Microsoft Azure
API Management — Gateway, Policies & Products
Put a managed gateway in front of your APIs, with auth, throttling and transformation handled before the backend.
API Management (APIM) sits in front of your APIs and applies the cross-cutting concerns in one place.
A hotel concierge desk. Guests are checked against the booking, limits are applied to what they can order, requests are translated for the kitchen, and the kitchen never deals with anyone directly.
Key Concepts
1
client -> APIM gateway -> App Service / AKS / Functions / on-prem
|
auth, rate limit, transform, cache, log2
Policies are the distinguishing feature. They are XML applied at four scopes, and they run in a pipeline:
3
inbound validate-jwt, rate-limit, set-header, rewrite-uri
backend forward-request, retry
outbound transform the response, set cache
on-error shape the error4
<inbound>
<validate-jwt header-name="Authorization">
<openid-config url="https://login.microsoftonline.com/.../v2.0/.well-known/openid-configuration" />
</validate-jwt>
<rate-limit-by-key calls="100" renewal-period="60"
counter-key="@(context.Subscription.Id)" />
</inbound>5
That rejects an unauthenticated or over-quota request before your backend sees it.
6
Scopes inherit, which is what makes it manageable: global, then product, then API, then operation, with <base /> marking where the parent's policy runs.
<base />
7
Products and subscriptions meter access. A product groups APIs and carries a quota; a consumer subscribes and gets a key. That is how you offer a free tier at 1,000 calls a month and a paid tier at a million without changing any code.
8
The tiers matter for cost and architecture.
Consumption serverless, per-call, no VNet
Basic/Standard fixed units
Premium multi-region, VNet injection, self-hosted gateway
Developer non-production only, no SLA9
Premium is the one that supports multi-region and putting the gateway inside a VNet to reach private backends — frequently the reason a design needs it despite the price.
10
The self-hosted gateway runs APIM's gateway as a container in your own cluster or data centre, managed from Azure. It is the answer for hybrid APIs that cannot leave the premises.
11
What the interviewer is probing.1. "What are APIM policies and at what scopes do they apply?" Probing: the core concept.
Stalls: "Configuration settings." Moves up: XML applied at global, product, API and operation
scope, running inbound, backend, outbound and on-error, with <base /> marking where the parent runs.
12
2. "Which tier do you need for VNet integration and multi-region?" Probing: the cost cliff.
Stalls: "Any of them." Moves up: Premium — which is a large jump in price and frequently the
reason a design needs it.
13
3. "How do you meter different customers?" Probing: products and subscriptions. Stalls:
"Count the requests." Moves up: products group APIs with a quota and consumers subscribe for a
key, so a free and a paid tier need no code change.
14
4. "Why validate the JWT before the rate-limit policy?" Probing: policy ordering. Stalls:
"Order does not matter." Moves up: if the rate-limit key comes from a claim, you would otherwise
be counting requests you have not authenticated.