# Gloo Gateway vs WSO2 API Manager

| Attribute | Gloo Gateway | WSO2 API Manager |
|---|---|---|
| **Vioscale score** | 51.4 (33% (low)) | 94.2 (33% (low)) |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"self_hosted":true}` |
| description.long | Enterprise-grade API gateway delivering high performance with flexibility for self-managed deployment. Handles 400k+ requests/sec, 7+ years in production, built on open-source Envoy with CNCF governance. | A gateway platform that centralizes management of APIs and AI model traffic across cloud and self-hosted environments, with built-in cost controls, security policies, and monetization capabilities. |
| features.capabilities | `{"hosting":"self","k8s_native":true,"grpc_support":true,"observability":true,"graphql_gateway":true,"request_transformation":true}` | `{"hosting":"both","k8s_native":true,"grpc_support":true,"monetization":true,"observability":true,"pricing_model":"free_open_source","rate_limiting":true,"graphql_gateway":true,"developer_portal":true,"plugin_ecosystem":"extensive","architecture_model":"open_source_proxy","request_transformation":true,"pii_redaction_and_data_masking_in_flight":true,"custom_rate_limiting_by_user_or_tenant_id":true,"universal_api_key_for_100_plus_llm_providers":true,"auto_fallback_routing_on_rate_limit_or_downtime":true,"organization_wide_cost_tracking_and_chargebacks":true,"semantic_caching_for_repeat_queries_and_cost_savings":true}` |
| integrations.count | - | 600 |
| integrations.list | - | `[{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Azure OpenAI"},{"name":"AWS Bedrock"},{"name":"Google Gemini"},{"name":"Mistral"},{"name":"AWS Bedrock Guardrails"},{"name":"Azure Content Safety"},{"name":"Moesif"},{"name":"Azure AI"},{"name":"Mistral AI"}]` |
| market.availability | - | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Open Source","summary":"Free, perpetual license","features":["Request routing by path, header, method, query parameter, host","Kubernetes Gateway API support","Traffic splitting and transformation","Multi-protocol support: REST, gRPC, GraphQL, WebSocket","Active community with regular releases"],"contactSales":false},{"free":false,"name":"Solo Enterprise","summary":"Contact sales for pricing","features":["24x7 Support SLA with guaranteed response times","N-3 Long Term Support with security patches and bug fixes","FIPS Compliant Images","Private Slack Channel with white-glove support"],"contactSales":true}],"summary":"Free open source forever. Enterprise support available.","freeTier":true,"sourceUrl":"https://www.solo.io/pricing","retrievedAt":"2026-08-13T17:04:52.281Z"}` | `{"type":"open_source","plans":[{"free":true,"name":"Self-Hosted","summary":"Apache 2.0 licensed open source. No per-gateway fees or usage caps.","features":["Full lifecycle API management","Design and publish REST, GraphQL, WebSocket, Webhook APIs","Developer portal with try-it console","Multi-gateway support","Kubernetes and Docker deployment","Air-gapped environments","Distributed rate limiting and caching","API analytics","LLM gateway with multi-model routing","MCP gateway and tools discovery"],"contactSales":false}],"summary":"Free and open source. No per-gateway fees or usage caps.","freeTier":true,"sourceUrl":"http://wso2.com/asgardeo/pricing-old/","retrievedAt":"2026-08-13T16:53:43.456Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | open_source |
| pricing.price_level | low | free |
| pricing.transparent | no | yes |
| reliability.status_page | - | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | - | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.pci | - | yes |
| security.soc2 | yes | yes |

## Capabilities (API Gateways)

| Capability | Gloo Gateway | WSO2 API Manager |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud + self-hosted |
| Kubernetes-native | ✓ | ✓ |
| **Traffic** |  |  |
| Rate limiting | - | ✓ |
| Request/response transformation | ✓ | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | - | - |
| Mutual TLS | - | - |
| **Protocols** |  |  |
| GraphQL gateway | ✓ | ✓ |
| gRPC support | ✓ | ✓ |
| **Delivery** |  |  |
| Developer portal | - | ✓ |
| Monetization | - | ✓ |
| **Ecosystem** |  |  |
| Plugin ecosystem | - | Extensive |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:39:56.264Z. "-" = undocumented, not absent.*
