Authorization
API Gateway
A control layer that secures and governs API traffic, especially for machine-to-machine access.
Definition
An API Gateway is a technical enforcement layer placed in front of APIs and service calls. In a Zero Trust IAM architecture, it helps protect non-human identities, secure machine-to-machine exchanges, and apply policy to API traffic. It extends authorization and control beyond interactive user sessions.
The Ariovis perspective
Ariovis separates governed entitlements, authentication and runtime authorization. When a decision depends on the user, resource, action and context, it should be made at the moment of use.
Related terms
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.