> For the complete documentation index, see [llms.txt](https://x7331.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://x7331.gitbook.io/notes/apisec/api-authentication/apis-and-gateways.md).

# APIs & Gateways

**Gateways** providing protection from common attacks (layer 7 firewalls).

<figure><img src="https://3960676229-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmjLkek16kB60c2WFd5lf%2Fuploads%2FbA6nBx6Ow9PBn4bVup1h%2Fapi_and_gateway.png?alt=media&amp;token=b9b3ce82-7266-4d8e-a25a-c846eb392849" alt=""><figcaption></figcaption></figure>

There are various ways that step 4 can happen:

1. Pure introspect (`/introspection`)
2. Embedded token in JSON (`"jwt":"ey..."`)
3. Token exchange (exchange access token to JWT token)

Regarding part 5, i.e., API to API calls, these can use the token obtained as follows:

1. Exchange - Use token exchange to get another token (on demand, powerful options)
2. Embed - Put more tokens inside the first token (when it happens on every request)
3. Share - Use the same token (when the APIs are in the same security domain)

## API Authorization

1. **Gateway check the request's scope(s)** in order to even let you through the door.
2. Then, **the app's API checks claims** to find grained authorization.

<figure><img src="https://3960676229-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmjLkek16kB60c2WFd5lf%2Fuploads%2FmMM9z1Ad7hFGa3DYQGS9%2Fapi_authorization.png?alt=media&amp;token=ed0553a1-f08a-4ead-96a3-059df7701fc7" alt=""><figcaption></figcaption></figure>
