0% found this document useful (0 votes)
171 views34 pages

The API Management Playbook

Uploaded by

Sai Charan
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
171 views34 pages

The API Management Playbook

Uploaded by

Sai Charan
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 34

The API Management Playbook

UNDERSTANDING SOLUTIONS FOR API MANAGEMENT


1 1
Table of Contents
Introduction- - - - - - - - - - - - - - - - - - - - - - 3 API Management Capabilities- - - - - - - - - 20 Layer7 API Management Portfolio
Winning at Digital Business - - - - - - - - - - - 4 API Design- - - - - - - - - - - - - - - - - - - - - - 22 Management Capabilities- - - - - - - - - - - - 26

The “Why” of Digital Business - - - - - - - - 5 API Runtime- - - - - - - - - - - - - - - - - - - - - 22 Design- - - - - - - - - - - - - - - - - - - - - - - - - 28

The “Why” of Digital Business - - - - - - - - - 6 API Protection - - - - - - - - - - - - - - - - - - - 23 Live API Creator- - - - - - - - - - - - - - - - - - 29

The “How” of Digital Business - - - - - - - - - 7 API Access Control- - - - - - - - - - - - - - - - 23 Secure and Manage- - - - - - - - - - - - - - - - 30

The Importance of APIs- - - - - - - - - - - - - - 8 API Ownership- - - - - - - - - - - - - - - - - - - 24 API Developer Portal- - - - - - - - - - - - - - - 31

Your API Management Team - - - - - - - - - 10 API Development - - - - - - - - - - - - - - - - - 24 Test and Monitor- - - - - - - - - - - - - - - - - - 32

Understanding the API Lifecycle- - - - - - - 13 API Intelligence - - - - - - - - - - - - - - - - - - 25


Conclusion- - - - - - - - - - - - - - - - - - - - - - 33
API Discovery- - - - - - - - - - - - - - - - - - - - 25
The API Management Plays - - - - - - - - - - 14
Integrate and Create APIs - - - - - - - - - - - 16
Secure the Open Enterprise- - - - - - - - - - - 17
Accelerate Mobile and IoT Development - - 18
Unlock the Value of Data- - - - - - - - - - - - 19

2
Winning at Digital Business
Introduction
Application programming interfaces (APIs) are essential for
executing ideas quickly and seizing new business opportunities.
They are the building blocks of digital transformation, enabling
organizations to deliver exceptional customer experiences, create
new revenue streams and connect employees, partners, apps and

The API Management Plays


devices to data—anytime, anywhere.
APIs are not necessarily a new technology, but in today’s connected world, they have risen in
prominence and become important to every facet of the enterprise. This has increased the
demand for effective API management. But what does an effective solution look like?

The API Management Playbook will help you understand:

• Why digital business is crucial in the application economy


• How APIs are the building blocks of digital business
• How APIs affect key stakeholders in your organization

API Management Capabilities


• What the API lifecycle is and how it relates to API management
• Thirteen key “plays” that API management should deliver
• The essential capabilities of an API management solution
• What Layer7 API Management brings to the table

Layers7 API Management


3
Winning at Digital Business
Winning at Digital Business

The API Management Plays


API Management Capabilities
Layers7 API Management
Digital transformation is not about incremental improvements or minor operational changes.
It’s about evolving core businesses to meet the demands of the connected world.

4
Winning at Digital Business
The “Why” of Digital Business
Digital transformation is no longer a new idea—digital business
is now a reality. 89% of organizations are currently in some
phase of implementing a digital-first approach to business
processes, operations and customer engagement.1 When IDG
surveyed 702 IT and business management decision-makers to

The API Management Plays


find out their top objectives for their digital business strategy,
responses were diverse and spanned almost every aspect of
the enterprise.

Top objectives of digital business strategy

Improve process efficiency through automation 64%

API Management Capabilities


Create better customer experiences 58%
Improve employee productivity 50%
Drive new revenue 43%
Keep up with customer expectations 40%

Improve security 38%


Reduce complexity 36%
Stay ahead/on pace with the competition 35%

Maintain overall revenue, given market shifts 17%

Improve staff retention rates and team morale 14%

Layers7 API Management


)% 10% 20% 30% 40% 50% 60% 70%

1 IDG, 2018 State of Digital Business Transformation. http://resources.idg.com/download/white-paper/2018-digital-business 5


Winning at Digital Business
The “Why” of Digital Business
Despite these differences in motivation, there is ample
evidence that digital transformation of any kind is a key
factor in business outperformance. In a 2018 Frost & Sullivan
study about how software development is helping business
executives achieve KPIs, respondents were asked about their

The API Management Plays


use of various modern application development components.
Not surprisingly, the companies who widely adopted APIs,
microservices and other tools were more mature in their digital
business strategy.

