Tyk Cloud, Hybrid & Self Managed API Management logo

    Tyk Cloud, Hybrid & Self Managed API Management

    Tyk is a high-performance API gateway and full lifecycle API management platform built for enterprises and engineered for scale. The Tyk platform provides governance and tooling for API design, security, governance, and automation, enabling teams to build, scale, govern and automate APIs efficiently while minimizing operational overhead. Built for open standards, enterprises can accelerate development, drive innovation, and create differentiated digital experiences through open standards and a scalable architecture.

    Ratings and reviews

    4.4
    57 ratings
    2 star
    1 star
    65%
    33%
    2%
    0%
    0%
    4 AWS reviews
    |
    53 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (57)
    Svetoslav Georgiev

    Modern API workflows have accelerated delivery and now need clearer security and AI governance

    Reviewed on Aug 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    As a platform architect for contact center solutions, TyK serves as the primary Middleware & API Gateway/Proxy between Genesys Cloud, Salesforce, and other back-end systems at the company.

    All customer lookups from the customer front-end portal are converted into REST calls to the back-end system and CRM when customers reach and identify with a particular number. Tyk is being used as an API Gateway via REST interfaces. Similar integrations include converting voice input into a string using Tyk back-end speech APIs, such as Google Cloud Speech-to-Text or Azure Speech Services. The concept remains the same: the front-end passes input, authenticates via OAuth2, and sends it to the back-end; the back-end does the reverse. In some use cases, the input could be decoded and encoded.

    The interface has been managed primarily by developers and system analysts from the middleware team, who have configured specific message inputs. It appeared convenient and user-friendly for their agile delivery processes

    How has it helped my organization?

    Flexibility, cost efficiency, and scalability are some of the strategic key benefits worth mentioning

    What is most valuable?

    From a security perspective, the authentication methods we have been using and the ability to easily switch between OAuth and OAuth2 are valuable. Tokenization and all pipeline chain controls are important, as is the ability to use standard protocols in the business, such as REST, SOAP, JSON, AsyncAPI, and MCP for AI agents.

    Monitoring, logging, and troubleshooting capabilities are quite satisfying

    Again, cost is definitely a key factor. A migration from TIBCO middleware to Tyk was driven by cost in many organizations. What I noticed is that the time-to-market was decent, and colleagues were quicker to deliver certain services and new requests from client platforms. It was a positive and smooth experience overall.

    Regarding time-to-market, on average, a new service request would arrive within average two sprints when using Agile delivery. It was much quicker and provided an easy way to test in the environment.

    What needs improvement?

    Documentation and consultancy could've been better. In the end, we managed to gather all the information and knowledge needed for my integration from various sources. Structured product information that is accessible to the end technical users can add value. Also, tooling for automated generation of the interface descriptions/agreements would be quite valuable

    Occasionally, slower performance and glitches may occur, but several factors could be influencing this.

    More information on security concepts and development would have been helpful to me. In the new landscape of AI agents and tools, I am not quite sure about governance. I would like to learn more about the governance model and existing out-of-the-box APIs & features to understand how I can enhance them when needed.

    Scalability appears to be good based on what I have seen. The API definitions were a little difficult for me to understand, but I am not a developer. There were some problems with rate limits, and in certain cases, the capacity was in question. I believe this has to do with proper scalability and upgrades across the entire cluster, since Tyk itself was not hosted within the company but in the cloud.

    For how long have I used the solution?

    I migrated my systems and started using TyK in 2022, marking four years of use.

    What do I think about the stability of the solution?

    Tyk is stable and exceeded expectations. Still, certain glitches can occur mentioned earlier

    What do I think about the scalability of the solution?

    My impression is that Tyk is pretty capable and scalable.

    How are customer service and support?

    The support is good, but we go through an integrator, so the support is not directly to Tyk as an organization.

    Which solution did I use previously and why did I switch?

    The company has been using TIBCO middleware and Data Power for quite some time. It was primarily based on SOAP, not on REST or other services. It was an on-premises solution that worked very well and met the enterprise integration needs, but was occasionally difficult to implement and significantly more expensive than Tyk.

    How was the initial setup?

    The transition was smooth overall. It was flexible and an open-source product that exceeded my expectations when the migration was initiated and the product was chosen. The migration, which was a phased approach, was positive and flexible. I rate the product between a seven and eight out of ten for overall quality. There are several improvements that I would expect to meet enterprise organization needs, but overall it was a positive experience.

