# Kong Gateway vs WSO2 API Manager

| Attribute | Kong Gateway | WSO2 API Manager |
|---|---|---|
| **Vioscale score** | 49.4 (76% (high)) | 94.2 (33% (low)) |
| activity.commits_last_30d | 1 | - |
| adoption.dependent_repos | 1 | - |
| adoption.github_stars | 44,043 | - |
| deployment.options | `{"cloud":true,"hybrid":true,"self_hosted":true}` | `{"cloud":true,"hybrid":true,"self_hosted":true}` |
| description.long | Kong provides a unified platform for building, testing, and governing APIs and AI agents. It handles both traditional API gateway functions—routing, rate limiting, authentication—and modern AI-specific concerns like token budgeting, context management, and LLM traffic control. Includes gateway, API management, testing tools, and event streaming capabilities. | A gateway platform that centralizes management of APIs and AI model traffic across cloud and self-hosted environments, with built-in cost controls, security policies, and monetization capabilities. |
| features.capabilities | `{"mtls":true,"hosting":"both","k8s_native":true,"oauth_oidc":true,"monetization":true,"observability":true,"rate_limiting":true,"developer_portal":true,"plugin_ecosystem":"extensive","request_transformation":true}` | `{"hosting":"both","k8s_native":true,"grpc_support":true,"monetization":true,"observability":true,"pricing_model":"free_open_source","rate_limiting":true,"graphql_gateway":true,"developer_portal":true,"plugin_ecosystem":"extensive","architecture_model":"open_source_proxy","request_transformation":true,"pii_redaction_and_data_masking_in_flight":true,"custom_rate_limiting_by_user_or_tenant_id":true,"universal_api_key_for_100_plus_llm_providers":true,"auto_fallback_routing_on_rate_limit_or_downtime":true,"organization_wide_cost_tracking_and_chargebacks":true,"semantic_caching_for_repeat_queries_and_cost_savings":true}` |
| integrations.count | 11 | 600 |
| integrations.list | `[{"name":"AWS Bedrock"},{"name":"Azure Content Safety"},{"name":"Google Cloud Model Armor"},{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Llama 3"},{"name":"Kubernetes"},{"name":"Helm"},{"name":"Git"},{"name":"Stripe"},{"name":"Twilio"}]` | `[{"name":"OpenAI"},{"name":"Anthropic"},{"name":"Azure OpenAI"},{"name":"AWS Bedrock"},{"name":"Google Gemini"},{"name":"Mistral"},{"name":"AWS Bedrock Guardrails"},{"name":"Azure Content Safety"},{"name":"Moesif"},{"name":"Azure AI"},{"name":"Mistral AI"}]` |
| language.primary | Lua | - |
| license.spdx | Apache-2.0 | - |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"subscription","currency":"USD","freeTier":true,"sourceUrl":"https://konghq.com","retrievedAt":"2026-08-14T11:10:49.823Z"}` | `{"type":"open_source","plans":[{"free":true,"name":"Self-Hosted","summary":"Apache 2.0 licensed open source. No per-gateway fees or usage caps.","features":["Full lifecycle API management","Design and publish REST, GraphQL, WebSocket, Webhook APIs","Developer portal with try-it console","Multi-gateway support","Kubernetes and Docker deployment","Air-gapped environments","Distributed rate limiting and caching","API analytics","LLM gateway with multi-model routing","MCP gateway and tools discovery"],"contactSales":false}],"summary":"Free and open source. No per-gateway fees or usage caps.","freeTier":true,"sourceUrl":"http://wso2.com/asgardeo/pricing-old/","retrievedAt":"2026-08-13T16:53:43.456Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | open_source |
| pricing.price_level | low | free |
| pricing.transparent | no | yes |
| release.cadence_days | 29 | - |
| release.history | `[{"url":"https://github.com/Kong/kong/releases/tag/3.9.3","date":"2026-06-17T06:02:19Z","type":"stable","version":"3.9.3"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.2","date":"2026-06-04T07:12:53Z","type":"stable","version":"3.9.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.1","date":"2025-06-04T09:20:05Z","type":"stable","version":"3.9.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.9.0","date":"2024-12-13T04:17:54Z","type":"stable","version":"3.9.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.1","date":"2024-11-18T20:52:27Z","type":"stable","version":"3.8.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.8.0","date":"2024-09-11T09:19:15Z","type":"stable","version":"3.8.0"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.5","date":"2024-06-24T14:54:52Z","type":"stable","version":"2.8.5"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.1","date":"2024-06-21T09:38:32Z","type":"stable","version":"3.7.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.7.0","date":"2024-05-28T16:00:45Z","type":"stable","version":"3.7.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.1","date":"2024-03-04T14:19:57Z","type":"stable","version":"3.6.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.6.0","date":"2024-02-09T22:08:50Z","type":"stable","version":"3.6.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.5.0","date":"2023-11-08T09:50:40Z","type":"stable","version":"3.5.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.2","date":"2023-10-12T10:50:05Z","type":"stable","version":"3.4.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.1","date":"2023-10-03T10:33:19Z","type":"stable","version":"3.4.1"},{"url":"https://github.com/Kong/kong/releases/tag/2.8.4","date":"2023-09-20T23:03:15Z","type":"stable","version":"2.8.4"},{"url":"https://github.com/Kong/kong/releases/tag/3.4.0","date":"2023-08-09T15:57:37Z","type":"stable","version":"3.4.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.1","date":"2023-07-11T08:58:57Z","type":"stable","version":"3.3.1"},{"url":"https://github.com/Kong/kong/releases/tag/3.3.0","date":"2023-05-18T17:19:41Z","type":"stable","version":"3.3.0"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.2","date":"2023-03-16T12:24:30Z","type":"stable","version":"3.2.2"},{"url":"https://github.com/Kong/kong/releases/tag/3.2.1","date":"2023-03-01T09:04:00Z","type":"stable","version":"3.2.1"}]` | - |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.gdpr | yes | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.pci | yes | yes |
| security.scorecard | 7.4 | - |
| security.soc2 | yes | yes |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2FKong%2Fkong&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (API Gateways)

| Capability | Kong Gateway | WSO2 API Manager |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud + self-hosted |
| Kubernetes-native | ✓ | ✓ |
| **Traffic** |  |  |
| Rate limiting | ✓ | ✓ |
| Request/response transformation | ✓ | ✓ |
| **Security** |  |  |
| OAuth2 / OIDC / JWT | ✓ | - |
| Mutual TLS | ✓ | - |
| **Protocols** |  |  |
| GraphQL gateway | - | ✓ |
| gRPC support | - | ✓ |
| **Delivery** |  |  |
| Developer portal | ✓ | ✓ |
| Monetization | ✓ | ✓ |
| **Ecosystem** |  |  |
| Plugin ecosystem | Extensive | Extensive |
| **Insight** |  |  |
| Observability | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:18:32.085Z. "-" = undocumented, not absent.*
