Install
brew install kong/deck/deckShowcase


Products
Kong, product by product →Kong ships more than one product — each judged line competes in its own arena on the same stories as everyone else.
| Line | Arena | Rank | PA Score | Agent-ready |
|---|---|---|---|---|
| Kong Gateway & Konnectthis page | API platforms | #2/5 | 36/100 | 48/100 |
| AI Gateway | Model Gateways & Routers | #6/7 | 19/100 | 47/100 |
| Insomniaacquired | API platforms | #4/5 | 34/100 | 37/100 |
Not yet judged (9 — no arena where they compete): Kong Mesh · Event Gateway · Ingress Controller & Operator · Dev Portal · Service Catalog & MCP Registry · Kong Identity · decK & kongctl · Metering & Billing · Volcano SDK
Verified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci scripting — stories about ci scripting in this arenaCi scriptingevidence →
Stories about ci scripting in this arena
Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaborationevidence →
Working as a team — sharing, comments, roles, simultaneous editing
Collections workspaces — stories about collections workspaces in this arenaCollections workspacesevidence →
Stories about collections workspaces in this arena
Environments secrets — stories about environments secrets in this arenaEnvironments secretsevidence →
Stories about environments secrets in this arena
Gateway traffic — stories about gateway traffic in this arenaGateway trafficevidence →
Stories about gateway traffic in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Spec design — stories about spec design in this arenaSpec designevidence →
Stories about spec design in this arena
Testing mocking — stories about testing mocking in this arenaTesting mockingevidence →
Stories about testing mocking in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Kong stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Webhooks · Official SDKs · Versioning policy · API sandbox
Subscribe to events via webhooks
—–
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
~6/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
~6/10
unlocks → Official SDKs
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
~5/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓8/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
~6/10
Plug MCP servers into this product so it can use their tools
~4/10
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci scripting — stories about ci scripting in this arenaCi scripting
Stories about ci scripting in this arena
Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration
Working as a team — sharing, comments, roles, simultaneous editing
Collections workspaces — stories about collections workspaces in this arenaCollections workspaces
Stories about collections workspaces in this arena
Environments secrets — stories about environments secrets in this arenaEnvironments secrets
Stories about environments secrets in this arena
Gateway traffic — stories about gateway traffic in this arenaGateway traffic
Stories about gateway traffic in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Spec design — stories about spec design in this arenaSpec design
Stories about spec design in this arena
Testing mocking — stories about testing mocking in this arenaTesting mocking
Stories about testing mocking in this arena
Sorted by importance (agentic first) (high → low) · 57/57 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 4/10 | Cclaimed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 6/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 5/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a± | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policies C Traffic management | platform-engineer | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 3 | full | 9/10 | Cclaimed | |
Enforce rate limits on API traffic per consumer or route C Traffic management | platform-engineer | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 3 | full | 9/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 9/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 6/10 | Cclaimed | |
Store collections as plain text files in my repo and version them with git C Collections | developer | Collections workspaces — stories about collections workspaces in this arenaCollections workspaces | 3 | partial | 6/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
Import an OpenAPI spec to generate requests and collections C Spec import export | developer | Spec design — stories about spec design in this arenaSpec design | 3 | partial | 3/10 | Cclaimed | |
Lint API specs against configurable style and governance rules C Governance | platform-engineer | Spec design — stories about spec design in this arenaSpec design | 3 | n/a | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | 0/10 | ||
Switch requests between dev, staging, and prod using environment variable sets C Environments | developer | Environments secrets — stories about environments secrets in this arenaEnvironments secrets | 3 | none | 0/10 | ||
Organize API requests into collections and folders and rerun them anytime C Collections | developer | Collections workspaces — stories about collections workspaces in this arenaCollections workspaces | 3 | n/a | untested | none yet | |
Run an entire collection as an automated test suite with a pass/fail report C Testing | developer | Testing mocking — stories about testing mocking in this arenaTesting mocking | 3 | n/a | untested | none yet | |
Run my API test collections in CI with a CLI and fail the build on regressions C Ci | developer | Ci scripting — stories about ci scripting in this arenaCi scripting | 3 | n/a | untested | none yet | |
