# AWS API Gateway vs Kong Gateway

**Leader by Vioscale score:** AWS API Gateway

| Attribute | AWS API Gateway | Kong Gateway |
|---|---|---|
| **Vioscale score** | 54.5 (41% (low)) | 49.4 (76% (high)) |
| activity.commits_last_30d | - | 1 |
| adoption.dependent_repos | - | 1 |
| adoption.github_stars | - | 44,043 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"hybrid":true,"self_hosted":true}` |
| description.long | A managed cloud service that handles the complete lifecycle of APIs—from creation and deployment to monitoring and security—including traffic management, authorization, throttling, and version control. | Kong provides a unified platform for building, testing, and governing APIs and AI agents. It handles both traditional API gateway functions—routing, rate limiting, authentication—and modern AI-specific concerns like token budgeting, context management, and LLM traffic control. Includes gateway, API management, testing tools, and event streaming capabilities. |
| features.capabilities | `{"hosting":"cloud","k8s_native":false,"grpc_support":false,"observability":true,"rate_limiting":true,"graphql_gateway":false,"developer_portal":true,"request_transformation":true}` | `{"mtls":true,"hosting":"both","k8s_native":true,"oauth_oidc":true,"monetization":true,"observability":true,"rate_limiting":true,"developer_portal":true,"plugin_ecosystem":"extensive","request_transformation":true}` |
| integrations.count | 10 | 11 |
| integrations.list | `[{"name":"AWS Lambda"},{"name":"Amazon CloudFront"},{"name":"Amazon CloudWatch"},{"name":"Amazon DynamoDB"},{"name":"Amazon S3"},{"name":"Amazon EC2"},{"name":"Amazon VPC"},{"name":"AWS PrivateLink"},{"name":"AWS Serverless Application Model"},{"name":"AWS IoT"}]` | `[{"name":"AWS Bedrock"},{"name":"Azure Content Safety"},{"name":"Google Cloud Model Armor"},{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Llama 3"},{"name":"Kubernetes"},{"name":"Helm"},{"name":"Git"},{"name":"Stripe"},{"name":"Twilio"}]` |
| language.primary | - | Lua |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"usage","plans":[{"free":false,"name":"HTTP APIs","summary":"1M free calls/month for 12 months; then $1.00/million (first 300M), $0.90/million above 300M","features":["1M free API calls per month for 12 months","Tiered pricing after free tier","Data transfer out charges apply"],"components":[{"per":{"qty":1000000,"unit":"requests"},"kind":"metered","amount":1,"currency":"USD"}],"description":"Pay per API call and data transfer out","contactSales":false,"includedLimits":{"free_tier_http_api_calls_per_month":"1M for 12 months (new AWS customers)"}},{"free":false,"name":"REST APIs","summary":"1M free calls/month for 12 months; then $3.50/million API calls (Edge Optimized/Regional)","features":["1M free API calls per month for 12 months","$3.50 per million for Edge Optimized/Regional APIs","No data transfer charges for Private APIs (PrivateLink charges apply)","Optional data caching at hourly rate"],"components":[{"per":{"qty":1000000,"unit":"requests"},"kind":"metered","amount":3.5,"currency":"USD"}],"description":"Pay per API call, data transfer, and optional caching","contactSales":false,"includedLimits":{"free_tier_rest_api_calls_per_month":"1M for 12 months (new AWS customers)"}},{"free":false,"name":"WebSocket APIs","summary":"1M free messages + 750k connection minutes/month for 12 months","features":["1M free messages per month for 12 months","750k free connection minutes per month for 12 months","Messages up to 128KB, metered in 32KB increments","Control frames (ping/pong) not metered"],"description":"Pay for messages sent/received and connection minutes","contactSales":false,"includedLimits":{"free_tier_messages_per_month":"1M for 12 months (new AWS customers)","free_tier_connection_minutes_per_month":"750000 for 12 months (new AWS customers)"}},{"free":false,"name":"API Gateway Portals","summary":"Monthly charge includes 10 PortalProducts with 40 REST endpoints each; additional PortalProducts billed separately","features":["Developer portal hosting","10 PortalProducts with 40 REST endpoints each included monthly","Additional PortalProducts billed separately","API discovery and documentation","Centralized governance","Prorated monthly charges"],"description":"Managed