Listing Thumbnail

    Kong Gateway Enterprise - Self-Hosted API and AI Gateway

     Info
    Sold by: Kong 
    Deployed on AWS
    AWS Free Tier
    Self-hosted API and AI gateway for platform engineers managing microservices, LLM traffic, and multi-cloud architectures on AWS EC2.
    4.4

    Overview

    Overview

    Kong Gateway Enterprise is a self-hosted API and AI gateway deployed as an AMI on AWS EC2, giving platform engineering teams full control over data residency, network topology, and infrastructure. Trusted by enterprises like United Airlines, HSBC, BMW, and SeatGeek, Kong processes over 1 trillion API and AI requests per day with a 99.99% availability SLA.

    With Kong Gateway Enterprise on EC2, you manage your own infrastructure without hosted control plane dependencies - ideal for organizations with strict compliance, data sovereignty, or network isolation requirements.

    Key Capabilities

    • API Gateway and Lifecycle Management: Route, load balance, authenticate, authorize, rate limit, and transform REST, GraphQL, gRPC, and event-based APIs from a single gateway
    • AI Gateway: Manage traffic to LLM providers with prompt and response management, semantic caching, and token-based rate limiting
    • Plugin Ecosystem: Extend functionality with 100+ pre-built plugins covering logging, authentication, observability, and AI providers
    • Service Mesh: East-west traffic management with mutual TLS (mTLS), traffic policies, and service-level observability
    • Developer Portal: Publish API products, manage access, and enable self-service API discovery for internal and external developers
    • Metering and Billing: Usage-based monetization of APIs and AI services with runtime entitlement enforcement

    Security and Compliance

    Kong Gateway Enterprise is built for regulated enterprise environments:

    • SOC 2 Type II audited and certified
    • PCI DSS 4.0.1 compliant
    • GDPR and CCPA compliant
    • NIST 800-218 (Secure Software Development Framework) self-attested
    • CSA STAR Level 1 self-assessment published
    • FIPS 140-2 support available for Ubuntu and Red Hat builds
    • Mutual TLS (mTLS) for service-to-service encryption
    • Role-based access control (RBAC), SSO, and audit logging
    • Annual third-party penetration testing by independent security firms
    • Software Bill of Materials (SBOM) published for supply chain transparency

    Integrations

    Kong integrates natively with AWS services including ALB, CloudWatch, and EKS. Additional integrations include Prometheus, Datadog, HashiCorp Vault, and OpenID Connect providers. Native Kubernetes support via Kong Ingress Controller enables consistent API governance across containerized and VM-based workloads.

    Deployment Prerequisites

    Supported operating systems:

    • Amazon Linux 2
    • Ubuntu (Jammy, Noble)
    • Red Hat Enterprise Linux
    • Debian

    Supported architectures: AMD64 and ARM64

    Minimum requirements: Ensure your EC2 instance has sufficient CPU and RAM for your expected traffic volume. Kong recommends starting with instances such as m5.large or larger for production workloads.

    Networking: Configure your VPC with appropriate security group rules. Kong Gateway requires inbound access on ports 8000 (proxy), 8443 (proxy SSL), 8001 (Admin API), and 8444 (Admin API SSL).

    Datastore: PostgreSQL database required for traditional mode. DB-less mode available with declarative configuration.

    Use Case: AI Gateway for LLM Traffic

    Route and govern traffic to multiple LLM providers with prompt management, semantic caching, and token-based rate limiting. SeatGeek uses Kong to handle 2.4 billion requests per month, demonstrating how the platform scales for AI-era workloads while maintaining security and cost controls.

    Customer Results

    • HSBC: 50% faster time-to-market
    • DELTA Fiber: 60% reduction in development costs
    • Enterprises report up to 57% reduction in operational costs
    • 35,000+ GitHub stars and 182,000+ community users worldwide

    Licensing Model

    This listing uses a Bring Your Own License (BYOL) model. The AMI software itself does not incur metered AWS Marketplace charges, but a valid Kong Enterprise license is required. Contact Kong sales to discuss licensing options for your organization.

