Gateway Sentry

Products / Web Protection / API Protection

Every Endpoint, Its Own Rules

Path-based rules, per-endpoint rate limits, and surgical blocking of abusive IPs, ranges, user agents, and methods, all declared at the edge in one rules engine.

per endpoint rate limitsglobal edge network2.1+ Tbps behind it

Built for APIs

Per-Endpoint Limits

Independent rate limits per path pattern, each with its own thresholds and burst allowances. Auth routes run tight while data APIs keep their headroom.

Surgical Blocking

Block abusive IPs, CIDR ranges, user agents, and HTTP methods per route, without touching the rest of your traffic. One noisy client is one rule, not an incident.

CORS at the Edge

Wildcard subdomain origins, credentials support, and configurable preflight caching, so your API code never sets a CORS header again.

Header Control

Strip Server and X-Powered-By, inject Strict-Transport-Security and friends, per route, with no application changes. The edge presents exactly the surface you choose.

Tight Where It Hurts

Authentication routes get strict thresholds because that is where credential stuffing lives; high-traffic data endpoints keep their headroom because that is where your product lives. Different limits per path pattern is the whole point.

No SDK, No Sidecar

Everything on this page is declared at the edge, so protecting an API is a routing decision, not a sprint. Moving an existing service over is covered in the migration guide.

Frequently Asked Questions

How does Gateway Sentry provide DDoS protection for an API gateway?
Gateway Sentry protects API gateways at the edge with path-based rules, per-endpoint rate limiting, and surgical blocking of abusive IPs, CIDR ranges, user agents, and HTTP methods. It runs across a global edge network backed by 2.1 Tbps of mitigation capacity, so attack traffic is absorbed before it reaches your origin.
Can I set different rate limits for different API endpoints?
Yes. You define independent per-endpoint rate limits per path pattern, each with its own thresholds and burst allowances. Limits can key on source IP, IP plus user agent, or path plus IP, so authentication routes get tighter limits while high-traffic data APIs get the headroom they need.
Does Gateway Sentry handle CORS and security headers for my API?
Yes. CORS is managed entirely at the edge with wildcard subdomain origins, credentials support, and configurable preflight caching, so your API code never sets a CORS header. You can also strip Server and X-Powered-By and inject headers like Strict-Transport-Security per route.
Do I need to change my application code to protect API endpoints?
No. Path-based protection, per-endpoint rate limits, CORS management, header control, method restrictions, and blocking are all declared in a single composable rules engine at the edge, with no application code changes required.
How is API threat protection priced?
API and web (L7) protection is usage-based pay-as-you-go at $30 per TB plus $0.55 per million requests, with no commitment. You can review the full breakdown on the pricing page.

Get Protected in Minutes

Point your DNS at the edge and deploy rules from one dashboard. No code changes.