Skip to content

Rank #2 of 5 in API platforms

Kong logo

Kong

Kong Inc. · commercial

44.1k3.7k/yrnpm 237/wk +56npm/wk +3

Showcase

Kong homepage screenshot
homepage · captured Sep 2026 · view live ↗
Kong docs screenshot
docs · captured Sep 2026 · view live ↗

Kong ships more than one product — each judged line competes in its own arena on the same stories as everyone else.

LineArenaRankPA Score
Kong Gateway & Konnectthis pageAPI platforms#2/536/100
AI GatewayModel Gateways & Routers#6/719/100
InsomniaacquiredAPI platforms#4/534/100

Not yet judged (9 — no arena where they compete): Kong Mesh · Event Gateway · Ingress Controller & Operator · Dev Portal · Service Catalog & MCP Registry · Kong Identity · decK & kongctl · Metering & Billing · Volcano SDK

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

34.9/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

31.0/100

Ci scripting — stories about ci scripting in this arenaCi scriptingevidence →

Stories about ci scripting in this arena

24.0/100

Collaboration — working as a team — sharing, comments, roles, simultaneous editingCollaborationevidence →

Working as a team — sharing, comments, roles, simultaneous editing

40.0/100

Collections workspaces — stories about collections workspaces in this arenaCollections workspacesevidence →

Stories about collections workspaces in this arena

33.6/100

Environments secrets — stories about environments secrets in this arenaEnvironments secretsevidence →

Stories about environments secrets in this arena

32.0/100

Gateway traffic — stories about gateway traffic in this arenaGateway trafficevidence →

Stories about gateway traffic in this arena

81.7/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

59.0/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Spec design — stories about spec design in this arenaSpec designevidence →

Stories about spec design in this arena

27.7/100

Testing mocking — stories about testing mocking in this arenaTesting mockingevidence →

Stories about testing mocking in this arena

0.0/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 57/57 stories · click a row’s chevron for the rationale and evidence

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3partial4/10C

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10C

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial±6/10T

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial±5/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/a±untestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1none0/10

Enforce authentication (API keys, OAuth2, JWT, mTLS) on upstream APIs via gateway plugins or policies C

Traffic management

platform-engineerGateway traffic — stories about gateway traffic in this arenaGateway traffic3full9/10C

Enforce rate limits on API traffic per consumer or route C

Traffic management

platform-engineerGateway traffic — stories about gateway traffic in this arenaGateway traffic3full9/10C

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full9/10C

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial6/10C

Store collections as plain text files in my repo and version them with git C

Collections

developerCollections workspaces — stories about collections workspaces in this arenaCollections workspaces3partial6/10C

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3partial5/10C

Import an OpenAPI spec to generate requests and collections C

Spec import export

developerSpec design — stories about spec design in this arenaSpec design3partial3/10C

Lint API specs against configurable style and governance rules C

Governance

platform-engineerSpec design — stories about spec design in this arenaSpec design3n/a0/10

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3none0/10

Switch requests between dev, staging, and prod using environment variable sets C

Environments

developerEnvironments secrets — stories about environments secrets in this arenaEnvironments secrets3none0/10

Organize API requests into collections and folders and rerun them anytime C

Collections

developerCollections workspaces — stories about collections workspaces in this arenaCollections workspaces3n/auntestednone yet

Run an entire collection as an automated test suite with a pass/fail report C

Testing

developerTesting mocking — stories about testing mocking in this arenaTesting mocking3n/auntestednone yet

Run my API test collections in CI with a CLI and fail the build on regressions C

Ci

developerCi scripting — stories about ci scripting in this arenaCi scripting3n/auntestednone yet

Share collections with my team in a synced shared workspace C

Team workspaces

developerCollaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration3n/auntestednone yet

Spin up a mock server from saved examples or a spec so consumers can build before the API exists C

Mocking

developerTesting mocking — stories about testing mocking in this arenaTesting mocking3n/auntestednone yet

Write test assertions against response status, body, and headers C

Testing

developerTesting mocking — stories about testing mocking in this arenaTesting mocking3n/auntestednone yet

Proxy and govern LLM/MCP traffic (token limits, prompt guards, provider routing) through the platform C

Ai gateway

ai-native userGateway traffic — stories about gateway traffic in this arenaGateway traffic2full9/10C

Route, load-balance, and transform requests between consumers and upstream services C

Traffic management

platform-engineerGateway traffic — stories about gateway traffic in this arenaGateway traffic2full9/10C

Keep credentials out of shared files with masked secrets or an external vault integration C

Secrets

platform-engineerEnvironments secrets — stories about environments secrets in this arenaEnvironments secrets2full8/10C

Manage API infrastructure as declarative config and sync it from CI (GitOps/APIOps) C

Gateway ops

platform-engineerGateway traffic — stories about gateway traffic in this arenaGateway traffic2full8/10C

Publish an internal catalog or portal where teams discover and consume our APIs C

Api catalog

platform-engineerCollaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration2full8/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2full7/10C

