# Alternatives to Apigee

Apigee is Google Cloud API management platform for designing, securing, publishing, monetizing, and analyzing APIs at enterprise scale.

Apigee ranks #5 of 8 in API gateways, with an Alt Score of 89. It is licensed under Proprietary — Google Cloud managed service and available on the web. 13 of 13 checklist rows are verified against a public source.

Source: https://altcatalog.com/alternatives/apigee/
Category: API gateways

## Overview

- **Who it's for**: Apigee is built for enterprise API teams and platform engineers at organizations that need to design, secure, monetize, and analyze APIs at scale across hybrid, multicloud, or Google Cloud-native environments.
- **What you get**: A fully managed API gateway and lifecycle platform covering API proxy creation, 50+ policies for traffic management, transformation, and security (OAuth2/JWT/API keys, quotas, spike arrest), a developer portal for onboarding API consumers, built-in analytics and near real-time monitoring dashboards, and an Advanced API Security add-on for bot and abuse detection, all accessible via a web UI, REST management API, and CLI tooling.
- **How it works**: Teams build API proxies (REST, gRPC, SOAP, or GraphQL front ends over backend services) using Apigee's policy framework in the Apigee UI or as XML/config bundles managed through source control and CI/CD, then deploy them either as fully managed Apigee X in Google Cloud or via Apigee hybrid, which keeps a Google-hosted management plane but runs the traffic-processing runtime plane on the customer's own Kubernetes cluster; usage is billed pay-as-you-go per API call or through negotiated subscription tiers, with a 60-day free evaluation available.

## Profile

- **License**: Proprietary — Google Cloud managed service (verified 2026-07-17)
- **Pricing model**: Usage-based (verified 2026-07-17)
- **Starts at**: $20 per 1M API calls (verified 2026-07-17)
- **Platforms**: Web
- **Status**: active (verified 2026-07-17)

## Ranked alternatives

| # | App | Alt Score | Licence | Platforms |
|---|-----|-----------|---------|-----------|
| 1 | [Gravitee](https://altcatalog.com/alternatives/gravitee.md) | 100 | Apache-2.0 | Web |
| 2 | [Kong](https://altcatalog.com/alternatives/kong.md) | 100 | Apache-2.0 | Web |
| 3 | [Tyk](https://altcatalog.com/alternatives/tyk.md) | 100 | MPL-2.0 | Web |
| 4 | [WSO2 API Manager](https://altcatalog.com/alternatives/wso2.md) | 100 | Apache-2.0 | Web |
| 5 | [KrakenD](https://altcatalog.com/alternatives/krakend.md) | 86 | Apache-2.0 | Linux, Web |
| 6 | [Traefik Hub](https://altcatalog.com/alternatives/traefik-hub.md) | 86 | Proprietary | Web |
| 7 | [Zuplo](https://altcatalog.com/alternatives/zuplo.md) | 86 | Proprietary — Zuplo gateway platform; Zudoku developer portal component is open source (MIT) | Web |

Alt Score = Verified coverage (90%) + Visibility (10%). See https://altcatalog.com/how-alt-score-works/

## Feature comparison

Legend: Yes / No / Partial / ? (not verified).

| API gateways checklist | Apigee | Gravitee | Kong | Tyk | WSO2 API Manager | KrakenD |
|---|---|---|---|---|---|---|
| Pricing model | Usage-based | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting |
| Starts at | $20 per 1M API calls | $2,500/month | $25/month | Free | Free | Free |
| License | Proprietary — Google Cloud managed service | Apache-2.0 | Apache-2.0 | MPL-2.0 | Apache-2.0 | Apache-2.0 |
| Platforms | Web | Web | Web | Web | Web | Linux, Web |
| Open source | No | Yes | Yes | Yes | Yes | Yes |
| Self-hostable | Partial | Yes | Yes | Yes | Yes | Yes |
| Managed / SaaS option | Yes | Yes | Yes | Yes | Yes | No |
| Rate limiting & throttling | Yes | Yes | Yes | Yes | Yes | Yes |
| Authentication (OAuth/JWT/API keys) | Yes | Yes | Yes | Yes | Yes | Yes |
| Developer portal | Yes | Yes | Yes | Yes | Yes | Partial |
| Plugin / extension ecosystem | Yes | Yes | Yes | Yes | Yes | Yes |
| Kubernetes-native / ingress | Yes | Yes | Yes | Yes | Yes | Partial |
| GraphQL support | Yes | Yes | Yes | Yes | Yes | Yes |
| gRPC support | Yes | Yes | Yes | Yes | Yes | Yes |
| Analytics & monitoring | Yes | Yes | Yes | Yes | Yes | Yes |
| Declarative / GitOps config | Yes | Yes | Yes | Yes | Yes | Yes |
| WAF / security policies | Yes | Yes | Yes | Yes | Yes | Yes |

