Azure's API gateway, where policies like rate limits, quotas, ip-filter and validate-jwt are defined once and apply to every API. Production VNet injection is offered in the Premium tier.
Also called APIM, APIM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains API Management in context, with comparison tables and the common traps.
Terms in this definition
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- validate-jwt
Before API Management passes a request on to the back end, this policy confirms the JWT has the expected issuer, audience and claims.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
Related terms
- AI gateway (Foundry)
API Management instance linked to a Microsoft Foundry resource; it sits in front of registered models, tools and agents, adding access control, rate limiting and diagnostics. Custom agents cannot be registered without one.
- AI gateway in Azure API Management
Collection of API Management gateway capabilities, offered in every tier rather than as its own product, for placing model APIs, MCP servers and A2A agent APIs behind caller authentication, token metering and content screening.
- API Management llm-content-safety policy
Policy for the AI gateway in API Management: it passes prompts or completions to Azure AI Content Safety and rejects the call with 403 if a blocklist matches, Prompt Shields detect an attack, or a harm category passes its threshold, where 0 is strictest and 7 most lenient.
- API Management validate-jwt policy
API Management inbound policy validating a JWT's issuer, audience, signature and required claims, for instance using the Microsoft Entra OpenID configuration. By default it answers 401 when a token is absent or invalid.
- APIM named values
Reusable name/value pairs referenced from API Management policies. A value can be held in plain text, encrypted inside APIM as a secret, or pulled from Key Vault through the instance's managed identity.
- APIM protocols and ciphers
Blade in API Management for switching TLS/SSL protocols (SSL 3.0, for example) and cipher suites on or off, on the client side and towards backends. By default the minimum is TLS 1.2.
- APIM subscription key
Caller key supplied either as a query-string parameter or in the Ocp-Apim-Subscription-Key header. API Management's gateway checks it as an APIM subscription key, which is not a Microsoft Entra token, while Foundry Tools like Content Safety read the resource key from it.
- Azure AD B2C
Identity platform for customer-facing apps; since 1 May 2025 new customers can't buy it and are directed to its successor, Microsoft Entra External ID. Tokens it issues can be checked by API Management's
validate-jwtpolicy via its OpenID configuration.