Glossary · System coordination, integration and orchestration
API gateway
Also known as: application programming interface gateway
German: API-Gateway
In software architecture, an API gateway is a service that acts as the single entry point for client requests to a set of backend services, routing each request and typically handling authentication, rate limiting, protocol translation and logging.
- System integration
- OT security
In one sentence
An API gateway is the single entry point for requests to backend services, handling routing, authentication, rate limiting and logging.
Example
Maintenance tablets call one API gateway, which authenticates the technician and forwards requests to the asset service, the work-order service and the document service.
How it applies
- Architecture: An API gateway decouples clients from the internal structure of services, so services can be split, moved or versioned without every client changing.
- Security: Because all requests pass through it, the gateway is a natural place for Authentication, authorization and request limits. It adds to, but does not replace, network segmentation between IT and OT and security controls inside the services.
- Documentation: API reference documentation should describe the interface as exposed by the gateway (base URL, authentication, versioning, error codes), not the internal service endpoints.
API gateway vs. edge gateway
An API gateway manages request traffic to software services. An Edge gateway is a device or runtime at the boundary of the shop floor that collects data from field devices and forwards it to higher-level systems. A plant may use both.