Implementing an API Gateway Pattern for Microservices

As microservices grow, each service requires its own authentication and routing, complicating client logic and increasing error risks. We implement the API Gateway Pattern, creating a single entry point with centralized routing, JWT authentication, and rate limiting. Our team handles the entire cycle—from tool selection to monitoring setup—delivering a reliable, scalable turnkey solution.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • Development of a web application for FEEDME
    Development of a web application for FEEDME
    1342
  • Development of an online store for the company FURNORO
    Development of an online store for the company FURNORO
    1304
  • Development of a web application for Enviok
    Development of a web application for Enviok
    1047
  • CRM development for Chasseurs
    CRM development for Chasseurs
    1094
  • Website development for SBH Partners
    Website development for SBH Partners
    1169
  • Website development for Red Pear
    Website development for Red Pear
    593

Implementing an API Gateway Pattern for Microservices

Imagine: you have 15 microservices, each with its own API. The frontend makes dozens of requests to different endpoints, and authentication is duplicated in every service. One bad refactor — and clients get 500 errors. An API Gateway solves this pain: a single entry point with centralized routing, authentication, and rate limiting. Instead of calling multiple services directly, the client talks to one gateway that routes requests, aggregates data, and enforces security policies.

This pattern simplifies security, reduces load on services, and makes the system scalable. Our engineers with 7+ years of experience in microservices implement API Gateway turnkey — from tool selection to monitoring setup. Contact us for a consultation on your project.

Technical Problems with Microservice Architecture

Note: when a client requests data from different services, multiple calls arise. For example, a profile page requires user data, their orders, and notifications. Without a gateway, the client makes 3 requests. With an API Gateway — one. The gateway collects data in parallel via Promise.allSettled and returns a single response. This reduces latency by 40% and simplifies client logic.

Another problem is duplicated authentication. Each microservice must verify JWTs, increasing latency and error risk. An API Gateway checks the token once and passes user data in headers. This reduces load on services and centralizes security.

How an API Gateway Solves the N+1 Request Problem

Request Aggregation (BFF Pattern in the Gateway)

A mobile client gets data from multiple services in one request. The gateway calls them in parallel and assembles the response into a single JSON. Example implementation on Express:

// Gateway aggregates data from multiple services
app.get('/api/dashboard/:userId', jwtMiddleware, async (req, res) => {
  const { userId } = req.params;
  const [user, orders, notifications] = await Promise.allSettled([
    userService.get(`/users/${userId}`),
    orderService.get(`/orders?customerId=${userId}&limit=5`),
    notificationService.get(`/notifications/${userId}/unread`)
  ]);
  res.json({
    user: user.status === 'fulfilled' ? user.value.data : null,
    recentOrders: orders.status === 'fulfilled' ? orders.value.data : [],
    unreadCount: notifications.status === 'fulfilled' ? notifications.value.data.count : 0
  });
});

What Metrics Does an API Gateway Improve?

TTFB decreases due to aggregation, and the number of network requests drops by 3-5 times. Core Web Vitals (LCP, CLS) improve because the client gets all data in one response. The gateway also offloads microservices — they only process validated requests.

Case in point: On a project with 15 microservices, we reduced frontend requests from 12 to 2, cutting TTFB by 60%. The client’s page load time dropped from 8s to 3.2s.

How We Implement an API Gateway

Functions We Configure

  • Routing — /api/orders → Order Service, /api/users → User Service
  • Authentication and Authorization — JWT/OAuth2 checked once at the gateway
  • Rate Limiting — abuse protection
  • SSL Termination — TLS terminates at the gateway, microservices communicate via HTTP inside the cluster
  • Request/Response Transformation — format changes, header additions
  • Request Aggregation — one client request → multiple service requests
  • Circuit Breaker — protection against cascading failures
  • Logging and Tracing — single point for access logs

Tool Comparison

Tool Type Key Features
Kong Self-hosted / Cloud Lua/Go plugins, Kubernetes Ingress
Traefik Self-hosted Auto-discovery in Docker/K8s
AWS API Gateway Managed Lambda integration, IAM
NGINX + Lua Self-hosted Maximum control
Envoy Proxy gRPC, complex scenarios
Express Gateway Node.js Simple cases

Kong is best for complex scenarios with custom plugins, Traefik excels in Kubernetes integration. We choose the tool based on your stack. Our experience includes projects with Kong (over 50 services) and Traefik (K8s clusters up to 30 nodes).

Kong Configuration

Kong is the most popular self-hosted gateway:

---
# kong.yaml (declarative configuration)
_format_version: "3.0"
services:
  - name: order-service
    url: http://order-service:3000
    routes:
      - name: orders-route
        paths: ["/api/orders"]
        methods: ["GET", "POST", "PUT", "DELETE"]
  - name: user-service
    url: http://user-service:3001
    routes:
      - name: users-route
        paths: ["/api/users"]
        methods: ["GET", "PUT"]
plugins:
  - name: jwt
    config:
      claims_to_verify: ["exp"]
  - name: rate-limiting
    config:
      minute: 100
      hour: 5000
      policy: local
  - name: request-transformer
    config:
      add:
        headers: ["X-Service-Version:1.0"]
---

Authentication at the Gateway Level

JWT is verified in the gateway, microservices receive already-validated user headers:

// Custom middleware on Express Gateway
async function jwtMiddleware(req, res, next) {
  const token = req.headers.authorization?.replace('Bearer ', '');
  if (!token) return res.status(401).json({ error: 'No token' });
  try {
    const payload = jwt.verify(token, process.env.JWT_SECRET);
    // Pass user data in headers
    req.headers['X-User-Id'] = payload.sub;
    req.headers['X-User-Role'] = payload.role;
    req.headers['X-User-Email'] = payload.email;
    next();
  } catch {
    res.status(401).json({ error: 'Invalid token' });
  }
}
Example Traefik Configuration in Kubernetes
---
# Traefik IngressRoute
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
  name: api-gateway
spec:
  entryPoints:
    - websecure
  routes:
    - match: PathPrefix(`/api/orders`)
      kind: Rule
      services:
        - name: order-service
          port: 3000
      middlewares:
        - name: jwt-auth
        - name: rate-limit
    - match: PathPrefix(`/api/users`)
      kind: Rule
      services:
        - name: user-service
          port: 3001
      middlewares:
        - name: jwt-auth
---
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
  name: rate-limit
spec:
  rateLimit:
    average: 100
    burst: 50
    period: 1m

Implementation Process

Stage Duration Outcome
Architecture audit 1-2 days Route map, security requirements
Basic gateway setup 3-5 days Working routing, JWT authentication
Advanced configuration 2-3 days Rate limiting, circuit breaker, logging
Custom aggregation 1-2 weeks BFF endpoints, query optimization

Pricing is calculated individually after auditing your architecture. Request a consultation — we will assess your project after reviewing the requirements.

What’s Included in the Implementation

  • Route and security policy design
  • Configuration of Kong, Traefik, or a cloud gateway for your infrastructure
  • Integration with JWT/OAuth2, LDAP, or another provider
  • Configuration of rate limiting, circuit breaker, and monitoring
  • API documentation and team instructions
  • Access transfer and training for your engineers

We also provide post-implementation support: version upgrades, performance optimization. Our engineers are certified in Kubernetes and Kong, with 7+ years of experience and 50+ successful projects. We guarantee stable gateway operation under load. Get a consultation for your project.

Additional Resources

Learn more about the pattern on Wikipedia. Official Kong documentation is available at konghq.com.