# Apache APISIX vs Gloo Gateway

| Attribute | Apache APISIX | Gloo Gateway |
|---|---|---|
| **Vioscale score** | 55.7 (54% (medium)) | 51.4 (33% (low)) |
| activity.commits_last_30d | 61 | - |
| adoption.dependent_repos | 1 | - |
| adoption.github_stars | 17,037 | - |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | A dynamic, high-performance gateway that routes and secures API traffic with built-in plugins for authentication, rate limiting, and observability. Runs anywhere from bare metal to Kubernetes with no vendor lock-in. | Enterprise-grade API gateway delivering high performance with flexibility for self-managed deployment. Handles 400k+ requests/sec, 7+ years in production, built on open-source Envoy with CNCF governance. |
| features.capabilities | `{"mtls":true,"hosting":"both","k8s_native":true,"oauth_oidc":true,"open_source":true,"grpc_support":true,"monetization":true,"observability":true,"pricing_model":"open-source-self-host","rate_limiting":true,"graphql_gateway":false,"deployment_model":"self-hosted","developer_portal":true,"plugin_ecosystem":"extensive","routing_strategy":"custom","streaming_support":true,"automatic_failover":false,"openai_compatible_api":false,"request_transformation":true}` | `{"hosting":"self","k8s_native":true,"grpc_support":true,"observability":true,"graphql_gateway":true,"request_transformation":true}` |
| integrations.count | 13 | - |
| integrations.list | `[{"name":"OpenAI"},{"name":"Anthropic"},{"name":"AWS Bedrock"},{"name":"DeepSeek"},{"name":"Ollama"},{"name":"gRPC"},{"name":"gRPC-Web"},{"name":"Open Policy Agent"},{"name":"Spring Boot"},{"name":"OAuth2"},{"name":"OpenID Connect"},{"name":"Keycloak"},{"name":"Istio"},{"name":"Kuma"},{"name":"AWS Lambda"},{"name":"Azure Serverless Function"},{"name":"Apache OpenWhisk"},{"name":"Vault"},{"name":"Dubbo"},{"name":"MQTT"},{"name":"etcd"}]` | - |
| language.primary | Lua | - |
| license.spdx | Apache-2.0 | - |
| platform.support | `{"cli":true,"linux":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"open_source","freeTier":true,"sourceUrl":"https://apisix.apache.org","retrievedAt":"2026-08-13T16:52:04.945Z"}` | `{"type":"hybrid","plans":[{"free":true,"name":"Open Source","summary":"Free, perpetual license","features":["Request routing by path, header, method, query parameter, host","Kubernetes Gateway API support","Traffic splitting and transformation","Multi-protocol support: REST, gRPC, GraphQL, WebSocket","Active community with regular releases"],"contactSales":false},{"free":false,"name":"Solo Enterprise","summary":"Contact sales for pricing","features":["24x7 Support SLA with guaranteed response times","N-3 Long Term Support with security patches and bug fixes","FIPS Compliant Images","Private Slack Channel with white-glove support"],"contactSales":true}],"summary":"Free open source forever. Enterprise support available.","freeTier":true,"sourceUrl":"https://www.solo.io/pricing","retrievedAt":"2026-08-13T17:04:52.281Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | open_source | freemium |
| pricing.price_level | free | low |
| pricing.transparent | yes | no |
| release.cadence_days | 61 | - |
| release.history | `[{"url":"https://github.com/apache/apisix/releases/tag/3.18.0","date":"2026-08-20T07:57:26Z","type":"stable","version":"3.18.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.17.0","date":"2026-06-16T07:22:13Z","type":"stable","version":"3.17.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.16.0","date":"2026-04-08T01:36:55Z","type":"stable","version":"3.16.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.15.0","date":"2026-02-05T13:55:04Z","type":"stable","version":"3.15.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.14.1","date":"2025-10-16T07:54:57Z","type":"stable","version":"3.14.1"},{"url":"https://github.com/apache/apisix/releases/tag/3.14.0","date":"2025-10-10T05:53:01Z","type":"stable","version":"3.14.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.13.0","date":"2025-06-27T07:28:29Z","type":"stable","version":"3.13.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.12.0","date":"2025-04-01T07:27:27Z","type":"stable","version":"3.12.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.11.0","date":"2024-10-17T03:20:22Z","type":"stable","version":"3.11.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.10.0","date":"2024-08-14T06:16:05Z","type":"stable","version":"3.10.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.9.1","date":"2024-04-24T07:56:23Z","type":"stable","version":"3.9.1"},{"url":"https://github.com/apache/apisix/releases/tag/3.8.1","date":"2024-04-29T03:06:26Z","type":"stable","version":"3.8.1"},{"url":"https://github.com/apache/apisix/releases/tag/3.9.0","date":"2024-03-25T10:09:53Z","type":"stable","version":"3.9.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.8.0","date":"2024-01-15T03:35:34Z","type":"stable","version":"3.8.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.7.0","date":"2023-11-21T00:57:26Z","type":"stable","version":"3.7.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.6.0","date":"2023-10-04T06:40:49Z","type":"stable","version":"3.6.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.5.0","date":"2023-09-01T15:55:01Z","type":"stable","version":"3.5.0"},{"url":"https://github.com/apache/apisix/releases/tag/3.2.2","date":"2023-07-22T16:32:15Z","type":"stable","version":"3.2.2"},{"url":"https://github.com/apache/apisix/releases/tag/3.4.1","date":"2023-07-20T09:42:19Z","type":"stable","version":"3.4.1"},{"url":"https://github.com/apache/apisix/releases/tag/3.4.0","date":"2023-06-30T12:07:12Z","type":"stable","version":"3.4.0"}]` | - |
| security.disclosure_policy | yes | yes |
| security.scorecard | 7.5 | - |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fapache%2Fapisix&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (API Gateways)

| Capability | Apache APISIX | Gloo Gateway |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Self-hosted only |
| Kubernetes-native | ✓ | ✓ |
| **Traffic** |  |  |
| Rate limiting | ✓ | - |
| Request/response transformation | ✓ | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | ✓ | - |
| Mutual TLS | ✓ | - |
| **Protocols** |  |  |
| GraphQL gateway | ✗ | ✓ |
| gRPC support | ✓ | ✓ |
| **Delivery** |  |  |
| Developer portal | ✓ | - |
| Monetization | ✓ | - |
| **Ecosystem** |  |  |
| Plugin ecosystem | Extensive | - |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:16:22.598Z. "-" = undocumented, not absent.*
