Contact Us 1-800-596-4880

Managing Policies on Gateway Providers

Manage policies not only on Anypoint and Mule gateways but on external gateway providers, such as Google Apigee, Azure API Management, and Kong Gateway. You work with these policies entirely through the Anypoint UI, from the Policies tab of an API instance in Portfolio.

Before You Begin

Before getting started, make sure you have:

  • An Anypoint Platform account.

  • The API Manager: Manage Policies permission to apply, edit, enable, disable, or remove policies.

    For more information, see Enhanced Experience Permissions.

  • A provider scanner already connected for each external provider whose policies you want to manage. Policy management reuses the same connection you set up for scanning. See Adding Scanners from Providers.

Reading Policies vs. Writing Policies

There are two distinct ways you interact with provider policies:

  • Read (discover and display): Provider scanners import the full catalog of policies attached on the provider so you can see them on the Policies tab. This is view-only. See View Read Policies Discovered by Scanners.

  • Write (create, edit, enable, disable, remove): From the same Policies tab, you can manage a curated subset of policies directly on the provider. This is the feature described in this section.

The Editability Rule

Anypoint recognizes and displays every policy it discovers, but you can create and edit only a curated set: the policies that back the universal use cases, plus several additional native Kong policies. See Universal Policies. Other recognized policies are view-only.

You can remove, enable, and disable policies more broadly than you can edit them, so it’s normal to see a policy where Edit Configuration is unavailable while Remove Policy and the enable and disable actions remain available, as long as the provider supports that action. See Applying and Managing Policies and Provider Support and Limitations for Policies.

How Policy Operations Work

Every policy change on an external provider, such as apply, edit, enable, disable, or remove, runs asynchronously: Anypoint accepts the request and performs the work on the provider in the background. Because an accepted request isn’t the same as an applied policy, confirm the outcome in the Activity log tab for the API instance. See Tracking Policy Operations in the Activity Log.