    Use Case: Financial Services API Security at Scale

    Financial institutions use Kong Gateway Enterprise to route millions of API calls across hybrid cloud environments while enforcing strict compliance policies on payment and transaction APIs. With mTLS, rate limiting, and centralized observability, teams maintain PCI DSS compliance while scaling API traffic across AWS regions and on-premises data centers.

    Get Started

    To obtain a Kong Enterprise license, book a guided demo, or discuss deployment requirements, contact the Kong team at sales@konghq.com  or visit https://konghq.com/contact-sales .

    Pricing

    This listing uses a Bring Your Own License (BYOL) model. The AMI software itself does not incur metered AWS Marketplace charges. A valid Kong Enterprise license is required, contact Kong sales at sales@konghq.com  to discuss licensing options for your organization.

    Highlights

    • Kong Gateway Enterprise processes over 1 trillion API and AI requests per day with a 99.99% availability SLA. The self-hosted AMI gives you full control over data residency and network topology on AWS EC2. Customers report up to 57% reduction in operational costs and 50% faster time-to-market. Supports REST, GraphQL, gRPC, and event-based APIs through a single gateway with 100+ pre-built plugins.
    • AI Gateway for LLM Traffic Management - Route and govern traffic to multiple LLM providers with prompt management, semantic caching, and token-based rate limiting. Enforce token budgets and cost controls at runtime. Built for platform engineers managing AI workloads alongside traditional API traffic. SeatGeek handles 2.4 billion requests per month through Kong, demonstrating enterprise-scale AI and API connectivity.
    • Enterprise-Grade Security and Extensibility - Zero-trust networking with mutual TLS (mTLS) between services, OAuth 2.0 and OpenID Connect authentication, role-based access control (RBAC), rate limiting, and audit logging. Extend functionality with 100+ plugins for logging, observability (Prometheus, Datadog), secrets management (HashiCorp Vault), and more. Native Kubernetes support via Kong Ingress Controller for consistent governance across hybrid environments.

    Details

    Sold by

    Delivery method

    Supported services

    Delivery option
    Kong Gateway Enteprise

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Kong Gateway Enterprise - Self-Hosted API and AI Gateway

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    AI Insights

     Info

    Dimensions summary

    You deploy this self-hosted API and AI gateway on your own AWS infrastructure, and the software itself is free. Pricing here reflects the underlying EC2 compute you run it on, billed per hour. You choose between two instance types: t4g.small and c6g.large. The t4g.small fits lighter or test workloads, while the c6g.large gives more compute for heavier traffic. Both bill by the hour based on how long the instance runs. Your cost scales with which instance you pick and how many hours you keep it running.

    Top-of-mind questions for buyers

    The t4g.small is a small ARM-based instance suited to lighter or test workloads. The c6g.large is a compute-focused ARM instance with more processing power for heavier API and AI traffic. You pick one based on your throughput needs, and billing follows the hours that instance runs.
    The hourly software rate meters running time only. A fully stopped instance does not accrue the per-hour software charge. Stopped instances may still incur underlying AWS storage fees for attached volumes, but those are separate from the gateway software billing shown here.
    The gateway software carries no licence charge. You pay for the AWS EC2 compute the software runs on, billed per hour for either the t4g.small or c6g.large instance. Your cost depends on which instance type you choose and how many hours it runs.
    developer.konghq.com
    Helpful?

    Vendor refund policy

    no refunds

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Kong Gateway Enteprise

    Supported services:
    • Amazon EC2 Image Builder
    EC2 Image Builder Component

    EC2 Image Builder is a fully managed AWS service. It automates creation, management, and deployment of custom, secure, and up-to-date server images. After procurement, use the EC2 Image Builder console/API to include this third-party component in golden images for future EC2 instances.

