Products / Web Protection / API Protection
Every Endpoint, Its Own Rules
Path-based rules, per-endpoint rate limits, and surgical blocking of abusive IPs, ranges, user agents, and methods, all declared at the edge in one rules engine.
Built for APIs
Per-Endpoint Limits
Independent rate limits per path pattern, each with its own thresholds and burst allowances. Auth routes run tight while data APIs keep their headroom.
Surgical Blocking
Block abusive IPs, CIDR ranges, user agents, and HTTP methods per route, without touching the rest of your traffic. One noisy client is one rule, not an incident.
CORS at the Edge
Wildcard subdomain origins, credentials support, and configurable preflight caching, so your API code never sets a CORS header again.
Header Control
Strip Server and X-Powered-By, inject Strict-Transport-Security and friends, per route, with no application changes. The edge presents exactly the surface you choose.
Tight Where It Hurts
Authentication routes get strict thresholds because that is where credential stuffing lives; high-traffic data endpoints keep their headroom because that is where your product lives. Different limits per path pattern is the whole point.
No SDK, No Sidecar
Everything on this page is declared at the edge, so protecting an API is a routing decision, not a sprint. Moving an existing service over is covered in the migration guide.
Frequently Asked Questions
How does Gateway Sentry provide DDoS protection for an API gateway?
Can I set different rate limits for different API endpoints?
Does Gateway Sentry handle CORS and security headers for my API?
Do I need to change my application code to protect API endpoints?
How is API threat protection priced?
Get Protected in Minutes
Point your DNS at the edge and deploy rules from one dashboard. No code changes.