Kong Gateway Enterprise is a self-hosted API and AI gateway deployed as an AMI on AWS EC2, giving platform engineering teams full control over data residency, network topology, and infrastructure. Trusted by enterprises like United Airlines, HSBC, BMW, and SeatGeek, Kong processes over 1 trillion API and AI requests per day with a 99.99% availability SLA.
With Kong Gateway Enterprise on EC2, you manage your own infrastructure without hosted control plane dependencies - ideal for organizations with strict compliance, data sovereignty, or network isolation requirements.
Key Capabilities
API Gateway and Lifecycle Management: Route, load balance, authenticate, authorize, rate limit, and transform REST, GraphQL, gRPC, and event-based APIs from a single gateway
AI Gateway: Manage traffic to LLM providers with prompt and response management, semantic caching, and token-based rate limiting
Plugin Ecosystem: Extend functionality with 100+ pre-built plugins covering logging, authentication, observability, and AI providers
Service Mesh: East-west traffic management with mutual TLS (mTLS), traffic policies, and service-level observability
Developer Portal: Publish API products, manage access, and enable self-service API discovery for internal and external developers
Metering and Billing: Usage-based monetization of APIs and AI services with runtime entitlement enforcement
Security and Compliance
Kong Gateway Enterprise is built for regulated enterprise environments:
SOC 2 Type II audited and certified
PCI DSS 4.0.1 compliant
GDPR and CCPA compliant
NIST 800-218 (Secure Software Development Framework) self-attested
CSA STAR Level 1 self-assessment published
FIPS 140-2 support available for Ubuntu and Red Hat builds
Mutual TLS (mTLS) for service-to-service encryption
Role-based access control (RBAC), SSO, and audit logging
Annual third-party penetration testing by independent security firms
Software Bill of Materials (SBOM) published for supply chain transparency
Integrations
Kong integrates natively with AWS services including ALB, CloudWatch, and EKS. Additional integrations include Prometheus, Datadog, HashiCorp Vault, and OpenID Connect providers. Native Kubernetes support via Kong Ingress Controller enables consistent API governance across containerized and VM-based workloads.
Deployment Prerequisites
Supported operating systems:
Amazon Linux 2
Ubuntu (Jammy, Noble)
Red Hat Enterprise Linux
Debian
Supported architectures: AMD64 and ARM64
Minimum requirements: Ensure your EC2 instance has sufficient CPU and RAM for your expected traffic volume. Kong recommends starting with instances such as m5.large or larger for production workloads.
Networking: Configure your VPC with appropriate security group rules. Kong Gateway requires inbound access on ports 8000 (proxy), 8443 (proxy SSL), 8001 (Admin API), and 8444 (Admin API SSL).
Datastore: PostgreSQL database required for traditional mode. DB-less mode available with declarative configuration.
Use Case: AI Gateway for LLM Traffic
Route and govern traffic to multiple LLM providers with prompt management, semantic caching, and token-based rate limiting. SeatGeek uses Kong to handle 2.4 billion requests per month, demonstrating how the platform scales for AI-era workloads while maintaining security and cost controls.
Customer Results
HSBC: 50% faster time-to-market
DELTA Fiber: 60% reduction in development costs
Enterprises report up to 57% reduction in operational costs
35,000+ GitHub stars and 182,000+ community users worldwide
Licensing Model
This listing uses a Bring Your Own License (BYOL) model. The AMI software itself does not incur metered AWS Marketplace charges, but a valid Kong Enterprise license is required. Contact Kong sales to discuss licensing options for your organization.
Use Case: Financial Services API Security at Scale
Financial institutions use Kong Gateway Enterprise to route millions of API calls across hybrid cloud environments while enforcing strict compliance policies on payment and transaction APIs. With mTLS, rate limiting, and centralized observability, teams maintain PCI DSS compliance while scaling API traffic across AWS regions and on-premises data centers.
This listing uses a Bring Your Own License (BYOL) model. The AMI software itself does not incur metered AWS Marketplace charges. A valid Kong Enterprise license is required, contact Kong sales at sales@konghq.com to discuss licensing options for your organization.
Highlights
Kong Gateway Enterprise processes over 1 trillion API and AI requests per day with a 99.99% availability SLA. The self-hosted AMI gives you full control over data residency and network topology on AWS EC2. Customers report up to 57% reduction in operational costs and 50% faster time-to-market. Supports REST, GraphQL, gRPC, and event-based APIs through a single gateway with 100+ pre-built plugins.
AI Gateway for LLM Traffic Management - Route and govern traffic to multiple LLM providers with prompt management, semantic caching, and token-based rate limiting. Enforce token budgets and cost controls at runtime. Built for platform engineers managing AI workloads alongside traditional API traffic. SeatGeek handles 2.4 billion requests per month through Kong, demonstrating enterprise-scale AI and API connectivity.
