Implementing an API Gateway Pattern for Microservices
Imagine: you have 15 microservices, each with its own API. The frontend makes dozens of requests to different endpoints, and authentication is duplicated in every service. One bad refactor — and clients get 500 errors. An API Gateway solves this pain: a single entry point with centralized routing, authentication, and rate limiting. Instead of calling multiple services directly, the client talks to one gateway that routes requests, aggregates data, and enforces security policies.
This pattern simplifies security, reduces load on services, and makes the system scalable. Our engineers with 7+ years of experience in microservices implement API Gateway turnkey — from tool selection to monitoring setup. Contact us for a consultation on your project.
Technical Problems with Microservice Architecture
Note: when a client requests data from different services, multiple calls arise. For example, a profile page requires user data, their orders, and notifications. Without a gateway, the client makes 3 requests. With an API Gateway — one. The gateway collects data in parallel via Promise.allSettled and returns a single response. This reduces latency by 40% and simplifies client logic.
Another problem is duplicated authentication. Each microservice must verify JWTs, increasing latency and error risk. An API Gateway checks the token once and passes user data in headers. This reduces load on services and centralizes security.
How an API Gateway Solves the N+1 Request Problem
Request Aggregation (BFF Pattern in the Gateway)
A mobile client gets data from multiple services in one request. The gateway calls them in parallel and assembles the response into a single JSON. Example implementation on Express:
// Gateway aggregates data from multiple services
app.get('/api/dashboard/:userId', jwtMiddleware, async (req, res) => {
const { userId } = req.params;
const [user, orders, notifications] = await Promise.allSettled([
userService.get(`/users/${userId}`),
orderService.get(`/orders?customerId=${userId}&limit=5`),
notificationService.get(`/notifications/${userId}/unread`)
]);
res.json({
user: user.status === 'fulfilled' ? user.value.data : null,
recentOrders: orders.status === 'fulfilled' ? orders.value.data : [],
unreadCount: notifications.status === 'fulfilled'
? notifications.value.data.count : 0
});
});
What Metrics Does an API Gateway Improve?
TTFB decreases due to aggregation, and the number of network requests drops by 3-5 times. Core Web Vitals (LCP, CLS) improve because the client gets all data in one response. The gateway also offloads microservices — they only process validated requests.
Case in point: On a project with 15 microservices, we reduced frontend requests from 12 to 2, cutting TTFB by 60%. The client’s page load time dropped from 8s to 3.2s.
How We Implement an API Gateway
Functions We Configure
- Routing —
/api/orders→ Order Service,/api/users→ User Service - Authentication and Authorization — JWT/OAuth2 checked once at the gateway
- Rate Limiting — abuse protection
- SSL Termination — TLS terminates at the gateway, microservices communicate via HTTP inside the cluster
- Request/Response Transformation — format changes, header additions
- Request Aggregation — one client request → multiple service requests
- Circuit Breaker — protection against cascading failures
- Logging and Tracing — single point for access logs
Tool Comparison
| Tool | Type | Key Features |
|---|---|---|
| Kong | Self-hosted / Cloud | Lua/Go plugins, Kubernetes Ingress |
| Traefik | Self-hosted | Auto-discovery in Docker/K8s |
| AWS API Gateway | Managed | Lambda integration, IAM |
| NGINX + Lua | Self-hosted | Maximum control |
| Envoy | Proxy | gRPC, complex scenarios |
| Express Gateway | Node.js | Simple cases |
Kong is best for complex scenarios with custom plugins, Traefik excels in Kubernetes integration. We choose the tool based on your stack. Our experience includes projects with Kong (over 50 services) and Traefik (K8s clusters up to 30 nodes).
Kong Configuration
Kong is the most popular self-hosted gateway:
# kong.yaml (declarative configuration)
_format_version: "3.0"
services:
- name: order-service
url: http://order-service:3000
routes:
- name: orders-route
paths: ["/api/orders"]
methods: ["GET", "POST", "PUT", "DELETE"]
- name: user-service
url: http://user-service:3001
routes:
- name: users-route
paths: ["/api/users"]
methods: ["GET", "PUT"]
plugins:
- name: jwt
config:
claims_to_verify: ["exp"]
- name: rate-limiting
config:
minute: 100
hour: 5000
policy: local
- name: request-transformer
config:
add:
headers: ["X-Service-Version:1.0"]
Authentication at the Gateway Level
JWT is verified in the gateway, microservices receive already-validated user headers:
// Custom middleware on Express Gateway
async function jwtMiddleware(req, res, next) {
const token = req.headers.authorization?.replace('Bearer ', '');
if (!token) return res.status(401).json({ error: 'No token' });
try {
const payload = jwt.verify(token, process.env.JWT_SECRET);
// Pass user data in headers
req.headers['X-User-Id'] = payload.sub;
req.headers['X-User-Role'] = payload.role;
req.headers['X-User-Email'] = payload.email;
next();
} catch {
res.status(401).json({ error: 'Invalid token' });
}
}
Example Traefik Configuration in Kubernetes
# Traefik IngressRoute
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
name: api-gateway
spec:
entryPoints:
- websecure
routes:
- match: PathPrefix(`/api/orders`)
kind: Rule
services:
- name: order-service
port: 3000
middlewares:
- name: jwt-auth
- name: rate-limit
- match: PathPrefix(`/api/users`)
kind: Rule
services:
- name: user-service
port: 3001
middlewares:
- name: jwt-auth
---
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: rate-limit
spec:
rateLimit:
average: 100
burst: 50
period: 1m
Implementation Process
| Stage | Duration | Outcome |
|---|---|---|
| Architecture audit | 1-2 days | Route map, security requirements |
| Basic gateway setup | 3-5 days | Working routing, JWT authentication |
| Advanced configuration | 2-3 days | Rate limiting, circuit breaker, logging |
| Custom aggregation | 1-2 weeks | BFF endpoints, query optimization |
Pricing is calculated individually after auditing your architecture. Request a consultation — we will assess your project free of charge.
What’s Included in the Implementation
- Route and security policy design
- Configuration of Kong, Traefik, or a cloud gateway for your infrastructure
- Integration with JWT/OAuth2, LDAP, or another provider
- Configuration of rate limiting, circuit breaker, and monitoring
- API documentation and team instructions
- Access transfer and training for your engineers
We also provide post-implementation support: version upgrades, performance optimization. Our engineers are certified in Kubernetes and Kong, with 7+ years of experience and 50+ successful projects. We guarantee stable gateway operation under load. Get a consultation for your project.
Additional Resources
Learn more about the pattern on Wikipedia. Official Kong documentation is available at konghq.com.







