Kong

🦍 The API and AI Gateway

Last verified:

Visit Kong

What is Kong?

Kong Gateway is a lightweight, fast, and flexible cloud-native API gateway built on the ultra-lightweight NGINX engine. It delivers 50K+ transactions per second per node and serves as an API layer for managing APIs and microservices. Kong acts as a reverse proxy that enables secure, reliable, and modular communication between clients and microservices, providing authentication, security, traffic control, analytics, monitoring, and request/response transformations.

Key features include APIOps for fully automated API lifecycle management through declarative configuration, deployment agnosticism supporting any environment from on-prem to cloud, Kubernetes, and serverless, and highly extensible plugins for security, authentication, transformation, and analytics. Kong Gateway offers Kubernetes-native configuration via Kong Ingress Controller, flexible policy design for data orchestration and transformation, and supports multiple protocols including REST, HTTP, LLM, Kafka, WebSockets, gRPC, and GraphQL.

Kong Gateway is designed for developers and enterprises building hybrid and multi-cloud architectures, optimizing for microservices and distributed systems. It is loved by developers for its flexibility and trusted by enterprises including Pexa, Australia Post, Mercedes Benz, and Optum for its performance and reliability at scale.

The gateway supports both database-backed and database-free configurations, and can be deployed in hybrid or cloud-hosted modes. Kong provides multiple installation options including Docker, Helm, Kubernetes Operator, and native Linux packages for comprehensive deployment flexibility.

Kong pricing

Pricing model: Freemium

Kong offers a 30-day Free Trial of Konnect Enterprise with no gateway limits and 30-day analytics retention, no credit card required. Kong Konnect Plus is a per-Gateway-per-month subscription with 1M API requests/month included, $200/month per additional 1M requests (up to 10M/month), up to 5 Serverless gateways, 2 Hybrid gateways, 2 Dedicated Cloud gateways, and 2 Developer Portals. AI Gateway includes up to 5 LLM models with $100/model overage. Kong Konnect Enterprise is a custom annual contract with unlimited Hybrid and Dedicated Cloud Gateways, unlimited Developer Portals and APIs, SSO, Audit Logs, dedicated Customer Success Manager, and custom SLAs. Kong Gateway Open Source is free and self-managed. Kong Gateway Enterprise requires contacting sales for licensing. Additional pricing: Additional Developer Portal $200/month, Published APIs 1-10 per portal $20/month each, Published APIs 11-20 per portal $10/month each.

Kong pros

  • Ultra-lightweight NGINX engine with 50K+ transactions per second per node
  • Infinitely scalable architecture for high-volume API traffic
  • Deployment agnostic - works on-prem, cloud, Kubernetes, and serverless
  • Database-free configuration option available
  • Hybrid and multi-cloud deployment support
  • Full APIOps automation through declarative configuration
  • Kubernetes-native configuration via Kong Ingress Controller
  • Over 200 out-of-the-box plugins for security, authentication, transformation, and analytics
  • Custom plugin development via Kong's Plugin Development Kit
  • Multi-protocol support including REST, HTTP, LLM, Kafka, WebSockets, gRPC, GraphQL
  • Advanced data transformation capabilities
  • Advanced rate limiting with granular control
  • Role-Based Access Control (RBAC) for security
  • FIPS 140-2 compliant data planes for enterprise security
  • Real-time analytics and observability up to 1 year data retention
  • 99.9% uptime SLA on Konnect control plane and database
  • Effortless upgrades with managed service
  • Gateway mocking for development testing
  • Federated API management with strong isolation via control planes
  • Request validation for API security
  • GraphQL support for modern API architectures
  • Kafka integrations for event-driven systems
  • OtB integration with third-party secret management tools
  • Software Bill of Materials for compliance

Kong cons

  • No native Windows install method - requires Docker on Windows
  • Open Source version lacks advanced authentication features
  • Open Source version missing Role-Based Access Control (RBAC)
  • Open Source version has no advanced authorization (OPA)
  • Self-managed versions require manual database management
  • Self-managed versions have no SLA guarantee
  • Enterprise features require paid licensing
  • Complex migration from OSS to Enterprise is irreversible
  • Requires PostgreSQL database for most deployments
  • Advanced data transformation only available in Enterprise
  • Advanced rate limiting only available in Enterprise
  • Developer Portal only available in Enterprise/Konnect
  • API Analytics limited in Open Source version
  • No hosted control plane for Open Source
  • Email support has 2-business-day SLA on Plus plan
  • Custom plugins require development expertise

Frequently asked questions about Kong

How do I migrate from Kong Gateway open source (OSS) to Kong Gateway Enterprise?

