News KrakenD CE 2.13.10 and EE 2.13.8 update released

Migrate From AWS API Gateway to KrakenD:

Migrate From AWS API Gateway to KrakenD:

AWS API Gateway Locks You In. KrakenD Sets You Free.

Same gateway problem. One bill that grows with your traffic, one that does not. One that runs anywhere, one that does not.

The gateway is not the bottleneck. The bill and the dependency are.

Start the Migration Conversation

The Hidden AWS API Gateway Bill

The Three Costs That Don't Appear on Your AWS API Gateway Invoice

The first part is the per-request pricing. The second is the AWS dependency. The third is the portability gap. Most teams discover the second when they try to run a workload outside AWS. They discover the third when they try to leave.

Your Growth Is AWS's Revenue

AWS API Gateway charges per million API calls. REST APIs: $3.50 per million for the first 333 million requests per month. HTTP APIs: $1.00 per million for the first 300 million. WebSocket: $1.00 per million messages plus $0.25 per million connection minutes. These rates tier down at volume, but they never reach zero. Every request your product handles is a revenue event for AWS.

KrakenD is priced by flat-tiered plans. A traffic spike that doubles your call volume does not change your invoice. A record-breaking sales day costs the same as a quiet Tuesday. Your gateway cost is a line in the annual budget, not a variable you monitor weekly in the AWS Cost Explorer.

AWS API Gateway Is an AWS Service, Not a Gateway

AWS API Gateway integrates natively with IAM for auth, Lambda for compute, CloudFront for edge, and Route 53 for DNS. That tight integration is its strength inside AWS. It is also why it cannot leave. Your API definitions reference Lambda ARNs. Your auth policies reference IAM roles. Your caching integrates with ElastiCache. None of that is portable. Moving to another cloud, to on-premise, or to a hybrid architecture means rebuilding the gateway layer from scratch.

KrakenD runs on any infrastructure: GCP, Azure, AWS, on-premise, air-gapped environments. The same Docker image, the same config file, the same CI/CD pipeline. Your gateway travels with your architecture, not with your cloud provider.

The Portability Gap

AWS API Gateway has no export format that other gateways can import. Your route definitions, your integrations, your auth policies: all of them are expressed in AWS-specific constructs. Teams that have tried to migrate report that the process is not a migration. It is a rebuild. The configuration does not translate, it gets rewritten.

KrakenD's declarative config is a JSON file in your Git repo. It deploys as a Docker image. Moving KrakenD between cloud providers or to on-premise is a CI/CD variable change. Moving AWS API Gateway off AWS is a project.

The Migration Payoff

What Changes With KrakenD

Config, not a managed service. Stateless by design. Try before you commit. One price, no per-request surprises. Your AWS API Gateway routes are not wasted. And you will not need a consultant.

Config, Not a Managed Service

KrakenD has no managed service, no cloud console to configure, no Lambda dependency. Your gateway is a declarative JSON file in Git. Changes go through your existing CI/CD pipeline. Every change is versioned, auditable, and reversible. Rollback is a Docker tag.

Config, Not a Managed Service

Stateless by Design

No database in the critical path. No coordination between nodes for standard operation. Each instance runs independently on any infrastructure. Horizontal scaling is linear: add an instance, add capacity. No AWS account required to run it.

Stateless by Design

Try Before You Commit

KrakenD's Community Edition is the same runtime as Enterprise. Teams deploy it against real infrastructure, validate the approach, and start a license conversation only after the technical case is closed. No AWS account required. No managed service to provision.

"We began by creating a model with the community version to assess its capabilities. Once we confirmed that this tool met our needs, we opted for an enterprise license." — Nicolas Gabetty, Senior Engineer, Coop Atlantique

Try Before You Commit

One Price, No Per-Request Surprises

KrakenD Enterprise is priced by flat-tiered plans. Every feature, including RBAC, OIDC, rate limiting, SOAP, gRPC, WebSockets, and observability, is included at every tier. What never changes is the model: flat per plan, no per-request uplift, no renegotiation when your traffic doubles.

One Price, No Per-Request Surprises

Your AWS API Gateway Routes Are Not Wasted

Your existing API definitions, auth policies, and routing logic map to KrakenD declarative config. The translation requires rewriting AWS-specific constructs into standard config, but the business logic, the routes, the policies, the transformations, all of it travels. Start with your lowest-dependency routes, those not tied to Lambda or IAM, and expand incrementally.

