing, blocking, price, India data and exit.

DimensionF5 API SecurityAkamai API SecuritySalt SecurityTraceable by HarnessCloudflare API ShieldLevo.ai
What it isSaaS plus Local EditionEx-Noname lifecycle toolRuntime-first, AI agentsPart of HarnessEdge add-on suiteYoung, test-led vendor
Where it runsSaaS, hybrid, air-gappedSaaS, hybrid or on-premCloud or Hybrid ServerSaaS agent or on-premCloudflare proxy onlyeBPF sensors on site
How APIs are foundCode, traffic, crawling40+ feeds plus codeMirrored trafficFive API stylesProxied traffic onlyeBPF + OpenAPI output
Posture and schemaSchema + sensitive dataSeven framework mapsEU AI Act, SOC 2 checksData to parameterOpenAPI checks, mTLSMaps to India’s DPDPA
Testing before releaseNot in this product200+ pipeline testsPolicy in AI codersXAST and DAST in CINo pipeline testingExploit-aware DAST
Blocking in productionInline blockingDetects; others blockOut of band, no lagPolicy in-platformInline at the edgeNewer runtime layer
AI-linked APIsAI apps; MCP not listedMCP and LLM endpointsAgents, MCP, modelsNot documentedFirewall for AI apartAdded in 2025
How it is pricedPackage or meteredQuote, unit unknownBy monthly API callsQuote onlyEnterprise add-onFree tier, then quote
Public price$1.079/LB-hour on AWSFree assessment only$100,000 a yearNot publishedNot publishedFree testing tier
Scale figuresNot published6B calls a month$250,000 for 100MSized by sales~500 Tbps networkSmall supplier
IntegrationsBIG-IP, NGINX, othersSIEM through CMDBGateways incl. F5WAFs, ITSM, WizCloudflare consoleCI/CD pipelines
India dataLocal Edition, or PoPsHybrid or on-premPayloads stay localRedact or self-hostLocalization Suiteindia-1 region
Exit and lock-inDistributed Cloud tieNo Akamai edge neededVendor-neutral feedsInside HarnessTied to the proxyContinuity question
Best fitBIG-IP and NGINX estatesMulti-CDN API estatesRuntime and AI agentsHarness CI/CD usersCloudflare EnterpriseShift-left, India region
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose F5 API Security if…

  • ✓BIG-IP, NGINX or Distributed Cloud already fronts your APIs and you want the attack blocked at that same point
  • ✓Some API traffic may never leave your building, and you need an on-prem edition that also runs air-gapped
  • ✓You want discovery that reads code, traffic and the browser side of your web apps, not gateway logs alone

Compare alternatives if…

  • ✓Security tests must run in every pipeline — Akamai, Traceable by Harness and Levo all document CI/CD testing
  • ✓MCP servers and AI agents need cataloguing now — Akamai and Salt both describe that coverage
  • ✓You want an Indian SaaS region for the analysis itself — Levo’s india-1 or Cloudflare’s Data Localization Suite

Do not expect…

  • ✓A list price on f5.com; the only public rates are AWS Marketplace meters
  • ✓Pipeline security testing inside the product; scanning is sold as another Distributed Cloud service
  • ✓Schema validation or data masking on the Essentials package

TechBag has no API security guide yet, so F5 API Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does tracking APIs by hand cost you?

Drag the sliders (APIs in your estate; AppSec hour cost). Estimates model engineering time spent listing APIs by hand, chasing undocumented endpoints and triaging attack alerts at an assumed 1.5 hours per API a year, with 70% of it removed by automatic discovery and inline blocking. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual API-security effort
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

f5.com publishes no price for F5 API Security. On AWS Marketplace pay-as-you-go (effective 1 January 2025), API Discovery is $1.079 per load balancer per hour and API Protection $0.328 per 1,000 requests, billed on top of the $3.704-an-hour Distributed Cloud base package; these are marketplace software fees, not a list price. Annual subscriptions, private offers and the Local Edition are quoted. TechBag estimates your request volume first, then quotes in INR with GST.

Distributed Cloud API Security

Best for APIs already in the cloud

  • Annual package or AWS pay-as-you-go
  • API Discovery $1.079 per LB-hour on AWS
  • Schema validation in the Enterprise package

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

API Security Local Edition

Best for sites that keep traffic in-house

  • Quoted; no public price
  • Installed on premises, air-gap capable
  • Analysis stays in your data centre

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Edition

Which API traffic may be analysed in F5’s cloud, and which must stay inside your walls on the Local Edition?

2
Enforcement

Do BIG-IP, NGINX or a third-party gateway front each API, and which of them will drop a blocked request?

3
Package

Do you need schema validation and data masking? Those sit in the WAAP Enterprise package, not Essentials.

4
Discovery inputs

Can F5 read the code repositories, and which web apps should the client-side crawler be allowed to visit?

5
Testing gap

Which tool will test APIs in CI/CD, since this product does not, and is Web App Scanning part of the plan?

6
AI estate

Do teams run MCP servers or agent-facing APIs that need inventorying, and how will you find them here?

7
Patch posture

If BIG-IP enforces, is it on 17.1, 17.5 or 21.x? Versions 15.1 and 16.1 are past end of support.

8
Commercials

Subscription, private offer or AWS pay-as-you-go? Ask TechBag for INR with GST and an estimate of request volume.

FAQ

Questions buyers ask

F5’s product for finding and protecting APIs. It inventories endpoints from code repositories, traffic and client-side web crawling, detects OWASP API Top 10 attacks at runtime and can block them inline. It comes as Distributed Cloud API Security (SaaS or hybrid) or an on-premises Local Edition.

Ready to evaluate F5 API Security?

Estimate your request volume and pick the edition first, or let a TechBag advisor run discovery on one product line and compare it with your gateway list.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.