WSO2 API Manager is an industry-leading full lifecycle API management platform for building, integrating, securing, and exposing an enterprise's digital services as managed APIs in cloud, on-premises, and hybrid architectures. Fast-track your API strategy with all the capabilities needed by API designers, product managers, operations, and consumers.
WSO2 API Manager is an industry-leading full lifecycle API management platform for building, integrating, securing, and exposing digital services as managed APIs across cloud, on-premises, and hybrid environments. Whether you're integrating services, providing developer-friendly APIs, or ensuring enterprise-grade security and compliance, it offers the flexibility, scalability, and control required for modern API ecosystems.
Key capabilities include:
API Design and Development: With a user-friendly API Publisher, developers can create and deploy APIs adhering to industry-standard specifications such as OpenAPI and GraphQL. This makes it a valuable tool for businesses of all sizes to accelerate their API-first initiatives.
API Security: Security is built into every layer of the platform, including authentication, authorization, traffic encryption, rate limiting, visibility control, threat protection, and token introspection, ensuring robust API protection.
API Gateway: Route, throttle, and secure traffic with an API gateway that adapts to different deployment needs—centralized for traditional enterprise models or decentralized for cloud native scale, performance, and autonomy.
API Developer Portal: Enable API discovery and adoption with a customizable developer portal. It offers categorization, tagging, and advanced AI-assisted search to help developers quickly find and consume the right APIs.
API Analytics: In-depth dashboards provide insights into API usage, performance, error trends, and user behavior, enabling teams to make data-driven decisions and optimize API strategies.
Kubernetes-Native API Management with the WSO2 Kubernetes Gateway: This lightweight, scalable, cloud native gateway uses Kubernetes' full potential for dynamic API management, supporting the entire API lifecycle (design to monetization). It integrates seamlessly with DevOps workflows and offers a unified experience across hybrid and Kubernetes-native environments.
Unified Control Plane: WSO2 API Manager features a unified control plane that can manage and monitor a network of federated API gateways. This includes integration with external systems such as AWS API Gateway and Solace Event Broker, providing a consistent governance and observability experience across distributed API environments.
AI Gateway: Extend API management principles to AI services using WSO2’s AI Gateway. This includes applying guardrails to ensure safe and controlled prompt usage, quality-of-service (QoS) enforcement, semantic caching, and policy-based routing, enabling secure, observable, and governed AI service consumption.
API Governance: Empower organizations to implement consistent governance across the API lifecycle. This includes API versioning policies, access control, documentation requirements, conformance checks, approval workflows, lifecycle states, and integration with source control systems for audit and traceability.
Flexible Deployment Options: WSO2 API Manager supports a wide range of deployment models to meet enterprise needs, whether in public clouds, private data centers, hybrid setups, or modern containerized platforms such as Kubernetes.
Highlights
Interoperability with Open Standards - Achieve seamless interoperability between diverse systems without vendor lock-in, utilizing modern approaches with REST, GraphQL, and AsyncAPIs. Unlock collaborative innovation, long-term sustainability, enhanced security, and regulatory compliance. Strategically adopt modern service delivery and development paradigms while retaining vital legacy systems.
Open Source, Extensible, and Customizable - As the leading open source API management platform, WSO2 API Manager is extensible and customizable, serving enterprises from startups to established businesses. It handles diverse scenarios, offering user-friendly extension opportunities for authenticators, policies, mediations, API lifecycles, workflows, portals, and login pages.
Flexible Deployment Models and Seamless Service Discovery for Developers - WSO2 API Manager can be deployed in the cloud, on-premises, or in a hybrid environment. This gives you the flexibility to choose the deployment option that best meets your needs. You can also embed it within your own SaaS or on-premises solution for redistribution.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
The public offer includes a POC setup without a subscription. The private offer will include a subscription based on the number of cores specified in the contract.
$0.001
Usage
The public offer includes a POC setup without a subscription. The private offer will include a subscription based on the usage specified in the contract.
$0.001
Support
Public Offer does not include support. Private Offer will include support as specified in the contract.
This listing uses contract-based pricing with three dimensions. The public offer gives you a proof-of-concept setup with no subscription attached. To move into production, you agree to a private offer with terms set in your contract. Two dimensions size that private subscription: Cores, based on the number of cores you specify, and Usage, based on the usage level you specify. The Support dimension is separate. The public offer includes no support, while a private offer adds support at the level named in your contract. You negotiate quantities and terms directly with the vendor.
Top-of-mind questions for buyers
What counts as one core for the Cores dimension?
A core is a processing unit assigned to the software gateways and control plane running in your deployment. You specify the number of cores your production infrastructure will run in the contract. Billing tracks the core count named in that agreement, not per-API-call volume.
What drives cost — the Cores dimension or the Usage dimension?
Both apply under the private offer and appear together. The Cores dimension sizes cost by the number of cores in your deployment. The Usage dimension sizes cost by the usage level you specify. Which dominates depends on whether your deployment is core-heavy infrastructure or high-usage traffic.
Does the public offer include vendor support?
No. The public offer is a proof-of-concept setup with no subscription and no support attached. Support is a separate dimension available only through a private offer, at the level named in your contract. Support options can include incident response and query assistance as agreed in the contract terms.
wso2.com
Helpful?
Vendor refund policy
All purchases are final. No refund is applicable.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
WSO2 API Manager 4.7.0
Additional details
Usage instructions
To access the deployed WSO2 API Manager, follow the steps below:
1. Configure Local Host Entry
Obtain the public IP address of the VM.