Share collections with my team in a synced shared workspace C Team workspaces | developer | Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration | 3 | n/a | untested | none yet | |
Spin up a mock server from saved examples or a spec so consumers can build before the API exists C Mocking | developer | Testing mocking — stories about testing mocking in this arenaTesting mocking | 3 | n/a | untested | none yet | |
Write test assertions against response status, body, and headers C Testing | developer | Testing mocking — stories about testing mocking in this arenaTesting mocking | 3 | n/a | untested | none yet | |
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platform C Ai gateway | ai-native user | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 2 | full | 9/10 | Cclaimed | |
Route, load-balance, and transform requests between consumers and upstream services C Traffic management | platform-engineer | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 2 | full | 9/10 | Cclaimed | |
Keep credentials out of shared files with masked secrets or an external vault integration C Secrets | platform-engineer | Environments secrets — stories about environments secrets in this arenaEnvironments secrets | 2 | full | 8/10 | Cclaimed | |
Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps) C Gateway ops | platform-engineer | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 2 | full | 8/10 | Cclaimed | |
Publish an internal catalog or portal where teams discover and consume our APIs C Api catalog | platform-engineer | Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration | 2 | full | 8/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | full | 7/10 | Cclaimed | |
Generate and publish API documentation from my collections or specs C Docs generation | developer | Spec design — stories about spec design in this arenaSpec design | 2 | full | 7/10 | Cclaimed | |
Monitor API traffic with metrics, logging, and tracing integrations C Monitoring | platform-engineer | Gateway traffic — stories about gateway traffic in this arenaGateway traffic | 2 | partial | 7/10 | Xcommunity | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Cclaimed | |
Work fully offline in a local workspace without a cloud account G Offline | developer | Collections workspaces — stories about collections workspaces in this arenaCollections workspaces | 2 | partial | 5/10 | Cclaimed | |
Script pre-request and post-response logic to chain requests and massage data C Scripting | developer | Ci scripting — stories about ci scripting in this arenaCi scripting | 2 | partial | 4/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Design an API spec-first and export it as OpenAPI C Spec import export | developer | Spec design — stories about spec design in this arenaSpec design | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control who can view or edit APIs and collections with roles and permissions G Access control | platform-engineer | Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration | 2 | none | untested | none yet | |
Have AI generate test cases or assertions for an endpoint from its spec or responses C Ai assist | ai-native user | Testing mocking — stories about testing mocking in this arenaTesting mocking | 2 | n/a | untested | none yet | |
Import and export collections in portable formats to move between tools C Collections | developer | Collections workspaces — stories about collections workspaces in this arenaCollections workspaces | 2 | n/a | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule collection runs as monitors that alert me when an API breaks C Monitors | developer | Ci scripting — stories about ci scripting in this arenaCi scripting | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Send GraphQL, gRPC, WebSocket, and SSE requests, not just REST C Protocols | developer | Collections workspaces — stories about collections workspaces in this arenaCollections workspaces | 2 | n/a | untested | none yet | |
Validate live responses against the API contract to catch drift C Contract testing | platform-engineer | Testing mocking — stories about testing mocking in this arenaTesting mocking | 2 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | partial | 4/10 | Cclaimed |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 30 stories with headroom
What would move Kong’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Missing: any documented in-product AI assistant/chat feature, evidence of task delegation to it, and independent confirmation of its use.
Environments secrets — stories about environments secrets in this arenaSwitch requests between dev, staging, and prod using environment variable sets
nonemoves PA Scoreimpact 30
Missing: explicit environment/variable-set switching UI or config, evidence of per-environment variable collections, and any workflow tying such sets to request execution.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
Missing: any documented feature or policy for preventing data from being used in model training (e.g., zero-retention enforcement, provider opt-out headers, data-use contracts).
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Kong's evidence focuses on AI Gateway/MCP traffic management (routing LLM calls, semantic security, observability plugins) but none of it shows Kong itself analyzing a user's own API/traffic data to generate AI insights or suggestions inside the product (e.g., an AI copilot summarizing gateway usage or recommending config changes).
