To put a service you are deploying in WSO2 Choreo behind a managed API gateway, set its endpoint visibility to Organization or Public, deploy the service component, and Choreo exposes the endpoint through the Choreo API Gateway. If you already have an API described by an OpenAPI specification, create an API proxy instead. Both routes produce managed APIs, but they start from different places, and choosing the wrong one adds steps you do not need.
Choose the entry point first
The decision depends on what already exists. A service component you are building and deploying in Choreo gets its managed API from its endpoint configuration. An API that already exists, and is described by an OpenAPI document, is wrapped with an API proxy. The table below sets out the difference.
As an Amazon Associate I earn from qualifying purchases.
| Starting point | Route in Choreo | What you configure | Protocol limits |
|---|---|---|---|
| A service component you are deploying in Choreo | Endpoint exposure through the Choreo API Gateway | Protocol, port, network visibility, schema, and context (HTTP and GraphQL only) | Managed API exposure is unavailable for gRPC, UDP, and TCP endpoints |
| An existing API with an OpenAPI specification or URL | API proxy | The OpenAPI definition supplied when the proxy is created | Not stated in the Choreo proxy tutorial |
Both routes can use API management features. A proxy is a wrapper around an API that already exists. An endpoint is a property of a service you run in Choreo, and it becomes a managed API only when its visibility and protocol meet the requirements described below.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Set endpoint visibility before you deploy
Visibility decides two things at once: who can reach the endpoint, and whether Choreo exposes it through its managed gateway. Choose it before deployment, because it is part of the endpoint configuration that Choreo applies when the component is deployed.
#1 Best Overall
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
- Project: the endpoint is reachable only from within the same project. Choreo does not expose a Project-visibility endpoint through its managed gateway.
- Organization: access is restricted to the organization. Managed API exposure is available.
- Public: any client can access the endpoint, regardless of location or organization. Managed API exposure is available.
The Choreo endpoint guide, “Configure Endpoints,” states the result of this setting directly: “Once you deploy the service component, Choreo will expose the endpoint as a managed API through the Choreo API Gateway.”
Managed API exposure is not available for gRPC, UDP, or TCP endpoints. The endpoint guide does not describe a managed alternative for those protocols, so services that depend on them should be planned outside this workflow.
Configure the endpoint details
Each endpoint has a protocol, a port, a network visibility setting, and a schema. HTTP and GraphQL endpoints also have a context, which is the path prefix under which the endpoint is served. How these values get set depends on the buildpack your component uses.
Ballerina and WSO2 MI REST endpoints
For components built with the Ballerina or WSO2 MI buildpacks, Choreo automatically detects REST endpoint details. You can review the detected values in the console, but for these buildpacks you do not need to enter them by hand.
Other buildpacks
For the other buildpacks listed in the endpoint guide, you configure endpoint details either in the console or in a .choreo/component.yaml file in the component repository. Choose the file if you want endpoint settings tracked in source control alongside the code they describe.
Which setting wins
When both exist, the .choreo/component.yaml file takes precedence over settings made in the console and over values Choreo generates automatically. If a change you make in the console appears to have no effect, check the file first.
Rank #3
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
Create and test an API proxy
The official Choreo tutorial, “Expose a Service as a Managed API,” uses a proxy built from an OpenAPI specification and a Petstore API as its example. The Petstore is only the tutorial’s sample; you can use any OpenAPI description that describes an API you can reach.
- Create the API proxy from an OpenAPI specification file or from a URL that serves one.
- Deploy the proxy to the Development environment.
- Test the deployed proxy in Development using the integrated OpenAPI Console, or with cURL against the Development endpoint.
- After the proxy passes testing, promote it to Production.
- Publish the API to the Developer Portal (publication is covered in the next section).
- Generate credentials for a consumer and invoke the API with them.
The proxy concept guide, “Develop an API Proxy from Scratch,” describes the management features a proxy carries, including security policies, rate limiting, and OAuth 2.0 as the default security setting. Review those defaults before you publish, since they determine how consumers authenticate.
The sources reviewed for this guide document this exact console sequence for proxies. For a service component, the same principle applies: deploy and check the endpoint before exposing it to consumers. The steps for a service endpoint may differ from the proxy steps above, so confirm them in the console for your component type.
Rank #4
- 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.64GHz, 4Cores 4threads 2MB L2 Cache, TDP 6.5w, supports AES-NI. It tested with pf-sens/opn-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
- 【Interfaces】The firewall pc has 4 * Intel I226 lan ports, 2 * USB3.0 ports, 1 * RS232COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
- 【Fanless Design】only 6.5W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, which can withstand temperatures up to 60°C. support 24/7 hours working, no noise.
- 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 128GB mSATA SSD, up to 512GB. Not support HDD. Size:5.27 * 4.98 * 1.43 inches, Weigh:500g, small but powerful.
- 【12 Months Service】You will get a firewall pc and accessories,If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
Publish and check environment exposure
Deployment and publication are separate actions. Deploying and testing a proxy does not make it visible to developers. You must publish the API to the Developer Portal as a distinct step.
The proxy tutorial notes that Production is exposed to the Developer Portal by default. It adds that organizations created before April 24, 2025 may have Development exposed by default as well. Check the environments exposed in your own organization before you announce an API, because this setting depends on when the organization was created.
Recommended Free Tools
Choreo Connect is a different gateway
Choreo Connect appears in the WSO2 API Manager 4.1.0 documentation as a gateway deployment option. That documentation describes it in two ways: as a gateway that works with API Manager, and as a standalone gateway managed with APICTL. This is a separate deployment path from the managed Choreo API Gateway used in the service workflow above, and the two should not be treated as interchangeable. The API Manager documentation does not provide a step-by-step guide for adding the managed Choreo gateway to a Choreo project, so use the Choreo guides above for that task.
Console labels, defaults, and supported protocols can change between releases. The Choreo documentation pages cited here were captured on different dates, some several months before this guide was prepared. If a step does not match what you see, check the current Choreo documentation before you make changes in production.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




