Skip to content
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
# Discover APIs on Google Apigee Gateway

WSO2 API Manager supports federated API discovery for APIs deployed on Google Apigee. This enables API proxies created and managed in Apigee to be discovered and brought under the centralized control plane of WSO2 API Manager.

Once discovered, these APIs can fully leverage the control plane capabilities of WSO2 API Manager, including:

- **Governance enforcement** – Apply security, compliance, and lifecycle policies consistently.
- **Unified management** – Maintain a centralized view of all APIs, eliminating manual imports and fragmented operations.
- **Developer Portal features** – Provide a unified catalog where developers can discover Apigee-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly.

By integrating Apigee APIs into the control plane, organizations can ensure consistent standards, stronger governance, and improved visibility across their API ecosystem.

Follow the steps below to configure Google Apigee as a Federated API Gateway for API discovery.

## Step 1: Create a GCP Service Account and Generate a JSON Key

1. Log in to the [Google Cloud Console](https://console.cloud.google.com/) and navigate to **IAM & Admin** > **Service Accounts**.
2. Click **Create Service Account** and provide a name (e.g., `wso2-apim-discovery`).
3. Grant the service account the `Apigee API Admin` role (or `Apigee API Reader` for read-only access).

If you maintain OpenAPI specifications for your API proxies in Apigee API Hub, also grant the `API Hub Viewer` role. Without it, the specifications cannot be read from API Hub, and the APIs are imported with a generated placeholder definition instead of their actual resources.
4. Navigate to the newly created service account, click **Keys** > **Add Key** > **Create new key**.
5. Select **JSON** as the key type and click **Create**. A JSON key file will be downloaded.

!!!warning
Keep this JSON key file safe. It contains credentials that grant access to your Apigee organization. You will need to paste the full JSON content when configuring the gateway in WSO2 API Manager.

## Step 2: Register Apigee Gateway as a Federated Gateway in WSO2 API Manager

1. Start WSO2 API Manager.

2. Sign in to the Admin Portal.

`https://<hostname>:9443/admin`

`https://localhost:9443/admin`

3. Add a new Gateway Environment.
1. Select the **Gateway Type** as **Apigee** from the dropdown and provide the relevant details in the fields accordingly.
2. Select the **Gateway Mode** as **Read Only**.
3. Under **Gateway Connector Configurations**, provide the following:
- **Apigee Organization** – The GCP project ID (e.g., `my-gcp-project`).
- **Apigee Environment** – The target environment name (e.g., `eval`, `test`, `prod`).
- **Service Account JSON Credentials** – The full contents of the GCP service account JSON key file obtained in Step 1. The content should start with `{` and end with `}`.
- **API Hostname** – The hostname where APIs are accessible (e.g., `34.49.61.76.nip.io` or `api.example.com`). Leave empty to use the default `{org}-{env}.apigee.net`.
- **API Hub Location** – The GCP region in which your API Hub instance is provisioned (e.g., `global`, `us-west1`). You can find this in the Google Cloud Console under **Apigee** > **API hub**, where the region is shown with the API hub instance.

!!! warning
The **API Hub Location** must match the region of your API hub instance exactly. If it does not, the specifications cannot be retrieved and the APIs are imported with a generated placeholder definition instead of their actual resources. See [OpenAPI Specifications for Discovered APIs](#openapi-specifications-for-discovered-apis).

4. Provide the scheduling interval for API discovery in minutes (e.g., set to `0` to disable background scheduling).
5. Save the configurations.

[![add apigee gateway discovery environment]({{base_path}}/assets/img/deploy/add-apigee-gw-discovery.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-apigee-gw-discovery.png)

## Step 3: Discover and Publish to Developer Portal

1. Sign in to the Publisher Portal.

`https://<hostname>:9443/publisher`

`https://localhost:9443/publisher`

2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/).
3. Once imported, click on the API from the listing to view its details.
4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal.

## Step 4: Invoke the API

1. Sign in to the Developer Portal.

`https://<hostname>:9443/devportal`

`https://localhost:9443/devportal`

2. Navigate to tryout and invoke the API.

!!!note
The Apigee connector operates in **Read-Only** mode. It only discovers APIs from Apigee, it does not deploy APIs to Apigee.

## OpenAPI Specifications for Discovered APIs

If you maintain OpenAPI specifications for your API proxies in Apigee API Hub, the connector attaches them to the discovered APIs. For a specification to be retrieved, its API Hub entry must reside in the region configured as the **API Hub Location**, and its display name must exactly match the name of the API proxy.

If a specification cannot be retrieved, the API is still imported, but with a generated placeholder definition that exposes a single wildcard resource instead of its actual resources. If you see this, verify the **API Hub Location**, confirm that the API Hub display name matches the proxy name, and ensure that the service account has the `API Hub Viewer` role.
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ Follow the instructions given below to configure AWS API Gateway as a Federated

## Step 1: Configure User Credentials in AWS API Gateway

!!!note
This step creates the static Access Key and Secret Key used by the first authentication method described in Step 2. If WSO2 API Manager runs on AWS infrastructure and you intend to use the IAM role of the host instead, you can skip this step.

1. Login to your [AWS](https://console.aws.amazon.com/) account and navigate to Console Home. Search for “IAM” in the search bar.
2. Click on the IAM service. Navigate to **Users** under **Access Management**.
3. Create an IAM user in AWS with `AmazonAPIGatewayAdministrator` permission.
Expand All @@ -27,7 +30,17 @@ Follow the instructions given below to configure AWS API Gateway as a Federated

3. Add a new Gateway Environment.
1. Select the Gateway type as AWS and provide the relevant details in the fields accordingly.
2. Enter the Access Key and Secret Key obtained in Step 1 under Gateway configurations.
2. Under **Gateway Connector Configurations**, provide the following:
- **AWS Region** – The region that hosts your AWS API Gateway (e.g., `us-east-1`).
- **Access Key** and **Secret Key** – The static keys obtained in Step 1. Leave both blank to use the IAM role of the host on which WSO2 API Manager runs, such as an EC2 instance profile or an EKS pod identity.
- **IAM Role ARN** – Optional. The ARN of an IAM role to assume (e.g., `arn:aws:iam::123456789012:role/MyRole`), which enables cross-account deployments.
- **Stage Name** – The default stage to which the APIs are deployed in AWS API Gateway (e.g., `prod`).

