NEW Enterprise API Management, delivered your way

Every API.
One control plane.

Conflux lets your teams publish, secure, monitor, govern, and scale APIs from a single console: in the cloud, on-premise, or hybrid, with enterprise-grade security at every layer.

  • 99.9%+ availability design
  • Zero-downtime deployments
  • Multi-tenant by design
console.conflux · Production All gateways healthy

REQUESTS / MIN

184,220

▲ 6.2%

P95 LATENCY

86 ms

▼ 11 ms

ERROR RATE

0.14%

SLA on track

Gateway traffic · last 60 min

2xx 4xx
/v2/payments Canary 10% Healthy
/v1/orders Blue-Green Healthy
/graphql Rate limit: 5k/min Throttling

The life of a request

trace_id: 8f3a-22c1 · total 86 ms

  1. 0 ms

    Client request

    REST · gRPC · GraphQL

  2. +9 ms

    Authenticate

    OAuth 2.0 · JWT · mTLS

  3. +2 ms

    Apply policies

    Rate limit · Quota · WAF

  4. +4 ms

    Transform

    Headers · Payload · URL

  5. +3 ms

    Route

    Canary · Split · Balance

  6. 200 OK

    Upstream service

    Cached · Traced · Logged

Every stage is observable, every policy is configurable, and every hop is captured in the audit trail. That is what a control plane should mean.

Module · API Gateway

Traffic control built for production reality

Ship changes safely with canary and blue-green deployments, split traffic by version, and keep upstreams protected with circuit breakers, retries, and timeout policies. Caching, compression, and connection pooling keep latency low even under heavy load.

  • Progressive delivery: canary, blue-green, version routing, and weighted traffic splitting.
  • Resilience policies: circuit breakers, retries, timeouts, and connection pooling per route.
  • Transformation engine: request and response mapping, header manipulation, URL rewriting, payload transforms.
  • Performance: response caching, compression, CORS management, and large payload support.
RESTSOAPGraphQLgRPCWebSocketAsync APIs

Release · payments-api v2.4

Canary live

CIRCUIT

Closed

RETRIES

3 max

TIMEOUT

2.5 s

Module · Security

Security as policy, not as an afterthought

Define authentication, authorization, and protection once, then enforce it across every API, environment, and gateway node. Conflux plugs into your identity stack and applies defense in depth at the edge.

Authentication

OAuth 2.0, OpenID Connect, JWT, API keys, SAML, mutual TLS, LDAP, and Active Directory.

Authorization

RBAC with fine-grained, resource-level, scope-based, and claims-based permissions.

Threat protection

Rate limiting, throttling, quotas, DDoS and bot protection, and WAF integration.

Access controls

IP allow and deny lists, geo restrictions, and token validation at every hop.

Encryption in transit and at rest, with certificate and secret management handled centrally in the admin console.

policy · payments-api.yaml Template applied
# Security policy · applied at the gateway
authentication:
  method: oauth2
  token_validation: jwt
  fallback: mtls
authorization:
  model: rbac
  scopes: [payments.read, payments.write]
protection:
  rate_limit: 5000/min
  quota: 2M/day
  geo_restrictions: enforced
  bot_protection: on
  waf: integrated
Versioned · Auditable · Reusable Enforced on 42 APIs

Module · Developer Portal

A portal your API consumers will actually use

Discovery, documentation, subscription, and testing in one self-service experience. Developers find an API, try it in the sandbox, generate keys, and ship: no tickets, no waiting.

API Catalog

Search 240 APIs
v2.4 ● Published

Payments API

Process transactions, refunds, and settlement reports.

OpenAPI Sandbox SDKs

TRY IT · SANDBOX

POST /v2/payments
{ "amount": 129.99, "currency": "USD" }

201 Created · 92 ms
{ "id": "pay_84h2", "status": "approved" }

Docs that stay current

Swagger and OpenAPI rendering with version history, lifecycle visibility, and sample code in the languages your consumers use.

Self-service credentials

Subscription workflows, key generation, and credential management with a safe sandbox environment for testing.

Usage in plain sight

Per-consumer usage dashboards so developers see their own traffic, quotas, and errors without opening a ticket.