    What about the implementation team?

    The implementation was handled through a service integrator that my company was working with.

    Which other solutions did I evaluate?

    Tyk was cheaper than some alternatives. The cost indications were pretty positive, and the pricing was provided by a third-party supplier.

    What other advice do I have?

    I would rate Tyk a solid seven (+) out of ten overall.

    I have the feeling that I do not have enough information or insight into certain features, but I know that Tyk provides multiple authentication mechanisms, including API keys, OAuth2 (which I used primarily), and basic authentication for some things. With AI and the new world of AI, I believe we will see an increasing need for fine-grained access, down to the endpoint or even the message control protocol level. I know that Tyk has a gRPC gateway that I am not familiar with, and perhaps this is in the right direction. Access lists, customer-specific IP restrictions, and policies are all in the right direction. However, as with any organization, we are still in the early implementation stages and will likely face some challenges. Security has become a major problem. There has been a recent major security breach in which Tyk has also been part of the pipeline.

    Regarding AI capabilities, I have limited experience, but I believe Tyk covers the main needs and is a generic product in that sense. I would be curious to learn more about it, and I would be happy to receive more input from the company, or at least a reference where I could find information about its capabilities. For example, how AI could be used in building up services within AI. I cannot provide further input on that yet, but I am open to learning more.

    I would expect Tyk and Salesforce to have more specific, service-oriented collaboration. I have noticed some challenges for my middleware colleagues when implementing services and invoking Salesforce and customer custom back-end APIs, though nothing in particular.

    What I felt with the implementation of Tyk is that it required fewer senior and more deep experts in middleware development and architecture. A less complicated product implementation meant fewer deep-custom-knowledge experts were needed. This is positive feedback because it looks like a more comprehensive and modern product. In the previous situation, much more deep custom knowledge was required.

    My advice would be to have clear use cases and do the homework well in advance. I mean to prepare for the selection process and to look not only at the current set of features but to discuss what is on the roadmap, expected growth, and especially the API needs, how things are going, the cost model, and the licenses. These are generally important inputs for the selection process.

    SaurabhKumar10

    Secure banking APIs have protected sensitive transactions and support daily compliance monitoring

    Reviewed on Aug 25, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Tyk is that it functions as an API gateway and API management platform in our organization. It is used to secure, expose, manage, monitor, and control API access in an enterprise environment. In our day-to-day operations, Tyk supports our cloud-native and microservice-based architecture application, which consists of multi-backend services that need to communicate securely and effectively. Tyk acts as a centralized gateway between clients and vendors in our application. It works for our mobile app, web application, partner, third-party, and backend services. Instead of allowing users to directly access the backend APIs, all requests are routed through Tyk, which ensures security and scalability.

    In one of our projects in banking, we use Tyk to secure our application. Our application belongs to the banking domain and is specifically for the credit card department. I work with the support team for an API hosted behind Tyk API gateway in the production banking environment. My responsibility for that particular application includes monitoring API health, troubleshooting, and analyzing 4xx to 5xx errors and Tyk API logs, and validating backend connectivity. In one incident, we received a report of a customer facing an HTTP 500 error while onboarding through our API. We investigated Tyk gateway logs and traced the request path, which identified a failed backend microservice deployment. After that, we coordinated with the deployment team, rolled back the deployment, restored service, and monitored the API traffic through Tyk to ensure stability, scalability, and security. Additionally, we have a service mesh team that also wanted to use Tyk. They used Tyk support to deploy their application, with us functioning as a control plane and them as a data plane. If they want to use and onboard any kind of API through Tyk, they usually connect with us, and we help them onboard the API through Tyk API for their application.

    Regarding my main use case for Tyk, it is very secure, more reliable, and encrypted for the application. If we have a banking application, every request goes through Tyk API, which is much more secure. This is a brilliant aspect of the solution.

    What is most valuable?

    Tyk offers many valuable features. For the API, the best features include API security such as API key authentication, JWT tokens, barriers, and OIDC. There is rate limiting and throttling to control how many requests a user can make at one time, such as 100 requests per minute or 1000 requests per minute. API gateway routing and load balancing are handled very smoothly, and API analytics and monitoring are comprehensive. Request-response transformations allow us to track customer ID and monitor how many requests can go to the API versioning. Tyk gives Kubernetes and cloud-native support, including Kubernetes, Docker, and AWS, depending on the cloud-native and cloud-based platform. Logging and troubleshooting capabilities are among the best features.

