centauri gateway is an API + LLM gateway whose configuration is bi-temporal facts (you can time-travel any past config) and whose per-request audit is a tamper-evident hash chain. It is also a young, single-binary gateway from a small project — so this page states plainly what Kong, Google, AWS, and Tyk do better. Documentation honesty is policy here: a ✗ is a ✗.
✓ = shipped and first-class · ~ = partial, or assembled from other pieces · ✗ = not offered. Nuance in small print; when in doubt, the cell errs in the competitor's favor.
| Centauri Gateway | Kong (OSS + Konnect) | Google Apigee | AWS API Gateway | Tyk | |
|---|---|---|---|---|---|
| Config model | bi-temporal factsroutes & keys are database facts; AS OF / AS KNOWN AT / HISTORY replay any past config; RETIRE, never delete | ✓declarative YAML (DB-less), Postgres-backed, or Konnect console; version via GitOps | ✓API proxies with numbered revisions; console + management API | ~console / CloudFormation / SAM; stages + deployment history | ✓API definitions in files, Redis, or the dashboard |
| Config time travel"what was live last Tuesday 9am?" | ✓one query; every change is a superseding fact | ✗reconstruct from git history / external audit | ~revision rollback exists; not point-in-time query | ~redeploy an old stage deployment | ✗ |
| Request audit trail | tamper-evidentper-request facts in a SHA-256 hash chain; centauri verify proves nothing was edited; metadata only, never bodies | ~rich logging via plugins to your sink; not independently verifiable | ✓managed analytics + Cloud Audit Logs; strong, but not a verifiable chain you hold | ~assemble CloudWatch + CloudTrail + Athena yourself | ~analytics via Tyk Pump to your store |
| AI / LLM routing | ✓OpenAI-compatible routes; SSE streaming passthrough; provider failover (until first byte); model pinning; per-key token metering stored as queryable facts | ✓dedicated AI-gateway plugin suite: multi-provider routing, token rate limiting, prompt guards | ~emerging LLM-ops features on Google's stack | ~assemble with Bedrock, Lambda, and usage plans | ~AI offering newer and less proven than Kong's |
| Authentication | ~✓ minted API keys (hash-only at rest), OIDC JWT validation (RS256/384/512, JWKS), mTLS client certs — AND issues service tokens (OAuth2 client-credentials at /gw/token, own JWKS). ✗ no human login/consent flows — bring your IdP for people | ✓full OAuth2/OIDC plugin suites, key auth, HMAC, LDAP, ACLs | ✓built-in OAuth2 authorization server, API keys, JWT | ✓IAM, Cognito, Lambda authorizers, mTLS | ✓OAuth2/OIDC, HMAC, mTLS, custom middleware auth |
| Rate limiting | ✓per-route, per-key, and per-IP budgets | ✓basic + advanced (sliding window, clustered) | ✓quotas + spike arrest policies | ✓throttling + usage plans | ✓quotas + rate limits per key/policy |
| Middleware / plugins | ~built-ins (CORS, header add/remove, IP allow/deny, body caps, path blocks, prefix strip, timeouts) + programmable CePL request policies (stored, versioned, AS OF-auditable) + webhook auth callouts. No third-party plugin marketplace | ✓hundreds of plugins + custom plugins in Lua/Go/JS/Python | ✓rich policy catalog (transform, mediate, callout) | ~mapping templates + Lambda integrations | ✓middleware in JS/Python/Go gRPC plugins |
| Kubernetes ingress / mesh | ✗no ingress controller, no mesh; runs fine *in* k8s as a plain deployment | ✓Kong Ingress Controller + Kuma/Kong Mesh | ~via Apigee adapters / Anthos service mesh | ~not a k8s ingress; ALB/App Mesh are separate products | ✓Tyk Operator + ingress support |
| Throughput class | ~Go stdlib reverse proxy; comfortable for small/mid APIs; no published high-throughput benchmarks — do not pick it for six-figure RPS | ✓NGINX/OpenResty core; very high, battle-tested throughput | ✓Google-scale managed infrastructure and SLAs | ✓serverless scale, regional redundancy | ✓Go gateway, high throughput, published benchmarks |
| Deployment weight | one binaryconfig + audit in one log file; no separate DB, no control-plane service; admin plane is the same binary | ~data plane + control plane; Postgres (DB mode) or DB-less files; Konnect adds SaaS control plane | ~managed SaaS; org/environment provisioning | ✓fully managed, nothing to host | ~gateway + Redis; dashboard/analytics components extra |
| Scale-out / HA | ~N gateways follow one primary control plane (-control-follow, read-only replicas); no multi-DC, no gateway leader election | ✓clustering, hybrid mode, multi-region via Konnect | ✓multi-region managed | ✓managed regional service | ✓clustered gateways, multi-DC in paid tiers |
