API Gateway Pricing, and Why the Request Fee Misleads
Gateway pricing gets compared on one number: the fee per million requests.
It’s the figure every vendor leads with and every comparison table lines up. On plenty of real bills it’s also the smaller line, once data transfer, logging and duplicated environments are added underneath it.
Model the whole bill before comparing request fees. Two gateways that differ by a dollar per million can differ by hundreds a month once everything else is counted.
Key Takeaways
- Comparing request fees alone misses egress, logging and environment costs.
- Crossing a certain volume flips per-request pricing from cheapest to dearest.
- Buying a management platform costs a multiple of the gateway most teams need.
- Running open source yourself trades a license fee for servers and on-call time.
The Four Pricing Models
Every gateway on the market charges in one of four shapes.
| Model | What you pay for | Cheapest when |
|---|---|---|
| Per request | Each call, in blocks of a million | Traffic is low or spiky |
| Per instance | Gateway capacity by the hour | Traffic is high and steady |
| Per service | A subscription for each API you run | You run few APIs at volume |
| Flat edge tier | A plan with generous request limits | Payloads are small and cacheable |
The large cloud providers mostly sell the first two. Specialist gateway vendors lean toward the third, and edge networks toward the fourth.

Lightweight and Full-Featured Tiers
The large providers sell two grades of gateway, and the price gap between them is wide.
The lightweight tier handles routing, authentication and basic rate limiting, and it’s priced at around 1 dollar per million requests. The full-featured tier adds request transformation, usage plans, API keys and caching, and it costs roughly three and a half times as much per call.
Start on the lightweight tier unless you need a feature it lacks. Teams pick the full-featured option by default and pay the premium on every call for features they never switch on.
Persistent connections are priced differently again. They bill per message and per connection minute, so a chat or live-dashboard API that holds thousands of idle connections open pays for the idling.
The Crossover Point
Per-request and per-instance pricing trade places at a specific volume, and it’s worth calculating.
Take a per-request tier at 1 dollar per million calls against an instance that costs 200 dollars a month flat. Below 200 million calls a month the per-request option is cheaper. Above it, the instance wins, and the gap widens with every million.
Find that number for the two options you’re weighing. Then check which side of it your traffic sits on this year and where it’s heading next year, because moving later means a migration.
The same crossover logic decides property management software pricing, where a monthly minimum hides the per-unit rate until a portfolio outgrows it.
What Sits Outside the Request Fee
Five charges commonly land on the same invoice, and none of them appears in the headline rate.
- Data transfer out, charged per gigabyte leaving the provider’s network.
- Request logging, charged by the volume of log data you keep.
- Response caching, priced by cache size and by the hour.
- Custom domains and certificates, sometimes a flat monthly line.
- Firewall rules in front of the gateway, billed per rule and per request.
Each is modest alone. Together they’re the reason a gateway budgeted from the request fee comes in at two or three times the estimate.
Egress Is the Line That Doubles Bills
Response size decides this one, and it’s easy to underestimate.
At 100 million requests a month returning 20 kilobytes each, you send roughly 2 terabytes out. Priced at typical cloud egress rates, that’s around 180 to 190 dollars a month, before a single request fee.
Against a 100-dollar request bill for the same traffic, the transfer line is the bigger number. Trimming response payloads is often the cheapest optimization available, and it reduces the gateway bill without touching the gateway.

Free Tiers and Where They End
Most managed gateways include a free allowance, and it’s generous for a first year.
A typical allowance covers around a million calls a month for the first twelve months. That’s enough to build and launch something small without a gateway bill, and it’s a fair way to test a provider before committing.
The catch is the cliff at month thirteen. A service that grew quietly under the allowance starts billing at full rate overnight.
Note the expiry date when you sign up, rather than discovering it on an invoice.
Rate Limits Are a Cost Control
They’re usually discussed as protection, and they’re also the cheapest way to cap a bill.
A per-client limit stops one misbehaving integration from generating a month of charges in an afternoon. A burst limit smooths spikes that would otherwise land as billed calls and billed egress.
Set both before launch. Tuning them afterwards is easy, while explaining an unexpected invoice to whoever approves the spend is not.
Gateway or Management Platform
The two get sold under similar names and priced at different levels entirely.
A gateway routes calls, checks credentials and enforces rate limits. That covers the needs of an internal API or a small number of partner integrations, and it’s the part billed per request or per instance.
A management platform adds a developer portal, usage analytics, API versioning and billing for external consumers. It usually costs a multiple of the gateway, and it earns that only if outside developers are signing up to use your API.
Buy the portal when you have a developer audience, not before. Plenty of teams pay for monetization features on APIs that only their own frontend ever calls.
Self-Hosting Is Not Free
Open source gateways remove the license fee and keep every other cost.
