Lesson 2 / 26
What an API Gateway Does
List the responsibilities of an API gateway and what should stay out of it.
One front door
An API gateway is the single entry point for client requests. Typical jobs: routing to the right backend by host, path, method or header; authentication and coarse authorisation (API keys, JWT or OAuth validation); rate limiting and quotas; TLS termination; request/response transformation (path rewriting, adding or removing headers); caching; load balancing and health checks; observability (access logs, metrics, request IDs); and sometimes aggregation of several backend calls. Keep business logic out of the gateway: it should be thin configuration and policy, otherwise it becomes a bottleneck and a deployment hazard that every team depends on.
The request path through a gateway
Each stage is a place to apply policy once instead of in every service.
client --HTTPS--> [ gateway ]
1. terminate TLS
2. authenticate (API key / JWT)
3. rate limit per client
4. route by host/path/header --> orders-service
5. add X-Request-ID, strip internal headers
6. log + metrics --> users-serviceKeep the gateway stateless
A stateless gateway scales by adding copies behind a load balancer and survives restarts. Store shared state (rate-limit counters, sessions) in a fast external store such as Redis.
Quick check: Which belongs in an API gateway?
- Authentication, rate limiting and routing
- Order pricing business rules
- Database migrations
- UI design
Answer
Authentication, rate limiting and routing — Cross-cutting policy fits the gateway; business rules belong in services.