Observe
Live throughput, latency percentiles, HTTP status distribution and per-gateway health — without leaving the console.
APIStrator is a multi-organisation API management platform — real-time monitoring, an opinionated lifecycle from Define → Publish → Subscribe, and policy-aware gateway endpoints, all behind one console.
Most API gateways stop at routing. APIStrator goes further: it models the organisations that own APIs, the clients that consume them, the plans that limit them and the policies that govern them — and ties all of it back to real-time traffic.
Built originally for multi-entity banking estates (Diamond Trust Bank Kenya, Tanzania and Uganda all run on the same instance), APIStrator handles the long-tail of API operations: rate limits, OAuth, authorization rules, contracts, key rotation and gateway health monitoring. One control plane. Many tenants. Zero spreadsheets.
Live throughput, latency percentiles, HTTP status distribution and per-gateway health — without leaving the console.
Organisations own APIs. Clients subscribe via Plans. Contracts and Policies bind them — a clean hierarchy in one schema.
Rate limiting, OAuth, fine-grained authorization rules per verb / path / role — versioned and locked policies.
Auth failure tracking, IP blocking, key issuance, severity-tagged security events — operational security as a first-class concern.
Overview → Analytics → Security. Each surface goes deeper.
APIStrator's monitoring stack starts wide and ends sharp. The Overview Dashboard surfaces peak throughput, response time, security events, request volume and gateway uptime — colour-coded gradient cards designed to be read across the room. API Analytics drills into latency percentiles (p50 / p95 / p99), HTTP method distribution and top endpoints by request volume. Security & Subscriptions goes deeper still: auth failures by method (JWT / OAuth / API Key), blocked IPs, severity-tagged security events and a live event log.
Organisations contain Clients. Clients consume APIs. APIs are constrained by Plans.
Most API management products flatten the world. APIStrator doesn't. The Organisations view sits at the top — every tenant (DTBK, DTBT, DTBU…) gets its own scope, with its own clients, APIs and plans. From an organisation, you drop into Clients (registered consumer apps), then APIs (definitions, versions, publish state), then Plans (rate limits applied to subscriptions). The same shape, every time. Switch Organisation is one click.
The full path from a new API to a client app consuming it — in three modals.
APIStrator turns the API lifecycle into a guided flow. The New API wizard walks four steps — Define, Implementation, Plans, Publish — so configuration drift becomes impossible. Once published, the API Contracts view shows every client app subscribed to that API, with version, plan and creation date. From the other side, opening a client surfaces every contract that client holds — each with Created / Broken states and one-click endpoint access.
From rate-limit policy down to the verb-level authorization rule — then the live endpoint, behind a single API key.
Policies in APIStrator are first-class objects, not config files. A Plan Policy (e.g. Plan100K) declares the rate limit — 100,000 requests per API per day — and is versioned and locked once published. Client Policies attach to individual consumer apps: Keycloak OAuth, Authorization rules, custom transforms. The Authorization editor lets you add per-verb, per-path-pattern rules tied to a required role, with explicit unmatched-request behaviour. And at the end of the chain: API Endpoints — every subscribed API surfaces as a live URL, gated by one API key, with usage stats one click away.
Live across three banking entities, 35+ consumer applications and 36 published APIs — with the same console, the same auth model and the same versioned policies.
Book a walkthrough and we'll demo APIStrator against your own API estate — multi-tenant org structure, client apps, rate-limit plans and authorization policies — using anonymised samples that match your real shape.
Platform teams running multi-tenant API estates at scale.