The last time this page covered the Forrester evaluation of this market, it ended with three questions it said readers should put to vendors directly. Rate limiting stops being a commercial term and becomes a safety control when the caller is an autonomous agent. Discovery stops being a convenience and becomes an attack surface. Authorization has to distinguish the agent from the person it acts for. None of that was in the 2024 criteria, and the honest instruction was to ask, because the answers were newer than the research.
The Q3 2026 edition has scored them. The evaluation now runs 22 criteria, its opening finding is that API management is evolving into agentic AI management, and MCP, a standard that did not exist when the previous edition was published, is now something buyers demand support for.
The report's answer, though, is not the one the AI gateway market is selling. Forrester's conclusion is that an isolated AI gateway makes the problem worse, which is the argument this page has been making about sprawl since it was written.
What the software actually does
Forrester describes the central role of an API management solution as managing relationships between API providers and API users, whether inside the enterprise or across its boundaries. That framing is more useful than a feature list, because it explains why the products contain what they contain.
The gateway enforces the relationship at runtime: authentication, authorization, rate limiting, quota enforcement, traffic routing, transformation, caching. The developer portal is where the relationship starts: documentation, specification browsing, key issuance, sandbox environments, and the sign-up flow that turns an interested engineer into a consumer. Lifecycle management governs how an interface changes over time, including versioning, deprecation, breaking-change policy, and the machinery that lets you retire something without breaking four teams who never told you they depended on it. Policy and security apply consistent controls across everything published, rather than leaving each team to implement its own interpretation of the standard. Analytics answer who is calling what, how often, and whether the thing is working. Monetization, where it applies, turns usage into billing.
The 2026 edition also makes the definition auditable, because it is the first inclusion criterion. A vendor has to ship all three core elements to be scored at all: an API consumer portal suitable for engaging an external developer audience, an administration portal for API providers, and an API gateway. That is a lower bar than it sounds, and the fact that Forrester states it explicitly tells you the market contains products which call themselves API management without one of the three.
Nobody has one gateway
The uncomfortable reality of this category is that the tidy architecture in the vendor diagram does not exist in any large organization. A typical enterprise has an API gateway from its cloud provider because it came with the platform. It has a second one that a product team adopted for a microservices estate. It has an older one from a full lifecycle vendor bought during a digital transformation program. It acquired a company that had its own. Somewhere there is a load balancer doing gateway work that nobody has classified as a gateway. Consolidating those is a multi-year project that competes against everything else, so mostly it does not happen.
The 2026 edition states the problem in almost those terms. Gateway sprawl has grown considerably in recent years, Forrester writes, and buyers with many gateways should consider vendors with strong federated API management to govern that sprawl and provide an easier path to migrate to fewer gateway vendors. Adding another gateway vendor for AI services, it adds, only exacerbates the problem.
That makes federation the capability the report points sprawl-afflicted buyers toward, which is why where it sits in the chart is worth noting. The two vendors with the deepest federation in this evaluation are both Strong Performers. Axway integrates with nine non-Axway gateways to support API discovery, client onboarding and analytics capture, plus discovery from Git and Akamai. Boomi, whose strength Forrester names as federated API management outright, supports client onboarding and API discovery across eight non-Boomi gateways.
Among the Leaders, Gravitee.io federates with more third-party gateways than most vendors in this evaluation, but limits the capability to API discovery and onboarding without analytics capture. IBM is credited with impressive support for federated API delivery and is recommended for handling gateway sprawl, though that framing is about federated delivery of APIs rather than governing gateways the vendor does not own.
The page's earlier observation was that Axway was alone in offering deep support for third-party federated gateways across a mature field. That is still roughly true, and the report still recommends Axway first for buyers with significant gateway sprawl. What changed is that Axway is no longer a Leader. The capability the report tells you to buy is concentrated in the tier below the top one.
Inside The Forrester Wave: API Management Software, Q3 2026
Published on 18 August 2026 and authored by David Mooter with three contributors, the evaluation scores thirteen providers against twenty-two criteria across current offering, strategy and customer feedback. Vendors supplied materials by 29 May 2026.
The Leaders are MuleSoft, IBM, WSO2, Kong and Gravitee.io. The Strong Performers are Axway, Boomi, Google, Sensedia and Tyk Technologies. The Contenders are Microsoft on Azure API Management, Broadcom on Layer7, and Solo.io.