What is interesting to note, however, is that the more mature companies that
adopted a modern application architecture grew twice as fast as those with a lower
adoption rate. 2

API Management Capabilities


Use of Modern Application Development Components Modern Application Development Maturity Level

APIs 52%
Microservices 46%
Containers 49%
DevOps 50%
34% Relatively Low
App Security 58%
Agile Practices 50%
43%

APIs 84%
Microservices 78%
Containers 79%
DevOps 79%
App Security 85% 39% Medium
Agile Practices 81 %
79%

Layers7 API Management


APIs 97%
Microservices 98%
Containers 97%
DevOps 99%
98%
27% High
App Security
Agile Practices 98%
98%

Base: All respondents (n=1,087)


Q16. How familiar are you with the following terms with regards to developing and deploying applications?
2 Frost & Sullivan, What Business Executives are Learning about Software Development and How it is Helping Achieve KPIs, 2018. 6
Winning at Digital Business
The “How” of Digital Business
Compared to the spectrum of business imperatives, there is
a more concise set of technology challenges that must be
solved by architects, developers and product managers before
their companies can deliver on the promise of a digital-first
business strategy. These projects make up the “how” of digital

The API Management Plays


transformation and are primarily focused on integration,
supporting the customer experience and accelerating software
development.

Most important digital initiatives3

Better integrate internal


and partner systems 86%

API Management Capabilities


Share data with partners to capture
new market opportunities 82%

Expand customer engagement


through IoT 79%

Provide omnichannel access to customers 76%

Accelerate mobile app development 72%

65% 70% 75% 80% 85% 90%

There is a clear connection between the above initiatives and the broader imperatives

Layers7 API Management


that drive them. These technology projects create the building blocks upon which
successful digital businesses can be built.

Successfully overcoming challenges like integrating apps, eliminating data silos and
providing omnichannel access makes an enterprise far more likely to reach transformative
goals such as creating better customer experiences and increasing differentiation.

3 Gatepoint Research, Trends in Digital Transformation with APIs, September 2015 7


Winning at Digital Business
The Importance of APIs
Because they connect data, people, systems and devices,
APIs are heavily relied on to deliver the robust and flexible
integrations needed for important digital initiatives. As the
rate of innovation and the number of connected devices have
increased, so too has the importance of APIs and how they are

The API Management Plays


created, consumed and managed at an enterprise scale.

In fact, according to a recent IDG survey, 40% of organizations are already


implementing APIs in their digital strategy, making it one of the top five
technologies being adopted.

API Management Capabilities


Cloud

External Developers

Your
Data
Digital
Mobile Business

Partners/External
Divisions

IoT Devices

Layers7 API Management


Implementing an effective API strategy empowers organizations to cope better with the
rising volume, scale and volatility of customer-facing applications. It also allows them to
meet constant demands for new or improved functionality and makes it easier to decouple
existing or potential endpoints from backend systems for improved performance, security
and manageability.

4 IDG, 2018 State of Digital Business Transformation. http://resources.idg.com/download/white-paper/2018-digital-business 8


Winning at Digital Business
The Importance of APIs
In Frost & Sullivan’s global survey of IT and business executives,
respondents almost universally agreed that APIs and
microservices are key success factors for transforming to a
digital business.

The API Management Plays


On average, 8 in 10 executives surveyed believe that a modern application architecture
paves the way for faster, better software development while accelerating time to market,
reducing costs, streamlining processes and generating better insights.

This is where an API management solution comes in—to provide a formal way of
creating, securing, managing and optimizing APIs at enterprise scale throughout the
API lifecycle. With so much riding on APIs, these solutions have become a preferred
strategy for the world’s most effective digital businesses.

