awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Open-Source API Management Platforms

Ranking updated Jun 30, 2026

For an open source platform for API management, the first results are tyktechnologies/tyk (Tyk is a full-featured API management platform with a built-in API gateway, authentication, rate limiting, analytics, and a plugin architecture for custom logic, making it a comprehensive self-hostable solution that matches all the key requirements), kong/kong and wso2/product-apim (WSO2 API Manager is a full open-source platform covering API gateway, authentication, rate limiting, analytics, and a developer portal, exactly matching the lifecycle management and feature set described in your search). gravitee-io/gravitee-api-management and mashape/kong round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

We curate open-source GitHub repositories matching “open-source API management and lifecycle platform like Kong or Tyk”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.

Open-Source API Management Platforms

Find the best repos with AI.We'll search the best matching repositories with AI.
  • tyktechnologies/tykTykTechnologies avatar

    TykTechnologies/tyk

    10,744View on GitHub↗

    Tyk is an open-source API gateway written in Go that routes, secures, and monitors network traffic across REST, GraphQL, TCP, and gRPC protocols. It functions as a multi-protocol proxy designed to deliver requests to backend services while managing the end-to-end API lifecycle. The system distinguishes itself through a plugin-based architecture that allows for the injection of custom logic into the request and response middleware chain. It also features native Kubernetes integration, operating as an ingress controller that uses operators and custom resource definitions to deploy security poli

    Tyk is a full-featured API management platform with a built-in API gateway, authentication, rate limiting, analytics, and a plugin architecture for custom logic, making it a comprehensive self-hostable solution that matches all the key requirements.

    GoAPI GatewaysAPI Gateways
    View on GitHub↗10,744
  • kong/kongKong avatar

    Kong/kong

    43,653View on GitHub↗

    Kong is a high-performance API gateway and service connectivity platform designed to manage, secure, and monitor traffic across distributed microservices and hybrid cloud environments. It functions as a centralized control plane for service governance, providing essential traffic routing, load balancing, and request transformation capabilities to ensure consistent policy enforcement across all service endpoints. The platform distinguishes itself through a modular plugin architecture and a declarative configuration engine that allows infrastructure behavior to be defined via version-controlled

    Kong is exactly the high-performance, open-source API gateway and management platform you described, with built-in traffic routing, authentication, rate limiting, analytics, and a powerful plugin architecture — all deployable on your own infrastructure, just like the Kong and Tyk examples you referenced.

    LuaAPI GatewaysAPI Performance Monitoring
    View on GitHub↗43,653
  • wso2/product-apimwso2 avatar

    wso2/product-apim

    989View on GitHub↗

    WSO2 API Manager is a complete platform for building, integrating, and exposing your digital services as managed APIs in the cloud, on-premise, and hybrid architectures to drive your digital transformation strategy.

    WSO2 API Manager is a full open-source platform covering API gateway, authentication, rate limiting, analytics, and a developer portal, exactly matching the lifecycle management and feature set described in your search.

    JavaAPI GatewaysAPI Management
    View on GitHub↗989
  • gravitee-io/gravitee-api-managementgravitee-io avatar

    gravitee-io/gravitee-api-management

    423View on GitHub↗

    Gravitee.io - OpenSource API Management

    Gravitee is an open-source API management platform that provides gateway, analytics, developer portal, and security features out of the box, directly matching the full lifecycle management this visitor seeks.

    JavaAPI Management
    View on GitHub↗423
  • mashape/kongM

    Mashape/kong

    0View on GitHub↗

    Kong is the exact open-source API management platform you described—it provides an API gateway, authentication, rate limiting, analytics, a developer portal, and a plugin architecture, making it the flagship tool for full API lifecycle management.

    Web Frameworks
    View on GitHub↗0
  • apache/apisixapache avatar

    apache/apisix

    16,767View on GitHub↗

    This project is a high-performance, distributed API gateway designed to manage, secure, and observe traffic for microservices, serverless functions, and artificial intelligence model providers. It functions as a dynamic service proxy and cloud-native ingress controller, centralizing policy enforcement and traffic routing through a unified configuration interface that synchronizes state across multiple nodes in real time. The platform distinguishes itself through a highly extensible architecture that utilizes a high-performance scripting engine to execute modular logic directly within the requ

    Apache APISIX is a high-performance, open-source API gateway and management platform with rich plugin support for authentication, rate limiting, and monitoring, though its built-in developer portal is less prominent than those of Kong or Tyk—still a strong fit for your core requirements.

    LuaAPI Gateways
    View on GitHub↗16,767
  • threemammals/ocelotThreeMammals avatar

    ThreeMammals/Ocelot

    8,710View on GitHub↗

    Ocelot is a .NET API gateway that functions as an HTTP reverse proxy to route, balance, and secure traffic between clients and backend services. It serves as a centralized manager for incoming requests, providing a single entry point for traffic orchestration. The project differentiates itself through dynamic request orchestration, allowing it to aggregate multiple backend service responses into a single result to minimize client network round trips. It also supports dynamic gateway configuration, enabling updates to system behavior and operational parameters without requiring a service resta

    Ocelot is a .NET API gateway for routing and securing traffic, but it lacks the integrated analytics, developer portal, and full plugin ecosystem that a complete API management platform (like Kong or Tyk) provides.

