
Welcome to API Gateway Plugin Hub

Discover powerful plugins to extend and enhance Apache APISIX’s capabilities for seamless API management
AI#

AI Aliyun Content Moderation
The ai-aliyun-content-moderation plugin uses Aliyun to evaluate selected request roles and LLM responses, including streaming responses, against a risk threshold.

AI AWS Content Moderation
The ai-aws-content-moderation plugin uses Amazon Comprehend to detect toxicity in selected request roles and LLM responses, including streaming responses.

AI Cache
The ai-cache plugin stores exact and semantically similar LLM responses in Redis, reducing response latency and repeated upstream model usage.

AI Lakera Guard
The ai-lakera-guard plugin screens AI traffic through the Lakera Guard API to detect prompt injection and other unsafe content in requests and LLM responses.

AI Prompt Decorator
The ai-prompt-decorator plugin decorates user prompts to LLMs by prefixing and appending pre-engineered prompts, streamlining API operation and content generation.

AI Prompt Template
The ai-prompt-template plugin supports pre-configured templates for user inputs to LLMs in a "fill in the blank" fashion, streamlining API management.

AI RAG
The ai-rag plugin retrieves context with Azure OpenAI embeddings and Azure AI Search before an LLM request is proxied.

AI Proxy
The ai-proxy plugin simplifies access to LLM and embedding models providers by converting plugin configurations into the required request format for OpenAI, DeepSeek, Anthropic, and other OpenAI-compatible APIs.

AI Prompt Guard
The ai-prompt-guard plugin safeguards prompts to LLM using allow/deny patterns, ensuring only approved inputs pass. It can check the latest message or full history.

AI Proxy Multi
The ai-proxy-multi plugin extends the capabilities of ai-proxy with load balancing, retries, fallbacks, and health checks, simplifying the integration with OpenAI, DeepSeek, and other OpenAI-compatible APIs.

AI Rate Limiting
The ai-rate-limiting plugin enforces token-based rate limiting for LLM service requests, preventing overuse, optimizing API consumption, and ensuring efficient resource allocation.

AI Request Rewrite
The ai-request-rewrite plugin forwards client requests to LLM services for processing before sending them upstream, enabling AI-driven redaction, enrichment, and reformatting.
OpenAPI to MCP
Expose OpenAPI services as MCP tools with APISIX or API7 Gateway, using Streamable HTTP or SSE and configurable upstream request headers.
Traffic Management#

GraphQL Limit Count
The graphql-limit-count plugin uses fixed windows to limit accumulated GraphQL document cost, with selection depth as the default measure.

GraphQL Proxy Cache
The graphql-proxy-cache plugin enables caching of responses for GraphQL queries, improving API performance.

Limit Count Advanced
The limit-count-advanced plugin enforces API rate limiting with a fixed window or sliding window algorithm, restricting requests within a time window. Requests over the quota are rejected.

Limit Req
The limit-req plugin enforces API rate limiting with a leaky bucket algorithm to rate limit requests, enabling effective throttling to manage traffic flow.

Limit Conn
The limit-conn plugin delays or rejects excess concurrent HTTP, WebSocket, and TCP connections in APISIX and API7 Gateway to prevent overload.

Limit Count
The limit-count plugin enforces API rate limiting with a fixed window algorithm, restricting requests within a time interval. Requests over the quota are rejected.

OAS Validator
The oas-validator plugin checks incoming HTTP requests against an OpenAPI specification before they are forwarded to upstream services.

Proxy Buffering
The proxy-buffering plugin disables NGINX response buffering for selected routes so streaming upstream responses are forwarded without proxy-buffering delays.

Proxy Cache
The proxy-cache plugin caches responses based on keys, supporting disk and memory caching for GET, POST, and HEAD requests, enhancing API performance.

Proxy Mirror
The proxy-mirror plugin copies all incoming requests or a sampled portion to a secondary upstream for inspection, testing, or analysis.

Request ID
The request-id plugin adds a unique ID to each request proxied through the API gateway, facilitating effective tracking of API requests for better API management.

