API Gateway
Route, secure and rate-limit traffic to your servers, apps and databases at the edge — with custom domains, automatic TLS and a built-in WAF — without running your own reverse proxy.
Creating a gateway
- Open API Gateway → Create.
- Choose a plan — plans are sized by throughput (max requests/sec) rather than raw compute.
- Pick shared (a slot on the platform's multi-tenant edge, fastest to provision) or dedicated (your own gateway instance with its own public IPv4/IPv6, for workloads that need isolation or a static IP).
- Optionally attach the gateway to a private network so it can reach backend resources (servers, databases, apps) over your tenant overlay instead of the public internet.
Routes
Add routes from the gateway's Routes tab:
- Domain — a custom domain (optional; a gateway also serves on its raw IP) or subdomain. Verification is optional — an unverified domain still routes, with a warning.
- Path — the URL path to match.
- Upstream — pick a server, app or database from a resource picker, or enter a raw host:port. Routing to a private upstream requires the gateway to be attached to that resource's network.
TLS certificates for verified custom domains are issued and renewed automatically.
WAF and rate limiting
Every route can be configured with:
- Rate limiting — cap requests per second per client.
- WAF rules — block common attack patterns (SQL injection, path traversal, scanner signatures) before they reach your backend.
- Custom headers, timeouts and caching, configured per route.
Managing in place
Gateway configuration changes are applied live from the console — there's no separate admin subdomain or SSH access needed. A YAML editor is available for advanced configuration alongside the guided UI.