The Forrester Wave™: API Management Software, Q3 2026
Top Vendor Products for API Management Software in 2026
List of all leaders in The Forrester Wave™: API Management Software, Q3 2026:
Gravitee.io
IBM
Kong
MuleSoft
WSO2
API Management Software Vendor Product Comparisons 2026
Key features and pros and cons of top API Management Software products:
Gravitee.io - Leaders
Pros:
Above-par policies for governing non-REST services and mediating them to REST, including GraphQL, gRPC, and SOAP
Event gateway with advanced policies and mediation for Kafka, Solace, SSE, and others
Deep visibility into API usage patterns, LLM token consumption, and MCP behaviors via thorough analytic dashboards
Gateway aids microservices with minimal compute consumption, gRPC support, and Kubernetes Gateway API
Data sovereignty via isolated SaaS and air-gapped self-hosted options
Federates with more third-party gateways than most vendors
Cons:
Portal is minimally customizable
Federation limited to API discovery and onboarding without analytics capture
Smaller partner ecosystem than most in evaluation, particularly with systems integrators
Minimal supporting services
IBM - Leaders
Pros:
API portal is highly customizable and well suits demanding externally facing portals
Isolated SaaS and air-gapped self-hosting bolster data sovereignty
Organizations and workspaces paired with federated linting rules provide impressive support for federated API delivery
Quality API design facilitated through AI agents, Spectral rules, and API testing framework
Above-par number of policies for REST and non-REST, supporting SOAP, GraphQL, and advanced policies for Kafka events
Strong customer support
Cons:
Below par for AI governance, offering no MCP proxy and limited LLM token governance at time of evaluation
Customers would like to see easier upgrades
Kong - Leaders
Pros:
Highly customizable analytics and monetization capabilities via OpenMeter acquisition, including cost chargeback reports for LLM tokens
More policies for LLM governance than any other vendor in evaluation
Gateway policies for GraphQL and advanced policies for Kafka streams
Gateway integrates with Kong's service mesh and implements Kubernetes Gateway API
Strong customer support and gateway performance
AI-assisted migration from competitors
Cons:
MCP support is currently minimal
Doesn't offer features for formal API lifecycle management or SOAP
Customers would like to see support for SOAP and a better API portal
MuleSoft - Leaders
Pros:
Gateway has broad policies for LLMs and MCP, including semantic routing, prompt optimization, and PII detection
Excellent analytics provide end-to-end visualizations of API and AI agent call chains
API Experience Hub is highly customizable portal
High-end API designer, MCP-based vibe designer for agentic IDEs, Anypoint Governance, and MUnit for automated tests
Above-par support for designing high-quality APIs
Strong partnerships with customers
Cons:
High cost
Some add-ons like automated design governance are additional charge
Customers limited to one portal instance per organization
Some partners indicate slowdown in MuleSoft
WSO2 - Leaders
Pros:
Highly customizable analytics and monetization capabilities via Moesif acquisition, including deep insights into LLM token costs
Excellent range of AI policies for both LLMs and MCP, including MCP tool authorization, progressive disclosure, semantic caching, PII protection, and contextual routing
Ability to enforce API design standards via natural language
Bespoke lifecycles plus advanced versioning management features extending beyond REST into MCP servers, AsyncAPI, and GraphQL
Gateway consumes minimal resources and implements Kubernetes Gateway API
Isolated SaaS and air-gapped self-hosting facilitate data sovereignty
Strong customer support and roadmap
Value for cost and price predictability
Customer Favorite in this evaluation
Cons:
Customers would like better-quality product documentation
Some GSIs indicate preference for WSO2 implementations due to price positioning
Axway - Strong Performers
Pros:
Integrates with nine non-Axway gateways to support API discovery, client onboarding, and analytics capture
API discovery from Git, Akamai, and other sources
Amplify Engage portal supports high degree of WYSIWYG customization and cataloging of MCP, agent cards, AsyncAPI, and gRPC
Broad range of monetization configurations
Sophisticated lifecycle management through custom lifecycles and quality enforcement gates
Strong partnership and support
Cons:
Gateway doesn't support Kubernetes Gateway API or sidecar deployments for microservices
Customers would like to see more features for AI governance
AI gateway can be purchased independently, potentially adding to gateway sprawl
Boomi - Strong Performers
Pros:
Strong federated API management supporting client onboarding and API discovery across eight non-Boomi gateways
Thorough dashboard for reporting on API design quality issues across entire API portfolio
Customers validate value and predictability of cost
Ease of use for API producers
Leading iPaaS bundled with API management
Cons:
Limited analytics - little more than cookie-cutter reports requiring OpenTelemetry support for advanced dashboards
API portal doesn't catalog AI assets
Gateway lacks policies for AI protocols at time of evaluation
Customers would like to see more support for MCP
Need to wait for roadmap to fulfill AI gateway promise
Google - Strong Performers