Enterprise-Grade Security and Extensibility - Zero-trust networking with mutual TLS (mTLS) between services, OAuth 2.0 and OpenID Connect authentication, role-based access control (RBAC), rate limiting, and audit logging. Extend functionality with 100+ plugins for logging, observability (Prometheus, Datadog), secrets management (HashiCorp Vault), and more. Native Kubernetes support via Kong Ingress Controller for consistent governance across hybrid environments.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You deploy this self-hosted API and AI gateway on your own AWS infrastructure, and the software itself is free. Pricing here reflects the underlying EC2 compute you run it on, billed per hour. You choose between two instance types: t4g.small and c6g.large. The t4g.small fits lighter or test workloads, while the c6g.large gives more compute for heavier traffic. Both bill by the hour based on how long the instance runs. Your cost scales with which instance you pick and how many hours you keep it running.
Top-of-mind questions for buyers
What compute specs come with the t4g.small versus the c6g.large instance?
The t4g.small is a small ARM-based instance suited to lighter or test workloads. The c6g.large is a compute-focused ARM instance with more processing power for heavier API and AI traffic. You pick one based on your throughput needs, and billing follows the hours that instance runs.
Am I charged the hourly rate when the instance is stopped or idle?
The hourly software rate meters running time only. A fully stopped instance does not accrue the per-hour software charge. Stopped instances may still incur underlying AWS storage fees for attached volumes, but those are separate from the gateway software billing shown here.
The software is free, so what am I actually paying for on this listing?
The gateway software carries no licence charge. You pay for the AWS EC2 compute the software runs on, billed per hour for either the t4g.small or c6g.large instance. Your cost depends on which instance type you choose and how many hours it runs.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
EC2 Image Builder is a fully managed AWS service. It automates creation, management, and deployment of custom, secure, and up-to-date server images. After procurement, use the EC2 Image Builder console/API to include this third-party component in golden images for future EC2 instances.
Access the knowledge base and troubleshooting guides
View documentation and community resources
Check Konnect Cloud service status
Getting Started with Support:
Log in to the Kong Support Center
Follow best practices for filing a support case to ensure fast resolution
Track your case status directly in the portal
Enterprise Support Tiers:
Diamond: 24x7 coverage with 30-minute response SLA
Platinum: 24x7 coverage with 1-hour response SLA
Business: Regional business hours with 2-hour response SLA
Plus Plan Support:
Email support with a 2-business-day SLA
Enterprise customers also receive access to dedicated Customer Success Managers, Technical Account Managers, and professional services for migration and onboarding assistance.
Licensing: This is a BYOL (Bring Your Own License) product. To obtain a Kong Enterprise license or discuss licensing options, contact Kong sales at https://konghq.com/contact-sales
For refund inquiries or billing questions related to your AWS Marketplace subscription, please contact Kong support through the portal above.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Kong Konnect is the unified API management platform delivered as a service that can manage Kong Gateway, Kong AI Gateway, Kong Ingress Controller, and Kong Mesh with a single management console to deliver API configuration, portal, service catalog, and analytics capabilities.
Launch a self hosted Kong API Gateway and AI Gateway on Ubuntu 26.04 LTS with Docker Compose, PostgreSQL, a public IP landing page, a working demo route, and an AI Gateway starter helper for OpenAI compatible traffic. Built for developers and teams that want fast API routing, testing, and AI gateway workflows inside their own AWS account. This is a repackaged open source software product wherein additional charges apply for Code Creator integration of Kong Gateway, PostgreSQL and Docker Compose, automated first boot public IP configuration, working API demo route, AI Gateway setup tooling, backup and configuration helpers, security configuration, and AWS Marketplace AMI engineering.
What I like most about Kong Konnect is that it gives us one centralized place to manage, secure, and monitor our API gateways across different environments. I also like the separation between the cloud control plane and local data planes, which makes deployment easier without adding latency to our backend traffic. Setting up things like OAuth2, rate limiting, and mTLS using the available plugins is also quite straightforward. The service catalog and Developer Portal are useful as well, especially when multiple teams are working with different APIs.
What do you dislike about the product?
Getting onboarded took longer than expected because the documentation mixes Konnect cloud concepts with self-hosted Kong Gateway setup, which caused some initial confusion. The user interface can also occasionally feel sluggish when managing large numbers of services and routes. Finally, the pricing jumps quite a bit between tiers once your API call volume begins scaling up.
What problems is the product solving and how is that benefiting you?
We struggled with inconsistent API security and manual gateway maintenance across distributed environments. Kong Konnect centralized our API management into a single dashboard, allowing us to enforce global security policies, authentication, and rate-limiting seamlessly. This has freed up valuable developer hours from managing infrastructure, improved our API uptime, and made onboarding new services much faster.
Jaydeepkumar R.
Centralized API Traffic Visibility That Makes Debugging and Testing Easier
Reviewed on Sep 10, 2026
Review provided by G2
What do you like best about the product?
