Product Brief Layer7 API Management
The Industry’s Leading Platform for
Enterprise-Scale API Management
At A Glance
Key Benefits Increasingly, enterprises are opening their data and applications to
partners, developers, mobile apps, and cloud services. APIs provide a
• Developer access. Empower internal standardized way to open up information assets across the web, mobile
and external developers to leverage
devices, service-oriented architecture (SOA), and the cloud. However, to
your APIs.
make API information sharing safe, reliable and cost-effective, enterprises
• Mobile access. Securely connect must deal with critical security, performance management, and data
the enterprise with mobile apps and adaptation challenges.
smart devices.
Layer7 API Management (formerly CA API Management) combines
• Partner access. Share information
and services across organizational
advanced functionality for back-end integration, mobile optimization,
boundaries. cloud orchestration, and developer management. It is unique in its ability to
address the full breadth of enterprise API management challenges.
• Data access. Produce a complete,
working system—everything you
need for your applications in minutes: Full API Lifecycle Management
data integration, application logic, The role of API management has expanded to cover a complete lifecycle
and a robust API that governs the creation, deployment, promotion and optimization of
APIs on the provisioning side, as well as their discovery, acquisition and
Critical Differentiators consumption by app developers and other API consumers.
• Ease of use. Layer7 API Management
offers a visual user interface to Provisioning: Enterprises are responsible for a continuous sequence of API
instantly create APIs or setup strategy, design, creation, orchestration, protection, testing, deployment,
complex security policies. It can promotion, and monitoring. Full lifecycle API management enables each of
easily connect S0A, ESB, and legacy these steps with functionality that also addresses security, scalability, and
applications. manageability concerns.
• Scale. Achieve high performance and Consumption: The provisioning cycle meshes with a parallel one for the
scaling with throttling, prioritization, developers who leverage APIs to design, build, launch, and iterate their
caching, and routing. Dynamically
apps. Full lifecycle API management provides them with a reliable mobile
scale up or down as needed.
data infrastructure, improved onboarding, and additional capabilities that
• Security. Protects against threats, accelerate, streamline, and improve mobile and IoT development.
0WASP vulnerabilities and controls
access with single sign-on and Functional coverage in all of these areas is important when evaluating API
identity management, providing end- management. A good solution will offer effective tools with clear benefits
to-end security for apps, mobile, and for all API stakeholders—enterprise architects, security specialists, product
IoT. managers, app developers, and business executives. Named as a leader
• Flexibility. Can be implemented as a in multiple analyst reports, Layer7 API Management offers the industry’s
SaaS, on-premises, or hybrid solution. leading products that accelerate and enable the entire API lifecycle.
It is available in a wide range of form
factors ranging across hardware,
software, virtual, and containers such
as Docker.
• Event-driven APIs. Support for
iOS, Android, Cordova, and MQTT
Websockets for a wide range of use
cases
Full API Lifecycle Management
Product Brief
Solution Overview
The following table shows the capabilities of Layer7 Full Lifecycle API Management.
Layer7 Full Lifecycle API Management Capabilities
API Strategy and Design • API Academy resource center
• Agile planning and delivery model
API & Microservice Creation • Connect to legacy data sources including SQL, noSQL, DB2, and more
• Automated solution for developing APIs and microservices
• Instantly generate APIs and microservices with business logic
• Drag and drop API creation
Testing & Publishing • Solutions for testing across the plan, create, or run phases
• Range of form factors including hardware, VMs, or containers
• Integration with service virtualization tools for real-time testing
• Cloud-agnostic deployment model
Security • Protect against threats and new 2017 OWASP vulnerabilities
• End-to-end omni-channel and SSO across devices
• Mobile and IoT security with OAuth (server and client) and OpenID Connect profile certification
• Common Criteria and FIPS 140-2 Certification
• Support for WebService (WS-) Security
Microservice Orchestration • Light, DevOps friendly, containerized, ephemeral gateway
• Integration with edge gateway for a complete application backend
• Discovery, access control, and routing for microservices built-in
• Advanced 360-degree microservices monitoring, real-time
Management • Integrates SOA, ESB, legacy applications and microservices
• Compression, caching, and aggregation to optimize throughput
• Protocol orchestration, adaptation, translation, and composition
• Enterprise scale with support for over 40,000 TPS
Discovery • Management features to enroll, engage, and educate developers
• Foundation for a digital ecosystem with analytics and optimization
• Developer friendly features including code generation and docs
• Works on-premises, in the cloud, or as a hybrid deployment
Mobile & IoT Development • Range of developer friendly tools, SDKs, and app services
• Reduces development time of core mobile functions like messaging
• Mobile SDK and OAuth Toolkit to ensure consistent security
• Support for iOS, Android, Cordova, and MQTT for a wide range of use cases
• Support for Websockets
Monitoring • Provides API performance metrics and reporting
• Precision monitoring for proactive identification and triage of issues
• Provides app and consumption metrics to optimize development
• Detailed transaction tracing from the gateway to backend systems
Supported Standards
XML, JSON, SOAP, REST, PCI-OSS, AJAX, XPath, XSLT, WSOL, XML Schema, LDAP, RADIUS, SAML, XACML,
OAuth 1.0a/2.0, PKCS, Kerberos, X.509 Certificates, FIPS 140-2, XML Signature, XML Encryption, SSL/TLS, SNMP,
SMTP, POP3, IMAP4, HTTP(S), JMS, MQ Series, Tibco EMS, Raw TCP, FTP(S), WS-Security, WSTrust, WS-Federation,
WS-SecureExchange, WSIL, WS-1, WS-Addressing, WS-Policy, SSecureConversation, WS-MetadataExchange,
WS-SecurityPolicy, WSPolicyAttachment,WS-1 BSP, UDOI, WSRR, MTOM, IPv6, WCF, MQTT, RabbitMQ, Kafka, JMS,
Websockets
For more information about Layer7 API Management, please visit ca.com/api.
For product information and a complete list of distributors, visit our website at: broadcom.com
Copyright © 2019 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.
Broadcom, the pulse logo, Connecting everything, CA Technologies, and the CA technologies logo are among the trademarks of
Broadcom.
CS200-274657-0519 May 13, 2019