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
Evidence shows Kong offers CLIs (decK, kongctl), Admin/OpenAPI API directories, and Kong Manager UI, but no evidence of official client SDKs (e.g., language-specific libraries) for building against Kong Gateway/AI Gateway/Konnect APIs.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Kong is an API/AI gateway product; the evidence covers proxying, MCP, LLM routing, logging, and OpenTelemetry metrics, but there is no mention of webhook subscription or event-driven notification delivery to AI-native consumers.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
While Kong publishes OpenAPI spec directories for its various APIs (kong-docs-9) and has extensive product documentation, no evidence in the pack describes API versioning conventions or any documented deprecation policy for Kong's own APIs (Admin API, Konnect API, AI Gateway API, etc.).
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
partialq4/10moves agent-readyimpact 27
Missing: clear documentation of Kong itself invoking/using tools from a connected MCP server (client-side tool use), independent/hands-on confirmation of this workflow, and detail on how a user 'plugs in' an arbitrary third-party MCP server for Kong's own use.
Showing the top 8 of 30 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map14 surfaces · 30 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
GitHub README20 stories
- Run the product headlessly / in CI for automation
- Plug MCP servers into this product so it can use their tools
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Script pre-request and post-response logic to chain requests and massage data
- Store collections as plain text files in my repo and version them with git
- Work fully offline in a local workspace without a cloud account
- Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platform
- Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)
- Monitor API traffic with metrics, logging, and tracing integrations
- Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policies
- Enforce rate limits on API traffic per consumer or route
- Route, load-balance, and transform requests between consumers and upstream services
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
Deck docs10 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Perform bulk operations across many items at once
- Version, review, and roll back my automations
- Store collections as plain text files in my repo and version them with git
- Work fully offline in a local workspace without a cloud account
- Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
Gateway docs9 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Work fully offline in a local workspace without a cloud account
- Keep credentials out of shared files with masked secrets or an external vault integration
- Monitor API traffic with metrics, logging, and tracing integrations
- Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policies
- Route, load-balance, and transform requests between consumers and upstream services
- Self-host the core product
Kongctl docs7 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Perform bulk operations across many items at once
- Version, review, and roll back my automations
- Work fully offline in a local workspace without a cloud account
- Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)
- Do everything through the API that I can do in the UI
API reference6 stories
- Drive the product through a documented public API
- Explore an interactive API reference with runnable examples
- Download a machine-readable API spec (OpenAPI or equivalent)
- Do everything through the API that I can do in the UI
- Generate and publish API documentation from my collections or specs
- Import an OpenAPI spec to generate requests and collections
AI gateway docs5 stories
- Plug MCP servers into this product so it can use their tools
- Operate the product with natural-language commands
- Define rules that trigger actions automatically on events
- Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platform
- Monitor API traffic with metrics, logging, and tracing integrations
Dev portal docs5 stories
- Explore an interactive API reference with runnable examples
- Download a machine-readable API spec (OpenAPI or equivalent)
- Publish an internal catalog or portal where teams discover and consume our APIs
- Generate and publish API documentation from my collections or specs
- Import an OpenAPI spec to generate requests and collections
Plugins docs5 stories
- Define rules that trigger actions automatically on events
- Script pre-request and post-response logic to chain requests and massage data
- Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platform
- Enforce rate limits on API traffic per consumer or route
- Route, load-balance, and transform requests between consumers and upstream services
Konnect platform docs3 stories
OpenAPI spec3 stories
MCP docs3 stories
Products docs3 stories
Catalog docs2 stories
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
6 of 14 testable claims verified · 0 contradicted → integrity 43/100
32 distinct capability claims found in Kong’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
6
Verified
8
Unverified
0
Contradicted
16
Undersold
Verified (10)
“decK CLI automates the full API lifecycle (APIOps) via declarative config commands”
“Plugins support request/response transformation, logging, and monitoring”
Monitor API traffic with metrics, logging, and tracing integrationspartialproof ↗
“Advanced routing, load balancing, and health checking configurable via RESTful admin API or declarative config”
Drive the product through a documented public APIfullproof ↗
“Kong can be configured via its Admin API or the decK CLI”
Drive the product through a documented public APIfullproof ↗
“Kong can be configured via its Admin API or the decK CLI”
“Publishes a directory of OpenAPI specifications for Kong's own APIs”