API Management Capabilities


Modern Application Development Success Factors5

APIs help us get to market APIs are helping us connect apps


80% 81%
faster with new apps and data to get better insights

Microservices help us get to Microservices enable us to deploy


79% 80%
market faster with new apps apps independently of one another

Containers make it easier to quickly


Containers help us get to

Layers7 API Management


77% 78% build apps more consistently
market faster with new apps
and with lower costs

Base: All lines of business except IT (n=768) Q17-Q19.


How much do you agree or disagree with the following statement?

5 Frost & Sullivan, What Business Executives are Learning about Software Development and How it is Helping Achieve KPIs, 2018. 9
Winning at Digital Business
The API Management Plays
Your API Management Team
Because digital transformation reaches deep into the enterprise—
affecting every facet of the business and involving every customer

API Management Capabilities


channel—there is a diverse range of stakeholders to consider.

Stakeholder Influencer Influencer User

Line of Business Security API Owner/


Lead Digital Transformation Secure the Open Enterprise Product Manager
Build, Deploy, Operate, and

Layers7 API Management


Optimize API Infrastructure
Stakeholder Influencer User

Enterprise Architect Developer


Integrate and Create APIs Accelerate Development

10
Winning at Digital Business
The API Management Plays
Your API Management Team
APIs affect each part of the enterprise differently—and are seen in a unique light by each of
the roles they touch. Business executives perceive them as a source of revenue or cost savings.
Architects see indispensable tools for integration. Security professionals view them as potential

API Management Capabilities


vulnerabilities. And developers appreciate them as a gateway to enterprise data and functionality.
The right API management platform offers each person the capabilities they need to do their jobs effectively,
so a nuanced understanding of their diverse requirements is essential for a world-class digital business.

Line of Business Enterprise Architect


Titles: C
 hief Digital Officer, Chief Experience Officer, Titles: Chief Architect, VP Integration,
VP Digital, Director of Omnichannel Director of Integration
Focus: Unlock the value of data Focus: Integrate and create APIs

These executives are responsible for meeting business Architects translate the digital business challenges into an

Layers7 API Management


goals and driving the organization’s competitive advantage ideal technology infrastructure. They see APIs as connective
and differentiators. They see APIs as a strategic enabler tissue that will orchestrate the data and functionality they
for launching innovative products or services, forging new need, and API management as a set of tools to help them
partnerships and improving the customer experience—so API model, design, shape and optimize these integrations for
management must be a trusted, reliable platform on which to years to come.
achieve this.

11
Winning at Digital Business
The API Management Plays
Your API Management Team
Line of Business is about providing advanced threat protection and
Titles: V
 P App Development, VP Mobile, Director of Apps, authentication capabilities without compromising the overall

API Management Capabilities


Mobile/Web Development Lead
mission of increasing connectivity and convenience.
Focus: Accelerate mobile and IoT development

Developers build front-end applications while discovering, API Owner


acquiring and consuming APIs as their gateway to enterprise Titles: VP Product Development,
data and capabilities. For this group, API management API Product Manager, API Specialist
represents stable, secure and scalable access to the back-end, Focus: Build, deploy, operate and optimize API infrastructure
as well as a source of tools and utilities to help them obtain
Once an overall API strategy has been determined, this group
and leverage the APIs more efficiently. ultimately becomes responsible for operating and maintaining its
technology infrastructure. For product managers and DevOps
Security professionals, API management is their lifeblood, allowing them to
Titles: C
 hief Information Security Officer, VP Information effectively control, measure, optimize and deploy a large number

Layers7 API Management


Security, Director of IT Security of APIs through every step of the lifecycle.
Focus: Secure the open enterprise

Because APIs are designed to “open the enterprise” by


establishing new digital value chains, they pose a unique
challenge when it comes to protecting the business against
vulnerabilities. For security professionals, API management
12
Winning at Digital Business
Understanding the API Lifecycle

The API Management Plays


The API lifecycle is a final area to consider. This is an approach that governs the creation, deployment,
promotion and optimization of APIs on the provisioning side, as well as their acquisition and usage by
API consumers.

API Consumption API Provisioning


Initiate Define
Iterate

API Management Capabilities


Ask Initiate Design
Optimize
Design

Acquire Secure Promote Create


Build

Launch Deploy

On the API provisioning side, enterprises are responsible for a Functional coverage within each area is important when
continuous sequence of definition, design, creation, deployment, considering API management because a good solution offers

Layers7 API Management


promotion, security and optimization. This meshes with a parallel effective tools with clear benefits for each role.
cycle for developers who design, acquire APIs for, build, launch
and iterate their apps, while potentially providing feedback to Good API management provides the foundation needed to
improve the overall digital business program. execute the entire API lifecycle, along with targeted tools,
to help stakeholders efficiently complete the work required
Although exact responsibilities will overlap and vary, each to move APIs through each step.
stakeholder has distinct areas of interest within the lifecycle.
13
Winning at Digital Business
The API Management Plays

The API Management Plays


API Management Capabilities
Layers7 API Management
With five different stakeholder groups, two interdependent lifecycles and 13 unique steps, it’s no
wonder that API management is often viewed as confusing. When you also consider the diverse
business imperatives that drive digital transformation, plus the intrinsic flexibility of API integrations,
the relative merits of different API management solutions can be hard to assess.

14
Winning at Digital Business
The API Management Plays

The API Management Plays


Consider evaluating API management capabilities based on their ability to make these tactical “plays”—a collection of the most
common and essential use cases, grouped into focus areas for each of the key stakeholders. The best part of this method is that almost
any business scenario that calls for a managed approach to deploying APIs will be composed of some combination of these 13 plays.

Outside the enterprise Within the enterprise


Integrate and Create APIs
• Easily connect SOA, ESB, and legacy applications
• Aggregate data including NoSQL up to 10x faster
• Build scalable connections to cloud solutions
• Automatically create data APIs with live
Internet of Things (IoT)

API Management Capabilities


business logic
Secure data

Secure the Open Enterprise


• Protect against threats and OWASP vulnerabilities
• Control access with SSO and identity management
Application Porfolio
Mobile • Provide end-to-end security for apps, mobile, and IoT

SaaS/cloud solutions
Accelerate Mobile/IoT Development ID/authentication

• Simplify and control developer access to data


• Build a wider partner or public developer ecosystem

Layers7 API Management


• Leverage tools that reduce mobile app delivery time

Partner ecosystems Reporting & analytics


Unlock the Value of Data
• Monetize APIs to generate revenue
• Build digital ecosystems to enhance business value
• Create efficiencies through analytics and optimization
External developers Internal teams

15
Winning at Digital Business
Integrate and Create APIs
Key Players: Enterprise Architects, API Owners

Digital initiatives based on APIs are all about providing scalable, reliable connectivity
between data, people, apps and devices. To support this mission, experienced
architects look for API management to help them solve the challenge of integrating

The API Management Plays


systems, adapting services, orchestrating data and rapidly creating modern,
enterprise-scale REST APIs from different sources. The right solution will help them:

• Easily connect SOA, ESB and legacy applications. API management will streamline
integrations across disparate systems such as CRM or databases by providing
protocol adaptation, mediation and transformation.
• Aggregate data including NoSQL up to 10 times faster. API management will
orchestrate both structured and unstructured data from multiple sources at the API
layer to accelerate the development of better, more engaging web and mobile apps.
• Build scalable connections to cloud solutions. API management will enable the

API Management Capabilities


creation of high-performing yet cost-effective digital platforms that integrate on-
premises systems and cloud solutions with robust traffic management.
• Automatically create data APIs with live business logic. API management will
provide point-and-click functionality that can instantly generate enterprise-grade
REST APIs from multiple data sources, with business logic processing to streamline
the integrations.

Layers7 API Management


Related eBook:
An Enterprise Architect’s Guide to API Integration for ESB and SOA

DOWNLOAD NOW

16
Winning at Digital Business
Secure the Open Enterprise
Key Players: Security, Developers

The open enterprise must be secured completely, from the app to the API, while
maintaining a streamlined user experience. Information security professionals
look for API management to identify and neutralize critical threats, enable robust

The API Management Plays


policies, offer consistent and repeatable security for mobile apps and provide the
capabilities needed to deliver features such as single sign-on and risk-based access.
The right solution will help them:

• Protect against threats and OWASP vulnerabilities. API management will provide
threat detection and neutralization for key OWASP vulnerabilities such as SQL
injections, cross-site scripting and denial-of-service (DDoS) attacks.
• Control access with SSO and identity management. API management will secure
apps and their connections, while maintaining or enhancing user convenience.
• Provide end-to-end security for apps, mobile and IoT. API management will

API Management Capabilities


protect the digital value chain from frontend app to backend API and bring security
to the IoT. It should extend controlled access to all touchpoints—from web apps to
vehicles—while supporting convenient features such as social login or risk-based
authentication.

Layers7 API Management


Related eBook:
Five Simple Strategies for Securing Your APIs

DOWNLOAD NOW

17
Winning at Digital Business
Accelerate Mobile and IoT
Development
Key Players: Developers, API Owners

Competitive pressure, rising customer expectations and the increasing pace of

The API Management Plays


change mean that applications—especially for mobile and IoT—must be delivered
faster and more efficiently than ever. Developers look for API management to help
them discover, acquire and consume APIs quickly, while also providing tools that
speed up or eliminate the “dirty work” of repeatedly building core functionality to
handle data and security. The right solution will help them:

• Simplify and control developer access to data. API management will provide
a controlled way to access systems of record that shields developers from
unnecessary complexity. It should aggregate and orchestrate data while ensuring
compliance through authorization, shaping and policy management.

API Management Capabilities


• Build a wider partner or public developer ecosystem. API management will
empower internal and external developers by streamlining API consumption
lifecycle tasks such as discovery, acquisition, design and collaboration.
• Leverage tools that reduce mobile app delivery time. API management will
accelerate and simplify mobile implementations by providing developers with
reusable services in the form of SDKs and APIs that handle security, messaging and
offline storage.

Layers7 API Management


Related eBook:
The Enterprise Guide to Mobile APIs and 5-Star Apps

DOWNLOAD NOW

18
Winning at Digital Business
Unlock the Value of Data
Key Players: Line of Business, API Owners

Line of business executives look to API management as a central launch point for
their digital strategies. APIs have a range of capabilities that support efforts to build a
robust digital ecosystem by expanding partnerships, nurturing developer communities,

The API Management Plays


monetizing data and leveraging digital connections to improve operations and efficiency.
The right solution will help them:

• Monetize APIs to generate revenue. API management will provide the functionality
needed to package, price and sell data products or services via any combination of
free, freemium, purchase, subscription or consumption models. It should also simplify
integration with analytics and billing services.
• Build digital ecosystems to enhance business value. API management will deliver the
granular control, compliance, security and reporting mechanisms needed to support
the expansion of digital value chains across a wide range of platforms, apps, devices,

API Management Capabilities


partners and third parties.
• Create efficiencies through analytics and optimization. API management will
encourage companies to build more efficient, higher-performing and scalable digital
ecosystems by providing instrumentation and analytics that allow them to optimize
technical and business performance.

By focusing on these 13 plays when considering an API management solution,


you can ensure that the platform will offer the right mix of functionality while
also providing a high degree of flexibility, scalability and security to meet
current and future requirements.

Layers7 API Management


Related eBook:
The Chief Digital Officer’s Guide to Digital Transformation

LEARN MORE

19
Winning at Digital Business The API Management Plays API Management Capabilities Layers7 API Management
20
API Management Capabilities
Winning at Digital Business
API Management Capabilities

The API Management Plays


Successfully covering all of the plays requires an API management solution to have features that address every step in the API lifecycle.
Layer7 API Management delivers this range of capabilities. It’s a strategic foundation for the entire API lifecycle that provides specific
tools needed by each persona to move APIs through the process, from design to monetization.

Outside the enterprise Within the enterprise


Integrate/Create
API Design API Runtime
• API Connectivity • Rules Processing
• Rapid API Creation • Traffic Management
• Adaptation • Aggregation
• Orchestration • Caching/Compression
Internet of Things (IoT)

API Management Capabilities


Secure data

API Protection API Access Control


• Fine-grained Policies • Authorization
Secure

• OWASP Vulnerabilities • Risk-based Access


• Security SDKs • SSO Application Porfolio
Mobile • Mobile/IoT Security • OAuth/OIDC

SaaS/cloud solutions
API Ownership API Development ID/authentication
Accelerate

• API Discovery/Portal • Mobile/IoT Services


• Collaboration Tools • Mobile Security
• Code Generation • Offline Data Storage

Layers7 API Management


• Documentation • Messaging/Pub-Sub
Partner ecosystems Reporting & analytics

API Intelligence API Discovery


• Performance Analytics • Account Management
Unlock

• Business Analytics • Keys/Provisioning


• Mobile App Analytics • Plans/Tiers
External developers Internal teams
• Billing Integration