Pros:
Superior productization capabilities with wide variety of API pricing configurations and billing with prepaid accounts
Uniquely strong analytics and reporting capabilities for REST APIs
On-par gateway capabilities for AI services, REST APIs, and non-REST APIs
Apigee API hub provides foundation for enforcing design quality governance across gateways
Strong GSI partner support for Apigee practices
Cons:
Very little analytics support for AI services
Customers must write custom plug-ins to integrate with non-Google gateways
Lacks features for formal lifecycle management
API versioning is just a version number field
Customers complain about being forced into Google Cloud and reliance on Drupal
Google did not provide reference customers
Lack of evidence for effective adoption strategy
Sensedia - Strong Performers
Pros:
Stands out for design and validation of API specifications
AI agent for API design and robust dashboard for governing portfolio design quality across multiple vendor gateways
Enforces API design quality before advancing to next lifecycle stage
Generates code to enforce quality rules in APIs' CI/CD automation for non-Sensedia gateways
Strong partnership, support, and ease of use
Range of supporting services including managed operations and compliance for open banking and insurance
Cons:
Below par AI governance support - just a few LLM policies and publishing REST endpoints as MCP servers
Portal doesn't support AsyncAPI or AI assets
Minimal customization unless subscribing to developer experience managed service
No self-managed option for control plane - only SaaS and hybrid deployments
Customers would like to see more AI in platform
Partner ecosystem mostly based in Latin America
Tyk Technologies - Strong Performers
Pros:
Stands out for security and governance beyond REST with deep support for GraphQL
Gateway to govern Kafka brokers, MQTT brokers, WebSockets, and more
Policies for gRPC, SSE, LLMs, and MCP
Strong portal support for publishing GraphQL and AsyncAPI
Client onboarding to event streams from portal
Self-hosted deployments of every component for control and sovereignty
Fully isolated SaaS hosting
Customers note strength as supportive partner and superior ease of use for production operations
Cons:
SOAP is absent
Automated API design governance is thin - runs Spectral rules but lacks scoring, portfolio-wide reports, or AI-generated suggestions
Pricing metered on number of data plane clusters rather than API call volume
Thin supporting services and offerings compared to peers
Customers would like to see stronger capabilities for automated API design governance
Broadcom - Contenders
Pros:
Large library of policies for authentication, authorization, payload validation, and attack protections
Wide array of protocol mediation policies
Information security teams can define parameterized policy templates and enforce global policies
Customers consistently give high praise for Layer7's security capabilities
Cons:
API portal offers very few customizations
Lacks support for LLM services, MCP, or A2A
Doesn't support federation with other gateways
Limited to self-hosting - SaaS offering lacks isolated hosting option
Partner ecosystem has shrunk as GSIs pull back on Layer7 implementations
Does not offer in-house professional services
Pricing is opaque and historically based on compute capacity rather than consumption
Customers complain price is too high
Broadcom did not provide reference customers
Microsoft - Contenders
Pros:
Azure API Center allows governing API security and design across any gateway
Solid on-par governance of AI services including LLM token governance and semantic caching
Conversion of REST into MCP tools
Integration with Azure AI Content Safety
Deep integration with Azure cloud for Azure-centric customers
Very broad supporting product offerings on Azure
Cons:
No generally available integrations with third-party gateways at time of evaluation
Thinner catalog of policies for REST and non-REST APIs like SOAP than most
Multicloud buyers lament poor integration with non-Azure products
Some customers look to competitors for stronger best-of-breed AI gateway
Recent innovations focused on AI gateway while neglecting gaps in traditional API management
Microsoft did not provide reference customers
Solo.io - Contenders
Pros:
AI gateway offers deep LLM and MCP policy controls including token governance and progressive MCP tool disclosure
Envoy-based API gateway excels for microservices - implements Kubernetes Gateway API, uses minimal compute, integrates with service mesh
Customers cite high performance and low resource consumption for microservices
Cons:
Limits deployments to Kubernetes with no support for virtual machines, bare metal, or SaaS
Portal customization limited to logo and favicon
Lacks unified portal for REST and AI
Doesn't offer formal lifecycle management
Little to ease API versioning
Limits services to basic setup and support
No partner ecosystem to speak of
Pricing meters infrastructure capacity rather than API call volume
Vision overlooks role of APIs in business strategies and need for governance across heterogenous gateways
Some customers split API portfolio between Solo.io and competitor due to lack of advanced features
Solo.io did not provide reference customers
FAQs
Q: Which vendors are Leaders in 2026?
A: Gravitee.io, IBM, Kong, MuleSoft, WSO2
Q: What does "Leader" mean in Forrester Wave terms?