    Version release notes

    Initial release - 3.8.1

    Support

    Vendor support

    Kong Support Center

    Kong provides technical support for Kong Gateway Enterprise customers through the Kong Support Center.

    Support Portal: https://support.konghq.com/s/ 

    From the support portal you can:

    • Create and track support cases
    • Access the knowledge base and troubleshooting guides
    • View documentation and community resources
    • Check Konnect Cloud service status

    Getting Started with Support:

    1. Log in to the Kong Support Center
    2. Follow best practices for filing a support case to ensure fast resolution
    3. Track your case status directly in the portal

    Enterprise Support Tiers:

    • Diamond: 24x7 coverage with 30-minute response SLA
    • Platinum: 24x7 coverage with 1-hour response SLA
    • Business: Regional business hours with 2-hour response SLA

    Plus Plan Support:

    • Email support with a 2-business-day SLA

    Enterprise customers also receive access to dedicated Customer Success Managers, Technical Account Managers, and professional services for migration and onboarding assistance.

    Licensing: This is a BYOL (Bring Your Own License) product. To obtain a Kong Enterprise license or discuss licensing options, contact Kong sales at https://konghq.com/contact-sales 

    Free Trial: Try Kong Konnect free for 30 days with no credit card required at https://konghq.com/products/kong-konnect/register 

    For refund inquiries or billing questions related to your AWS Marketplace subscription, please contact Kong support through the portal above.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    361 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    64%
    32%
    2%
    1%
    1%
    5 AWS reviews
    |
    356 external reviews
    External reviews are from G2  and PeerSpot .
    Adith S.

    Great Control Plane, but Has a Learning Curve

    Reviewed on Sep 16, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Kong Konnect is that it gives us one centralized place to manage, secure, and monitor our API gateways across different environments. I also like the separation between the cloud control plane and local data planes, which makes deployment easier without adding latency to our backend traffic. Setting up things like OAuth2, rate limiting, and mTLS using the available plugins is also quite straightforward. The service catalog and Developer Portal are useful as well, especially when multiple teams are working with different APIs.
    What do you dislike about the product?
    Getting onboarded took longer than expected because the documentation mixes Konnect cloud concepts with self-hosted Kong Gateway setup, which caused some initial confusion. The user interface can also occasionally feel sluggish when managing large numbers of services and routes. Finally, the pricing jumps quite a bit between tiers once your API call volume begins scaling up.
    What problems is the product solving and how is that benefiting you?
    We struggled with inconsistent API security and manual gateway maintenance across distributed environments. Kong Konnect centralized our API management into a single dashboard, allowing us to enforce global security policies, authentication, and rate-limiting seamlessly. This has freed up valuable developer hours from managing infrastructure, improved our API uptime, and made onboarding new services much faster.
    Jaydeepkumar R.

    Centralized API Traffic Visibility That Makes Debugging and Testing Easier

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    From a testing perspective, having a centralized layer to observe API traffic has made it much easier to debug failed test runs. I can see exactly which requests and responses passed through, instead of having to dig through individual service logs. The rate-limiting and throttling plugins have also been useful for load and stress testing scenarios, and the request/response transformation plugins make it easier to simulate different payloads for stronger negative test coverage.
    What do you dislike about the product?
    The learning curve is pretty steep if you’re coming from a QA background without much infrastructure exposure—concepts like services, routes, and plugins take time to get comfortable with. Automating tests against the gateway also adds some friction, since you have to manage auth tokens and consumer credentials just to get CI pipelines running smoothly. The documentation tends to lean more toward admin-focused use cases as well, which leaves a noticeable gap when you’re looking for QA-specific workflows.
    What problems is the product solving and how is that benefiting you?
    It’s given us a single, consistent place to validate authentication and security policies, rather than having to test each API’s custom implementation separately, which was often inconsistent and time-consuming. Because traffic flows through one observable layer, integration issues show up earlier, and we’ve seen fewer flaky test failures caused by mismatched rate-limiting or authentication behavior across environments.
    Trupti S.

