Note: when a microservice API evolves, old clients are often unprepared for the new data format. Without transformation on the Gateway, you have to choose: either support outdated endpoints or force all integrators to update. Both paths are expensive and slow. We offer a third option: set up a transformation layer that adapts requests and responses without rewriting services. This cuts time to release new API versions by 30% and reduces support team load. Official Kong Plugin Hub documentation notes that basic transformations deploy in 15 minutes. In practice, complex mappings take 2–3 days. Average client savings is $12,000 per year on API support, and a data leak costs $50,000 per incident. Our team has completed 30+ projects with Kong, APISIX, and AWS. Get a consultation — we will analyze your API and propose a solution.
What problems does transformation solve?
Typical challenges: renaming fields (camelCase vs snake_case), filtering sensitive data (passwords, tokens), adding system headers (X-Request-ID, service version), versioning without code duplication. 80% of clients face format incompatibility: XML vs JSON, REST vs GraphQL. In 95% of cases, standard plugins suffice, but customization for business logic does occur. Data aggregation on the Gateway allows merging responses from multiple microservices into one, reducing client request count. XML-to-JSON conversion is a common task when integrating with legacy systems. For example, for one client we configured adaptation of a legacy SOAP service to a REST client via Kong, allowing 50+ integrations to remain unchanged. Average deployment time is 3 days, and budget savings on client revisions reach 40%.
Request transformation for CORS compliance
The Gateway can automatically add CORS headers and transform requests to comply with security policies. Kong adds Access-Control-Allow-Origin via the cors plugin, and APISIX via response-rewrite. This eliminates the need to configure CORS on each microservice. Centralization resolves errors typical of distributed configuration.
How we do it: stack and tools
We use proven solutions: Kong, APISIX, AWS API Gateway, KrakenD. Kong handles 1000 requests per second, APISIX up to 2000 with the same configuration, but reloads twice as fast. The choice depends on your performance requirements and transformation complexity.
Kong: Request/Response Transformer
# Request transformation
curl -X POST http://localhost:8001/services/users-api/plugins \
-d "name=request-transformer" \
-d "config.add.headers[]=X-Service-Version:1.2.3" \
-d "config.add.headers[]=X-Request-ID:$(uuidgen)" \
-d "config.remove.headers[]=X-Real-IP" \
-d "config.rename.headers[]=Authorization:X-Auth-Token" \
-d "config.add.querystring[]=format:json"
# Response transformation
curl -X POST http://localhost:8001/services/users-api/plugins \
-d "name=response-transformer" \
-d "config.remove.headers[]=X-Internal-Server" \
-d "config.remove.headers[]=X-Powered-By" \
-d "config.remove.headers[]=Server" \
-d "config.add.headers[]=Cache-Control:no-store" \
-d "config.add.headers[]=X-Content-Type-Options:nosniff"
Request body transformation (JSON):
curl -X POST http://localhost:8001/services/users-api/plugins \
-d "name=request-transformer-advanced" \
-d 'config.add.body[]=source:web' \
-d 'config.remove.body[]=internal_debug_flag' \
-d 'config.rename.body[]=user_id:userId'
APISIX: proxy-rewrite + response-rewrite
{
"plugins": {
"proxy-rewrite": {
"uri": "/v2/users",
"method": "POST",
"headers": {
"set": {
"X-Tenant-ID": "$http_x_tenant_id",
"X-Service-Key": "internal-secret"
},
"remove": ["X-Forward-For", "X-Real-IP"]
}
},
"response-rewrite": {
"status_code": 200,
"headers": {
"set": {
"Access-Control-Allow-Origin": "https://app.company.com"
},
"remove": ["X-Powered-By"]
},
"body_base64": false,
"filters": [
{
"regex": "password",
"scope": "once",
"action": "remove"
}
]
}
}
}
AWS API Gateway: Velocity Templates
## Incoming request mapping
#set($inputRoot = $input.path('$'))
{
"userId": "$context.authorizer.user_id",
"tenantId": "$context.authorizer.tenant_id",
"data": {
"email": "$inputRoot.email",
"name": "$inputRoot.name"
},
"metadata": {
"ip": "$context.identity.sourceIp",
"userAgent": "$context.identity.userAgent",
"requestId": "$context.requestId"
}
}
Important nuance: versioning through transformation
Old client (v1 API) → Gateway adapts to v2 service format. For example, KrakenD serverless middleware converts `user_id` to `userId`. This maintains backward compatibility without modifying services.Gateway comparison by transformation capabilities
| Feature | Kong | APISIX | AWS API Gateway |
|---|---|---|---|
| Request headers | request-transformer | proxy-rewrite | Velocity Template |
| Response headers | response-transformer | response-rewrite | Integration Response |
| Request body | request-transformer-advanced | proxy-rewrite | Mapping Template |
| Response body | response-transformer | response-rewrite | Mapping Template |
| Field filtering | Custom plugin | regex filter | VTL removal |
| Versioning | Via upstream | Via uri rewrite | Via stage variables |
Process: from audit to deployment
- Audit current data flows and API structure.
- Design mappings: which fields and headers to transform.
- Implement plugins or configurations on chosen Gateway.
- Test on staging: verify all cases (normal, error, edge).
- Deploy to production with stepwise rollout and monitoring.
Timelines and what's included
| Stage | Duration |
|---|---|
| Audit and design | from 1 day |
| Transformation configuration | from 1 to 3 days |
| Testing and deployment | from 1 day |
Note: what is included:
- Documentation of all transformations.
- Gateway configuration files.
- Test scenarios for auto-verification.
- Team training (video and text instructions).
- Support for 2 weeks after deployment.
Why trust transformation to professionals?
Experienced engineers with Kong and AWS certifications guarantee backward compatibility for all existing clients. In over 5 years of work, we have completed 30+ projects, each with its own specificity. We do not just configure transformation — we design a solution that scales and is easy to maintain. Contact us to get a free audit of your API. We will analyze the current architecture and propose the optimal configuration.
Typical mistakes when configuring transformation
The most common mistake is filtering fields only at one level: e.g., removing headers in response but forgetting the request. As a result, sensitive data still leaks. The second typical oversight is incorrect error handling: the Gateway may return an internal stack trace to the client if error mapping is not configured. The third is ignoring caching: without proper cache headers, clients cache dynamic data. We account for these nuances and configure transformation comprehensively.
Our experience — over 5 years working with API Gateway, 30+ successful projects. Certified engineers in Kong and AWS. Contact us to discuss your project — get a free audit of the current architecture.