Add the following entry to your local machine's /etc/hosts file:
<VM-PUBLIC-IP> am.wso2.com
2. Access the API Manager Portals
Once the host entry is configured, access the WSO2 API Manager portals via the following URLs:
API Publisher Portal: <https://am.wso2.com:9443/publisher>
API Developer Portal: <https://am.wso2.com:9443/devportal>
API Admin Portal: <https://am.wso2.com:9443/admin>
API Management Console: <https://am.wso2.com:9443/carbon>
3. View API Manager Server Logs
To monitor server logs:
SSH into the VM using its public IP address.
Username: ubuntu
Use the SSH key that was configured during instance launch.
WSO2 offers two types of support models - Basic Support and Enterprise Support.
Basic Support offers 12x5 support while Enterprise Support is 24x7 support. For more details, please refer to https://wso2.com/licenses/support-policy/5.9/.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for hardening, security configuration, and support.
WSO2 API Manager is an open-source, full-lifecycle API management platform: design, publish, secure, rate-limit, monetize and analyze APIs with a Publisher, a Developer Portal, an API Gateway, and a built-in Key Manager (OAuth2/OIDC/JWT) - all in one node. Unlike bare WSO2 AMIs that run on the embedded H2 dev database, ship the publicly known default wso2carbon.jks key, and expose the consoles with the static admin/admin password, this Lynxroute build is production-ready: a bundled local PostgreSQL for the shared and API-Manager databases, a freshly generated keystore and a random admin password at first boot, PostgreSQL bound to localhost, UFW pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no open-core feature gating, no vendor lock-in.
WSO2 Identity Server is a powerful, modern identity and access management solution for your on-premises or cloud environment. It enables organizations to deliver exceptional, trusted digital experiences to all types of users: internal workforce, external consumers, business customers or API consumers. Preferred by customer reviewers over Okta, WSO2 Identity Server offers a more compelling technical direction, better feature updates, and superior support quality.
This product has charges associated with it for hardening, security configuration, and support.
WSO2 Integrator: MI (formerly WSO2 Micro Integrator) is a configuration-driven enterprise service bus that mediates REST and SOAP APIs, JMS and RabbitMQ queues, file transfers and scheduled tasks, running as a JVM service alongside the WSO2 Integration Control Plane web console. This Lynxroute build is hardened and ready out of the box: per-instance admin passwords generated at first launch for both the console and the management API, regenerated TLS keystores, HTTPS-only administration, TLS 1.2 and 1.3 only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
Extensible, Feature-Rich Platform with Excellent Support
Reviewed on May 22, 2026
Review provided by G2
What do you like best about the product?
* Extensibility - ability to plug in custom mediation logic * Excellent product support * Feature full
What do you dislike about the product?
* Configuration and troubleshooting can be complex compared to others. However excellent product support resolves this
What problems is the product solving and how is that benefiting you?
* API Management * API lifecycle management * Authorization of APIs and API resources * Throttling
Shehzad S.
Flexible, Extensible Platform Built for Large Enterprises
Reviewed on May 22, 2026
Review provided by G2
What do you like best about the product?
The flexibility and extensibility of this platform is a strong bonus, specially for large Enterprises who cannot use cookie cutter implementations
What do you dislike about the product?
Product innovations specially in the realm of AI. But most other products are also trying to grapple with that challenge.
What problems is the product solving and how is that benefiting you?
High transaction volumes and extensibility for our main requirements, which are satisfied by WSO2
Octavio d.
Centralized API Management with Impeccable Security
Reviewed on May 15, 2026
Review provided by G2
What do you like best about the product?
I like how intuitive the WSO2 API Platform is and the ease of making changes. I also appreciate all the options it offers for security, design, management, optimization, and versatility. I find the applications part especially useful, as it allows me to limit access to API consumers by project and by method. Additionally, I found the initial setup very easy, and I find it very useful and effective to centralize the most important configurations in one file. The documentation is clear, which makes it easy to resolve any doubts.
What do you dislike about the product?
The costs and the images, lately the costs have increased significantly, making it no longer as profitable. On the other hand, the limitation on image downloads that they are going to implement further limits its profitability.
What problems is the product solving and how is that benefiting you?
I use WSO2 API Platform to have my APIs centralized, with security, certificate management, version control, and ease of changing endpoints, which allows for better management of business flows.
Consulting
Powerful Integration with a Steep Learning Curve
Reviewed on May 13, 2026
Review provided by G2
What do you like best about the product?
I use WSO2 API Platform to design, publish, secure, manage, and monitor APIs across multiple applications and services. I appreciate how it helps with API governance, authentication, traffic management, and integration between internal systems and external customers. The platform has robust integration capabilities, making it suitable for complex enterprise environments and scalable API management needs. These capabilities make it easier to connect different applications, legacy systems, and third-party services through standardized APIs, streamlining data exchange, reducing development efforts, and improving interoperability across systems.
What do you dislike about the product?
There's a steep learning curve, especially for new users, and the setup and configuration process can be quite complex. The installation, configuration, and environment setup require careful planning and technical expertise, especially for enterprise-scale deployments. It would help to have simplified configuration management, more beginner-friendly documentation, improved troubleshooting guides, and clearer error messages.
What problems is the product solving and how is that benefiting you?
I use WSO2 API Platform to design, publish, secure, manage, and monitor APIs across applications, handling API governance, authentication, traffic management, and integration with customers. It solves secure API exposure, centralized API governance, and seamless integration between systems.
Computer Software
WSO2 APIM enables control without vendor lock-in, making it exceptional for digital businesses.
Reviewed on Mar 19, 2026
Review provided by G2
What do you like best about the product?
WSO2 APIM is ideal for enterprises needing control, scalability and deep customization
What do you dislike about the product?
Major version jumps may require manual migration steps.
What problems is the product solving and how is that benefiting you?
Centrally manage API lifecycles (design → deprecation) across microservices