An API gateway controls traffic across the boundary between API consumer and API implementation; it also enforces the terms and conditions for API consumption defined by the API owner. Historically, we've tended to think of different types of gateways — be they web, security, messaging, or API gateways — as being distinct "boxes" in a deployment topology. In a hybrid world of devices, people, and software, however, the perception of distinct gateway boxes is rapidly evaporating. As the scale and variety of interaction grow by orders of magnitude, it's operationally advantageous to have a unified gateway strategy with a single command-andcontrol center for any traffic that crosses internal or external boundaries.