Policies

TIBCO API Exchange Gateway enables API providers to enforce business and technical requirements, including security, validation, and service level agreements through declarative policies.

TIBCO API Exchange includes the following polices:

Security Policies
Security policies provide authentication, authorization, encryption, validation, and digital signature and certificate management. Support is provided for WSS Username Token, SAML, X.509, Kerberos, OAuth, and LDAP.
Throttle Policies
Throttle policies provide limits or quotas by partner, service, or other criteria. Throttles can be based on request rate, concurrent load, or error rate and used to restrict access at the facade (such as through a commercial SLA or product plan), or against the target service (technical throttle).
Validation Policies
Validation policies check content against schemas or rules and reject invalid or hostile messages.
Transformation and Mediation Policies
Transformation and mediation policies provide transformation of request, response and fault messages.
Logging
Logging traces requests for audit or debugging.