Your AWS API Gateway Routes Are Not Wasted

You Will Not Need a Consultant

G2 Fall 2026 API Management, Mid-Market: 100% of KrakenD implementations are done in-house with no vendor services and no external consultants. Average time to go-live: 2 months.

You Will Not Need a Consultant

Drop-In Compatibility

What Doesn't Change With KrakenD

You are not leaving AWS. You are adding an infrastructure-independent gateway layer.

Deploys on AWS, and Everywhere Else

KrakenD runs as a standard Docker image on EKS, ECS, EC2, or any Kubernetes cluster. No managed service to provision. No AWS-specific constructs in the config. Dev and staging instances are unlimited across all plans, so you can run AWS API Gateway and KrakenD in parallel at no additional licensing cost during the migration.

Your Observability and Auth Stack Stay Untouched

Native OpenTelemetry. CloudWatch, Prometheus, Grafana, Datadog, New Relic, your SIEM. JWT, OIDC, mTLS, API Keys, OAuth2: all native. If your team uses Cognito or IAM for identity today, KrakenD integrates with your IdP of choice during and after migration.

No Protocol Left Behind

REST, gRPC, GraphQL, WebSockets, SOAP, Kafka, AMQP. Each instance handles 40,000 to 80,000 RPS with stateless horizontal scaling. No Redis required for standard operation. Each instance runs independently with stateless rate limiting.

The Cost Curve

What Your Gateway Costs When Traffic Grows

AWS API Gateway pricing has a structural trap. What you pay is tied to how many requests your product handles: $3.50 per million for REST APIs, $1.00 per million for HTTP APIs. There is no flat-rate option and no ceiling. Every successful product launch, every traffic spike, every integration you add is a line item that grows with your business.

KrakenD is priced by flat-tiered plans. A traffic spike that doubles your call volume does not change your invoice. A record-breaking sales day costs the same as a quiet Tuesday. Your gateway cost is a line in the annual budget, not a variable you track weekly. Scale your traffic as fast as your business demands. The gateway bill stays the same.

Chart: KrakenD's flat-tiered cost versus AWS API Gateway's per-request REST and HTTP pricing as traffic grows
KrakenD: One gateway for APIs & AI Workloads
image G2 High Performer, Fall 2026
image G2 Momentum Leader, Fall 2026
image G2 Easiest Admin, Mid-Market, Fall 2026
image G2 Fastest Implementation, Small-Business, Fall 2026
image G2 Users Love Us, Fall 2026

Independent Data: AWS Pricing & KrakenD G2 Performance

Independent Data: AWS Pricing & KrakenD G2 Performance

Metric

KrakenD

AWS API Gateway

Pricing model

Flat per plan tierPer million API calls

Quality of Support, Mid-Market

98%87%

Meets Requirements

93%87%

Ease of Setup

92%85%

Ease of Admin

93%87%

ROI payback, Mid-Market

3 months13 months

G2 quadrant, Overall

High PerformerLeader

Runs on any cloud / on-premise

YesNo

AWS API Gateway pricing sourced from aws.amazon.com/api-gateway/pricing, verified August 2026. G2 satisfaction scores: Fall 2026 API Management report, Amazon API Gateway profile (142 reviews). KrakenD G2 data: Fall 2026 API Management reports, data collected July 28, 2026.

Teams Running at AWS Scale

Real Migrations, Real Reasons

Rappi is one of the top 100 AWS resource consumers worldwide: 7,000+ EC2 servers, 1,800+ Kubernetes nodes, 750+ developers, 3,500+ microservices. Neostella runs its integration platform on AWS ECS and replaced AWS API Gateway directly for richer rate limiting and no vendor lock-in. And a regional healthcare network in northern Italy operating AWS API Gateway managed by their cloud provider evaluated KrakenD to regain control of their API layer, independent of the cloud contract.

They Ran at AWS Scale. They Chose KrakenD.

KrakenD is an elegant and powerful API gateway that's enabled us to build an industry-changing API-first platform that we know our customers can rely on.

Scott Wolski VP of Technology Operations, Neostella
Read the Case Study »

What About AI?

