API Proxies
An index and topic collection covering reverse-proxy and edge-proxy software used in front of APIs, including HTTP reverse proxies, edge proxies, load balancers, caching proxies, and service mesh sidecars. API proxies sit between API consumers and upstream services to provide TLS termination, routing, rate limiting, observability, traffic shaping, caching, authentication enforcement, and resilience features such as retries and circuit breaking. This collection includes general-purpose reverse proxies like NGINX, HAProxy, Caddy, Apache HTTP Server, Traefik, and Varnish, edge and service mesh proxies like Envoy, Linkerd2-proxy, Istio, Consul Connect, and AWS App Mesh, and proxy-oriented gateways like KrakenD, Tyk, Ambassador, Emissary, and Apache APISIX that overlap with the API gateway category but operate primarily as L7 proxies.
Index entry only — little beyond a description and a link, and nothing machine-readable enough for an agent to act on without a human reading the site first.
API Evangelist profiles API Proxies the way a machine reads it — 30 machine-readable artifacts, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — API Proxies scores 9.5/100 (minimal), with a separate agent-readiness read of 0/100 (human only). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance. Every facet and dimension name is a link: it opens that measurement's page on APIs.io, where the rating runs across the whole catalog — the exact checks that feed it, how every profiled provider distributes on it, and who is at the top of it.
Put this on your own site. The badge is drawn live from API Proxies's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/api-proxies/"
title="API Proxies on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/api-proxies.svg"
alt="API Proxies Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/api-proxies/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/api-proxies/"
title="API Proxies on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/api-proxies/card.svg"
alt="API Proxies Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile API Proxies
Each block below is one kind of artifact we hold for API Proxies. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
Features 8
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Layer 7 Reverse Proxying
API proxies terminate HTTP/HTTPS connections from clients and forward requests to upstream API services, hiding internal topology and providing a single front door.
TLS Termination and mTLS
Proxies like NGINX, HAProxy, Envoy, and Linkerd2-proxy terminate TLS at the edge and can enforce mutual TLS between services in a mesh.
Routing and Traffic Splitting
Edge proxies route requests by host, path, header, or method, and support traffic splitting, canary releases, and blue-green deployments.
Rate Limiting and Throttling
Reverse proxies enforce rate limits, quotas, and concurrency limits at the edge to protect upstream APIs from abuse and overload.
Caching and HTTP Acceleration
Caching proxies like Varnish, NGINX, Squid, and Cloudflare cache API responses to reduce upstream load and improve client latency.
Observability and Access Logging
Proxies emit structured access logs, metrics, and traces (OpenTelemetry, Prometheus, statsd) for every request crossing the edge or mesh.
Service Mesh Sidecar Pattern
Sidecar proxies like Envoy, Linkerd2-proxy, and Consul Connect run alongside each service to provide identity, encryption, retries, and traffic policy without changing applicati...
WAF and Edge Security
Edge proxies and CDNs like Cloudflare, Akamai, and Azure Application Gateway provide WAF rules, bot mitigation, and DDoS protection in front of APIs.
Scroll within the panel for all 8 ·
Semantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Api Proxies Context
JSON-LDJSON Schema 2
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
ProxyRoute
JSON SCHEMAUpstreamCluster
JSON SCHEMAJSON Structure 2
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Api Proxies Proxy Route Structure
JSON STRUCTUREApi Proxies Upstream Cluster Structure
JSON STRUCTUREExamples 2
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Use Cases 7
What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.
What developers build with this provider.
API Edge Termination
Front internal APIs with NGINX, HAProxy, or Envoy to handle TLS, HTTP/2, HTTP/3, compression, and request normalization before requests reach application servers.
Multi-Cluster Ingress
Use Envoy Gateway, Emissary, Ambassador, or Traefik as Kubernetes ingress controllers to expose APIs running across multiple clusters and namespaces.
Service Mesh East-West Traffic
Deploy Istio, Linkerd, or Consul Connect to manage service-to-service API calls with mTLS, retries, and traffic policy inside a Kubernetes cluster.
Global API Acceleration
Front public APIs with Cloudflare, Fastly, or Akamai to terminate connections at the edge, cache safe responses, and absorb DDoS traffic.
Canary and Progressive Delivery
Use proxy-based traffic splitting in Envoy, Istio, or Linkerd to shift a percentage of API traffic to a new version and roll back on error budget breach.
Legacy API Modernization
Place HAProxy, NGINX, or Apache HTTP Server in front of legacy SOAP or HTTP services to add TLS, modern auth, rate limiting, and observability without rewriting the backend.
API Migration and Strangler Pattern
Use a reverse proxy to gradually route traffic from a legacy monolith API to new microservice APIs based on path or header rules.
Scroll within the panel for all 7 ·
Integrations 8
Pre-built integrations with other platforms tell you where this provider already fits in a stack.
Pre-built integrations with other platforms and tools.
Envoy
CNCF L7 proxy used as the data plane for Istio, Consul Connect, Envoy Gateway, Ambassador, and Emissary, with an xDS configuration API.
NGINX
Widely deployed open-source web server and reverse proxy with HTTP/2, HTTP/3, load balancing, caching, and Lua-based extension via OpenResty.
HAProxy
High-performance TCP and HTTP reverse proxy and load balancer with a runtime Data Plane API for dynamic configuration.
Traefik
Cloud-native reverse proxy and ingress controller with automatic service discovery for Kubernetes, Docker, and Consul.
Caddy
HTTP/2 reverse proxy with automatic HTTPS via ACME, a JSON config API, and a plugin architecture.
Istio
Service mesh that uses Envoy sidecars to provide mTLS, traffic management, and policy for Kubernetes APIs.
Linkerd
Lightweight CNCF service mesh built around a purpose-built Rust micro-proxy (linkerd2-proxy) for east-west API traffic.
Cloudflare
Global edge proxy and CDN providing TLS termination, WAF, bot management, and caching in front of APIs and websites.
Scroll within the panel for all 8 ·
Resources
Every other property we hold for API Proxies — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 1
Portal, sign-up, and the first successful call
Build 1
SDKs, sample code, and the tooling you integrate with
← All providers · Data indexed from github.com/api-evangelist/api-proxies · machine-readable index on apis.io
This is an independent, third-party profile of API Proxies, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.