21
Winning at Digital Business
API Management Capabilities

The API Management Plays


API Design API Runtime
Area of Focus: Integrate and Create APIs Area of Focus: Integrate and Create APIs
Key Players: Enterprise Architects, API Owners Key Players: Enterprise Architects, API Owners
• API connectivity centralizes connectivity and authentication • Rules processing significantly reduces the complexity of
between on-premises enterprise platforms, social networks, composing data from multiple sources by applying reactive
cloud apps and notification services. business logic at runtime.
• Rapid API creation generates enterprise-grade APIs from • Traffic management improves performance and user

API Management Capabilities


multiple data sources—including RDBMS, NoSQL, existing satisfaction by prioritizing traffic to ensure that APIs remain
APIs and JSON—with an efficient point-and-click interface available and responsive.
that supports pagination, optimistic locking, filtering, sorting
• Aggregation reduces on-device processing and latency by
and more.
aggregating API responses for mobile apps and the IoT.
• Adaptation reliably externalizes services and data as modern
• Caching/compression improves performance and service
RESTful APIs for Web, mobile and IoT consumption.
availability by caching responses to common API requests,
• Orchestration composes and orchestrates modern REST and pre-fetching content, doing JSON conversion and performing
OData APIs from existing or legacy backend APIs. message compression.

Layers7 API Management


22
Winning at Digital Business
API Management Capabilities

The API Management Plays


API Protection API Access Control
Area of Focus: Secure the Open Enterprise Area of Focus: Secure the Open Enterprise
Key Players: Security, Developers Key Players: Security, Developers
• Fine-grained policies centrally manage and secure data • Authorization provides trusted, industry-standard access
assets, with integrations to popular IAM systems and support control for front-end apps, with support for a wide range of
for standards such as OAuth and OpenID Connect, in a protocols and standards. Tracks policy violations and failed
platform that is FIPS 140-2 compliant with Common Criteria authentications to identify patterns and potential threats.

API Management Capabilities


Certification.
• Risk-based access adds additional trust and convenience
• OWASP vulnerabilities protects apps and APIs against critical to authentication with access based on geolocation, social
threats such as SQL injections, cross-site scripting and DDoS credentials and device proximity through QRC, NFC or BLE
attacks, and validates HTTP parameters, REST queries, JSON connections.
data structures, XML schemas and other payloads.
• SSO improves the user experience with SSO capabilities that
• Security SDKs improves mobile security with client-side integrate with popular IAM applications including CA Single
libraries, code, documentation and mobile services to help Sign-On, LDAP and platforms from other vendors.
developers simplify the implementation of SSO, encryption,
• OAuth/OpenID Connect offers support for common
certificates and secure offline data storage.
standards including OAuth 2.0, OpenID Connect, SAML, X.509
• Mobile/IoT security extends enterprise security infrastructure certificates and LDAP.

Layers7 API Management


to new endpoints by integrating popular IAM systems with
mobile and IoT apps.

23
Winning at Digital Business
API Management Capabilities

The API Management Plays


API Ownership API Development
Area of Focus: Accelerate Mobile and IoT Development Area of Focus: Accelerate Mobile and IoT Development
Key Players: API Owners, Developers Key Players: API Owners, Developers
• API Discovery/Portal streamlines API publication with a full • Mobile/IoT services provide common backend services in the
suite of portal features including developer enrollment and form of APIs and SDKs that can be used and shared across
onboarding, key management, provisioning and reporting. multiple mobile or IoT apps, improving implementation speed,
consistency and security.
• Collaboration tools deliver a better developer experience and

API Management Capabilities


ecosystem via a sophisticated content management system, • Mobile security protects mobile and IoT apps with a wide
support tools and discussion forums. range of methods, including OAuth 2.0 and OpenID Connect
for authorization, mutual SSL for encryption, PKI support and
• Code generation allows developers to automatically generate
secure offline data storage.
client-side code in popular programming languages including
JavaScript, node.js, Python, Ruby, PHP, Objective C, Java™ • Offline data storage allows for secure, easy-to-use local and
and Curl. cloud data stores in mobile apps, with standards-based APIs,
native mobile SDKs and encryption.
• Documentation automatically produces interactive
documentation from industry-standard WADL/RAML files to • Messaging/pub-sub provides user and group management
help developers accelerate implementation. via SCIM 2.0, secure messaging and publish-subscribe services
using MQTT and native mobile SDKs.