    In terms of product benefits, Tyk secures the credit card API, protects the payment API, monitors transactions, handles traffic spikes, reduces downtime, troubleshoots with failover, and improves application reliability.

    Tyk has positively impacted my organization as it is not just an API gateway but has become a critical business platform that helps organizations securely expose, manage, monitor, and scale their APIs in the modern banking domain, fintech, and commercial insurance environments in cloud-native settings. Almost every application communicates through APIs, and Tyk ensures that the API remains secure, scalable, and has high availability.

    What needs improvement?

    There are many features in Tyk, but a few things need to be improved from the developer side. Some of the features are a bit slow, but that can be worked on. I believe that the upgrade will come soon.

    For how long have I used the solution?

    I have been using Tyk for the past four years.

    What other advice do I have?

    For the API security and monitoring features in my daily work, if I am working on production deployment and support, the API security task involves investigating 401 unauthorized errors and conducting daily checks, verifying JWT token validity, token expiry validation, and API gateway operations. An example would be an issue where a customer is unable to access the credit card API due to an expired JWT token. API key management is part of my daily activity as well, including creating API keys, managing new consumers, revoking compromised keys, and updating access permissions. We work on access control validation, SSL and TLS certificate monitoring, renewals, and production issues, and conduct security incident investigations as part of API monitoring tasks such as API status and response time monitoring. We use these kinds of services from Tyk on a daily basis.

    I have noticed outcomes such as secure and faster onboarding since using Tyk. There are no issues, and it is done in a secure way, using the encrypted method that Tyk uses to onboard the API application for the other teams.

    Regarding Tyk's governance and security, it truly follows compliance and security standards, and it is provided through encrypted APIs, API tokens, and security keys, with reliability and encrypted password tokens. Everything is excellent and well-designed.

    Concerning Tyk's accuracy and reliability of output, accuracy is really fast, and reliability is also very secure. The accuracy is 99 percent out of 100. The latency for the request response time is excellent and very good.

    I would say Tyk is better than other applications as it is much more reliable, secure, scalable, and it delivers faster results for the application. Tyk is not just an application; it is a critical business platform that helps organizations secure, expose, manage, monitor, and scale their applications.

    I would rate Tyk an 8 out of 10 because I see they need some improvement on the slowness. Tyk is truly brilliant and the best, but some of the product services are quite slow, not excessively, but that is adjustable. I hope that another fix will come from the developer, and it will work faster.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Gilson Watanabe

    Gateway has improved API security and has simplified authentication and rate limiting concepts

    Reviewed on Aug 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    At the time, my main use case for Tyk was more for security and exposure matters related to business. Part of what I was trying to solve with Tyk was authentication, access control, request volume, protection, and a bit of protection against code injection such as SQL Injection, and from there on it was already extras.

    What is most valuable?

    In my opinion, the best features that Tyk offers were the rate limiting and authentication themselves.

    The positive impact was more in terms of understanding because the other tools I evaluated were harder to understand how to use and how to configure. In that respect, I found it much more intuitive and it helped me better understand the concepts and the functioning itself, which I thought was easier to use. I noticed the ease of configuration and the knowledge itself.

    What needs improvement?

    I cannot really say much about Tyk because it has probably already improved significantly since the last time I used it. I chose the number eight because I think at the time I ended up using the version and I had not found, or there was not, a way for me to install it locally to study and learn a way of using the tool.

    For how long have I used the solution?

    In IT itself, it has been more than twenty years, but in software architecture specifically I would say it has been at least about fifteen years.

    What do I think about the stability of the solution?

    Tyk was stable even during the tests I performed.

    What do I think about the scalability of the solution?

    I did not run any tests regarding scalability or performance, and I did not run any test in that sense.

    How are customer service and support?

    I was well served regarding customer support during my evaluation period, but I only used email contact at the time. Regarding questions themselves, not necessarily support, I used only the official documentation available on the website itself.

    Which solution did I use previously and why did I switch?

    I evaluated other options before choosing Tyk. I had evaluated Axway's, IBM's, Kong's, Google's, and I think a couple more that I do not remember off the top of my head.

    How was the initial setup?

    Tyk was implemented in my environment during this evaluation period in the provider's own cloud.

    What was our ROI?

    In terms of return on investment, it was more in terms of learning, as it was the tool that I suggested to other people to start learning and using the concepts of. It was more in the sense of knowledge sharing itself.

    Which other solutions did I evaluate?