The **IAM Role ARN** is not an alternative to the credentials above it. When provided, the role is assumed using whichever credentials were resolved, so it can be combined with either the static keys or the IAM role of the host.

!!!note
To assume a role, the identity resolved from the credentials above must be allowed to perform the `sts:AssumeRole` action, and the trust policy of the role being assumed must permit that identity to assume it. The assumed role must also carry the API Gateway permissions described in Step 1.

3. Save the configurations.

[![add aws gateway environment]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,21 +4,26 @@ From 4.6.0 release, WSO2 API Manager supports federated API discovery for APIs d

Once discovered, these APIs can fully leverage the control plane capabilities of WSO2 API Manager, including:

Governance enforcement – apply security, compliance, and lifecycle policies consistently.

Unified management – maintain a centralized view of all APIs, eliminating manual imports and fragmented operations.

Developer Portal Features – provide a unified catalog where developers can discover AWS-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly.
- **Governance enforcement** – Apply security, compliance, and lifecycle policies consistently.
- **Unified management** – Maintain a centralized view of all APIs, eliminating manual imports and fragmented operations.
- **Developer Portal features** – Provide a unified catalog where developers can discover AWS-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly.

By integrating AWS APIs into the control plane, organizations can ensure consistent standards, stronger governance, and improved visibility across their API ecosystem.

Follow the instructions given below to configure AWS API Gateway as a Federated API Gateway.

## Step 1: Configure User Credentials in AWS API Gateway

!!!note
This step creates the static Access Key and Secret Key used by the first authentication method described in Step 2. If WSO2 API Manager runs on AWS infrastructure and you intend to use the IAM role of the host instead, you can skip this step.

1. Login to your [AWS](https://console.aws.amazon.com/) account and navigate to Console Home. Search for “IAM” in the search bar.
2. Click on the IAM service. Navigate to **Users** under **Access Management**.
3. Create an IAM user in AWS with `AmazonAPIGatewayAdministrator` permission.

!!!tip
When the gateway is registered in **Read Only** mode, the identity only reads APIs from AWS API Gateway, so read-level permissions such as `apigateway:GET` are sufficient.

4. Obtain an Access Key and Secret Access Key for the IAM user created in the previous step. Select **Third-party service** as the use case.

!!!note
Expand All @@ -37,7 +42,17 @@ Follow the instructions given below to configure AWS API Gateway as a Federated
3. Add a new Gateway Environment.
1. Select the Gateway Type as AWS Gateway from the dropdown and provide the relevant details in the fields accordingly.
2. Select the Gateway Mode as Read Only, or Read Write based on the requirement.
3. Enter the Access Key and Secret Key obtained in Step 1 under Gateway Connector Configurations.
3. Under **Gateway Connector Configurations**, provide the following:
- **AWS Region** – The region that hosts your AWS API Gateway (e.g., `us-east-1`).
- **Access Key** and **Secret Key** – The static keys obtained in Step 1. Leave both blank to use the IAM role of the host on which WSO2 API Manager runs, such as an EC2 instance profile or an EKS pod identity.
- **IAM Role ARN** – Optional. The ARN of an IAM role to assume (e.g., `arn:aws:iam::123456789012:role/MyRole`), which enables cross-account API discovery.
- **Stage Name** – The default stage of the APIs in AWS API Gateway (e.g., `prod`).

The **IAM Role ARN** is not an alternative to the credentials above it. When provided, the role is assumed using whichever credentials were resolved, so it can be combined with either the static keys or the IAM role of the host.

!!!note
To assume a role, the identity resolved from the credentials above must be allowed to perform the `sts:AssumeRole` action, and the trust policy of the role being assumed must permit that identity to assume it. The assumed role must also carry the API Gateway permissions described in Step 1.

4. Provide the scheduling interval for API discovery in minutes.
5. Save the configurations.

Expand All @@ -47,16 +62,16 @@ Follow the instructions given below to configure AWS API Gateway as a Federated
[![add aws gateway discovery environment]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-aws-gw-discovery.png)


## Step 3 : Deploy to Developer Portal
## Step 3: Discover and Publish to Developer Portal

1. Sign in to Publisher Portal.
1. Sign in to the Publisher Portal.
`https://<hostname>:9443/publisher`

`https://localhost:9443/publisher`

2. Go to APIs view and the APIs discovered from AWS API Gateway will be listed.
3. Click on the API to view the API details.
4. From the left menu, click **Lifecycle** and select **Publish** so that API will deploy to the Developer Portal.
2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/).
3. Once imported, click on the API from the listing to view its details.
4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal.

## Step 4 : Invoke the API
1. Sign in to the Developer Portal.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,9 +65,9 @@ Follow the instructions given below to configure Azure API Gateway as a Federate

`https://localhost:9443/publisher`

2. Go to APIs view and the APIs discovered from Azure API Gateway will be listed.
3. Click on the API to view the API details.
4. From the left menu, click **Lifecycle** and select **Publish** so that API will deploy to the Developer Portal.
2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/).
3. Once imported, click on the API from the listing to view its details.
4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal.

## Step 4 : Invoke the API
1. Sign in to the Developer Portal.
Expand Down
Loading