Identity
7- API keyv1
- Basic authv1
- OAuth2v1
- JWT verifyv1
- JWT generatev1
- HMACv1
- mTLSv1
Policy catalog
A policy is a small piece of configuration with a schema behind it. It lives inside a bundle revision, so runtime behavior moves with the API that uses it.
policy types, each with a published schema
phases: request, response, fault
callout runtimes: JavaScript and Python
Machine readable by default
Policy types are built into the gateway. Each one publishes a JSON Schema for its settings. You write a policy as a short YAML file in the bundle, and it is checked against that schema before it can be published.
kind: Policy
name: protect-orders
type: quota/v1
condition: request.method == "POST"
onError: fault
config:
identifier: token.appId
limit: product.quota
interval: product.quotaInterval
timeUnit: product.quotaTimeUnit
type: sliding
distributed: true
onStoreFailure: fail-open{
"type": "quota",
"version": 1,
"group": "Traffic",
"phases": ["request"],
"configSchema": {
"required": ["identifier", "limit", "timeUnit"],
"properties": {
"identifier": { "$ref": "#/$defs/varString" },
"limit": { "$ref": "#/$defs/varString" },
"interval": { "$ref": "#/$defs/varString" },
"timeUnit": { "$ref": "#/$defs/varString" },
"type": { "enum": ["sliding", "calendar"] },
"distributed": { "type": "boolean", "default": true },
"onStoreFailure": { "enum": ["fail-open", "fail-closed"] }
}
}
}