    I did not use a different solution for this type of need yet; it was a proposal exactly to choose a solution for that.

    What other advice do I have?

    As it was more experimental, I also did not end up using it in production or in real cases. As it was in isolation, I do not have anything to add, but probably if it had gone ahead there might have been some integration with the company's security control. It is difficult to say regarding advice I would give to other people who are thinking about using Tyk. As it has been a long time since I did this evaluation, probably a lot has changed since then, and I do not think I have anything else to add beyond what has already been asked. I would rate this review an eight.
    Lew M.

    Full-Featured API Gateway with Powerful Open-Source and Pro Capabilities

    Reviewed on Aug 06, 2026
    Review provided by G2
    What do you like best about the product?
    First, it has full-fledge of capabilities, such as api routings, rate limiting, middleware etc. Second, it has both open-source and professional. Even open-source version is full of useful functionalities.
    What do you dislike about the product?
    Last time I use Tyk (not open-source), and it requires a token. Maybe can increase the duration of the token to enhance user experience. It will be helpful for new user to explore the functionality of Tyk.
    What problems is the product solving and how is that benefiting you?
    1. API routing -> route API
    2. Rate Limiting -> rate limit api request
    3. Custom middleware -> custom function adds before/after api request
    4.

    These functionalities help me to solve the development requirements in my job.
    Shubham C.

    Flexible, Reliable API Gateway That Scales Smoothly

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    I've been using Tyk for a few years now, and one of the things I appreciate most is how flexible it is. We use it to manage a fairly large set of APIs, and it's been reliable even as our traffic has grown.

    The UI is clean enough to get most day-to-day work done without digging through documentation, and for anything more advanced, the API and configuration options give you a lot of control. Integrating with OAuth, JWT, rate limiting, analytics, and different backend services has been straightforward.

    Performance has also been solid. The gateway introduces very little overhead, and we've been able to scale without running into bottlenecks. Overall, it strikes a good balance between ease of use and the level of customization backend teams usually need.

    The documentation is generally good, but when you're implementing less common integrations or debugging edge cases, it sometimes requires a bit of trial and error. I also think the AI capabilities could be expanded further; for example, suggesting policy optimizations, detecting unusual traffic patterns, or helping troubleshoot gateway configurations would save engineers a lot of time.

    Pricing may also feel a bit steep for smaller teams, although for larger deployments the value becomes much easier to justify.
    What do you dislike about the product?
    There are a few areas that could be improved. While the UI works well for common tasks, some advanced configurations can feel spread across different sections, so it takes time to find exactly what you're looking for.

    The documentation is generally good, but when you're implementing less common integrations or debugging edge cases, it sometimes requires a bit of trial and error. I also think the AI capabilities could be expanded further for example, suggesting policy optimizations, detecting unusual traffic patterns, or helping troubleshoot gateway configurations would save engineers a lot of time.

    Pricing may also feel a bit steep for smaller teams, although for larger deployments the value becomes much easier to justify.
    What problems is the product solving and how is that benefiting you?
    Before using Tyk, we had API authentication, rate limiting, and access policies implemented differently across services, which made maintenance difficult and onboarding new APIs time-consuming. Every new integration required additional custom work, and troubleshooting production issues wasn't always straightforward.

    With Tyk, we now have a centralized API gateway where security, traffic management, analytics, and integrations are managed consistently. Onboarding new APIs is much faster—we've reduced the setup time by around **40-50%**, and developers can focus on business logic instead of reinventing gateway functionality.

    The platform has also been reliable under production traffic, with minimal latency overhead and good visibility into API usage and performance. The built-in integrations with authentication providers and monitoring tools have simplified operations, while the intuitive UI makes routine management easy even for engineers new to the platform.

    From an ROI perspective, Tyk has helped reduce operational effort and maintenance costs by eliminating duplicated gateway logic across services. The support team has also been responsive whenever we've needed assistance. Looking ahead, I'd like to see stronger AI-driven capabilities, such as intelligent policy recommendations and proactive anomaly detection, but overall it's been a solid investment for managing APIs at scale.
    Siddhant S.

    Powerful, Hands-Off API Gateway with Flexible Plugins and Easy Self-Hosting

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    Honestly, the thing I like most is that Tyk just gets out of the way and lets us do our job. The open source version already has pretty much everything you'd want in an API gateway. Rate limiting, quotas, JWT and OIDC auth, transformations. So we didn't have to fight for budget just to cover the basics.

