Home/Labs/API Gateway Pipeline
All 280 Labs
INTERACTIVE LAB🚪

API Gateway Pipeline Lab (Interactive)

Fire web, mobile, bot, and expired-token requests through gateway stages and count what dies at the edge. Toggle AuthN, Redis rate limiting, protocol transcoding, and BFF aggregation. Measure backend calls avoided, roundtrips saved, and latency added per pipeline stage.

API Gateway Cross-Cutting Pipeline

Send client traffic through Auth → Rate Limit → Transcode → Aggregate and see what dies at the edge.

Validates signature + scopes; injects X-User-Id downstream.

✓ passed

Sliding window: 100 req/min per API key.

Public JSON/REST → binary gRPC into the VPC (~80% payload cut).

✓ passed

Fans out to User+Order+Recs in parallel, returns ONE lean response.

✓ passed

Response to 📱 Mobile App (home feed)200 OK (composed)

› Backend calls consumed: 3

› Edge RTT: 115ms (vs 285ms if the phone made 3 roundtrips itself)

› Gateway CPU: 1.2ms/req · internal gRPC payload saved 3KB

BFF SPLIT

› Web BFF: rich 48KB tables (fiber, big screen). Mobile BFF: 4KB aggregated feed (battery + cellular). TV BFF: tile queries only. Each frontend owns its gateway, decoupling release cycles.

Load controls

Bot sends 1 req/minute-window; if that exceeds the limit and limiting is on, the gateway returns 429 at the edge.

Rejected at edge0 reqs
Roundtrips saved2 RTT

7 responsibilities

1 Routing · 2 AuthN/AuthZ · 3 Rate limiting · 4 Protocol translation · 5 Aggregation · 6 Tracing (X-Request-Id) · 7 Circuit breaking.

Warning: an unscaled gateway is itself a SPOF and a team-velocity bottleneck — that is why BFFs exist.

How It Works Under the Hood

Letting mobile and web clients call dozens of microservices directly duplicates JWT verification, rate limiting, and CORS across every team and forces chatty multi-roundtrip fetches over cellular. The API Gateway is the single public entry point: it validates tokens and injects clean X-User-Id headers, enforces Redis-backed sliding-window limits, transcodes public JSON/REST into internal binary gRPC, and composes parallel fan-outs to User, Order, and Recommendation services into one lean response. The BFF pattern specializes a gateway per client platform — rich payloads for desktop, sub-5KB aggregated feeds for mobile.

Core Architectural Principles

  • Edge AuthN rejects expired JWTs and rate limiting kills abusive keys before any pod spends CPU.
  • Protocol transcoding converts public REST/JSON to internal gRPC; composition collapses 3 mobile roundtrips into 1.
  • Backend-for-Frontend gateways tailor payload shape and size per client platform.
Interview Round Script

Enumerate the gateway responsibilities deliberately — routing, AuthN/AuthZ, rate limiting, protocol translation, aggregation, tracing, circuit breaking — then introduce BFF when the design has both mobile and web clients. Always note the gateway itself must scale horizontally or it becomes the new bottleneck.

Key Trade-Offs

One place for cross-cutting concerns and fewer client roundtrips, versus a central component that must scale and can bottleneck team release cycles.

Related Curriculum Chapter

API Gateway Concept & Responsibilities

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs