API gateway comparison

Centauri Gateway vs Kong, Apigee, AWS & Tyk — honestly.

centauri gateway is an API + LLM gateway whose configuration is bi-temporal facts (you can time-travel any past config) and whose per-request audit is a tamper-evident hash chain. It is also a young, single-binary gateway from a small project — so this page states plainly what Kong, Google, AWS, and Tyk do better. Documentation honesty is policy here: a ✗ is a ✗.

The feature matrix

✓ = shipped and first-class · ~ = partial, or assembled from other pieces · ✗ = not offered. Nuance in small print; when in doubt, the cell errs in the competitor's favor.

Centauri GatewayKong (OSS + Konnect)Google ApigeeAWS API GatewayTyk
Config model bi-temporal factsroutes & keys are database facts; AS OF / AS KNOWN AT / HISTORY replay any past config; RETIRE, never delete ✓declarative YAML (DB-less), Postgres-backed, or Konnect console; version via GitOps ✓API proxies with numbered revisions; console + management API ~console / CloudFormation / SAM; stages + deployment history ✓API definitions in files, Redis, or the dashboard
Config time travel"what was live last Tuesday 9am?" ✓one query; every change is a superseding fact ✗reconstruct from git history / external audit ~revision rollback exists; not point-in-time query ~redeploy an old stage deployment ✗
Request audit trail tamper-evidentper-request facts in a SHA-256 hash chain; centauri verify proves nothing was edited; metadata only, never bodies ~rich logging via plugins to your sink; not independently verifiable ✓managed analytics + Cloud Audit Logs; strong, but not a verifiable chain you hold ~assemble CloudWatch + CloudTrail + Athena yourself ~analytics via Tyk Pump to your store
AI / LLM routing ✓OpenAI-compatible routes; SSE streaming passthrough; provider failover (until first byte); model pinning; per-key token metering stored as queryable facts ✓dedicated AI-gateway plugin suite: multi-provider routing, token rate limiting, prompt guards ~emerging LLM-ops features on Google's stack ~assemble with Bedrock, Lambda, and usage plans ~AI offering newer and less proven than Kong's
Authentication ~✓ minted API keys (hash-only at rest), OIDC JWT validation (RS256/384/512, JWKS), mTLS client certs — AND issues service tokens (OAuth2 client-credentials at /gw/token, own JWKS). ✗ no human login/consent flows — bring your IdP for people ✓full OAuth2/OIDC plugin suites, key auth, HMAC, LDAP, ACLs ✓built-in OAuth2 authorization server, API keys, JWT ✓IAM, Cognito, Lambda authorizers, mTLS ✓OAuth2/OIDC, HMAC, mTLS, custom middleware auth
Rate limiting ✓per-route, per-key, and per-IP budgets ✓basic + advanced (sliding window, clustered) ✓quotas + spike arrest policies ✓throttling + usage plans ✓quotas + rate limits per key/policy
Middleware / plugins ~built-ins (CORS, header add/remove, IP allow/deny, body caps, path blocks, prefix strip, timeouts) + programmable CePL request policies (stored, versioned, AS OF-auditable) + webhook auth callouts. No third-party plugin marketplace ✓hundreds of plugins + custom plugins in Lua/Go/JS/Python ✓rich policy catalog (transform, mediate, callout) ~mapping templates + Lambda integrations ✓middleware in JS/Python/Go gRPC plugins
Kubernetes ingress / mesh ✗no ingress controller, no mesh; runs fine *in* k8s as a plain deployment ✓Kong Ingress Controller + Kuma/Kong Mesh ~via Apigee adapters / Anthos service mesh ~not a k8s ingress; ALB/App Mesh are separate products ✓Tyk Operator + ingress support
Throughput class ~Go stdlib reverse proxy; comfortable for small/mid APIs; no published high-throughput benchmarks — do not pick it for six-figure RPS ✓NGINX/OpenResty core; very high, battle-tested throughput ✓Google-scale managed infrastructure and SLAs ✓serverless scale, regional redundancy ✓Go gateway, high throughput, published benchmarks
Deployment weight one binaryconfig + audit in one log file; no separate DB, no control-plane service; admin plane is the same binary ~data plane + control plane; Postgres (DB mode) or DB-less files; Konnect adds SaaS control plane ~managed SaaS; org/environment provisioning ✓fully managed, nothing to host ~gateway + Redis; dashboard/analytics components extra
Scale-out / HA ~N gateways follow one primary control plane (-control-follow, read-only replicas); no multi-DC, no gateway leader election ✓clustering, hybrid mode, multi-region via Konnect ✓multi-region managed ✓managed regional service ✓clustered gateways, multi-DC in paid tiers
Observability ✓Prometheus metrics + the audit log is itself queryable (CeQL) — token spend per key is a query ✓Prometheus, Datadog, OpenTelemetry plugins ✓full analytics + monetization reporting suite ✓CloudWatch metrics/logs, X-Ray tracing ✓Tyk Pump → Prometheus/Elastic/etc.
API monetization ✗token/request metering as facts, but no billing engine ~via plugins/partners ✓first-class monetization suite ~usage plans + marketplace ~in paid dashboard tiers
Commercial support ✗GitHub issues + docs; no support org today ✓enterprise support org, professional services ✓Google Cloud support + SLAs ✓AWS support plans + SLAs ✓commercial support on paid plans
Pricing modelindicative public list pricing, mid-2026 — verify with vendors $0The software is free; you pay for a small VM (≈$5–20/mo) you already control. Optional cloud-LLM usage is billed by the model provider, off by default OSS: free. Konnect Plus: ≈$105/mo per gateway service incl. 1M requests, ≈+$200 per extra 1M. Enterprise: custom, ≈$30k–50k+/yr entry ≈$20 per 1M calls + environment fees from ≈$365/mo per region; security/analytics add-ons extra ≈$1.00/M (HTTP APIs) or ≈$3.50/M (REST APIs) — cheapest per call, but AWS-locked; audit/analytics are separate billed services OSS gateway free (self-hosted); cloud/dashboard tiers paid, quotes vary
License The PostgreSQL LicenseOSI-approved, permissive, free for any use incl. commercial, no copyleft OSS: Apache 2.0 · Konnect/Enterprise: proprietary proprietary (Google Cloud service) proprietary (AWS service) gateway: MPL 2.0 · dashboard/cloud: proprietary

Pricing sources: Kong Konnect, Google Cloud Apigee, and AWS API Gateway public pricing pages, mid-2026. List prices change and enterprise contracts vary — verify with each vendor before budgeting.

What Centauri does that the others don't

Three things are genuinely different, and they all come from the gateway being built on a bi-temporal database rather than on a config store:

1 · Config you can time-travel

Routes and keys are facts with two clocks. FACTS OF route:api FACET config AS OF 'last tuesday 9am' shows what was live then; AS KNOWN AT shows what you believed then; HISTORY OF route:api shows every version ever. Nobody reconstructs an incident from git archaeology.

2 · An audit you can prove

Every request writes a metadata fact into the same append-only, hash-chained log. centauri verify recomputes the chain byte-for-byte — if anyone edited the traffic record after the fact, it points at the exact line. Logs in a bucket cannot make that promise.

3 · LLM spend as a query

The LLM gateway pins models, fails over across providers, streams SSE, and writes model, prompt_tokens, and completion_tokens into the audit fact per request. "What did key ci-bot spend on GPT-5.5 last week?" is a CeQL query, not a billing-export project.

When to choose which — honest guidance

Choose Kong when…

…you need raw throughput, a huge plugin ecosystem, Kubernetes ingress or service mesh, OAuth2 flows where the gateway acts with a full IdP integration surface, multi-DC topologies, or an enterprise support organization on the other end of a contract. Kong's NGINX core and plugin catalog are years ahead of anything Centauri offers, and its AI gateway is mature. That is what the Konnect subscription buys.

Choose Apigee when…

…you monetize APIs as products: developer portals, rate plans, billing, and a full analytics suite, with Google-scale SLAs and someone else running the infrastructure. None of that exists in Centauri.

Choose AWS API Gateway when…

…your stack is already AWS and you want serverless scale with the lowest per-call price and zero hosts to manage. IAM/Cognito integration and Lambda authorizers are native. Accept that you assemble audit and analytics from separate services, and that leaving AWS means rebuilding the layer.

Choose Tyk when…

…you want a fast, open-source Go gateway with a real plugin system and k8s support, self-hosted without NGINX, and are happy pairing it with Redis and (optionally) its paid dashboard.

Choose Centauri Gateway when…

…your gateway's history matters as much as its throughput: regulated or audit-sensitive APIs, AI/LLM traffic where per-key token accounting must be provable, small-to-mid request volumes, and teams who want one $0 binary with no Postgres, no Redis, and no control-plane bill. It is also the natural choice if you already run Centauri as a system of record.

When NOT to choose Centauri: six-figure requests-per-second at the edge; Kubernetes ingress duty; OAuth2 human login/consent flows (it validates JWTs and issues service tokens via client-credentials, but has no login UI — it is not a full IdP); multi-datacenter active/active; anything that needs a plugin marketplace or a commercial support contract. Writes are single-writer per log and the working set is RAM-resident unless the archive tier is enabled. If those are your constraints, the vendors above earn their price — and this page will still be here when your audit requirements catch up with you.

Try it

One binary, two commands: centauri gateway -data gateway.log -addr :8080 -admin :7771 starts the proxy and its admin dashboard; PUT route:api FACET config SET prefix='/api/', upstream='http://127.0.0.1:9000', auth='key' is the whole route config. Mint keys in the browser at /console.

⬇ Download Centauri Gateway guide → Pricing & licensing