API Gateway Security, OAuth2, and Threat Protection Policies
Protect enterprise APIs against attacks using API Gateway security policies: Mutual TLS (mTLS), JWT/OAuth2 token validation, rate limiting, and XML/JSON threat filters.
Key Takeaways
- API Gateways sit at the enterprise DMZ perimeter, enforcing authentication, authorization, rate limiting, and threat protection before traffic reaches backend microservices
- Mutual TLS (mTLS / 2-Way SSL) validates cryptographic X.509 client certificates during the TLS handshake
- OAuth2 Token Validation policies verify JSON Web Tokens (JWT) issued by external Identity Providers (Okta, Azure AD, Ping)
- Threat protection policies inspect payload size, JSON depth, XML entity expansion (XML Bombs), and SQL injection patterns
The Diagnostic Context
Exposing backend services directly to external partners or the internet is an extreme security risk. An API Gateway acts as a hardened security shield at the enterprise DMZ perimeter, inspecting, validating, and governing every incoming API transaction.
The Core Technique
API Gateway Multi-Layer Defense
graph TD
Client["External Client / Partner"] --> Gateway["Enterprise API Gateway (DMZ Perimeter)"]
subgraph SecurityPolicies["Active Gateway Policy Pipeline"]
P1["1. Transport Security: Enforce HTTPS & mTLS 2-Way SSL"]
P2["2. Threat Protection: XML Bomb, JSON Depth, SQLi Filters"]
P3["3. Traffic Management: Rate Limiting & Spike Arrest (100 req/sec)"]
P4["4. Identity & Auth: Validate OAuth2 JWT from Okta / Azure AD"]
P5["5. Transformation: Mask Outbound PII Fields (Credit Cards)"]
end
Gateway --> P1 --> P2 --> P3 --> P4 --> P5
P5 --> Backend["Protected Internal Microservice / Integration Server"]
Core Security Policy Categories
-
Identification & Authentication:
- API Key Enforcement: Validates headers for basic application tracking.CODE / PROMPT
x-api-key
- OAuth 2.0 / JWT Validation: Verifies digital signature (RS256), expiration (), issuer (CODE / PROMPT
exp
), and audience (CODE / PROMPTiss
) claims on incoming Bearer tokens against the IdP public JWKS endpoint.CODE / PROMPTaud
- Mutual TLS (mTLS): Enforces client certificate verification against the Gateway truststore during the TLS handshake.
- API Key Enforcement: Validates
-
Threat Protection Policies:
- XML Threat Protection: Restricts DTD processing to prevent Billion Laughs / XML Entity Expansion attacks that exhaust JVM RAM.
- JSON Threat Protection: Limits maximum string length, object depth (e.g., max 10 nested levels), and array sizes to block memory-exhaustion payloads.
- SQL & Regex Injection: Scans query parameters and body payloads for malicious SQL syntax (,CODE / PROMPT
UNION SELECT
).CODE / PROMPT' OR '1'='1
-
Traffic Management (Rate Limiting & Throttling):
- Spike Arrest: Smoothes traffic spikes by limiting requests to micro-windows (e.g., maximum 50 requests per second).
- Tiered Quotas: Grants bronze tier consumers 1,000 calls/day and platinum tier consumers 100,000 calls/day.
Try This Right Now
Configure a rate-limiting policy simulation: Define a rule that allows a maximum of 5 requests per minute per IP address. Test submitting 7 consecutive requests and observe the standard HTTP `429 Too Many Requests` response code returned on the 6th call.
Tip: Knowledge only becomes capability once you run the prompt yourself.