You can migrate to Kong Gateway Enterprise using the kong migrations CLI commands. Warning: This action is irreversible, so backup your production data before migrating. You can only migrate to a Kong Gateway Enterprise version that supports the same OSS version. The latest OSS version is 3.9.2. Steps: 1) Download the Kong Gateway Enterprise package matching your installed OSS version, 2) Configure it to point to the same data store as your Kong Gateway OSS node, 3) Run kong migrations up and kong migrations finish with the -f flag if adding new plugins, 4) Confirm all entities are available on your Enterprise node, 5) Optionally upgrade to your desired Enterprise version.

How do I install Kong Gateway on Windows?

To install Kong Gateway on Windows, use Docker. Kong does not provide a native Windows install method for Kong Gateway. The easiest way to get started running Kong Gateway is to use Docker, which works seamlessly on Windows systems.

What are the installation options for Kong Gateway?

Kong Gateway offers multiple installation options: Docker (including Docker Compose and read-only mode), Linux packages (.deb for apt and .rpm for yum), Kubernetes via Helm or Kong Operator, and Kubernetes Ingress Controller (KIC) via Helm or Kong Operator. Kong Gateway is available as a Docker image for containerized environments and as prebuilt deb and rpm packages for native Linux installations.

How do I install a downloaded Kong Gateway package file?

If you have downloaded a Kong Gateway package file, install it using your package manager. For .deb files: sudo apt install --yes /path/to/kong-enterprise-edition__amd64.deb. For .rpm files: sudo yum install -y kong-enterprise-edition-<version>.

Where can I find all supported platforms and packaging options?

To find all supported platforms and package types for Kong Gateway, see the supported platforms and versions in the Kong Gateway version support policy. If you don't see your Kong Gateway version listed, it has reached end of life and Kong no longer publishes packages or images for it.

What is Konnect and how does it differ from self-managed Kong Gateway?

Konnect is Kong's SaaS platform for running Kong Gateway without any infrastructure to manage. It provides a fully managed Control Plane, real-time analytics, and enterprise-grade security. Unlike self-managed Kong Gateway where you manage the control plane and database, Konnect offers a 99.9% uptime SLA, effortless upgrades, and full SaaS API Gateway functionality without infrastructure management overhead.

What protocols does Kong Gateway support?

Kong Gateway supports REST, HTTP, LLM (for AI), Kafka, WebSockets, gRPC, and GraphQL. This multi-protocol plugin support enables Kong to handle diverse API and microservices architectures across modern distributed systems.

What plugins are available with Kong Gateway?

Kong Gateway offers out-of-the-box security, authentication, transformation, and analytics plugins. Key plugins include basic and advanced authentication, role-based access control (RBAC), bot detection, CORS controls, ACLs, advanced authorization via OPA, request validation, advanced rate limiting, proxy cache, GraphQL support, Kafka integrations, and basic/advanced data transformations. Custom plugins can be developed using Kong's Plugin Development Kit.

What is the difference between Kong Gateway Open Source, Enterprise, and Konnect?

Kong Gateway Open Source is free and self-managed with basic traffic control plugins, simple data transformations, basic authentication, and self-managed Kong Manager. Kong Gateway Enterprise adds advanced authentication, RBAC, advanced authorization (OPA), advanced data transformation, advanced rate limiting, developer portal, API analytics, and enterprise support. Kong Konnect is the fully managed SaaS option with hosted control plane, hosted database, 99.9% SLA, effortless upgrades, openTelemetry, service hub, up to 1 year data retention, audit logging, and gateway event hooks.

How do I get started with Kong Gateway?

The easiest way to get started is to use Docker. You can install via Docker following the documentation, or use the quickstart script which automatically enables Kong Manager. For Kubernetes deployments, install via Helm or Kong Operator. Kong Manager GUI is automatically enabled with the quickstart and can be accessed at http://localhost:8002. You can configure Kong Gateway using an API, web UI (Kong Manager), or declarative configuration for CI/CD pipeline management.

Categories

Browse all AI tools on NeedAnAI