Request Validation
The request-validation plugin checks requests for compliance before forwarding them to upstream services, enhancing security in API operations.

Traffic Label
The traffic-label plugin labels traffic based on user-defined rules, enabling actions based on labels and associated weights for improved API traffic management.

Workflow
The workflow plugin enables conditional execution of user-defined actions on client traffic based on specific rules, allowing granular API traffic management.

Traffic Split
The traffic-split plugin directs traffic to multiple upstream services based on conditions or weights, providing a flexible approach for API release strategies and traffic management.
Transformation#
Attach Consumer Label
The attach-consumer-label plugin attaches custom consumer labels to authenticated requests, for upstream services to implement additional business logics.

Body Transformer
The body-transformer plugin converts request and response bodies between formats, such as JSON to XML, facilitating seamless data exchange.

degraphql
The degraphql plugin maps HTTP routes to predefined GraphQL queries and forwards selected request values as GraphQL variables.

Exit transformer
The exit-transformer plugin customizes responses generated by gateway plugins or missing routes before APISIX sends them to clients.

Fault Injection
The fault-injection plugin tests application resiliency by simulating controlled faults or delays, making it ideal for chaos engineering and failure condition analysis.

gRPC Transcode
The grpc-transcode plugin converts between HTTP and gRPC requests and responses, facilitating seamless communication between different API protocols.

gRPC Web
The grpc-web plugin enables the gateway to handle gRPC-Web requests from browsers and JavaScript clients by translating them into standard gRPC calls and forwarding them to upstream gRPC services.

Mocking
The mocking plugin simulates API responses without forwarding requests to upstream services, offering customization of status codes, response bodies, headers, and more for API testing and development.

Proxy Rewrite
The proxy-rewrite plugin offers flexible options to rewrite requests that API gateway forwards to upstream services, enhancing API management.

Response Rewrite
The response-rewrite plugin allows rewriting of responses from API gateway and upstream services, providing flexibility in API responses.

SOAP
The soap plugin converts JSON requests into SOAP operations from a WSDL definition and returns upstream SOAP responses as JSON.
Authentication#

Authz Keycloak
The authz-keycloak plugin delegates UMA permission decisions to Keycloak Authorization Services for APISIX and API7 Gateway requests.

Basic Auth
The basic-auth plugin provides basic access authentication, requiring clients to authenticate before accessing upstream resources, enhancing API security.

Forward Auth
The forward-auth plugin integrates with external authorization services, enhancing API security and access control.

JWT Auth
The jwt-auth plugin supports the use of JSON Web Token (JWT) for client authentication before accessing upstream resources, enhancing API security measures.
JWE Decrypt
The jwe-decrypt plugin decrypts a JWE compact serialization token and forwards the plaintext in a configured request header.

Key Auth
The key-auth plugin allows clients to authenticate using an authentication key before accessing upstream resources, enhancing API security measures.

HMAC Auth
The hmac-auth plugin supports HMAC authentication to ensure request integrity, preventing modifications during transmission and enhancing API security.

LDAP Auth Advanced
The ldap-auth-advanced plugin authenticates clients against an LDAP directory and maps the authenticated user onto a consumer, so directory identities can be used with per-consumer plugins, rate limits, and analytics.

Multi Auth
The multi-auth plugin enables consumers using diverse authentication methods to share the same route or service, streamlining API lifecycle management.

OpenID Connect
The openid-connect plugin integrates with OIDC providers like Keycloak and Auth0, simplifying user authentication in API management.

SAML Auth
The saml-auth plugin provides SAML 2.0 single sign-on and single logout for APISIX and API7 Gateway routes using identity providers such as Keycloak.

OPA
The opa plugin integrates with Open Policy Agent, enabling unified policy definition and enforcement for authorization in API operations.
Security#

ACL
The acl plugin authorizes requests by matching consumer or external user labels against allow and deny policies.

Chaitin WAF
The chaitin-waf plugin integrates with Chaitin WAF (SafeLine) to detect and block web threats, strengthening application security and protecting user data.

CORS
The cors plugin enables cross-origin resource sharing, allowing servers to specify permitted origins and instructing browsers to load resources from those origins, enhancing API accessibility.