Modules · Lifecycle & Governance

Ship APIs with process, not paperwork

Every API moves through a governed pipeline with approvals, environment promotion, and a complete audit trail. Standards are enforced by the platform, so reviews focus on design instead of formatting.

  1. STAGE 1

    Draft

    Design the spec, clone from an existing API, or import OpenAPI.

  2. STAGE 2

    Review

    Naming standards and policy checks run automatically.

  3. STAGE 3

    Approve

    Configurable approval workflows with change management.

  4. STAGE 4

    Publish

    Promote across dev, staging, and production environments.

  5. STAGE 5

    Version

    Side-by-side versions with routing and one-click rollback.

  6. STAGE 6

    Retire

    Deprecate on a schedule, archive, and keep the history.

Policy templates & standards

Centralized policy management, reusable templates, API classification, and naming standards applied across every team.

Immutable audit history

User activity, configuration history, and security events captured in tamper-evident logs with configurable retention and export.

Audit-ready reporting

Compliance-aligned reports and environment governance that give your risk and audit teams the evidence they ask for.

Modules · Analytics & Monitoring

Know your APIs like your uptime depends on it

Real-time dashboards for usage, latency, error rate, throughput, and availability, sliced by API, consumer, and geography. Operational monitoring watches every gateway node and endpoint, with alerting, log aggregation, and distributed tracing wired in from day one.

  • SLA monitoring: track commitments per API and per consumer, with alerts before breaches happen.
  • Consumer analytics: top APIs, top consumers, failed requests, and geographic usage patterns.
  • Incident dashboard: health checks, event notifications, and node-level gateway status in one view.
  • Custom dashboards: build the views your teams need and export reports on a schedule.

SLA overview · Q3

Export report
payments-api99.98%
orders-api99.95%
catalog-api99.72%

DISTRIBUTED TRACE · /v1/orders

gateway 6 ms
auth 9 ms
orders-svc 38 ms
inventory 21 ms
Alert: catalog-api p95 above 250 ms Routed to on-call

Module · Integration Framework

Meets your stack where it already lives

Prebuilt connectors for identity, ITSM, observability, cloud, CI/CD, and messaging, plus an extensible plugin framework and platform APIs for everything else.

Identity providers

OktaAzure ADKeycloakLDAP

ITSM

ServiceNowJira

Observability

DatadogPrometheusGrafanaSplunk

Cloud

AWSAzureGoogle Cloud

CI/CD

GitHubGitLabAzure DevOpsJenkins

Messaging

KafkaRabbitMQ

DevOps-native by default

GitOps workflows, Infrastructure as Code, automated testing, configuration export and import, and deployment pipelines.

conflux promote --env production

Module · Deployment

Runs where your architecture says it should

Cloud-native and microservices-based, packaged for Kubernetes and Docker, and proven across multi-region, multi-cluster topologies. Your data residency and network rules decide the deployment model, not ours.

Cloud

Deploy on AWS, Azure, or Google Cloud with auto scaling, high availability, and zero-downtime upgrades.

On-premise

Full platform inside your data center for regulated workloads, with backup, restore, and disaster recovery built in.

Hybrid

Gateways at the edge and in your VPCs, one control plane over all of them, synchronized across environments.

99.9%+

Availability design target

Multi-region

Active-active clusters

Zero

Downtime deployments

DR-ready

Backup, restore, failover

Beyond the software

Built, documented, and supported for the enterprise

A platform is only as good as the team behind it. Conflux ships with the documentation, training, and support model that enterprise operations expect.

Talk through your requirements

24×7 support

Ticketing with SLA management, incident and problem management, patch management, upgrades, performance tuning, and health checks.

Training programs

Administrator, developer, and operations tracks with an online learning portal, video tutorials, and in-product guidance.

Complete documentation

Admin, developer, and installation guides, API references, architecture docs, runbooks, and operational manuals.

Open and accessible

Open standards, API-first architecture, WCAG-aligned interfaces, cross-browser support, and a mobile-responsive admin portal.

Let's Talk About Your Product

Get expert guidance on scope, architecture, timelines, and delivery approach so you can move forward with confidence.

What happens next?