Database per Service Pattern :👈 👉:Securing an ASP.NET Core Web API

API Gateway Security

API Gateway Security in Microservices

API Gateway Security refers to implementing security controls at the API Gateway layer to protect all backend microservices from unauthorized access, attacks, and misuse.

Instead of securing every microservice individually for common security concerns, the API Gateway acts as the central security checkpoint.

Why API Gateway Security?

Without an API Gateway:

Client
  │
  ├── Customer Service
  ├── Order Service
  ├── Payment Service
  ├── Inventory Service
  └── Shipping Service

Every service must implement:

  • Authentication
  • Authorization
  • Rate Limiting
  • SSL Handling
  • Logging
  • IP Filtering

This results in duplicated code and inconsistent security.

With API Gateway

                   API Gateway
                        │
        ┌───────────────┼───────────────┐
        │               │               │
        ▼               ▼               ▼
 Customer Service   Order Service   Payment Service

The gateway becomes the single entry point.

All requests pass through it first.

Security Responsibilities of API Gateway

1. Authentication

Authentication answers:

"Who are you?"

The gateway validates:

  • JWT Tokens
  • OAuth Tokens
  • OpenID Connect Tokens

Flow:

User Login
    │
    ▼
Identity Provider
    │
    ▼
JWT Token Generated
    │
    ▼
API Gateway
    │
 Validate Token
    │
    ▼
Microservice

Example JWT

Authorization: Bearer eyJhbGciOi...

The gateway validates the token before forwarding the request.

2. Authorization

Authorization answers:

"What are you allowed to do?"

Example:

Admin
    -> Create Product
    -> Delete Product
Customer
    -> View Product
    -> Place Order

Gateway checks:

{
  "role": "Admin"
}

before forwarding requests.

3. SSL/TLS Termination

HTTPS encryption is usually handled at the gateway.

Client
   │ HTTPS
   ▼
API Gateway
   │ HTTP/HTTPS
   ▼
Microservices

Benefits:

  • Central certificate management
  • Reduced service complexity
  • Easier certificate renewal

4. Rate Limiting

Prevents abuse and DDoS-like traffic.

Example:

Maximum 100 Requests/Minute/User

If a client exceeds the limit:

429 Too Many Requests

Example

User A
      ↓
5000 requests/minute

Gateway blocks excess requests.

5. IP Whitelisting and Blacklisting

Allow only specific IP addresses.

Allowed:
10.10.1.1
10.10.1.2

Block:

Unknown IPs

Used in:

  • Banking
  • Healthcare
  • Internal corporate systems

6. API Key Validation

Some APIs require an API key.

x-api-key: abcd1234

Gateway validates the key before forwarding.

7. Request Validation

Checks:

  • Required headers
  • Required fields
  • Payload size
  • Content type

Example:

Content-Type: application/json

Reject invalid requests before they hit microservices.

8. Protection Against Malicious Requests

Gateway can block:

SQL Injection

Attack:

' OR 1=1 --

XSS

Attack:

<script>alert('hack')</script>

Large Payload Attacks

100 MB Request Body

Gateway rejects suspicious requests.

9. Logging and Auditing

Gateway records:

Who accessed?
When?
Which API?
Response Status?

Example Log:

User: john
API: /orders
Status: 200
Time: 10:20 AM

Useful for:

  • Auditing
  • Troubleshooting
  • Compliance

10. Distributed Denial of Service (DDoS) Protection

Gateway can detect:

1 Million Requests
in a short period

and throttle/block traffic.

Common cloud protections:

  • Azure Front Door
  • Azure WAF
  • AWS Shield
  • Cloudflare

.NET Example Using Ocelot API Gateway

Install Packages

dotnet add package Ocelot
dotnet add package Microsoft.AspNetCore.Authentication.JwtBearer

Configure JWT Authentication

Program.cs

builder.Services
    .AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.Authority =
            "https://localhost:5001";
        options.Audience = "microservices-api";
    });
builder.Services.AddAuthorization();

Configure Ocelot

ocelot.json

{
  "Routes": [
    {
      "UpstreamPathTemplate": "/orders/{everything}",
      "DownstreamPathTemplate": "/api/orders/{everything}",
      "DownstreamScheme": "https",
      "DownstreamHostAndPorts": [
        {
          "Host": "localhost",
          "Port": 7001
        }
      ],
      "AuthenticationOptions": {
        "AuthenticationProviderKey": "Bearer"
      }
    }
  ]
}

Enable Authentication Middleware

app.UseAuthentication();
app.UseAuthorization();
await app.UseOcelot();

Now:

Client
   │
   ▼
Ocelot Gateway
   │
 Verify JWT
   │
   ▼
Order Service

Example Request Flow

  1. User logs in
  2. Identity Server issues JWT
  3. User calls:
GET /orders/1001
  1. API Gateway validates JWT
  2. Authorization check
  3. Rate-limit check
  4. Logs request
  5. Forward to Order Service
  6. Response returned

Best Practices

✅ Never Expose Microservices Directly

Internet
   │
   ▼
API Gateway
   │
   ▼
Microservices

✅ Use JWT Authentication

Stateless and scalable.

✅ Enable HTTPS Everywhere

TLS 1.2+

✅ Apply Rate Limiting

Protects from abuse.

✅ Centralized Logging

Use:

  • Serilog
  • Seq
  • ELK Stack
  • Application Insights

✅ Use WAF (Web Application Firewall)

Extra protection against:

  • SQL Injection
  • XSS
  • Bot attacks

Real-World Example

For an e-commerce application:

Client
   │
   ▼
API Gateway
   │
   ├── Customer Service
   ├── Product Service
   ├── Order Service
   ├── Payment Service
   └── Shipping Service

Security handled by Gateway:

  • JWT Authentication
  • Role-Based Authorization
  • Rate Limiting
  • HTTPS
  • Request Validation
  • Logging
  • DDoS Protection

Backend services focus only on business logic.

Interview Answer

API Gateway Security is the practice of implementing security controls at the API Gateway layer in a microservices architecture. The gateway acts as a central entry point that handles authentication, authorization, SSL/TLS termination, rate limiting, API key validation, request filtering, logging, and protection against attacks such as DDoS, SQL Injection, and XSS. This centralizes security, reduces duplication across microservices, and improves manageability and consistency.

Back to Index
Database per Service Pattern :👈 👉:Securing an ASP.NET Core Web API