developer portals for API discovery and governance","contactSales":true,"includedLimits":{"portal_products":"10 per month","product_rest_endpoints":"40 per product"}}],"summary":"Usage-based pricing with no minimum fees or upfront commitments. HTTP APIs: $1.00/million calls; REST APIs: $3.50/million calls; data transfer charges apply. Free tier: 1M API calls per month for 12 months (new AWS customers). $200 free tier credit for new customers as of July 15, 2025.","currency":"USD","freeTier":true,"sourceUrl":"https://aws.amazon.com/api-gateway/pricing/","retrievedAt":"2026-08-16T20:53:52.220Z","startingPrice":{"amount":1,"period":"month","currency":"USD"},"billingPeriods":["month"]}` | `{"type":"subscription","currency":"USD","freeTier":true,"sourceUrl":"https://konghq.com","retrievedAt":"2026-08-14T11:10:49.823Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | low |
| pricing.transparent | yes | no |
| release.cadence_days | - | 29 |
| release.history | - | `[{"url":"https://github.com/Kong/kong/releases/tag/3.9.3","date":"2026-06-17T06:02:19Z","type":"stable","version":"3.9.3"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.2","date":"2026-06-04T07:12:53Z","type":"stable","version":"3.9.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.1","date":"2025-06-04T09:20:05Z","type":"stable","version":"3.9.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.0","date":"2024-12-13T04:17:54Z","type":"stable","version":"3.9.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.1","date":"2024-11-18T20:52:27Z","type":"stable","version":"3.8.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.0","date":"2024-09-11T09:19:15Z","type":"stable","version":"3.8.0"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.5","date":"2024-06-24T14:54:52Z","type":"stable","version":"2.8.5"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.1","date":"2024-06-21T09:38:32Z","type":"stable","version":"3.7.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.0","date":"2024-05-28T16:00:45Z","type":"stable","version":"3.7.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.1","date":"2024-03-04T14:19:57Z","type":"stable","version":"3.6.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.0","date":"2024-02-09T22:08:50Z","type":"stable","version":"3.6.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.5.0","date":"2023-11-08T09:50:40Z","type":"stable","version":"3.5.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.2","date":"2023-10-12T10:50:05Z","type":"stable","version":"3.4.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.1","date":"2023-10-03T10:33:19Z","type":"stable","version":"3.4.1"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.4","date":"2023-09-20T23:03:15Z","type":"stable","version":"2.8.4"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.0","date":"2023-08-09T15:57:37Z","type":"stable","version":"3.4.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.1","date":"2023-07-11T08:58:57Z","type":"stable","version":"3.3.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.0","date":"2023-05-18T17:19:41Z","type":"stable","version":"3.3.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.2","date":"2023-03-16T12:24:30Z","type":"stable","version":"3.2.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.1","date":"2023-03-01T09:04:00Z","type":"stable","version":"3.2.1"}]` |
| reliability.status_page | - | yes |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.pci | yes | yes |
| security.scorecard | - | 7.4 |
| security.soc2 | - | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2FKong%2Fkong&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (API Gateways)

| Capability | AWS API Gateway | Kong Gateway |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| Kubernetes-native | ✗ | ✓ |
| **Traffic** |  |  |
| Rate limiting | ✓ | ✓ |
| Request/response transformation | ✓ | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | - | ✓ |
| Mutual TLS | - | ✓ |
| **Protocols** |  |  |
| GraphQL gateway | ✗ | - |
| gRPC support | ✗ | - |
| **Delivery** |  |  |
| Developer portal | ✓ | ✓ |
| Monetization | - | ✓ |
| **Ecosystem** |  |  |
| Plugin ecosystem | - | Extensive |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:18:44.845Z. "-" = undocumented, not absent.*
