Policy catalog

Explicit behavior. Versioned contracts.

A policy is a small piece of configuration with a schema behind it. It lives inside a bundle revision, so runtime behavior moves with the API that uses it.

35

policy types, each with a published schema

3

phases: request, response, fault

2

callout runtimes: JavaScript and Python

Identity

7
  • API keyv1
  • Basic authv1
  • OAuth2v1
  • JWT verifyv1
  • JWT generatev1
  • HMACv1
  • mTLSv1

Traffic

7
  • Quotav1
  • Spike arrestv1
  • Concurrencyv1
  • Timeoutv1
  • Retryv1
  • Circuit breakerv1
  • Traffic splitv1

Transformation

6
  • Headersv1
  • Bodyv1
  • URL rewritev1
  • Assign messagev1
  • Extract variablesv1
  • Service calloutv1

Protection

5
  • IP restrictionv1
  • Threat protectionv1
  • Bot detectionv1
  • Request sizev1
  • Request validationv1

Response

5
  • CORSv1
  • Cachev1
  • Mock responsev1
  • Terminatev1
  • Fault shapingv1

Operations

5
  • Correlation IDv1
  • Message loggingv1
  • Metricsv1
  • Key-value lookupv1
  • Calloutv1

Machine readable by default

The schema is the contract.

Policy types are built into the gateway. Each one publishes a JSON Schema for its settings. You write a policy as a short YAML file in the bundle, and it is checked against that schema before it can be published.

policies/protect-orders.policy.yamlAuthored in the bundle
kind: Policy
name: protect-orders
type: quota/v1
condition: request.method == "POST"
onError: fault
config:
  identifier: token.appId
  limit: product.quota
  interval: product.quotaInterval
  timeUnit: product.quotaTimeUnit
  type: sliding
  distributed: true
  onStoreFailure: fail-open
schemas/policies/quota.v1.jsonPublished by the gateway · excerpt
{
  "type": "quota",
  "version": 1,
  "group": "Traffic",
  "phases": ["request"],
  "configSchema": {
    "required": ["identifier", "limit", "timeUnit"],
    "properties": {
      "identifier": { "$ref": "#/$defs/varString" },
      "limit": { "$ref": "#/$defs/varString" },
      "interval": { "$ref": "#/$defs/varString" },
      "timeUnit": { "$ref": "#/$defs/varString" },
      "type": { "enum": ["sliding", "calendar"] },
      "distributed": { "type": "boolean", "default": true },
      "onStoreFailure": { "enum": ["fail-open", "fail-closed"] }
    }
  }
}
Open the complete reference