Data Mask
The data-mask plugin removes or replaces sensitive information in request headers, bodies, and URL queries for logging purposes, enhancing data privacy and security.

Consumer Restriction
The consumer-restriction plugin implements access controls based on consumer name, route ID, service ID, or consumer group ID, enhancing API security.

IP Restriction
The ip-restriction plugin restricts access to upstream resources based on an IP address whitelist or blacklist, improving API security.

MCP Tools ACL
The mcp-tools-acl plugin provides per-consumer access control for MCP tool calls on routes powered by openapi-to-mcp, supporting rule-based allowlist and denylist modes with optional expression conditions.

UA Restriction
The ua-restriction plugin restricts access to upstream resources using an allowlist or denylist of user agents, preventing overload from web crawlers and enhancing API security.
Observability#

ClickHouse Logger
The clickhouse-logger plugin pushes request and response logs to ClickHouse databases in batches, allowing for customizable log formats to enhance data management.

Datadog
The datadog plugin sends APISIX and API7 Gateway request metrics to Datadog through DogStatsD for monitoring traffic, latency, status, and payload size.

Elasticsearch Logger
The elasticsearch-logger plugin sends gateway request and response logs to Elasticsearch in batches and supports customizable log formats and index names.

Error Log Collect
The error-log-collect plugin captures the error logs produced while processing selected requests, including lower-severity entries that the configured log level would otherwise discard, and writes them to the gateway error log for targeted debugging.

Error Log Logger
The error-log-logger plugin sends APISIX and API7 Gateway error logs to TCP, Apache SkyWalking, Apache Kafka, or ClickHouse servers.

Google Cloud Logging
The google-cloud-logging plugin sends request and response logs to Google Cloud Logging in batches and supports customizable log formats.

HTTP Logger
The http-logger plugin sends request and response logs to HTTP or HTTPS endpoints in batches and supports customizable log formats.

Kafka Logger
The kafka-logger plugin pushes request and response logs as JSON objects to Apache Kafka clusters in batches, allowing for customizable log formats to enhance data management.

Loki Logger
The loki-logger plugin sends APISIX and API7 Gateway request and response logs to Grafana Loki in batches with customizable log formats.

Prometheus
The Prometheus plugin integrates with Prometheus for metric collection and continuous monitoring, enhancing API observability.
OpenTelemetry
The opentelemetry plugin exports sampled APISIX and API7 Gateway request traces to OpenTelemetry Collectors over OTLP/HTTP for distributed tracing.

RocketMQ Logger
The rocketmq-logger plugin sends APISIX and API7 Gateway request and response logs to Apache RocketMQ in batches with customizable formats.

SkyWalking Logger
The skywalking-logger plugin sends customizable APISIX and API7 Gateway request and response logs to a SkyWalking OAP server in batches for analysis.

syslog
The syslog plugin sends request and response logs to syslog servers in batches and supports customizable log formats.

SkyWalking
The skywalking plugin sends APISIX and API7 Gateway request traces to Apache SkyWalking for distributed tracing, request analysis, and trace-log correlation.

Splunk HEC Logging
The splunk-hec-logging plugin sends request and response logs to Splunk HTTP Event Collector in batches and supports customizable log formats.

Zipkin
The zipkin plugin instruments the API gateway to send traces to Zipkin or compatible collectors like Jaeger and Apache SkyWalking, enhancing request tracing capabilities.
General#

Error Page
The error-page plugin customizes gateway-generated 404, 500, 502, and 503 responses without modifying responses returned by upstream services.

Public API
The public-api plugin exposes internal API endpoints, allowing external access while maintaining control over API management and security.

Real IP
The real-ip plugin enables the API gateway to fetch the client's real IP using the IP address from the HTTP header or query string, improving data quality.
Serverless#

AWS Lambda
The aws-lambda plugin simplifies APISIX integration with AWS Lambda and Amazon API gateway, supporting authentication via IAM user credentials and API keys.

Serverless Functions
The serverless function plugins (pre-function and post-function) allow execution of user-defined logic at the start or end of specified execution phases in API gateway.