WSO2 is the Customer Favorite, the designation for the vendor whose reference customers were most positive. It is the only double halo on the chart. Axway carries the only single halo, meaning above-average customer feedback relative to the other evaluated vendors. Every other marker is plain.
Set that against the field this page previously recorded. The Q3 2022 edition, then titled API Management Solutions, scored fifteen providers against twenty-six criteria. The Q3 2024 edition kept the same fifteen providers and cut the criteria to twenty-four. The 2026 edition scores thirteen against twenty-two, which makes this the third consecutive edition in which the criteria count has fallen, and the first in which the field has.
Two of the departures explain themselves in the profiles of the vendors that remain. IBM's API Connect, Forrester writes, is a combination of its traditional product and webMethods API Management, which it acquired from Software AG. Boomi is described as a long-standing integration platform provider that expanded into API management, bolstered by acquisitions of Mashery and APIIDA. Software AG and TIBCO were both in the field this page recorded in 2022, and neither exists as an independent API management vendor in the 2026 chart. The market did not lose them so much as absorb them, and two of the 2026 entrants are the companies that did the absorbing.
The inclusion criteria explain the rest. A vendor needs at least 25 million dollars in API management revenue in the prior year, at least 180 enterprise customers with a thousand or more employees, a complete product that is credible as a standalone purchase, and frequent mention by Forrester's clients as a product under consideration. Forrester points readers to The API Management Software Landscape, Q1 2026 for the wider field.
One methodology detail changes how much weight the chart deserves. Broadcom, Google, Microsoft and Solo.io declined to participate in the full evaluation. Forrester scored them from primary and secondary research and, where necessary, estimates, and published their positions alongside everyone else's. The same four vendors did not provide reference customers. That does not make their placements wrong, but it means the customer-feedback axis was measured for nine of the thirteen, and the four unmeasured vendors all landed in the bottom half of the chart.
The questions the 2024 edition could not score
The three changes this page described in 2024 have held up, and the report now scores them. Rate limiting on an agent is a safety control rather than a negotiated commercial term. A portal that exists to help humans find capabilities will also help an agent find every capability, including the ones published for a specific partner and forgotten. And delegated authority has to be narrower than the delegator, which is not what most API programs were built to express.
What the 2026 edition adds is a judgment about the shape of the answer. AI governance via an AI gateway is now at the top of many buyer evaluations, Forrester writes, and buyers are demanding strong MCP support. But the same research says that these endpoints need lifecycle and versioning just the same as REST endpoints, and more, and concludes that an AI gateway alone does not meet those needs, so Forrester recommends a holistic solution over isolated AI gateways. Its advice to a buyer filling a gap with a standalone AI gateway is to pick a vendor credible as a future replacement for the rest of the API management estate.
The scoring, though, does not sort the way the market conversation does. IBM is a Leader whose gateway Forrester places below par for AI governance, offering no MCP proxy and limited LLM token governance. Kong is a Leader whose gateway has more policies for LLM governance than any other vendor in the evaluation, and whose MCP support is currently minimal. Microsoft is a Contender with solid on-par governance of AI services, including token governance, semantic caching to control cost, and conversion of REST into MCP tools.
MuleSoft's position is breadth: policies for LLMs and MCP that include semantic routing, prompt optimization and PII detection, with analytics that visualize API and AI agent call chains end to end. WSO2's is depth on the specific problems, with MCP tool authorization and progressive disclosure among what Forrester calls an excellent range of AI policies for both LLMs and MCP, plus the ability to enforce API design standards in natural language. Solo.io, from the Contender tier, offers deep LLM and MCP policy controls including token governance and progressive MCP tool disclosure through a gateway built for Kubernetes.
The pattern is that AI governance is now a criterion rather than a differentiator, and it is scored unevenly enough that a Leader can be weak on it and a Contender can be strong. That is not an argument for buying from the tier below. It is an argument for reading the scorecard rather than the tier, which is the same advice the report gives in different words when it tells buyers to align features with their strategy.
The discipline the tooling assumes
API product management appears in the report's list of increasing needs, and it is the part organizations most often skip. The software assumes somebody is treating APIs as products, which means an owner, a roadmap, a defined consumer segment, versioning commitments, a deprecation policy, and a view on whether each interface is worth continuing to run.
