October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Adding an API Gateway to a Microservices Project with WSO2 Choreo

Choose between exposing a WSO2 Choreo service endpoint as a managed API and creating an API proxy from an OpenAPI description, with visibility, protocol, and publishing steps.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To put a service you are deploying in WSO2 Choreo behind a managed API gateway, set its endpoint visibility to Organization or Public, deploy the service component, and Choreo exposes the endpoint through the Choreo API Gateway. If you already have an API described by an OpenAPI specification, create an API proxy instead. Both routes produce managed APIs, but they start from different places, and choosing the wrong one adds steps you do not need.

Choose the entry point first

The decision depends on what already exists. A service component you are building and deploying in Choreo gets its managed API from its endpoint configuration. An API that already exists, and is described by an OpenAPI document, is wrapped with an API proxy. The table below sets out the difference.

As an Amazon Associate I earn from qualifying purchases.

Starting point Route in Choreo What you configure Protocol limits
A service component you are deploying in Choreo Endpoint exposure through the Choreo API Gateway Protocol, port, network visibility, schema, and context (HTTP and GraphQL only) Managed API exposure is unavailable for gRPC, UDP, and TCP endpoints
An existing API with an OpenAPI specification or URL API proxy The OpenAPI definition supplied when the proxy is created Not stated in the Choreo proxy tutorial

Both routes can use API management features. A proxy is a wrapper around an API that already exists. An endpoint is a property of a service you run in Choreo, and it becomes a managed API only when its visibility and protocol meet the requirements described below.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set endpoint visibility before you deploy

Visibility decides two things at once: who can reach the endpoint, and whether Choreo exposes it through its managed gateway. Choose it before deployment, because it is part of the endpoint configuration that Choreo applies when the component is deployed.

#1 Best Overall
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  • Project: the endpoint is reachable only from within the same project. Choreo does not expose a Project-visibility endpoint through its managed gateway.
  • Organization: access is restricted to the organization. Managed API exposure is available.
  • Public: any client can access the endpoint, regardless of location or organization. Managed API exposure is available.

The Choreo endpoint guide, “Configure Endpoints,” states the result of this setting directly: “Once you deploy the service component, Choreo will expose the endpoint as a managed API through the Choreo API Gateway.”

Managed API exposure is not available for gRPC, UDP, or TCP endpoints. The endpoint guide does not describe a managed alternative for those protocols, so services that depend on them should be planned outside this workflow.

Configure the endpoint details

Each endpoint has a protocol, a port, a network visibility setting, and a schema. HTTP and GraphQL endpoints also have a context, which is the path prefix under which the endpoint is served. How these values get set depends on the buildpack your component uses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ballerina and WSO2 MI REST endpoints

For components built with the Ballerina or WSO2 MI buildpacks, Choreo automatically detects REST endpoint details. You can review the detected values in the console, but for these buildpacks you do not need to enter them by hand.

Other buildpacks

For the other buildpacks listed in the endpoint guide, you configure endpoint details either in the console or in a .choreo/component.yaml file in the component repository. Choose the file if you want endpoint settings tracked in source control alongside the code they describe.

Which setting wins

When both exist, the .choreo/component.yaml file takes precedence over settings made in the console and over values Choreo generates automatically. If a change you make in the console appears to have no effect, check the file first.

Rank #3
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Create and test an API proxy

The official Choreo tutorial, “Expose a Service as a Managed API,” uses a proxy built from an OpenAPI specification and a Petstore API as its example. The Petstore is only the tutorial’s sample; you can use any OpenAPI description that describes an API you can reach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Create the API proxy from an OpenAPI specification file or from a URL that serves one.
  2. Deploy the proxy to the Development environment.
  3. Test the deployed proxy in Development using the integrated OpenAPI Console, or with cURL against the Development endpoint.
  4. After the proxy passes testing, promote it to Production.
  5. Publish the API to the Developer Portal (publication is covered in the next section).
  6. Generate credentials for a consumer and invoke the API with them.

The proxy concept guide, “Develop an API Proxy from Scratch,” describes the management features a proxy carries, including security policies, rate limiting, and OAuth 2.0 as the default security setting. Review those defaults before you publish, since they determine how consumers authenticate.

The sources reviewed for this guide document this exact console sequence for proxies. For a service component, the same principle applies: deploy and check the endpoint before exposing it to consumers. The steps for a service endpoint may differ from the proxy steps above, so confirm them in the console for your component type.

Rank #4
VNOPN Fanless Firewall Appliance Intel J3710 4C/4T, Firewall Mini PC, 4 x Intel i226 LAN Ports, Network Gateway, Soft Router, Support PF-Sense/OPN-Sense, AES-NI (8GB RAM 128GB SSD)
  • 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.64GHz, 4Cores 4threads 2MB L2 Cache, TDP 6.5w, supports AES-NI. It tested with pf-sens/opn-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
  • 【Interfaces】The firewall pc has 4 * Intel I226 lan ports, 2 * USB3.0 ports, 1 * RS232COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
  • 【Fanless Design】only 6.5W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, which can withstand temperatures up to 60°C. support 24/7 hours working, no noise.
  • 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 128GB mSATA SSD, up to 512GB. Not support HDD. Size:5.27 * 4.98 * 1.43 inches, Weigh:500g, small but powerful.
  • 【12 Months Service】You will get a firewall pc and accessories,If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Publish and check environment exposure

Deployment and publication are separate actions. Deploying and testing a proxy does not make it visible to developers. You must publish the API to the Developer Portal as a distinct step.

The proxy tutorial notes that Production is exposed to the Developer Portal by default. It adds that organizations created before April 24, 2025 may have Development exposed by default as well. Check the environments exposed in your own organization before you announce an API, because this setting depends on when the organization was created.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choreo Connect is a different gateway

Choreo Connect appears in the WSO2 API Manager 4.1.0 documentation as a gateway deployment option. That documentation describes it in two ways: as a gateway that works with API Manager, and as a standalone gateway managed with APICTL. This is a separate deployment path from the managed Choreo API Gateway used in the service workflow above, and the two should not be treated as interchangeable. The API Manager documentation does not provide a step-by-step guide for adding the managed Choreo gateway to a Choreo project, so use the Choreo guides above for that task.

Console labels, defaults, and supported protocols can change between releases. The Choreo documentation pages cited here were captured on different dates, some several months before this guide was prepared. If a step does not match what you see, check the current Choreo documentation before you make changes in production.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.