## Sources

Sources for Apigee. Each alternative is sourced on its own page.

- **License**: Proprietary — Google Cloud managed service — <https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee> (verified 2026-07-17)
  - Note: Apigee is a commercial Google Cloud product sold via pay-as-you-go or subscription pricing; no open-source license is published for the platform itself.
  - Quote: “Apigee is Google Cloud's native API management platform that can be used to build, manage, and secure APIs — for any use case, environment, or scale.”
- **Pricing model**: Usage-based — <https://cloud.google.com/apigee/pricing> (verified 2026-07-17)
  - Note: Apigee offers both metered pay-as-you-go pricing (per API call) and negotiated annual subscription tiers (Standard/Enterprise, contact sales), plus a free 60-day evaluation.
  - Quote: “Pay-as-you-go pricing Unlock Apigee with no upfront commitment and pay only for what you use”
- **Starts at**: $20 per 1M API calls — <https://cloud.google.com/apigee/pricing> (verified 2026-07-17)
  - Note: Cheapest pay-as-you-go entry point (Standard API Proxy tier). A free 60-day sandbox evaluation is also available: "Evaluate Apigee in your own sandbox at no cost for 60 days."
  - Quote: “Costs provided are per 1M API calls. $20 (up to 50M API calls) $16 (from 50M to 500M API calls) $13 (above 500M API calls)”
- **Platforms**: Web — <https://cloud.google.com/apigee/docs/api-platform/develop/policy-attachment-and-enforcement> (verified 2026-07-17)
  - Note: Apigee is managed entirely through a web-based UI (Apigee UI / Cloud console) and REST APIs/CLI; no native desktop or mobile client exists.
  - Quote: “After you attach a policy or make changes to an existing policy, use the Apigee UI or the Apigee API to deploy the changes.”
- **Status**: active — <https://cloud.google.com/apigee/docs/release-notes> (verified 2026-07-17)
  - Note: Release notes show continuous feature, security, and version updates through July 2026 (current date).
  - Quote: “July 15, 2026 Apigee UI Fixed ... July 10, 2026 ... we released an updated version of the Apigee hybrid software, v1.16.7.”
- **Open source**: No — <https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee> (verified 2026-07-17)
  - Note: Apigee is a proprietary Google Cloud managed offering; no source code is published for the platform.
  - Quote: “Apigee is Google Cloud's native API management platform that can be used to build, manage, and secure APIs — for any use case, environment, or scale.”
- **Self-hostable**: Partial — <https://cloud.google.com/apigee/docs/hybrid/v1.10/what-is-hybrid> (verified 2026-07-17)
  - Note: Apigee hybrid lets you run the runtime plane (traffic processing) on your own Kubernetes cluster, but the management plane (UI, analytics, config) remains hosted by Google — so it is partially, not fu
  - Quote: “The hybrid model includes a management plane hosted by Apigee in the Cloud and a runtime plane that you install and manage on one of the supported Kubernetes platforms.”
- **Managed / SaaS option**: Yes — <https://cloud.google.com/apigee/pricing> (verified 2026-07-17)
  - Note: Apigee X is Google's fully managed SaaS API management offering; pay-as-you-go and subscription plans are both fully managed cloud options.
  - Quote: “Evaluate Apigee in your own sandbox at no cost for 60 days”
- **Rate limiting & throttling**: Yes — <https://cloud.google.com/apigee/docs/api-platform/reference/policies/quota-policy> (verified 2026-07-17)
  - Note: Apigee also offers a separate SpikeArrest policy specifically for traffic-burst rate limiting.
  - Quote: “A quota is an allotment of requests that an API proxy will accept over a specified time interval, or until the Quota is explicitly reset using the ResetQuota policy.”
