Skip to content

APIs & gateways

An API platform lives on adoption. Standing up a gateway is a week's work. The hard part is making one that twenty teams choose to use, because onboarding takes minutes, the security model is consistent, and nobody has to ask permission to ship.

What I do

  • Gateway strategy. Choosing and combining AWS API Gateway, Azure APIM, Kong and Apigee for a hybrid or multi-cloud estate, with the reasoning written down.
  • Security governance. OAuth2/OIDC flows, mTLS, key rotation, and a single auth model (Okta, Auth0, Entra ID) across teams.
  • Lifecycle and developer experience. Versioning, deprecation, discovery, rate-limiting and quota, with self-service onboarding through infrastructure-as-code so the platform scales without a gatekeeper.

Evidenced by

  • Integration platform: an operations API behind JWT that gives the owning teams replay, pause and inspect without console access, which is what made a shared runtime adoptable at all.
  • Cloud Gateway: a federated AWS + Azure API platform serving 18–20 teams, with Terraform-driven onboarding that cut lead time from days to minutes and saved ~€250–300k a year.

Background: hands-on across all four major gateways; AWS Security – Specialty.