Download a machine-readable API spec (OpenAPI or equivalent)partialproof ↗
“Dev Portal lets developers browse/search API docs, try operations, and manage their own credentials”
Explore an interactive API reference with runnable examplespartialproof ↗
“Konnect lets you catalog, connect to, and monitor all gateway control planes and data plane nodes in one place”
Monitor API traffic with metrics, logging, and tracing integrationspartialproof ↗
“Can auto-discover APIs and compose their endpoints into MCP tools”
“Can auto-generate MCP servers from composed tools with one-click deploy to AI Gateway infrastructure”
Unverified (25)
“Kong Gateway is a reverse-proxy API gateway for managing and routing APIs”
Route, load-balance, and transform requests between consumers and upstream servicesfullproof ↗
“Provides a connectivity and governance layer for AI-native applications”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“AI Gateway gives control and visibility over AI agent infrastructure via MCP capabilities”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“decK CLI automates the full API lifecycle (APIOps) via declarative config commands”
Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)fullproof ↗
“Can add authentication to an API in minutes via plugin configuration”
Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policiesfullproof ↗
“Universal LLM API routes requests across multiple providers (OpenAI, Anthropic, Bedrock, Gemini, etc.)”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Plugins enforce rate limiting on traffic”
Enforce rate limits on API traffic per consumer or routefullproof ↗
“Plugins support request/response transformation, logging, and monitoring”
Route, load-balance, and transform requests between consumers and upstream servicesfullproof ↗
“Supports declarative databaseless deployment and hybrid control-plane/data-plane deployment models”
Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)fullproof ↗
“Advanced routing, load balancing, and health checking configurable via RESTful admin API or declarative config”
Route, load-balance, and transform requests between consumers and upstream servicesfullproof ↗
“Provides MCP traffic governance, security, and observability plus MCP autogeneration from any RESTful API”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Supports authentication/authorization methods like JWT, basic auth, OAuth, and ACLs”
Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policiesfullproof ↗
“Offers 60+ AI features including observability, semantic security/caching, and semantic routing”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Acts as a central layer for proxying, routing, load balancing, health checking, and authentication of microservices”
Route, load-balance, and transform requests between consumers and upstream servicesfullproof ↗
“Provides advanced AI traffic capabilities: multi-LLM support, semantic security, MCP traffic security, and analytics”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Vaults let you securely store and reference secrets without exposing them in plaintext”
Keep credentials out of shared files with masked secrets or an external vault integrationfullproof ↗
“Catalog provides a single inventory across APIs, API packages, AI models, MCP servers, and agents”
Publish an internal catalog or portal where teams discover and consume our APIsfullproof ↗
“Secures, manages, speeds up, monetizes, and cost-controls every LLM, MCP, event, and API request”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Setup script creates a Konnect control plane and deploys a local Dockerized data plane with automatic licensing”
Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)fullproof ↗
“Secrets can be added to Vaults via environment variables, Konnect Config Store, or third-party backend vaults”
Keep credentials out of shared files with masked secrets or an external vault integrationfullproof ↗
“Dev Portal APIs can be published using OpenAPI or AsyncAPI specs plus Markdown documentation”
Generate and publish API documentation from my collections or specsfullproof ↗
“Can compose API packages from existing operations to serve specific partners or use cases”
Publish an internal catalog or portal where teams discover and consume our APIsfullproof ↗
“Lets you define entitlements, meter, and bill against agent/LLM/MCP context consumption”
Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platformfullproof ↗
“Kong Gateway runs in front of any RESTful API and can be extended via plugins”
Route, load-balance, and transform requests between consumers and upstream servicesfullproof ↗
“Provides Docker installation for running Kong Gateway in DB-less mode”
Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps)fullproof ↗
Undersold (16)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Plug MCP servers into this product so it can use their toolspartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Script pre-request and post-response logic to chain requests and massage datapartialproof ↗
Store collections as plain text files in my repo and version them with gitpartialproof ↗
Work fully offline in a local workspace without a cloud accountpartialproof ↗
Do everything through the API that I can do in the UIfullproof ↗
Export all of my data in open formats and leavepartialproof ↗
Read the product's source under an open licensepartialproof ↗
Import an OpenAPI spec to generate requests and collectionspartialproof ↗
Claims outside our story set (1)
Real capability claims found in Kong’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Runs natively on Kubernetes via an official Ingress Controller”
source ↗
Business model
Kong Gateway core is open source and free to self-host; Konnect SaaS adds a free tier, usage-based Plus, and custom Enterprise plans across the gateway runtimes and platform services.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt down since Sep 11 '26 (30d, checked every 6h since Sep 8 '26)
