# WSO2

**Canonical:** https://apis.io/providers/wso2/  
**Website:** https://wso2.com/api-manager/  
**APIs profiled:** 90

WSO2 API Manager is an open-source API management platform supporting REST, SOAP, and GraphQL with flexible hybrid deployment. It provides a unified control plane for managing APIs, AI models, and agents across on-premises, hybrid, and cloud environments. WSO2 is recognized as a Leader in the Forrester Wave API Management Q3 2024 report.

## Kin Score — 54.4 / 100 (strong)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.0 from 54.4).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 57.1 |
| Governance | 9.8 |
| Contract Governance | 9.8 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 52.4 |
| Commercial Clarity | 68.4 |
| Access Clarity | 68.4 |

## Agent readiness — 40.9 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | documented |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (90)

- **WSO2 Advanced Policy (Collection) API** — The Advanced Policy (Collection) API from WSO2 — 1 operation(s) for advanced policy (collection).
- **WSO2 Advanced Policy (Individual) API** — The Advanced Policy (Individual) API from WSO2 — 1 operation(s) for advanced policy (individual).
- **WSO2 AIServiceProvider API** — The AIServiceProvider API from WSO2 — 1 operation(s) for aiserviceprovider.
- **WSO2 AIServiceProviders API** — The AIServiceProviders API from WSO2 — 1 operation(s) for aiserviceproviders.
- **WSO2 Alert Subscriptions API** — The Alert Subscriptions API from WSO2 — 1 operation(s) for alert subscriptions.
- **WSO2 Alerts API** — The Alerts API from WSO2 — 1 operation(s) for alerts.
- **WSO2 Api Artifact API** — The Api Artifact API from WSO2 — 1 operation(s) for api artifact.
- **WSO2 API Categories API** — The API Categories API from WSO2 — 1 operation(s) for api categories.
- **WSO2 API Category (Collection) API** — The API Category (Collection) API from WSO2 — 1 operation(s) for api category (collection).
- **WSO2 API Category (Individual) API** — The API Category (Individual) API from WSO2 — 2 operation(s) for api category (individual).
- **WSO2 API Chat API** — The API Chat API from WSO2 — 1 operation(s) for api chat.
- **WSO2 API Documents API** — The API Documents API from WSO2 — 3 operation(s) for api documents.
- **WSO2 API Monetization API** — The API Monetization API from WSO2 — 1 operation(s) for api monetization.
- **WSO2 Api Provider Change API** — The Api Provider Change API from WSO2 — 1 operation(s) for api provider change.
- **WSO2 APIKeys API** — The APIKeys API from WSO2 — 16 operation(s) for apikeys.
- **WSO2 APIs API** — The APIs API from WSO2 — 9 operation(s) for apis.
- **WSO2 Application API** — The Application API from WSO2 — 2 operation(s) for application.
- **WSO2 Application (Collection) API** — The Application (Collection) API from WSO2 — 1 operation(s) for application (collection).
- **WSO2 Application Keys API** — The Application Keys API from WSO2 — 10 operation(s) for application keys.
- **WSO2 Application Policy (Collection) API** — The Application Policy (Collection) API from WSO2 — 1 operation(s) for application policy (collection).
- **WSO2 Application Policy (Individual) API** — The Application Policy (Individual) API from WSO2 — 1 operation(s) for application policy (individual).
- **WSO2 Application Secrets API** — The Application Secrets API from WSO2 — 3 operation(s) for application secrets.
- **WSO2 Application Tokens API** — The Application Tokens API from WSO2 — 2 operation(s) for application tokens.
- **WSO2 Applications API** — The Applications API from WSO2 — 3 operation(s) for applications.
- **WSO2 Artifact Compliance API** — for accessing artifact compliance.
- **WSO2 Bot Detection Alert Subscriptions API** — The Bot Detection Alert Subscriptions API from WSO2 — 2 operation(s) for bot detection alert subscriptions.
- **WSO2 Bot Detection Data API** — The Bot Detection Data API from WSO2 — 1 operation(s) for bot detection data.
- **WSO2 Comments API** — The Comments API from WSO2 — 6 operation(s) for comments.
- **WSO2 Config API** — The Config API from WSO2 — 1 operation(s) for config.
- **WSO2 Consumption API** — The Consumption API from WSO2 — 1 operation(s) for consumption.
- **WSO2 Custom Rules (Collection) API** — The Custom Rules (Collection) API from WSO2 — 1 operation(s) for custom rules (collection).
- **WSO2 Custom Rules (Individual) API** — The Custom Rules (Individual) API from WSO2 — 1 operation(s) for custom rules (individual).
- **WSO2 Deny Policies (Collection) API** — The Deny Policies (Collection) API from WSO2 — 1 operation(s) for deny policies (collection).
- **WSO2 Deny Policy (Individual) API** — The Deny Policy (Individual) API from WSO2 — 1 operation(s) for deny policy (individual).
- **WSO2 End Points API** — The End Points API from WSO2 — 1 operation(s) for end points.
- **WSO2 Environments API** — The Environments API from WSO2 — 3 operation(s) for environments.
- **WSO2 Get API Info API** — The Get API Info API from WSO2 — 2 operation(s) for get api info.
- **WSO2 Get Application Info API** — The Get Application Info API from WSO2 — 1 operation(s) for get application info.
- **WSO2 Get Subscription Info API** — The Get Subscription Info API from WSO2 — 1 operation(s) for get subscription info.
- **WSO2 Global Key Manager (Collection) API** — The Global Key Manager (Collection) API from WSO2 — 1 operation(s) for global key manager (collection).
- …and 50 more, listed in full on the page.

## Agentic access (1)

- **Wso2 Agentic Access** — 274 operations · 124 acting · 6 human-in-the-loop

## Security (4)

- **Wso2 Authentication** — oauth2 · 1 scheme
- **Wso2 Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Wso2 Vulnerability Disclosure** — disclosure policy published
- **Wso2 Trust Center** — SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR

## Plans (1)

- **Wso2 Plans Pricing**

## Use cases (6)

- **API Program Management** — Centrally manage the full lifecycle of all enterprise APIs.
- **Developer Self-Service** — Developer portal for API discovery, subscription, and key management.
- **AI Agent Integration** — Expose REST APIs as MCP tools for AI and agent consumption.
- **LLM Traffic Management** — Route, monitor, and govern traffic to large language model APIs.
- **Compliance and Governance** — Enforce API design standards and validate compliance across teams.
- **B2B API Monetization** — Define subscription tiers and billing for API usage-based monetization.

## Tags

API Management, Gateways, Open-Source, API Lifecycle, GraphQL, SOAP, REST

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/wso2/). Scores are computed from the provider's own public artifacts under a published rubric.
