A APIStrator by Extio Request access →
v2.0 · 4 gateway regions · 38,710 req / 12h

The API control plane.

APIStrator is a multi-organisation API management platform — real-time monitoring, an opinionated lifecycle from Define → Publish → Subscribe, and policy-aware gateway endpoints, all behind one console.

Request access See how it works
Gateways
4 regions, live
APIs
36 published
Clients
35 registered apps
Auth
JWT · OAuth · API Key
apistrator.extio.io / overview
APIStrator Overview Dashboard showing request volume chart, gateway instances and recent events
// Why APIStrator

One console for every API that pays the bills.

Most API gateways stop at routing. APIStrator goes further: it models the organisations that own APIs, the clients that consume them, the plans that limit them and the policies that govern them — and ties all of it back to real-time traffic.

Built originally for multi-entity banking estates (Diamond Trust Bank Kenya, Tanzania and Uganda all run on the same instance), APIStrator handles the long-tail of API operations: rate limits, OAuth, authorization rules, contracts, key rotation and gateway health monitoring. One control plane. Many tenants. Zero spreadsheets.

// The platform

Four primitives, one platform.

P · 01

Observe

Live throughput, latency percentiles, HTTP status distribution and per-gateway health — without leaving the console.

P · 02

Model

Organisations own APIs. Clients subscribe via Plans. Contracts and Policies bind them — a clean hierarchy in one schema.

P · 03

Govern

Rate limiting, OAuth, fine-grained authorization rules per verb / path / role — versioned and locked policies.

P · 04

Secure

Auth failure tracking, IP blocking, key issuance, severity-tagged security events — operational security as a first-class concern.

// MODULE 01Monitoring

Real-time monitoring, three depths.

Overview → Analytics → Security. Each surface goes deeper.

APIStrator's monitoring stack starts wide and ends sharp. The Overview Dashboard surfaces peak throughput, response time, security events, request volume and gateway uptime — colour-coded gradient cards designed to be read across the room. API Analytics drills into latency percentiles (p50 / p95 / p99), HTTP method distribution and top endpoints by request volume. Security & Subscriptions goes deeper still: auth failures by method (JWT / OAuth / API Key), blocked IPs, severity-tagged security events and a live event log.

4,821 RPM peak 94ms p50 99.97% gateway uptime JWT · OAuth · API Key Severity feed
API Analytics dashboard with latency percentiles, HTTP method distribution and top endpoints
analytics · endpoint performance01.1
Security and Subscriptions dashboard with auth failures and security event severity
security · auth + threats01.2
Overview dashboard with request volume chart, gateway instances table and live events
overview · platform health01.3
// MODULE 02Management

A hierarchy
that actually scales.

Organisations contain Clients. Clients consume APIs. APIs are constrained by Plans.

Most API management products flatten the world. APIStrator doesn't. The Organisations view sits at the top — every tenant (DTBK, DTBT, DTBU…) gets its own scope, with its own clients, APIs and plans. From an organisation, you drop into Clients (registered consumer apps), then APIs (definitions, versions, publish state), then Plans (rate limits applied to subscriptions). The same shape, every time. Switch Organisation is one click.

3 organisations 35 clients 36 APIs published 3 plans (100K / 1K / 5M)
Tenant
Organisations
Consumer
Clients
Producer
APIs
Quota
Plans
Organisations list with DTBK, DTBT, DTBU tenants
organisations · multi-tenant root02.1
Clients list showing ABCAgency, ACEMoney, Aurionpro client apps with contracts, policies and subscriptions actions
clients · registered consumer apps02.2
APIs catalog with AZCardPaymentServices, AZCoreServices and other published APIs
apis · catalog & publish state02.3
API Plans list with Plan100K, Plan1K and Plan5M rate limit plans
plans · rate-limit packages02.4
// MODULE 03Lifecycle

Define → Publish
Subscribe.

The full path from a new API to a client app consuming it — in three modals.

APIStrator turns the API lifecycle into a guided flow. The New API wizard walks four steps — Define, Implementation, Plans, Publish — so configuration drift becomes impossible. Once published, the API Contracts view shows every client app subscribed to that API, with version, plan and creation date. From the other side, opening a client surfaces every contract that client holds — each with Created / Broken states and one-click endpoint access.

4-step wizard Versioned APIs Contract-based subscriptions Break / restore
New API wizard step 1 of 4 — Define API with Organisation, name, description and initial version fields
step 01 · define03.1
API Contracts modal showing 6 client apps subscribed to AZCardPaymentServices
step 02 · publish & subscribe03.2
Client subscription contracts showing AZCoreServices, AZCardPaymentServices and other APIs subscribed by Cellulant-Phoenix-REST
step 03 · manage subscriptions03.3
// MODULE 04Policies

Policies, plans and the key at the end.

From rate-limit policy down to the verb-level authorization rule — then the live endpoint, behind a single API key.

Policies in APIStrator are first-class objects, not config files. A Plan Policy (e.g. Plan100K) declares the rate limit — 100,000 requests per API per day — and is versioned and locked once published. Client Policies attach to individual consumer apps: Keycloak OAuth, Authorization rules, custom transforms. The Authorization editor lets you add per-verb, per-path-pattern rules tied to a required role, with explicit unmatched-request behaviour. And at the end of the chain: API Endpoints — every subscribed API surfaces as a live URL, gated by one API key, with usage stats one click away.

Rate limiting Keycloak OAuth Per-verb authorization Versioned + locked One key, many endpoints
Plan Policies modal showing Rate Limiting policy with 100,000 requests per API per Day, locked version
plan policy · rate limiting04.1
Client Policies modal with Keycloak OAuth Policy and Authorization Policy attached to Cellulant-Phoenix-REST
client policies · attached set04.2
Authorization Policy editor with verb path role rules including GET /co/query-account-direct
authorization editor · verb · path · role04.3
API Endpoints modal showing subscribed gateway endpoints and a single API key for Cellulant-Phoenix-REST
endpoints · the keyed gateway view04.4
// By the numbers

An API platform that respects the operators.

Live across three banking entities, 35+ consumer applications and 36 published APIs — with the same console, the same auth model and the same versioned policies.

3+
Tenant organisations on one console
36
Published APIs across organisations
35
Registered consumer applications
4
Live gateway regions monitored
// Ship faster, govern better

Ready to put APIStrator in front of your gateway?

Book a walkthrough and we'll demo APIStrator against your own API estate — multi-tenant org structure, client apps, rate-limit plans and authorization policies — using anonymised samples that match your real shape.

Talk to us

hello@extio.io

Product

apistrator.extio.io

Built for

Platform teams running multi-tenant API estates at scale.