Implementing an API Gateway Pattern for Microservices

Implementing an API Gateway Pattern for Microservices

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1281
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1237
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    977
  • image_crm_chasseurs_493_0.webp
    CRM development for Chasseurs
    1025
  • image_website-sbh_0.webp
    Website development for SBH Partners
    1103
  • image_website-_0.webp
    Website development for Red Pear
    550

Implementing an API Gateway Pattern for Microservices

Imagine: you have 15 microservices, each with its own API. The frontend makes dozens of requests to different endpoints, and authentication is duplicated in every service. One bad refactor — and clients get 500 errors. An API Gateway solves this pain: a single entry point with centralized routing, authentication, and rate limiting. Instead of calling multiple services directly, the client talks to one gateway that routes requests, aggregates data, and enforces security policies.

This pattern simplifies security, reduces load on services, and makes the system scalable. Our engineers with 7+ years of experience in microservices implement API Gateway turnkey — from tool selection to monitoring setup. Contact us for a consultation on your project.

Technical Problems with Microservice Architecture

Note: when a client requests data from different services, multiple calls arise. For example, a profile page requires user data, their orders, and notifications. Without a gateway, the client makes 3 requests. With an API Gateway — one. The gateway collects data in parallel via Promise.allSettled and returns a single response. This reduces latency by 40% and simplifies client logic.

Another problem is duplicated authentication. Each microservice must verify JWTs, increasing latency and error risk. An API Gateway checks the token once and passes user data in headers. This reduces load on services and centralizes security.

How an API Gateway Solves the N+1 Request Problem

Request Aggregation (BFF Pattern in the Gateway)

A mobile client gets data from multiple services in one request. The gateway calls them in parallel and assembles the response into a single JSON. Example implementation on Express:

// Gateway aggregates data from multiple services app.get('/api/dashboard/:userId', jwtMiddleware, async (req, res) => { const { userId } = req.params; const [user, orders, notifications] = await Promise.allSettled([ userService.get(`/users/${userId}`), orderService.get(`/orders?customerId=${userId}&limit=5`), notificationService.get(`/notifications/${userId}/unread`) ]); res.json({ user: user.status === 'fulfilled' ? user.value.data : null, recentOrders: orders.status === 'fulfilled' ? orders.value.data : [], unreadCount: notifications.status === 'fulfilled' ? notifications.value.data.count : 0 }); }); 

What Metrics Does an API Gateway Improve?

TTFB decreases due to aggregation, and the number of network requests drops by 3-5 times. Core Web Vitals (LCP, CLS) improve because the client gets all data in one response. The gateway also offloads microservices — they only process validated requests.

Case in point: On a project with 15 microservices, we reduced frontend requests from 12 to 2, cutting TTFB by 60%. The client’s page load time dropped from 8s to 3.2s.

How We Implement an API Gateway

Functions We Configure

  • Routing — /api/orders → Order Service, /api/users → User Service
  • Authentication and Authorization — JWT/OAuth2 checked once at the gateway
  • Rate Limiting — abuse protection
  • SSL Termination — TLS terminates at the gateway, microservices communicate via HTTP inside the cluster
  • Request/Response Transformation — format changes, header additions
  • Request Aggregation — one client request → multiple service requests
  • Circuit Breaker — protection against cascading failures
  • Logging and Tracing — single point for access logs

Tool Comparison

Tool Type Key Features
Kong Self-hosted / Cloud Lua/Go plugins, Kubernetes Ingress
Traefik Self-hosted Auto-discovery in Docker/K8s
AWS API Gateway Managed Lambda integration, IAM
NGINX + Lua Self-hosted Maximum control
Envoy Proxy gRPC, complex scenarios
Express Gateway Node.js Simple cases

Kong is best for complex scenarios with custom plugins, Traefik excels in Kubernetes integration. We choose the tool based on your stack. Our experience includes projects with Kong (over 50 services) and Traefik (K8s clusters up to 30 nodes).

Kong Configuration

Kong is the most popular self-hosted gateway:

# kong.yaml (declarative configuration) _format_version: "3.0" services: - name: order-service url: http://order-service:3000 routes: - name: orders-route paths: ["/api/orders"] methods: ["GET", "POST", "PUT", "DELETE"] - name: user-service url: http://user-service:3001 routes: - name: users-route paths: ["/api/users"] methods: ["GET", "PUT"] plugins: - name: jwt config: claims_to_verify: ["exp"] - name: rate-limiting config: minute: 100 hour: 5000 policy: local - name: request-transformer config: add: headers: ["X-Service-Version:1.0"] 

Authentication at the Gateway Level

JWT is verified in the gateway, microservices receive already-validated user headers:

// Custom middleware on Express Gateway async function jwtMiddleware(req, res, next) { const token = req.headers.authorization?.replace('Bearer ', ''); if (!token) return res.status(401).json({ error: 'No token' }); try { const payload = jwt.verify(token, process.env.JWT_SECRET); // Pass user data in headers req.headers['X-User-Id'] = payload.sub; req.headers['X-User-Role'] = payload.role; req.headers['X-User-Email'] = payload.email; next(); } catch { res.status(401).json({ error: 'Invalid token' }); } } 
Example Traefik Configuration in Kubernetes
# Traefik IngressRoute apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: api-gateway spec: entryPoints: - websecure routes: - match: PathPrefix(`/api/orders`) kind: Rule services: - name: order-service port: 3000 middlewares: - name: jwt-auth - name: rate-limit - match: PathPrefix(`/api/users`) kind: Rule services: - name: user-service port: 3001 middlewares: - name: jwt-auth --- apiVersion: traefik.containo.us/v1alpha1 kind: Middleware metadata: name: rate-limit spec: rateLimit: average: 100 burst: 50 period: 1m 

Implementation Process

Stage Duration Outcome
Architecture audit 1-2 days Route map, security requirements
Basic gateway setup 3-5 days Working routing, JWT authentication
Advanced configuration 2-3 days Rate limiting, circuit breaker, logging
Custom aggregation 1-2 weeks BFF endpoints, query optimization

Pricing is calculated individually after auditing your architecture. Request a consultation — we will assess your project free of charge.

What’s Included in the Implementation

  • Route and security policy design
  • Configuration of Kong, Traefik, or a cloud gateway for your infrastructure
  • Integration with JWT/OAuth2, LDAP, or another provider
  • Configuration of rate limiting, circuit breaker, and monitoring
  • API documentation and team instructions
  • Access transfer and training for your engineers

We also provide post-implementation support: version upgrades, performance optimization. Our engineers are certified in Kubernetes and Kong, with 7+ years of experience and 50+ successful projects. We guarantee stable gateway operation under load. Get a consultation for your project.

Additional Resources

Learn more about the pattern on Wikipedia. Official Kong documentation is available at konghq.com.