# What an API Gateway Does — API Gateway and Service Mesh

Source: https://www.geekswithgeeks.com/en/api-gateway-service-mesh/c-gateway-role

> List the responsibilities of an API gateway and what should stay out of it.

## One front door

An **API gateway** is the single entry point for client requests. Typical jobs: **routing** to the right backend by host, path, method or header; **authentication** and coarse authorisation (API keys, JWT or OAuth validation); **rate limiting** and quotas; **TLS termination**; **request/response transformation** (path rewriting, adding or removing headers); **caching**; **load balancing** and health checks; **observability** (access logs, metrics, request IDs); and sometimes **aggregation** of several backend calls. Keep **business logic out of the gateway**: it should be thin configuration and policy, otherwise it becomes a bottleneck and a deployment hazard that every team depends on.

## The request path through a gateway

Each stage is a place to apply policy once instead of in every service.

```text
client --HTTPS--> [ gateway ]
                     1. terminate TLS
                     2. authenticate (API key / JWT)
                     3. rate limit per client
                     4. route by host/path/header   --> orders-service
                     5. add X-Request-ID, strip internal headers
                     6. log + metrics            --> users-service
```

## Keep the gateway stateless

A stateless gateway scales by adding copies behind a load balancer and survives restarts. Store shared state (rate-limit counters, sessions) in a fast external store such as Redis.

**Quiz:** Which belongs in an API gateway?

- [x] Authentication, rate limiting and routing
- [ ] Order pricing business rules
- [ ] Database migrations
- [ ] UI design

*Answer:* Authentication, rate limiting and routing. Cross-cutting policy fits the gateway; business rules belong in services.