Generate and publish API documentation from my collections or specs C

Docs generation

developerSpec design — stories about spec design in this arenaSpec design2full7/10C

Monitor API traffic with metrics, logging, and tracing integrations C

Monitoring

platform-engineerGateway traffic — stories about gateway traffic in this arenaGateway traffic2partial7/10X

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10C

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10C

Work fully offline in a local workspace without a cloud account G

Offline

developerCollections workspaces — stories about collections workspaces in this arenaCollections workspaces2partial5/10C

Script pre-request and post-response logic to chain requests and massage data C

Scripting

developerCi scripting — stories about ci scripting in this arenaCi scripting2partial4/10C

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2none0/10

Design an API spec-first and export it as OpenAPI C

Spec import export

developerSpec design — stories about spec design in this arenaSpec design2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Control who can view or edit APIs and collections with roles and permissions G

Access control

platform-engineerCollaboration — working as a team — sharing, comments, roles, simultaneous editingCollaboration2noneuntestednone yet

Have AI generate test cases or assertions for an endpoint from its spec or responses C

Ai assist

ai-native userTesting mocking — stories about testing mocking in this arenaTesting mocking2n/auntestednone yet

Import and export collections in portable formats to move between tools C

Collections

developerCollections workspaces — stories about collections workspaces in this arenaCollections workspaces2n/auntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Schedule collection runs as monitors that alert me when an API breaks C

Monitors

developerCi scripting — stories about ci scripting in this arenaCi scripting2n/auntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

Send GraphQL, gRPC, WebSocket, and SSE requests, not just REST C

Protocols

developerCollections workspaces — stories about collections workspaces in this arenaCollections workspaces2n/auntestednone yet

Validate live responses against the API contract to catch drift C

Contract testing

platform-engineerTesting mocking — stories about testing mocking in this arenaTesting mocking2noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial4/10C

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 30 stories with headroom

What would move Kong’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product

    nonemoves Built-in AIimpact 45

    Missing: any documented in-product AI assistant/chat feature, evidence of task delegation to it, and independent confirmation of its use.

  2. Environments secrets — stories about environments secrets in this arenaSwitch requests between dev, staging, and prod using environment variable sets

    nonemoves PA Scoreimpact 30

    Missing: explicit environment/variable-set switching UI or config, evidence of per-environment variable collections, and any workflow tying such sets to request execution.

  3. Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models

    nonemoves PA Scoreimpact 30

    Missing: any documented feature or policy for preventing data from being used in model training (e.g., zero-retention enforcement, provider opt-out headers, data-use contracts).

  4. Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product

    nonemoves Built-in AIimpact 30

    Kong's evidence focuses on AI Gateway/MCP traffic management (routing LLM calls, semantic security, observability plugins) but none of it shows Kong itself analyzing a user's own API/traffic data to generate AI insights or suggestions inside the product (e.g., an AI copilot summarizing gateway usage or recommending config changes).

  5. Agenticness — how well agents can access and operate the productBuild against official SDKs

    nonemoves agent-readyimpact 30

    Evidence shows Kong offers CLIs (decK, kongctl), Admin/OpenAPI API directories, and Kong Manager UI, but no evidence of official client SDKs (e.g., language-specific libraries) for building against Kong Gateway/AI Gateway/Konnect APIs.

  6. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    Kong is an API/AI gateway product; the evidence covers proxying, MCP, LLM routing, logging, and OpenTelemetry metrics, but there is no mention of webhook subscription or event-driven notification delivery to AI-native consumers.

  7. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    While Kong publishes OpenAPI spec directories for its various APIs (kong-docs-9) and has extensive product documentation, no evidence in the pack describes API versioning conventions or any documented deprecation policy for Kong's own APIs (Admin API, Konnect API, AI Gateway API, etc.).

  8. Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools

    partialq4/10moves agent-readyimpact 27

    Missing: clear documentation of Kong itself invoking/using tools from a connected MCP server (client-side tool use), independent/hands-on confirmation of this workflow, and detail on how a user 'plugs in' an arbitrary third-party MCP server for Kong's own use.

Showing the top 8 of 30 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map14 surfaces · 30 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

6 of 14 testable claims verified · 0 contradictedintegrity 43/100

32 distinct capability claims found in Kong’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

6

Verified

8

Unverified

0

Contradicted

16

Undersold

Verified (10)
Unverified (25)
Undersold (16)
Claims outside our story set (1)

Real capability claims found in Kong’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Runs natively on Kubernetes via an official Ingress Controller

    source ↗
Suggest a story for these →

Business model

open-sourcefree-tierusage-basedenterprise-custom

Kong Gateway core is open source and free to self-host; Konnect SaaS adds a free tier, usage-based Plus, and custom Enterprise plans across the gateway runtimes and platform services.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score37 (Sep 3 '26)36 (Sep 16 '26)
Agent-ready47 (Sep 3 '26)48 (Sep 16 '26)

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

Agent surface uptime llms.txt down since Sep 11 '26 (30d, checked every 6h since Sep 8 '26)