AWS AI Gateway Is Bedrock. KrakenD Is Provider-Agnostic.

AWS has launched AI Gateway capabilities as part of its managed service ecosystem, integrated with Bedrock and other AWS AI services. If you are on AWS, the integration is seamless. If you are not, or if you need governance over traffic going to non-AWS models (OpenAI, Anthropic, on-premise inference), AWS AI Gateway does not cover it.

KrakenD's AI Gateway is native config: LLM routing, prompt guarding, semantic caching, token budgets, and an MCP server. Provider-agnostic. OpenAI, Anthropic, Bedrock, Azure OpenAI, Gemini, on-premise models: all governed through the same config, on any infrastructure.

See How KrakenD Governs LLM Traffic

KrakenD AI Gateway

AWS API Gateway Migration FAQ

Frequently Asked Questions

1. Is the migration a big-bang cutover or can we do it incrementally?

Incremental, with one important caveat. Routes that are not coupled to Lambda or IAM-specific auth can migrate directly to KrakenD declarative config. Routes that rely on Lambda triggers or IAM authorization require decoupling those integrations first. Start with the routes that use standard JWT or API key auth and have HTTP backends. Those translate directly. Expand from there.

2. We use AWS Lambda as our compute layer. Does KrakenD integrate with it?

Yes. KrakenD can route to Lambda functions via HTTP using Lambda Function URLs. The difference is that KrakenD's Lambda integration is one backend option among many, not the only architectural path. During migration, Lambda backends continue working while you evaluate whether to keep, replace, or parallel-run them.

3. We use IAM and Cognito for auth. What replaces them?

KrakenD integrates with Cognito as a JWT and OIDC provider natively. IAM-based authorization (signing requests with AWS Signature V4) is specific to AWS services and does not translate directly. If your current auth model relies on IAM for gateway-level authorization, migrating that layer requires moving to a standard OIDC or JWT model, which Cognito supports natively. The migration assessment call will map this explicitly.

4. AWS API Gateway has no egress cost for traffic within AWS. Does migrating add egress costs?

Potentially. If your backends are AWS services (Lambda, EC2, RDS) and your KrakenD instances run on AWS, traffic stays within AWS and egress costs do not change. If you move KrakenD outside AWS while backends remain inside, inter-cloud egress costs apply. A migration that keeps KrakenD on AWS (EKS, ECS, EC2) while removing AWS API Gateway adds no egress overhead.

5. How long does a migration take?

G2 Fall 2026 Mid-Market: KrakenD's average time to go-live is 2 months, with 100% of implementations done in-house. The actual timeline depends on the number of routes and how tightly coupled they are to Lambda or IAM. Routes with standard HTTP backends and JWT auth can go live in days. Lambda-coupled routes take longer to decouple.

6. We are evaluating AWS AI Gateway capabilities via Bedrock. Should that change our timing?

AWS's AI Gateway capabilities are integrated with Bedrock and optimized for AWS AI services. If your LLM infrastructure is entirely on Bedrock and you plan to keep it there, that integration works well within the AWS ecosystem. If you use OpenAI, Anthropic, Azure OpenAI, Gemini, or on-premise models alongside Bedrock, AWS AI Gateway does not govern that traffic. KrakenD's AI Gateway is provider-agnostic: all models, any infrastructure, the same config. The migration assessment will map which AI traffic KrakenD governs and what stays under AWS tooling.

7. What other AWS API Gateway costs are not included in the per-request price?

Several. Data transfer out is billed separately at standard AWS Data Transfer rates. Caching on REST APIs is optional but billed hourly by cache size, a fixed cost that runs whether or not you use it heavily. WebSocket APIs add a per-million connection-minute charge on top of the per-message fee. Execution logs and detailed CloudWatch metrics are billed separately for ingestion and storage. Private APIs behind a VPC endpoint add an hourly PrivateLink charge plus per-GB data processing. None of these show up in the headline per-million-request rate, and all of them push the real bill higher than the request count alone suggests.

Start the
Migration Conversation

Walk through your current AWS API Gateway setup, the routes and integrations involved, and what a phased, low-risk migration path looks like for your architecture.

Start the Migration Conversation    See the Full KrakenD vs AWS API Gateway Comparison

Stay up to date with KrakenD releases and important updates