Most organizations do not have that. They have APIs that got built because a project needed them, owned by whoever happens still to work there, documented at the moment of creation and never since, with no view on who depends on them. A management platform deployed over that situation produces a very well-instrumented picture of a mess. The analytics will be excellent. The sprawl will be unchanged, because sprawl is a governance problem rather than a tooling problem, and tooling only enforces decisions somebody made.
The 2026 edition makes the point from the buyer's side. Organizations that fail to align their product requirements to their business strategy, it says, often end up overbuying and pay more than necessary. Buyers using APIs to deliver new products need the richer feature sets of a higher-rated vendor, including a portal that markets their brand. Buyers with simpler goals, such as supporting efficient operations with trusted connectivity, may find a lower-rated vendor with a capable gateway to be more fit for purpose and better value for the price point. That is a report telling its readers that the top tier is not always the right purchase, which is rare enough to be worth repeating.
What to test
The agent questions are no longer off-script. MCP support, token governance and agent identity are scored criteria in this edition, so the useful move is to ask for the detailed scorecard rather than for a roadmap, and to compare the AI-governance criteria specifically rather than accepting the tier as a summary of them.
Bring your real gateway estate to the evaluation. Not the target architecture. The actual list, including the one nobody wants to talk about. Then ask what governance the platform can enforce over gateways it does not own, and whether that includes analytics capture or stops at discovery and onboarding, because the report's own findings show that distinction separating vendors that otherwise look similar. Axway and Boomi capture analytics across foreign gateways. Gravitee.io, a tier above both, does not.
Test the developer portal with someone who has never seen your APIs. Time how long it takes them to get from arriving to making a successful authenticated call. That number predicts adoption better than any feature comparison, and it is the single metric most internal API programs fail on.
Ask about deprecation with a real example. Take an API you need to retire, and ask the vendor to walk through how the platform gets you from here to switched off, including finding consumers you do not know about. Publishing is easy. Retiring is where lifecycle management earns its keep, and it is one of the areas where the tier and the capability diverge, since Kong is a Leader without formal API lifecycle management.
And for any vendor on the shortlist that declined full participation in the evaluation, ask what it thinks the report got wrong. Four vendors took that route this year, their placements rest partly on Forrester's estimates rather than their own submissions, and a vendor with a considered disagreement is more informative than one that simply accepts the tier.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of API management software. The Forrester Wave: API Management Software, Q3 2026, published 18 August 2026 and authored by David Mooter with three contributors, scores 13 providers against 22 criteria across current offering, strategy and customer feedback, on materials supplied by 29 May 2026. The Leaders are MuleSoft, IBM, WSO2, Kong and Gravitee.io, with WSO2 named a Customer Favorite. The Strong Performers are Axway, Boomi, Google, Sensedia and Tyk Technologies and the Contenders are Microsoft, Broadcom and Solo.io. Inclusion requires at least 25 million dollars in API management revenue in the prior year, at least 180 enterprise customers with a thousand or more employees, a complete product covering an API consumer portal, an administration portal and an API gateway, credibility as a standalone purchase, and relevancy to Forrester's enterprise clients. Broadcom, Google, Microsoft and Solo.io declined to participate in the full evaluation and did not provide reference customers; Forrester scored them using primary and secondary research and estimates. The API Management Software Landscape, Q1 2026 covers the wider market. The previous edition this page covered was The Forrester Wave: API Management Software, Q3 2024, published 1 July 2024, which scored 15 providers against 24 criteria and named MuleSoft, WSO2, Axway and IBM as Leaders.
Source research
- The Forrester Wave: API Management Software, Q3 2026
- The API Management Software Landscape, Q1 2026
- The Forrester Wave: API Management Software, Q3 2024
- The Forrester Wave: API Management Software, Q3 2024
- Buyer's Guide: API Management Software, 2024
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.
This pairs closely with AppGen And Low-Code Platforms, where Forrester's own framing is blunt: AppGen is eating low-code. Generation quality is converging across vendors, which means the enterprise platform underneath, not the creation experience, is what actually decides a purchase.
This market sits next to AI Gateways, covered separately on this site. Gartner's first Magic Quadrant for AI gateways is still a year out, but Palo Alto Networks already bought one of the strongest independent vendors, Portkey, before the scorecard could weigh in.