Ana içeriğe atla

Endpoint

Authentication

Requires a Personal API Access Token.

Request

Headers

Path Parameters

Request Body

Full JSON Body Example - Update All Metadata

Full JSON Body Example - Update Name Only

Full JSON Body Example - Update Description and Categories

Full JSON Body Example - Update Sharing Type

Full JSON Body Example - Update Body Read Behavior

Request Body Fields

EnumSharingType (sharingType)

  • BOTH - Share with both internal and external users
  • NONE - Do not share (private)
  • EXTERNAL - Share only with external users
  • INTERNAL - Share only with internal users

EnumContractDirection

  • REQUEST_RESPONSE - Standard request/response API
  • REQUEST_ONLY - Fire-and-forget (request only, no response expected)
  • RESPONSE_ONLY - Response only (e.g., server push, event stream)

Body Read Behavior (requestBodyReadBehavior / responseBodyReadBehavior)

Controls when the gateway reads the request or response body. This setting can optimize performance by skipping unnecessary body reads.
  • ALWAYS_READ - Always read the body (default behavior)
  • READ_IF_POLICY_EXISTS - Read the body only if a policy that needs body access exists
  • NEVER_READ - Never read the body

Notes

  • All fields are optional
  • At least one field must be provided
  • If name is provided, it must be unique within the project
  • categoryList can be empty array to clear all categories
  • description can be set to empty string to clear description
  • sharingType controls who can access the API Proxy

Response

Success Response (200 OK)

When deploy=true is specified:

Response Fields

Error Response (400 Bad Request)

Common Causes

  • Provided name already exists in the project
  • Invalid sharingType value

Error Response (401 Unauthorized)

Error Response (404 Not Found)

cURL Example

Example 1: Update All Metadata

Example 2: Update Name Only

Example 3: Update Description and Categories

Example 4: Update Sharing Type

Example 5: Update Body Read Behavior

Example 6: Update Advanced Settings

Example 7: Assign Global API Proxy Setting

Example 8: Clear Categories

Example 9: Save and Deploy

Notes and Warnings

  • Name Uniqueness:
    • API Proxy names must be unique within the project
    • If you try to set a name that already exists, the request will fail
    • Name changes are immediate and affect API Proxy identification
  • Partial Updates:
    • You can update any combination of fields
    • Fields not provided will remain unchanged
    • Empty arrays clear categories
  • Sharing Type:
    • BOTH - API Proxy is visible to both internal and external users
    • INTERNAL - API Proxy is visible only to internal users
    • EXTERNAL - API Proxy is visible only to external users
    • NONE - API Proxy is private (not shared)
  • Body Read Behavior:
    • ALWAYS_READ reads the body for every request (default)
    • READ_IF_POLICY_EXISTS optimizes performance by skipping body read when no policy needs it
    • NEVER_READ never reads the body, useful for pass-through proxies
    • Applies independently to request and response
  • Categories:
    • Categories are used for API Proxy organization and discovery
    • Multiple categories can be assigned to a single API Proxy
    • Categories are case-sensitive
    • Empty array clears all categories
  • Description:
    • Description provides additional information about the API Proxy
    • Can be used for documentation and discovery
    • Can be set to empty string to clear description
  • Contract Direction:
    • REQUEST_RESPONSE is the standard mode for most APIs
    • REQUEST_ONLY is for fire-and-forget scenarios
    • RESPONSE_ONLY is for server push or event stream scenarios
  • Gateway Access:
    • When disableDirectAccessToGateways=true, clients must access the API through the API Portal
  • Global Settings:
    • globalApiProxySettingName accepts the setting name (not ID) — the system resolves it internally
    • The named setting must exist in the same project
  • Backend Proxy:
    • backendProxyApplyPolicies controls whether policies are applied when this proxy is invoked as a backend by another proxy
  • SOAP Fix:
    • fixSoapApiPortType is only applicable to SOAP API Proxies
  • Deploy: When deploy=true, the API proxy is automatically deployed to the specified environments after saving

Permissions

User must have API_MANAGEMENT + MANAGE permission in the project.
  • Immediate Effect:
    • Metadata changes take effect immediately
    • Name changes affect API Proxy identification
    • Sharing type changes affect API Proxy visibility
  • API Proxy Discovery:
    • Metadata is used for API Proxy discovery and search
    • Categories help users find relevant API Proxies
    • Description provides context about API Proxy purpose