    We've also gotten a lot of mileage out of the custom plugins. Being able to drop in our own Go middleware for business logic is something I didn't realise I needed until I had it. Self hosting was painless, and it's nice knowing there's no phone home stuff running in the background. Once it was up, it kind of just worked. Uptime's been solid, the dashboard is easy enough that even newer folks on the team can find their way around, and we haven't had to babysit it.
    What do you dislike about the product?
    The documentation is probably my biggest gripe. It covers the basics well but once you get into anything advanced, like custom plugins or edge cases with auth, you end up digging through GitHub issues or community threads to piece things together. A few more real world examples and video walkthroughs would go a long way.

    The learning curve is also steeper than it looks at first. Tyk is powerful, but figuring out how APIs, policies, keys, and security profiles all fit together takes time, especially if you're coming in fresh. And while the dashboard analytics are useful for quick checks, they're pretty basic. If you want proper insight into API usage and performance, you end up pushing data out to another tool anyway.
    What problems is the product solving and how is that benefiting you?
    Before Tyk, we had auth, rate limiting, and routing logic scattered across different services, and every team was kind of doing their own thing. Tyk gave us one place to handle all of that, so our backend services can just focus on business logic instead of reinventing the same middleware over and over.

    It's also made onboarding new APIs a lot faster. Spinning up a new endpoint with proper auth, quotas, and monitoring used to be a whole project. Now it's mostly configuration. The self hosted setup means we keep full control over our data and traffic, which was a hard requirement for us, and the plugin system lets us handle the weird custom stuff without waiting on a vendor roadmap.

    Overall it's saved us a lot of engineering time and given us way more confidence in how we expose and secure our APIs.
    Anonymous

    Efficient API Management with Seamless Security

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    I use Tyk as an API gateway to expose our backend APIs securely. I appreciate how Tyk centralizes API management, which is really beneficial. I like the API management features, specifically authentication, rate limiting, and routing versioning, which help secure our APIs and manage traffic efficiently. The initial setup of Tyk was easy, and this tool has really streamlined our processes.
    What do you dislike about the product?
    n
    What problems is the product solving and how is that benefiting you?
    I use Tyk to securely expose our backend APIs, centralizing API management. It helps secure APIs, manage traffic efficiently with features like authentication, rate limiting, and routing versioning.
    Abhishek C.

    Technical Evaluations and features of Ttk API Gateway

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    What i like most about tyk is its simplicity and flexibility if comparing with other tool i have worked on nginx, kong gatewayand traefik as well but the easiness tyk comes up with its excellent also about the pricing part which makes it more valueable. About the interation with our product application is really good. so the overall performance is very good as comparing with other market tools. and the onboarding experience which is self hosting is also seamless as a user point of view.
    What do you dislike about the product?
    see its best api gateway but that does not make it to fit in every usecase as per my understanding. also if we talk about the community support is less comparing with others. plugin supports seams less and not everyone knows about it.
    What problems is the product solving and how is that benefiting you?
    every service or microservice has to handle security, rate-limitings and authentication in there code own which make the code duplication and increase the complexicity into business while if we implement tyk api gateway thn we need to focus more on business logics and the purpose our services serves rather making it more security and complex codes.
    Avineet A.

    Effortless API Management with Simple Integration

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    I like Tyk for its ease of integration, which makes my work more manageable. The simple UI is another plus, ensuring continued usage and making it easy to fix issues when they arise. The initial setup was also easy, which helped in getting started without any hassle.
    What do you dislike about the product?
    I think Tyk could improve with more API support and quicker response times. I also noticed there can be drops in responses, which is something I hope gets fixed.
    What problems is the product solving and how is that benefiting you?
    I use Tyk for API platform management. It unifies multi-vendor APIs, which is a big help. The ease of integration and simple UI ensure continued usage and make it easy to fix issues.
    Emmanuel A.

    Easy Implementation and Solid Docs, but Too Expensive for Startups

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Firstly the ease of implementation and the docs are readily available plus you can easily switch to previous versions but again the costing is a bit expensive
    What do you dislike about the product?
    i think its too expensive for enterprise expecially for startups that are just getting started and have less then 50 employees in their organizations.
    What problems is the product solving and how is that benefiting you?
    i centralized entry point for our backend APIs. Instead of building security, authentication, rate limiting, and traffic controls into every microservice individually, It also speeds up our development cycle significantly because developers don't have to rewrite authentication or rate limiting code for every new service.