For an open source platform for API management, the first results are tyktechnologies/tyk (Tyk is a full-featured API management platform with a built-in API gateway, authentication, rate limiting, analytics, and a plugin architecture for custom logic, making it a comprehensive self-hostable solution that matches all the key requirements), kong/kong and wso2/product-apim (WSO2 API Manager is a full open-source platform covering API gateway, authentication, rate limiting, analytics, and a developer portal, exactly matching the lifecycle management and feature set described in your search). gravitee-io/gravitee-api-management and mashape/kong round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
We curate open-source GitHub repositories matching “open-source API management and lifecycle platform like Kong or Tyk”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
Tyk is an open-source API gateway written in Go that routes, secures, and monitors network traffic across REST, GraphQL, TCP, and gRPC protocols. It functions as a multi-protocol proxy designed to deliver requests to backend services while managing the end-to-end API lifecycle. The system distinguishes itself through a plugin-based architecture that allows for the injection of custom logic into the request and response middleware chain. It also features native Kubernetes integration, operating as an ingress controller that uses operators and custom resource definitions to deploy security poli
Tyk is a full-featured API management platform with a built-in API gateway, authentication, rate limiting, analytics, and a plugin architecture for custom logic, making it a comprehensive self-hostable solution that matches all the key requirements.
Kong is a high-performance API gateway and service connectivity platform designed to manage, secure, and monitor traffic across distributed microservices and hybrid cloud environments. It functions as a centralized control plane for service governance, providing essential traffic routing, load balancing, and request transformation capabilities to ensure consistent policy enforcement across all service endpoints. The platform distinguishes itself through a modular plugin architecture and a declarative configuration engine that allows infrastructure behavior to be defined via version-controlled
Kong is exactly the high-performance, open-source API gateway and management platform you described, with built-in traffic routing, authentication, rate limiting, analytics, and a powerful plugin architecture — all deployable on your own infrastructure, just like the Kong and Tyk examples you referenced.
WSO2 API Manager is a complete platform for building, integrating, and exposing your digital services as managed APIs in the cloud, on-premise, and hybrid architectures to drive your digital transformation strategy.
WSO2 API Manager is a full open-source platform covering API gateway, authentication, rate limiting, analytics, and a developer portal, exactly matching the lifecycle management and feature set described in your search.
Gravitee.io - OpenSource API Management
Gravitee is an open-source API management platform that provides gateway, analytics, developer portal, and security features out of the box, directly matching the full lifecycle management this visitor seeks.
Kong is the exact open-source API management platform you described—it provides an API gateway, authentication, rate limiting, analytics, a developer portal, and a plugin architecture, making it the flagship tool for full API lifecycle management.
This project is a high-performance, distributed API gateway designed to manage, secure, and observe traffic for microservices, serverless functions, and artificial intelligence model providers. It functions as a dynamic service proxy and cloud-native ingress controller, centralizing policy enforcement and traffic routing through a unified configuration interface that synchronizes state across multiple nodes in real time. The platform distinguishes itself through a highly extensible architecture that utilizes a high-performance scripting engine to execute modular logic directly within the requ
Apache APISIX is a high-performance, open-source API gateway and management platform with rich plugin support for authentication, rate limiting, and monitoring, though its built-in developer portal is less prominent than those of Kong or Tyk—still a strong fit for your core requirements.
Ocelot is a .NET API gateway that functions as an HTTP reverse proxy to route, balance, and secure traffic between clients and backend services. It serves as a centralized manager for incoming requests, providing a single entry point for traffic orchestration. The project differentiates itself through dynamic request orchestration, allowing it to aggregate multiple backend service responses into a single result to minimize client network round trips. It also supports dynamic gateway configuration, enabling updates to system behavior and operational parameters without requiring a service resta
Ocelot is a .NET API gateway for routing and securing traffic, but it lacks the integrated analytics, developer portal, and full plugin ecosystem that a complete API management platform (like Kong or Tyk) provides.
Sa-Token is a Java-based authentication and authorization framework designed to manage user sessions, permissions, and identity verification within web applications and microservice architectures. It provides a centralized security layer that enforces access control policies and identity validation across distributed service environments and API gateways. The framework distinguishes itself through its support for cross-domain single sign-on and its ability to function as an OAuth2 identity provider. It manages user session lifecycles by applying configurable rules for single or multi-login re
Sa-Token is a Java authentication and authorization framework that handles session management and access control for APIs, but it is not an API management platform—it lacks API gateway proxying, analytics, rate limiting, and a developer portal, so it covers only a narrow security piece of the full lifecycle you need.
Pig is a microservice-based RBAC permission management platform built on Spring Cloud and Spring Boot, with OAuth2 authentication and authorization at its core. It provides a dedicated authorization server that issues access and refresh tokens using authorization code, password, and refresh token grant types, while embedding role and permission checks into each microservice to secure API endpoints. The platform distinguishes itself through a comprehensive set of integrated capabilities, including automatic CRUD code generation from database schemas that produces controller, service, mapper, a
Pig is an RBAC permission management platform focused on authentication and authorization for microservices, but it does not include the API gateway, rate limiting, analytics, or developer portal that define a full API management platform like Kong or Tyk.
Unkey is an API key management platform and gateway control plane designed for issuing, verifying, and revoking secure keys with global distribution. It provides the infrastructure necessary to authenticate requests and authorize access to protected resources with low latency. The platform distinguishes itself through edge-based request authentication and distributed rate limiting, which allow for the verification of keys and enforcement of request quotas at the network edge. It also features a usage-based billing engine and a self-service developer portal, enabling the tracking of metered AP
Unkey is an API key management and gateway control plane with authentication, rate limiting, and a developer portal, but it lacks the full API proxy/routing, analytics, and plugin architecture of a comprehensive API management platform like Kong or Tyk.
Stack Auth is an open-source authentication and authorization platform that provides pre-built UI components, OAuth integration, team management, and session handling for web applications. It offers a complete authentication lifecycle covering sign-in, sign-up, session management, password recovery, and multi-factor security, with support for passkey authentication and OAuth providers including Google, GitHub, and Apple. The platform includes a team-based permission system with role-based access control, allowing users to be organized into teams with granular permissions for membership manage
Stack Auth is a focused authentication and authorization platform, not a full API management platform — it provides identity and access control but lacks the API gateway, rate limiting, analytics, and developer portal that this search needs.
LocalStack is an infrastructure development environment that provides a local simulation of cloud services. By leveraging container-orchestrated service lifecycles, it allows developers to build, test, and debug cloud-native applications on their local machines without requiring remote connectivity or incurring cloud provider costs. The platform distinguishes itself through sophisticated traffic redirection and request routing, which intercept cloud service calls at the network layer and redirect them to local handlers. This enables seamless integration with existing development workflows, al
LocalStack simulates cloud services locally for development and testing, not a dedicated API management platform with gateway, analytics, and developer portal features like Kong or Tyk.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| tyktechnologies/tyk | 10.7K | Go | NOASSERTION | |
| kong/kong | 43.7K | Lua | Apache-2.0 | |
| wso2/product-apim |
| 989 |
| Java |
| Apache-2.0 |
| gravitee-io/gravitee-api-management | 423 | Java | Apache-2.0 |
| mashape/kong | 0 | — | — | — |
| apache/apisix | 16.8K | Lua | Apache-2.0 |
| threemammals/ocelot | 8.7K | C# | MIT |
| dromara/sa-token | 18.6K | Java | apache-2.0 |
| pig-mesh/pig | 6.6K | Java | Apache-2.0 |
| unkeyed/unkey | 5.4K | TypeScript | NOASSERTION |