API gateway

Kong Integration

Use Kong gateway data to discover APIs, enrich traffic context and route findings by service ownership.

Minimum privilegeControlled data flowAuditability
What this covers

Compare Kong policy with the API behaviour ThreatCanary observes.

Reconcile Kong services, routes, plugins and consumers with externally observed API behaviour and control differences.

01

Purpose of the connection

  • Services, routes, plugins, consumers and workspace context from approved Kong environments.
  • Compare gateway configuration with discovered and observed API behaviour.
02

Operational outcome

  • Attach validated findings to the exact service, route and control that requires change.
  • Keep the full evidence chain in ThreatCanary while exposing the status and context the receiving team needs.
03

Security and governance

  • Exact permissions, events and data fields are confirmed during technical design; availability should not be inferred from this page alone.
  • Use least-privilege credentials, explicit environment scope, secret rotation and revocation.
  • Log configuration changes, data delivery and integration errors for review.