Skip to main content

Documentation

01

Getting Started with API Gateway

API Gateway provides a secure, scalable REST API platform with built-in authentication, rate limiting, and auto-generated OpenAPI documentation. Deploy your API in minutes with zero configuration required. Our platform handles authentication tokens, request throttling, and comprehensive API documentation automatically, so you can focus on building great products.

plain
curl -X GET https://api.gateway.com/v1/users \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" # Response { "status": "success", "data": [ { "id": "usr_123", "email": "user@example.com", "created_at": "2024-01-15T10:30:00Z" } ], "rate_limit": { "limit": 1000, "remaining": 999, "reset": 1705320600 } }

Frequently Asked Questions

How do I authenticate API requests?

All API requests require an API key passed in the Authorization header as a Bearer token. Generate your API key from the dashboard at /app/api-keys. Include the header 'Authorization: Bearer YOUR_API_KEY' with every request. Keys can be scoped with specific permissions and rotated at any time for security.

What rate limits apply to my account?

Rate limits vary by plan tier. Free accounts receive 1,000 requests per hour, Pro accounts get 10,000 requests per hour, and Enterprise plans offer custom limits. Rate limit headers are included in every response showing your current usage, remaining quota, and reset time. Monitor your usage in real-time at /app/usage.

How is the OpenAPI documentation generated?

API Gateway automatically generates OpenAPI 3.0 specification documents from your API endpoints. The documentation includes request/response schemas, authentication requirements, and example payloads. Access your interactive API docs through the dashboard, export the spec file, or integrate with tools like Swagger UI and Postman.

Can I customize rate limiting rules?

Yes, Pro and Enterprise plans support custom rate limiting configurations. Set different limits per endpoint, implement burst allowances, or create tiered limits based on API key permissions. Configure your rate limits at /app/rate-limits with granular control over time windows, quota thresholds, and response behavior.

What happens when I exceed my rate limit?

When you exceed your rate limit, the API returns a 429 Too Many Requests status code with details about when your quota resets. Your application should implement exponential backoff and respect the Retry-After header. Upgrade your plan at /pricing for higher limits, or contact our team for Enterprise custom quotas.

Is there a sandbox environment for testing?

Every account includes a dedicated sandbox environment with separate API keys and rate limits. Test your integration without affecting production data or consuming your live quota. Sandbox requests are clearly marked in your usage dashboard and support all the same features as production, including authentication and rate limiting.