WSO2 Named a Leader and a Customer Favorite in API Management
- Derric Gilling
- Vice President & General Manager - API Platform BU, WSO2
WSO2 API Platform was named a Leader and a Customer Favorite in The Forrester Wave™: API Management Software, Q3 2026. Across the 15 current offering criteria, WSO2 received the highest scores possible in 11 of them. Complimentary access to the report is now available from WSO2.
The report includes the vendor scorecard, Forrester's analysis of every provider, and Forrester's guidance for API management buyers. In an interview for part of this report, we shared our vision and thoughts on where API management and our product are going. To help understand our approach, below is a quick look of where we think API management is headed, and the criteria in the evaluation we think help to back up this vision outside of the walls of WSO2.
What changed in this market
The report opens on a shift that will be familiar to anyone who has tried to put any kind of governance around their AI services in the last 18 months. LLM endpoints and MCP servers ride the same HTTP plumbing as your REST APIs, which is exactly why they look like a solved problem. They're not. Token cost, tool-level authorization, prompt and response inspection: that is a new policy surface, and it needs a gateway built for it. Ours is a separate AI gateway for this reason, available as part of our overall platform.
For those who have been using the technologies, it makes sense. It’s also coming across in reports like Forrester’s, which states that "API management buyers are demanding strong MCP support" and "AI governance via an AI gateway is thus now at the top of many buyer evaluations."
Then comes the part I would underline for any platform team currently being pitched a standalone AI gateway. On LLM and MCP endpoints, the report says they "need lifecycle and versioning just the same as REST endpoints, and more. An AI gateway alone does not meet those needs, so Forrester recommends a holistic solution over isolated AI gateways."
Forrester’s guidance aligns with what we hear from customers. AI traffic does not arrive in a separate estate. It arrives inside the one you already run on the gateways you already have, and the governance problem it creates is an API management problem wearing new clothes. The report makes the point directly: "API gateway sprawl has grown, and organizations find themselves supporting more API gateways than ever before. Adding yet another gateway vendor for AI services only exacerbates the problem."
Our vision for API management
What our customers are up against shapes where we are taking API management in the age of AI. We believe that four capabilities are going to carry API management into this new era, including:
- Agentic-ready. Your existing APIs become tools that agents can discover and do real work with, not just call. Readiness is measurable, so you know what is ready for AI before you publish it, and the platform keeps those tools in step as your capabilities change so agent workflows do not break.
- Universal governance. Having one control plane means teams ship AI as fast as they want and governance still holds. Every LLM and MCP call is visible, every dollar traces back to a team, and every agent carries its own identity. In both directions, across the gateways you already run.
- Freedom to choose. Unbundled and 100% open source mean you can build the platform you need and change it when the rules do. Run it as SaaS, hybrid, self-managed or air-gapped, and federate what you already have. That is what makes sovereignty and open-source mandates like DORA straightforward to meet.
- Monetization-native. Metering is not monetization. Attribution and chargeback are what make an AI investment defensible to finance, which is what AI FinOps means in practice, and usage-based billing turns an API or AI program into a revenue stream.
None of the four asks you to stop shipping first. Each governs what is already running, or what lands next. That is the point of an unbundled platform: take what you need today, and add the rest when you need it.
Why WSO2 API Platform
WSO2 API Platform gives our customers the freedom to build their platform their way, without lock-in, and to run it as SaaS, hybrid, or 100% self-managed for regulated estates. As an open platform, we include over 50 first- and third-party AI guardrails to protect data, control cost, and enforce access.
Hundreds of the world's largest financial institutions and government agencies run on WSO2 API Platform, which carries 60 trillion transactions a year on a 100% open-source foundation. AI governance is what those customers ask about now. ICA, Sweden's leading grocery retailer, uses WSO2 API Platform to expose AI to agents safely and keep AI spend under control, at 3 billion transactions a month across their estate.
AI spend is scaling faster than the governance around it, and no enterprise should have to replace its API platform to catch up. Governance has to meet AI traffic where it already runs, and it has to be adoptable one piece at a time. Anything that starts with a migration is probably going to arrive too late to matter.
Where WSO2 scored 5.00
Forrester scores each vendor in each criterion from 1 to 5, with a score of 5 defined as "superior relative to others evaluated." WSO2 received a 5.00 in 11 of the current offering criteria. If you are opening the report with a shortlist in hand, start here:
- Policy and security governance: AI. The report describes "an excellent range of AI policies for both LLMs and MCP," including "MCP tool authorization and progressive disclosure, semantic caching, PII protection, and contextual routing."
- Federated API management and Federated API delivery teams. A 5.00 in each. The report advises buyers with many gateways to look for "strong federated API management to govern that sprawl."
- Analytics and reporting. The Moesif acquisition brings "deep insights into LLM token costs." Metering is not monetization; attribution and chargeback are.
- Architecture and deployment options. "Isolated SaaS and air-gapped self-hosting facilitate data sovereignty." For regulated estates, that is the requirement, not a feature bullet.
- Six more criteria with 5.00 scores: Formal lifecycle management, Versioning and delivery tooling, Specification design and validation, API product management, REST API proxy mediation, and Microservices support and integration.
On API design, the report adds: "Unique to WSO2 is the ability to enforce API design standards via natural language."
Within the strategy category, WSO2 scored a 5.00 in the Pricing flexibility and transparency criterion, which brings the total in which Forrester gave WSO2 the highest possible scores to 12 of the 22 criteria.
What reference customers told Forrester
Forrester's methodology includes gathering direct customer feedback. Being named a Customer Favorite indicates outstanding customer feedback among evaluated vendors. WSO2 was named a Customer Favorite in this evaluation.
The specifics matter more than the designation. The report states that "Customers cite WSO2's customer support and roadmap as key strengths", and that "Pricing uses consumption meters, and WSO2 customers validated its value for the cost and price predictability." It also records that "Customers do not believe the changes in ownership and CEO will negatively affect the company." Coming after both an ownership change and a CEO transition, that is the feedback I am most glad our customers gave.
Read the evaluation
The Forrester Wave™: API Management Software, Q3 2026 is complimentary. It includes the vendor scorecard for all 13 providers, Forrester's analysis of each one, and its guidance for buyers. Weigh the criteria against what your teams are shipping now, and how fast that is changing.