API Gateway Platform · View 08 of 21 · Structure
Decisions
- Four inbound credential types are supported because the ecosystem already has four kinds of caller; a single scheme would be cleaner and would exclude the partners.
- The authorisation server is reached only to refill a cache, never on the hot path — that is what makes ADR-01 hold for OAuth traffic.
- The only synchronous outbound obligation is the upstream call. Everything else is pushed, cached or asynchronous.
Assumptions
- Access records ≈ 1 KB each, ≈ 2 TB/day compressed after sampling (assumption).
- Audit and authentication events are never sampled, at any volume.
Omitted
- Analytics and billing read from the usage bus and are not gateway integrations; the sandbox estate is a route target rather than a separate surface.
- Two edge labels on this page sit close to an adjacent parallel line — a known cosmetic warning from the route checker, left rather than shortening the labels past the point of meaning.