- **Authentication (OAuth/JWT/API keys)**: Yes — <https://cloud.google.com/apigee/docs/api-platform/security/api-keys> (verified 2026-07-17)
  - Note: Apigee also has dedicated OAuthV2 and VerifyJWT policies; see https://cloud.google.com/apigee/docs/api-platform/security/oauth/oauth-introduction ("The OAuth 2.0 authorization framework enables a thir
  - Quote: “An API key (known in Apigee as a consumer key) is a string value passed by a client app”
- **Developer portal**: Yes — <https://cloud.google.com/apigee/docs/api-platform/publish/intro-portals> (verified 2026-07-17)
  - Note: Apigee offers both a simple self-service "integrated portal" and a fully customizable Drupal 10-based portal option.
  - Quote: “Consider building an Apigee integrated portal if you plan to support common use cases for portal development, such as standard registration and app creation flows, and more stylistic than functional c”
- **Plugin / extension ecosystem**: Yes — <https://cloud.google.com/apigee/docs/api-platform/reference/policies/reference-overview-policy> (verified 2026-07-17)
  - Note: Apigee's model is policy-based extensibility (50+ standard policies plus extensible/custom-code policies) rather than a third-party plugin marketplace.
  - Quote: “Extensible policies provide more functionality than standard policies, including for traffic management, mediation, and security. The extensible policies also include policies to implement custom logi”
- **Kubernetes-native / ingress**: Yes — <https://cloud.google.com/apigee/docs/hybrid/v1.10/what-is-hybrid> (verified 2026-07-17)
  - Note: Apigee hybrid runtime deploys as containerized services on GKE or other supported Kubernetes platforms.
  - Quote: “Apigee hybrid consists of a management plane maintained by Google and a runtime plane that you install on a supported Kubernetes platform.”
- **GraphQL support**: Yes — <https://cloud.google.com/apigee/docs/api-platform/develop/graphql> (verified 2026-07-17)
  - Quote: “The GraphQL policy can parse GraphQL request payloads into message flow variables, verify the request against a GraphQL schema, or both.”
- **gRPC support**: Yes — <https://cloud.google.com/apigee> (verified 2026-07-17)
  - Quote: “Apigee supports styles like REST, gRPC, SOAP, and GraphQL, providing flexibility to implement any architecture.”
- **Analytics & monitoring**: Yes — <https://cloud.google.com/apigee> (verified 2026-07-17)
  - Note: Apigee Analytics and API Monitoring provide near real-time dashboards, custom reports, and alerting.
  - Quote: “Built-in and custom API analytics dashboards Use built-in dashboards to investigate spikes, improve performance, and identify improvement opportunities”
- **Declarative / GitOps config**: Yes — <https://cloud.google.com/apigee/docs/hybrid/preview/new-install-user-guide> (verified 2026-07-17)
  - Note: Apigee also documents managing API proxy configs (XML bundles) via source control and CI/CD pipelines outside of hybrid; see https://cloud.google.com/apigee/docs/api-platform/antipatterns/no-source-co
  - Quote: “The new method of installing Apigee hybrid can be integrated with existing Kubernetes CI/CD tools like Argo, Flux or Anthos Config Management which do not use an overrides.yaml configuration file.”
- **WAF / security policies**: Yes — <https://cloud.google.com/apigee/pricing> (verified 2026-07-17)
  - Note: Apigee integrates with Google Cloud Armor (WAAP) for edge WAF protection; see https://cloud.google.com/apigee ("Google Cloud WAAP combines three solutions (Apigee, Cloud Armor, and reCAPTCHA Enterpris
  - Quote: “Advanced API Security enables you to protect your APIs from misconfigurations, malicious bot attacks, and critical abuses.”

---
Ranked by verified data, never by who paid. https://altcatalog.com/trust/