    Strong API Security and Centralized Authentication That Saves Time

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    The API security and authentication features are the strongest part of the platform for us. Setting up OAuth, API key policies, and rate limiting per consumer has given us a much tighter grip on who's accessing what across our services. Managing auth centrally instead of building it into every individual API has saved a lot of duplicated effort, and the audit trial for API access has been genuinely useful when troubleshooting or reviewing security posture.
    What do you dislike about the product?
    The learning curve is steep, especially early on. There is lot of terminology and moving pieces (services, routes, plugins consumes) that take time to fully understand, and the initial setup wasn't as intuitive as I expected. Documentation helps, but getting the security policies configured exactly right the first time took more trial and error that I'd have liked. It would benefit from clearer guided setup for common auth scenarios.
    What problems is the product solving and how is that benefiting you?
    Before adopting Konnect, authentication and authorization logic was inconsistent across our APIs, with each service handling it slightly different, which made auditing and securing everything harder. Centralizing auth policies through Konnect has given us consistent security enforcement across the board, reduced the risk of gaps or misconfigurations, and made onboarding new APIs into our ecosystem significantly faster since the security groundwork is already standardized.
    Mansi N.

    Solid API Gateway with Easy Traffic Management and Great Visibility

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    The API gateway and traffic management side of things has been solid for us. Rate limiting, load balancing, and routing rules are straightforward to configure once you get the hang of the platform, and it scales well without a lot of babysitting. The centralized visibility into API traffic across services has made it much easier to spot issues before they become bigger problems. Onboarding new APIs into the gateway is fairly quick once the initial setup is done.
    What do you dislike about the product?
    Support response time has been the main pain point for us. When we've run into issues that actually needed help (not just documentation lookups), turnaround has been slower than I'd like, especially for anything time-sensitive.
    What problems is the product solving and how is that benefiting you?
    Before Konnect, managing traffic and rate limits across our APIs was scattered and inconsistent, which made troubleshooting slow and error-prone. Having a single place to manage gateway policies has cut down the time we spend chasing down traffic issues and given us much better visibility into what's actually happening across our API layer. It's made scaling our API infrastructure less of a headache overall.
    Kirpalsinh R.

    Centralized API governance and sub-millisecond proxy routing for microservices

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    Managing API routing across a distributed microservices environment requires strict consistency, and Kong Konnect's hybrid architecture handles this exceptionally well. The SaaS control plane provides a unified view for configuring services, while the self-hosted data plane instances run locally near our Kubernetes workloads to keep proxy latency negligible. Implementing edge concerns—such as OAuth2 token validation, rate-limiting, and request transformation—via out-of-the-box plugins offloads significant overhead from our application code. Furthermore, managing the gateway state declaratively using the decK CLI seamlessly integrates into our GitOps pipelines, making deployment changes across staging and production environments predictable and fully version-controlled.
    What do you dislike about the product?
    Developing custom plugin logic still requires working with Lua or building WebAssembly modules, which introduces extra friction for development teams accustomed to higher-level languages like Python or Go. When troubleshooting synchronization mismatches between the SaaS management console and self-hosted runtime groups, navigating low-level proxy logs to isolate SSL certificate or schema errors can be time-consuming. Additionally, licensing costs scale up quickly as request throughput and the number of active runtime instances expand across enterprise environments.
    What problems is the product solving and how is that benefiting you?
    It eliminates fragmented traffic management and inconsistent security policies across independent backend services. Prior to adopting the gateway, individual teams implemented their own authentication layers and throttling mechanisms, creating maintenance debt and audit risks. Centralizing policy enforcement at the gateway level establishes uniform security standards across all endpoints while freeing developers to focus entirely on domain-specific business logic.
    View all reviews