What are API Manager policies and what are the most commonly used ones?
Suggested answer
API Manager policies enforce governance on APIs at runtime (applied to the API gateway layer without changing the Mule application code). Common policies:
1. Rate Limiting: Restrict number of requests per time window (per API or per client).
2. Spike Control: Queue requests exceeding limits rather than rejecting them.
3. Client ID Enforcement: Require callers to pass a valid client_id and client_secret (registered in Exchange) in headers or query params.
4. OAuth 2.0 Access Token Enforcement: Validate Bearer tokens from an external OAuth provider.
5. JWT Validation: Validate JSON Web Tokens.
6. IP Allowlist/Blocklist: Restrict or deny traffic from specific IP ranges.
7. Header Injection: Add request/response headers automatically. Policies execute before the Mule flow — they are applied and managed in API Manager independent of the application deployment.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.