Running one yourself means servers in at least two zones for availability, a monitoring stack, upgrade work each release, and somebody on call when it fails at night. For a small team that time is the expensive part.
Self-hosting starts to pay once traffic is high enough that managed per-request fees become a large line and you already run infrastructure at that standard. Below that, the managed option is cheaper even though its rate card looks higher.
Multiple Regions Multiply It Again
A gateway in two regions is billed as two gateways.
Teams add a second region for latency or for resilience, and both are good reasons. The cost consequence is that instance pricing doubles outright, and per-request pricing splits the same traffic while adding cross-region transfer between them.
Decide whether the second region is for speed or for failover before you price it. A standby region that only carries traffic during an outage is far cheaper on per-request pricing.
On instance pricing it bills around the clock for capacity it rarely uses.
Switching Costs More Than Choosing Well
The gateway sits in front of every API, so moving off it touches everything behind it.
Routes, authentication rules, rate limits and custom domains all have to be rebuilt on the new platform and tested against real clients. That’s weeks of engineering time, which dwarfs the monthly saving that prompted the move.
That’s the practical argument for modelling growth at the start. A model that fits this year but crosses over next year means paying for a migration you could have avoided by choosing once.
Environments Multiply Everything
Development, staging and production are three gateways, not one.
Per-instance pricing charges for each environment whether or not it carries traffic, so an idle staging gateway costs the same as a busy one. Per-request pricing is kinder here, since quiet environments generate few calls.
Count your environments before comparing models. A team running four environments on instance pricing can spend more on test gateways than on production.
Security Belongs in the Estimate
The gateway is where authentication and rate limiting happen, so it’s also where abuse gets billed.
A scraper hammering an unprotected endpoint generates real request fees and real egress. Rate limits and credential checks at the gateway cap that cost, and they’re a line to switch on before launch rather than after the first surprising invoice.
The broader discipline is the same one covered in protecting software from hackers: control what reaches the system before worrying about the system itself.
Modelling Your Own Number
Five inputs produce a realistic monthly figure.
- Monthly requests, taken from current logs rather than a guess.
- Average response size, which drives the egress line.
- Environment count, including staging and any preview environments.
- Log retention, meaning the number of days of request logs you keep.
- Growth over twelve months, so the crossover gets checked in advance.
Run those through two candidate models and the comparison usually settles itself. The request fee becomes one row in five rather than the whole decision.
Price Should Not Always Decide It
Below a few hundred dollars a month, cost differences rarely justify a harder platform.
At that scale, the gateway your team already knows, on the cloud you already use, is usually the cheaper choice in total. Integration time, debugging familiarity and one fewer vendor outweigh a dollar per million.
Pricing starts to decide it once the gateway is a meaningful share of infrastructure spend. That’s the point to model the options properly and consider moving.
Questions to Ask a Vendor
- Ask what the rate is per million requests, and where the tier breaks fall.
- Ask whether data transfer out is included or billed separately.
- Ask how logging is priced, and what the default retention is.
- Ask whether each environment is billed as a separate gateway.
- Ask what happens to the bill when traffic spikes unexpectedly.
The spike question matters most. Some plans cap throughput and some bill every extra call, and finding out during an incident is the expensive way to learn which.
Comparing the Tools Themselves
Once the pricing model is chosen, the product decision narrows quickly.
The API management software category lists the gateways and platforms side by side. Filter by the pricing model that fits your traffic first, and the shortlist gets short.
Questions People Ask About API Gateway Pricing
How much does an API gateway cost?
Managed gateways charge roughly 1 to 3.50 dollars per million requests at list price, before data transfer and logging. Instance-priced gateways run from about 50 dollars to four figures a month regardless of traffic.
Is per-request pricing cheaper?
At low volume, yes. Per-request pricing scales with traffic, so it overtakes a flat instance price once monthly requests pass the crossover point for that pair of options.
What costs sit outside the request fee?
Data transfer out, request logging, caching, custom domains and firewall rules are the usual extras. Egress alone can match or exceed the request fee on payload-heavy APIs.
API gateway or API management: what’s the difference?
An API gateway is the runtime layer that routes, authenticates and rate-limits calls. API management adds a developer portal, analytics and monetization, and costs a multiple of it.
Is a self-hosted open source gateway free?
The license is free and the running is not. Servers, upgrades, monitoring and on-call time usually cost more than a managed gateway until traffic is high.
Price the Bill, Not the Rate
Write down your requests, response size and environment count, then price each candidate across all five lines.
The request fee that looked decisive usually ends up the third-largest number on the page, and the cheapest-looking gateway is frequently not the cheapest one to run.
Add SocialAtoZ as a preferred source
See us more often in your Google results.