# Gloo Gateway vs Kong Gateway

| Attribute | Gloo Gateway | Kong Gateway |
|---|---|---|
| **Vioscale score** | 51.4 (33% (low)) | 49.4 (76% (high)) |
| activity.commits_last_30d | - | 1 |
| adoption.dependent_repos | - | 1 |
| adoption.github_stars | - | 44,043 |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"self_hosted":true}` |
| description.long | Enterprise-grade API gateway delivering high performance with flexibility for self-managed deployment. Handles 400k+ requests/sec, 7+ years in production, built on open-source Envoy with CNCF governance. | Kong provides a unified platform for building, testing, and governing APIs and AI agents. It handles both traditional API gateway functions—routing, rate limiting, authentication—and modern AI-specific concerns like token budgeting, context management, and LLM traffic control. Includes gateway, API management, testing tools, and event streaming capabilities. |
| features.capabilities | `{"hosting":"self","k8s_native":true,"grpc_support":true,"observability":true,"graphql_gateway":true,"request_transformation":true}` | `{"mtls":true,"hosting":"both","k8s_native":true,"oauth_oidc":true,"monetization":true,"observability":true,"rate_limiting":true,"developer_portal":true,"plugin_ecosystem":"extensive","request_transformation":true}` |
| integrations.count | - | 11 |
| integrations.list | - | `[{"name":"AWS Bedrock"},{"name":"Azure Content Safety"},{"name":"Google Cloud Model Armor"},{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Llama 3"},{"name":"Kubernetes"},{"name":"Helm"},{"name":"Git"},{"name":"Stripe"},{"name":"Twilio"}]` |
| language.primary | - | Lua |
| license.spdx | - | Apache-2.0 |
| market.availability | - | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Open Source","summary":"Free, perpetual license","features":["Request routing by path, header, method, query parameter, host","Kubernetes Gateway API support","Traffic splitting and transformation","Multi-protocol support: REST, gRPC, GraphQL, WebSocket","Active community with regular releases"],"contactSales":false},{"free":false,"name":"Solo Enterprise","summary":"Contact sales for pricing","features":["24x7 Support SLA with guaranteed response times","N-3 Long Term Support with security patches and bug fixes","FIPS Compliant Images","Private Slack Channel with white-glove support"],"contactSales":true}],"summary":"Free open source forever. Enterprise support available.","freeTier":true,"sourceUrl":"https://www.solo.io/pricing","retrievedAt":"2026-08-13T17:04:52.281Z"}` | `{"type":"subscription","currency":"USD","freeTier":true,"sourceUrl":"https://konghq.com","retrievedAt":"2026-08-14T11:10:49.823Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | low |
| pricing.transparent | no | no |
| release.cadence_days | - | 29 |
| release.history | - | `[{"url":"https://github.com/Kong/kong/releases/tag/3.9.3","date":"2026-06-17T06:02:19Z","type":"stable","version":"3.9.3"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.2","date":"2026-06-04T07:12:53Z","type":"stable","version":"3.9.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.1","date":"2025-06-04T09:20:05Z","type":"stable","version":"3.9.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.0","date":"2024-12-13T04:17:54Z","type":"stable","version":"3.9.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.1","date":"2024-11-18T20:52:27Z","type":"stable","version":"3.8.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.0","date":"2024-09-11T09:19:15Z","type":"stable","version":"3.8.0"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.5","date":"2024-06-24T14:54:52Z","type":"stable","version":"2.8.5"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.1","date":"2024-06-21T09:38:32Z","type":"stable","version":"3.7.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.0","date":"2024-05-28T16:00:45Z","type":"stable","version":"3.7.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.1","date":"2024-03-04T14:19:57Z","type":"stable","version":"3.6.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.0","date":"2024-02-09T22:08:50Z","type":"stable","version":"3.6.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.5.0","date":"2023-11-08T09:50:40Z","type":"stable","version":"3.5.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.2","date":"2023-10-12T10:50:05Z","type":"stable","version":"3.4.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.1","date":"2023-10-03T10:33:19Z","type":"stable","version":"3.4.1"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.4","date":"2023-09-20T23:03:15Z","type":"stable","version":"2.8.4"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.0","date":"2023-08-09T15:57:37Z","type":"stable","version":"3.4.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.1","date":"2023-07-11T08:58:57Z","type":"stable","version":"3.3.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.0","date":"2023-05-18T17:19:41Z","type":"stable","version":"3.3.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.2","date":"2023-03-16T12:24:30Z","type":"stable","version":"3.2.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.1","date":"2023-03-01T09:04:00Z","type":"stable","version":"3.2.1"}]` |
| reliability.status_page | - | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | - | yes |
| security.pci | - | yes |
| security.scorecard | - | 7.4 |
| security.soc2 | yes | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2FKong%2Fkong&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (API Gateways)

| Capability | Gloo Gateway | Kong Gateway |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud + self-hosted |
| Kubernetes-native | ✓ | ✓ |
| **Traffic** |  |  |
| Rate limiting | - | ✓ |
| Request/response transformation | ✓ | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | - | ✓ |
| Mutual TLS | - | ✓ |
| **Protocols** |  |  |
| GraphQL gateway | ✓ | - |
| gRPC support | ✓ | - |
| **Delivery** |  |  |
| Developer portal | - | ✓ |
| Monetization | - | ✓ |
| **Ecosystem** |  |  |
| Plugin ecosystem | - | Extensive |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T17:08:07.830Z. "-" = undocumented, not absent.*