| Observability | ✓Prometheus metrics + the audit log is itself queryable (CeQL) — token spend per key is a query | ✓Prometheus, Datadog, OpenTelemetry plugins | ✓full analytics + monetization reporting suite | ✓CloudWatch metrics/logs, X-Ray tracing | ✓Tyk Pump → Prometheus/Elastic/etc. |
| API monetization | ✗token/request metering as facts, but no billing engine | ~via plugins/partners | ✓first-class monetization suite | ~usage plans + marketplace | ~in paid dashboard tiers |
| Commercial support | ✗GitHub issues + docs; no support org today | ✓enterprise support org, professional services | ✓Google Cloud support + SLAs | ✓AWS support plans + SLAs | ✓commercial support on paid plans |
| Pricing modelindicative public list pricing, mid-2026 — verify with vendors | $0The software is free; you pay for a small VM (≈$5–20/mo) you already control. Optional cloud-LLM usage is billed by the model provider, off by default | OSS: free. Konnect Plus: ≈$105/mo per gateway service incl. 1M requests, ≈+$200 per extra 1M. Enterprise: custom, ≈$30k–50k+/yr entry | ≈$20 per 1M calls + environment fees from ≈$365/mo per region; security/analytics add-ons extra | ≈$1.00/M (HTTP APIs) or ≈$3.50/M (REST APIs) — cheapest per call, but AWS-locked; audit/analytics are separate billed services | OSS gateway free (self-hosted); cloud/dashboard tiers paid, quotes vary |
| License | The PostgreSQL LicenseOSI-approved, permissive, free for any use incl. commercial, no copyleft | OSS: Apache 2.0 · Konnect/Enterprise: proprietary | proprietary (Google Cloud service) | proprietary (AWS service) | gateway: MPL 2.0 · dashboard/cloud: proprietary |
Pricing sources: Kong Konnect, Google Cloud Apigee, and AWS API Gateway public pricing pages, mid-2026. List prices change and enterprise contracts vary — verify with each vendor before budgeting.
Three things are genuinely different, and they all come from the gateway being built on a bi-temporal database rather than on a config store:
Routes and keys are facts with two clocks. FACTS OF route:api FACET config AS OF 'last tuesday 9am' shows what was live then; AS KNOWN AT shows what you believed then; HISTORY OF route:api shows every version ever. Nobody reconstructs an incident from git archaeology.
Every request writes a metadata fact into the same append-only, hash-chained log. centauri verify recomputes the chain byte-for-byte — if anyone edited the traffic record after the fact, it points at the exact line. Logs in a bucket cannot make that promise.
The LLM gateway pins models, fails over across providers, streams SSE, and writes model, prompt_tokens, and completion_tokens into the audit fact per request. "What did key ci-bot spend on GPT-5.5 last week?" is a CeQL query, not a billing-export project.
…you need raw throughput, a huge plugin ecosystem, Kubernetes ingress or service mesh, OAuth2 flows where the gateway acts with a full IdP integration surface, multi-DC topologies, or an enterprise support organization on the other end of a contract. Kong's NGINX core and plugin catalog are years ahead of anything Centauri offers, and its AI gateway is mature. That is what the Konnect subscription buys.
…you monetize APIs as products: developer portals, rate plans, billing, and a full analytics suite, with Google-scale SLAs and someone else running the infrastructure. None of that exists in Centauri.
…your stack is already AWS and you want serverless scale with the lowest per-call price and zero hosts to manage. IAM/Cognito integration and Lambda authorizers are native. Accept that you assemble audit and analytics from separate services, and that leaving AWS means rebuilding the layer.
…you want a fast, open-source Go gateway with a real plugin system and k8s support, self-hosted without NGINX, and are happy pairing it with Redis and (optionally) its paid dashboard.
…your gateway's history matters as much as its throughput: regulated or audit-sensitive APIs, AI/LLM traffic where per-key token accounting must be provable, small-to-mid request volumes, and teams who want one $0 binary with no Postgres, no Redis, and no control-plane bill. It is also the natural choice if you already run Centauri as a system of record.
One binary, two commands: centauri gateway -data gateway.log -addr :8080 -admin :7771 starts the proxy and its admin dashboard; PUT route:api FACET config SET prefix='/api/', upstream='http://127.0.0.1:9000', auth='key' is the whole route config. Mint keys in the browser at /console.