---
type: "Glossary term"
title: "API gateway"
description: "Runtime enforcement point for authn/z, rate limiting, routing and logging."
tags: [glossary]
generated: { by: human:crpage, at: 2026-07-09T09:44:00Z }
aliases: "api gateway; gateway"
status: stable
---

# Definition
A runtime enforcement point for authentication/authorisation, rate limiting, routing and logging — **not** a semantic layer.

# Used in this bundle
Appears in: [openapi](../standards/openapi.md), [policy-enforcement](../stack/policy-enforcement.md).

# Related terms
[policy as code](policy-as-code.md).
