# Envoy Gateway vs WSO2 API Manager

| Attribute | Envoy Gateway | WSO2 API Manager |
|---|---|---|
| **Vioscale score** | 59.6 (33% (low)) | 94.2 (33% (low)) |
| activity.commits_last_30d | 100 | - |
| adoption.dependent_repos | 0 | - |
| adoption.github_stars | 2,989 | - |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"self_hosted":true}` |
| description.long | Open-source gateway providing traffic management, security controls, and observability for Kubernetes applications following the Gateway API specification. Can be deployed either standalone or as part of a Kubernetes cluster. | A gateway platform that centralizes management of APIs and AI model traffic across cloud and self-hosted environments, with built-in cost controls, security policies, and monetization capabilities. |
| features.capabilities | `{"mtls":true,"hosting":"self","k8s_native":true,"oauth_oidc":true,"observability":true,"rate_limiting":true}` | `{"hosting":"both","k8s_native":true,"grpc_support":true,"monetization":true,"observability":true,"pricing_model":"free_open_source","rate_limiting":true,"graphql_gateway":true,"developer_portal":true,"plugin_ecosystem":"extensive","architecture_model":"open_source_proxy","request_transformation":true,"pii_redaction_and_data_masking_in_flight":true,"custom_rate_limiting_by_user_or_tenant_id":true,"universal_api_key_for_100_plus_llm_providers":true,"auto_fallback_routing_on_rate_limit_or_downtime":true,"organization_wide_cost_tracking_and_chargebacks":true,"semantic_caching_for_repeat_queries_and_cost_savings":true}` |
| integrations.count | - | 600 |
| integrations.list | - | `[{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Azure OpenAI"},{"name":"AWS Bedrock"},{"name":"Google Gemini"},{"name":"Mistral"},{"name":"AWS Bedrock Guardrails"},{"name":"Azure Content Safety"},{"name":"Moesif"},{"name":"Azure AI"},{"name":"Mistral AI"}]` |
| language.primary | Go | - |
| license.spdx | Apache-2.0 | - |
| market.availability | - | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"open_source","sourceUrl":"https://gateway.envoyproxy.io","retrievedAt":"2026-08-16T21:35:24.255Z"}` | `{"type":"open_source","plans":[{"free":true,"name":"Self-Hosted","summary":"Apache 2.0 licensed open source. No per-gateway fees or usage caps.","features":["Full lifecycle API management","Design and publish REST, GraphQL, WebSocket, Webhook APIs","Developer portal with try-it console","Multi-gateway support","Kubernetes and Docker deployment","Air-gapped environments","Distributed rate limiting and caching","API analytics","LLM gateway with multi-model routing","MCP gateway and tools discovery"],"contactSales":false}],"summary":"Free and open source. No per-gateway fees or usage caps.","freeTier":true,"sourceUrl":"http://wso2.com/asgardeo/pricing-old/","retrievedAt":"2026-08-13T16:53:43.456Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | open_source |
| pricing.price_level | free | free |
| pricing.transparent | - | yes |
| release.cadence_days | 6 | - |
| release.history | `[{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.9.0","date":"2026-08-15T12:31:24Z","type":"stable","version":"v1.9.0"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.9.0-rc.1","date":"2026-08-09T01:54:41Z","type":"prerelease","version":"v1.9.0-rc.1"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.8.3","date":"2026-07-22T18:59:16Z","type":"stable","version":"v1.8.3"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.5","date":"2026-07-08T15:36:49Z","type":"stable","version":"v1.7.5"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.8.2","date":"2026-07-01T07:14:42Z","type":"stable","version":"v1.8.2"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.8.1","date":"2026-06-05T07:32:33Z","type":"stable","version":"v1.8.1"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.4","date":"2026-06-05T07:55:38Z","type":"stable","version":"v1.7.4"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.8.0","date":"2026-05-13T15:45:46Z","type":"stable","version":"v1.8.0"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.3","date":"2026-05-09T23:13:52Z","type":"stable","version":"v1.7.3"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.8.0-rc.1","date":"2026-05-01T05:58:00Z","type":"prerelease","version":"v1.8.0-rc.1"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.6.7","date":"2026-04-27T20:16:54Z","type":"stable","version":"v1.6.7"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.2","date":"2026-04-17T01:33:18Z","type":"stable","version":"v1.7.2"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.6.6","date":"2026-04-16T14:08:03Z","type":"stable","version":"v1.6.6"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.6.5","date":"2026-03-13T02:12:48Z","type":"stable","version":"v1.6.5"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.1","date":"2026-03-12T17:15:44Z","type":"stable","version":"v1.7.1"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.6.4","date":"2026-02-11T18:48:14Z","type":"stable","version":"v1.6.4"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.5.9","date":"2026-02-11T17:32:53Z","type":"stable","version":"v1.5.9"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.0","date":"2026-02-05T22:23:47Z","type":"stable","version":"v1.7.0"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.0-rc.2","date":"2026-02-03T22:28:07Z","type":"prerelease","version":"v1.7.0-rc.2"},{"url":"https://github.com/envoyproxy/gateway/releases/tag/v1.7.0-rc.1","date":"2026-01-30T11:49:29Z","type":"prerelease","version":"v1.7.0-rc.1"}]` | - |
| reliability.status_page | - | yes |
| security.disclosure_policy | - | yes |
| security.gdpr | - | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.pci | - | yes |
| security.scorecard | 8 | - |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=helm&package_name=gateway-crds-helm%2Fgateway-crds-helm&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (API Gateways)

| Capability | Envoy Gateway | WSO2 API Manager |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud + self-hosted |
| Kubernetes-native | ✓ | ✓ |
| **Traffic** |  |  |
| Rate limiting | ✓ | ✓ |
| Request/response transformation | - | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | ✓ | - |
| Mutual TLS | ✓ | - |
| **Protocols** |  |  |
| GraphQL gateway | - | ✓ |
| gRPC support | - | ✓ |
| **Delivery** |  |  |
| Developer portal | - | ✓ |
| Monetization | - | ✓ |
| **Ecosystem** |  |  |
| Plugin ecosystem | - | Extensive |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:51:10.282Z. "-" = undocumented, not absent.*