Layers7 API Management


24
Winning at Digital Business
API Management Capabilities

The API Management Plays


API Intelligence API Discovery
Area of Focus: Unlock the Value of Data Area of Focus: Unlock the Value of Data
Key Players: Line of Business, API Owners Key Players: Line of Business, API Owners
• Performance analytics deliver up-to-the minute tracking of • Account management provides plans, accounts and tiers to
operational KPIs such as transactions, availability and latency organize filter and stratify developers, and monitors application
for troubleshooting and adherence to SLAs. usage to determine which developers are the most valuable
and allows account managers to be assigned.
• Business analytics generate summary reports to track how

API Management Capabilities


developers are utilizing APIs against their quota, and provide • Keys/provisioning allows managers to create, assign,
custom, ad-hoc reporting into the health and performance of suspend or revoke API keys and optionally gate the
the API ecosystem for forecasting or analysis. generation of keys for each application, as well as provides
throttling and shaping to customize access to APIs based on
• Mobile app analytics track applications as they move from
different SLAs once authorized.
development through testing to production and report on
metrics such as revenue generation per app or developer • Plans/tiers allow for standard or unique plans and tiers for
over time. each API, with individual quotas, rate limits and other fine-
grained controls.
• Billing integration provides a revenue planner to help map
the monetization potential of charging developers for API

Layers7 API Management


usage and allows the model to be applied to a billing system
with a single click.

25
Winning at Digital Business
Layer7 API Management Portfolio
Management Capabilities

The API Management Plays


API Management Capabilities
Layers7 API Management
For maximum flexibility, Layer7 API Management is comprised of several products, each focused
on a specific area of the API lifecycle. In addition, many of the capabilities are offered in several
deployment options—on-premises, cloud or hybrid—to meet the infrastructure and investment
preferences of any business.

26
Winning at Digital Business
The Layer7 API Management Portfolio

The API Management Plays


Layer7 API Management is a flagship solution that addresses and streamlines the entire API lifecycle and digital value chain. The
functionality it provides allows organizations to rapidly integrate and create APIs, secure the open enterprise, accelerate mobile
development and unlock the value of data.
Mobile SDKs

ID/Authentication

API Management Capabilities


Internet of Things (IoT)
API Gateway
Mobile API Gateway

Live API Creator

Mobile SQL Data

Cloud/cloud solutions
AWS, Google, SFDC …

NoSQL Data

Layers7 API Management


API Developer Portal
Partner ecosystems

External developers
27
Winning at Digital Business
Design
The API Academy provides insights and practical guidance on strategy, architecture
and design for APIs and microservices. It is a resource for Enterprise Architects and
API Owners to discover how to create the right API strategy for their organization,
and is filled with blogs, podcasts, and articles around API design and thoroughly
covers the emerging microservices market, including downloadable books on how
to implement a microservice architecture and securing microservice APIs.

The API Management Plays


Visit API Academy today to learn more about API strategy, design, and
microservices.

API Management Capabilities


Layers7 API Management
28
Winning at Digital Business
Live API Creator
Live API Creator is an innovative API lifecycle product that allows businesses
to almost instantly create responsive, enterprise-grade REST APIs from both
legacy and modern data sources. It significantly reduces time and cost during the
development process by adding automation and business logic enforcement to the
definition, design, creation and runtime steps of the API lifecycle.

The API Management Plays


Enterprise architects, developers and API owners can build and extend REST
endpoints that combine data from structured, unstructured and other API sources
using a streamlined point-and-click interface. A reactive programming model 40x
more concise than code vastly improves productivity over traditional approaches. A
high-performing API server allows for the live execution of business rules at runtime.

For any organization that has embraced APIs and is ready to expand the scope of
their lifecycle beyond management and enforcement, Live API Creator offers an
incredible opportunity to shift left and move forward.