From a testing perspective, having a centralized layer to observe API traffic has made it much easier to debug failed test runs. I can see exactly which requests and responses passed through, instead of having to dig through individual service logs. The rate-limiting and throttling plugins have also been useful for load and stress testing scenarios, and the request/response transformation plugins make it easier to simulate different payloads for stronger negative test coverage.
What do you dislike about the product?
The learning curve is pretty steep if you’re coming from a QA background without much infrastructure exposure—concepts like services, routes, and plugins take time to get comfortable with. Automating tests against the gateway also adds some friction, since you have to manage auth tokens and consumer credentials just to get CI pipelines running smoothly. The documentation tends to lean more toward admin-focused use cases as well, which leaves a noticeable gap when you’re looking for QA-specific workflows.
What problems is the product solving and how is that benefiting you?
It’s given us a single, consistent place to validate authentication and security policies, rather than having to test each API’s custom implementation separately, which was often inconsistent and time-consuming. Because traffic flows through one observable layer, integration issues show up earlier, and we’ve seen fewer flaky test failures caused by mismatched rate-limiting or authentication behavior across environments.
Trupti S.
Strong API Security and Centralized Authentication That Saves Time
Reviewed on Sep 10, 2026
Review provided by G2
What do you like best about the product?
The API security and authentication features are the strongest part of the platform for us. Setting up OAuth, API key policies, and rate limiting per consumer has given us a much tighter grip on who's accessing what across our services. Managing auth centrally instead of building it into every individual API has saved a lot of duplicated effort, and the audit trial for API access has been genuinely useful when troubleshooting or reviewing security posture.
What do you dislike about the product?
The learning curve is steep, especially early on. There is lot of terminology and moving pieces (services, routes, plugins consumes) that take time to fully understand, and the initial setup wasn't as intuitive as I expected. Documentation helps, but getting the security policies configured exactly right the first time took more trial and error that I'd have liked. It would benefit from clearer guided setup for common auth scenarios.
What problems is the product solving and how is that benefiting you?
Before adopting Konnect, authentication and authorization logic was inconsistent across our APIs, with each service handling it slightly different, which made auditing and securing everything harder. Centralizing auth policies through Konnect has given us consistent security enforcement across the board, reduced the risk of gaps or misconfigurations, and made onboarding new APIs into our ecosystem significantly faster since the security groundwork is already standardized.
Mansi N.
Solid API Gateway with Easy Traffic Management and Great Visibility
Reviewed on Sep 09, 2026
Review provided by G2
What do you like best about the product?
The API gateway and traffic management side of things has been solid for us. Rate limiting, load balancing, and routing rules are straightforward to configure once you get the hang of the platform, and it scales well without a lot of babysitting. The centralized visibility into API traffic across services has made it much easier to spot issues before they become bigger problems. Onboarding new APIs into the gateway is fairly quick once the initial setup is done.
What do you dislike about the product?
Support response time has been the main pain point for us. When we've run into issues that actually needed help (not just documentation lookups), turnaround has been slower than I'd like, especially for anything time-sensitive.
What problems is the product solving and how is that benefiting you?
Before Konnect, managing traffic and rate limits across our APIs was scattered and inconsistent, which made troubleshooting slow and error-prone. Having a single place to manage gateway policies has cut down the time we spend chasing down traffic issues and given us much better visibility into what's actually happening across our API layer. It's made scaling our API infrastructure less of a headache overall.
Kirpalsinh R.
Centralized API governance and sub-millisecond proxy routing for microservices
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
Managing API routing across a distributed microservices environment requires strict consistency, and Kong Konnect's hybrid architecture handles this exceptionally well. The SaaS control plane provides a unified view for configuring services, while the self-hosted data plane instances run locally near our Kubernetes workloads to keep proxy latency negligible. Implementing edge concerns—such as OAuth2 token validation, rate-limiting, and request transformation—via out-of-the-box plugins offloads significant overhead from our application code. Furthermore, managing the gateway state declaratively using the decK CLI seamlessly integrates into our GitOps pipelines, making deployment changes across staging and production environments predictable and fully version-controlled.
What do you dislike about the product?
Developing custom plugin logic still requires working with Lua or building WebAssembly modules, which introduces extra friction for development teams accustomed to higher-level languages like Python or Go. When troubleshooting synchronization mismatches between the SaaS management console and self-hosted runtime groups, navigating low-level proxy logs to isolate SSL certificate or schema errors can be time-consuming. Additionally, licensing costs scale up quickly as request throughput and the number of active runtime instances expand across enterprise environments.
What problems is the product solving and how is that benefiting you?
It eliminates fragmented traffic management and inconsistent security policies across independent backend services. Prior to adopting the gateway, individual teams implemented their own authentication layers and throttling mechanisms, creating maintenance debt and audit risks. Centralizing policy enforcement at the gateway level establishes uniform security standards across all endpoints while freeing developers to focus entirely on domain-specific business logic.