    C#API GatewaysAPI Rate Limiting
    View on GitHub↗8,710
  • dromara/sa-tokendromara avatar

    dromara/Sa-Token

    18,626View on GitHub↗

    Sa-Token is a Java-based authentication and authorization framework designed to manage user sessions, permissions, and identity verification within web applications and microservice architectures. It provides a centralized security layer that enforces access control policies and identity validation across distributed service environments and API gateways. The framework distinguishes itself through its support for cross-domain single sign-on and its ability to function as an OAuth2 identity provider. It manages user session lifecycles by applying configurable rules for single or multi-login re

    Sa-Token is a Java authentication and authorization framework that handles session management and access control for APIs, but it is not an API management platform—it lacks API gateway proxying, analytics, rate limiting, and a developer portal, so it covers only a narrow security piece of the full lifecycle you need.

    JavaOAuth2 ProvidersRole-Based Access Control
    View on GitHub↗18,626
  • pig-mesh/pigpig-mesh avatar

    pig-mesh/pig

    6,644View on GitHub↗

    Pig is a microservice-based RBAC permission management platform built on Spring Cloud and Spring Boot, with OAuth2 authentication and authorization at its core. It provides a dedicated authorization server that issues access and refresh tokens using authorization code, password, and refresh token grant types, while embedding role and permission checks into each microservice to secure API endpoints. The platform distinguishes itself through a comprehensive set of integrated capabilities, including automatic CRUD code generation from database schemas that produces controller, service, mapper, a

    Pig is an RBAC permission management platform focused on authentication and authorization for microservices, but it does not include the API gateway, rate limiting, analytics, or developer portal that define a full API management platform like Kong or Tyk.

    JavaOAuth2 ProvidersRole-Based Access Control
    View on GitHub↗6,644
  • unkeyed/unkeyunkeyed avatar

    unkeyed/unkey

    5,356View on GitHub↗

    Unkey is an API key management platform and gateway control plane designed for issuing, verifying, and revoking secure keys with global distribution. It provides the infrastructure necessary to authenticate requests and authorize access to protected resources with low latency. The platform distinguishes itself through edge-based request authentication and distributed rate limiting, which allow for the verification of keys and enforcement of request quotas at the network edge. It also features a usage-based billing engine and a self-service developer portal, enabling the tracking of metered AP

    Unkey is an API key management and gateway control plane with authentication, rate limiting, and a developer portal, but it lacks the full API proxy/routing, analytics, and plugin architecture of a comprehensive API management platform like Kong or Tyk.

    TypeScriptDeveloper PortalsRole-Based Access Control
    View on GitHub↗5,356
  • stack-auth/stack-authstack-auth avatar

    stack-auth/stack-auth

    6,699View on GitHub↗

    Stack Auth is an open-source authentication and authorization platform that provides pre-built UI components, OAuth integration, team management, and session handling for web applications. It offers a complete authentication lifecycle covering sign-in, sign-up, session management, password recovery, and multi-factor security, with support for passkey authentication and OAuth providers including Google, GitHub, and Apple. The platform includes a team-based permission system with role-based access control, allowing users to be organized into teams with granular permissions for membership manage

    Stack Auth is a focused authentication and authorization platform, not a full API management platform — it provides identity and access control but lacks the API gateway, rate limiting, analytics, and developer portal that this search needs.

    TypeScriptAPI Key AuthenticationAPI Key AuthenticationRole-Based Access Control
    View on GitHub↗6,699
  • localstack/localstacklocalstack avatar

    localstack/localstack

    64,423View on GitHub↗

    LocalStack is an infrastructure development environment that provides a local simulation of cloud services. By leveraging container-orchestrated service lifecycles, it allows developers to build, test, and debug cloud-native applications on their local machines without requiring remote connectivity or incurring cloud provider costs. The platform distinguishes itself through sophisticated traffic redirection and request routing, which intercept cloud service calls at the network layer and redirect them to local handlers. This enables seamless integration with existing development workflows, al

    LocalStack simulates cloud services locally for development and testing, not a dedicated API management platform with gateway, analytics, and developer portal features like Kong or Tyk.

    PythonAPI Gateways
    View on GitHub↗64,423
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
tyktechnologies/tyk10.7KGoNOASSERTIONJun 17, 2026
kong/kong43.7KLuaApache-2.0Jun 17, 2026
wso2/product-apim
989
Java
Apache-2.0
Jun 26, 2026
gravitee-io/gravitee-api-management423JavaApache-2.0Jun 26, 2026
mashape/kong0———
apache/apisix16.8KLuaApache-2.0Jun 23, 2026
threemammals/ocelot8.7KC#MITJun 22, 2026
dromara/sa-token18.6KJavaapache-2.0Feb 20, 2026
pig-mesh/pig6.6KJavaApache-2.0Jun 22, 2026
unkeyed/unkey5.4KTypeScriptNOASSERTIONJun 23, 2026

Related searches

  • a web framework for building APIs in Kotlin
  • a native security platform for APIs
  • an API docs generator
  • an api gateway for microservice traffic routing
  • an open source tool for API testing
  • an open source platform for managing IoT
  • a load testing tool for simulating traffic on APIs
  • an open source platform for frontend deployment