API Management Capabilities


Layers7 API Management
29
Winning at Digital Business
Secure and Manage
Layer7 API Gateway, Mobile API Gateway and Microgateway are the heart of the
API management portfolio and enable enterprises to securely open their data and
applications to both internal and third-party developers. They combine policy
management with runtime policy enforcement and can integrate with identity and
access management products for a true plug-and-play solution to building a secure
digital ecosystem.

The API Management Plays


API Gateway can be configured in a variety of form factors, scales easily and may
be deployed in a failover environment for high availability.

Mobile API Gateway adds additional capabilities that simplify the process of
adapting internal data, applications and security to meet the needs of mobile
endpoints and IoT.

Finally, Microgateway is a lightweight, containerized API gateway that is designed


to scale within highly decentralized environments, including microservices
architectures. CA Microgateway is easily deployable and configurable by developers

API Management Capabilities


at design time using provided templates and integrates with DevOps toolchains for
scripted production deployments. It supports common patterns for microservices,
including service discovery, circuit breakers, routing and last mile security, and can
be extended to support new or custom use cases by creating new templates.

Layers7 API Management


30
Winning at Digital Business
API Developer Portal
Layer7 API Developer Portal gives businesses a central place to empower
developers who are building Web, mobile and IoT applications based on enterprise
APIs. It provides robust developer management capabilities that make it easier to
plan, package, provision and monitor the usage of

APIs by both internal and external resources. It supports the developers themselves

The API Management Plays


with tools such as documentation, automatic code generation and collaboration
features that simplify and accelerate front-end development.

When integrated with the gateway products, the API Developer Portal eliminates
the need to deploy solutions from multiple vendors, greatly reducing acquisition
costs, infrastructure requirements and maintenance overhead.

API Management Capabilities


Layers7 API Management
31
Winning at Digital Business
Test and Monitor
After designing and building your API, it’s important to ensure that it is properly
functioning (including returning the correct result) through API testing. API Testing
allows simulation of thousands or millions of users from multiple geo-locations,
evaluate performance, and to continue testing after deployment to ensure a
delightful customer experience.

The API Management Plays


Likewise, downtime can have far-reaching impact on any business. Without
proper visibility into the traffic running through your apps and infrastructure,
diagnosing and solving the problem means using up valuable time and resources.
API monitoring surfaces issues directly from the internal and third-party APIs
that power your apps and infrastructure. It works by running API monitors on a
continuous schedule to give you visibility into API problems so you can prevent,
identify and solve them fast—before your customers notice.

Runscope prevents slow or broken APIs from affecting your bottom line.

API Management Capabilities


Layers7 API Management
32
Winning at Digital Business
Conclusion
APIs are the building blocks of digital transformation. They enable
organizations to deliver exceptional customer experiences, create
new revenue streams and connect employees, partners, apps and
devices to data—anytime, anywhere.

The API Management Plays


Layer7 API Management is a central launch point for these digital initiatives. It
provides the full range of capabilities needed to orchestrate legacy and modern
systems, rapidly create APIs to safely expose data, protect these integrations with
military-grade security, accelerate mobile development and unlock the value of
these digital ecosystems through analytics and monetization. And because every
business is unique, Layer7 API Management offers the most flexible deployment
options, including on-premises, cloud or a hybrid combination—all with enterprise-
grade scalability and performance.

API Management Capabilities


CA Technologies a Broadcom Company, was named a Leader in Gartner’s 2018
Magic Quadrant for Full Life Cycle API Management, and is the only vendor to be
named a Leader for six consecutive reports.6 Analyst firm KuppingerCole placed
CA Technologies atop the “Overall Leadership” category in its KuppingerCole
Leadership Compass: API Security Management report in July 2015.

Layers7 API Management


6 Gartner, Inc. “Magic Quadran t for Full Life Cycle API Management,” Paolo Malinverno, Mark O’Neill, April 30, 2018
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select
only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research
organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this
research, including any warranties of merchantability or fitness for a particular purpose.

33
Learn more
about the
advantages
of Layer7 API
Management
PLEASE VISIT CA.COM/API

For product information please visit our website at: ca.com


Copyright © 2019 Broadcom. All Rights Reserved. Broadcom, the pulse logo, Connecting everything, CA Technologies, the CA technologies logo, and System z are among
the trademarks of Broadcom. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.
BC-XXXXEN-0619 June 26,.2019

34 34

You might also like