Connect Akto with AWS API Gateway
AWS API Gateway is a fully managed service from AWS that helps developers create, publish, monitor, and secure APIs at scale. By integrating AWS API Gateway with Akto, you'll automatically discover and test the security of all your REST APIs, HTTP APIs, and WebSocket APIs deployed through API Gateway, ensuring comprehensive API security across your AWS infrastructure.

To connect Akto with AWS API Gateway, follow these steps -
Set up and configure Akto Traffic Processor. The steps are mentioned here.
Add AWS API Gateway connector
Go to API gateway in AWS console
Go to your API, click on
Stagesfrom the left menu.
Scroll down to
Logs and tracingsection and click onEdit.
Select
Error and info logsandData tracingand save these settings.{ "requestId":"$context.requestId", "extendedRequestId":"$context.extendedRequestId","ip": "$context.identity.sourceIp", "caller":"$context.identity.caller", "user":"$context.identity.user", "requestTime":"$context.requestTime", "httpMethod":"$context.httpMethod", "resourcePath":"$context.resourcePath", "status":"$context.status", "protocol":"$context.protocol", "responseLength":"$context.responseLength" }
Find out the
cloudwatch log groupfor your API gateway for the stage which has the above logs enabled and save it. We'll need it later.Deploy the connector (Kubernetes, Docker Compose, or CloudFormation).
For
LOG_GROUP_NAME, use the CloudWatch log group name (from API Gateway Stage logs). You can use comma-separated (,) names to add multiple log group names.For
AWS_REGION, use the AWS region where that log group exists.For
AKTO_KAFKA_BROKER_MAL, use the Akto mini-runtime Kafka endpoint (<AktoNLB-DNS>:9092).For Kubernetes and Docker Compose: For
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEYandAWS_SESSION_TOKEN, use credentials that have permission to read the above CloudWatch log group. (CloudFormation uses IAM instance roleāno credentials needed.)For
DATABASE_ABSTRACTOR_TOKEN, copy the token from Akto dashboard.Use one of the deployment options below.
Option A: Kubernetes deployment
Option B: Docker Compose
Create a docker-compose.yml and watchtower.env on your connector host:
docker-compose.yml:
watchtower.env:
Run:
Option C: CloudFormation (Automated deployment)
Download the CloudFormation scripts from the Akto infra repository:
Repo path: https://github.com/akto-api-security/infra/tree/feature/quick-setup
Use folder:
api-gateway-connect-cloudformation
Example:
Update parameters.json with your values, then deploy:
This CloudFormation option creates the connector EC2 instance and runs the API Gateway connector automatically using Docker Compose.
Environment variables reference
AKTO_BYTES_IN_THRESHOLD
Keep default (100) unless tuning needed
Akto connector runtime tuning value
AKTO_TRAFFIC_BATCH_TIME_SECS
Keep default (10) unless tuning needed
Akto connector runtime tuning value
AKTO_TRAFFIC_BATCH_SIZE
Keep default (100) unless tuning needed
Akto connector runtime tuning value
AKTO_KAFKA_BROKER_MAL
<AktoNLB-DNS>:9092
If mini-runtime is deployed using CloudFormation, go to stack Outputs, copy AktoNLB, and append :9092
AWS_ACCESS_KEY_ID
Access key ID (Kubernetes, Docker Compose only)
IAM user or temporary STS credentials with CloudWatch Logs read permissions
AWS_SECRET_ACCESS_KEY
Secret access key (Kubernetes, Docker Compose only)
IAM user or temporary STS credentials
AWS_SESSION_TOKEN
Session token if using temporary credentials (Kubernetes, Docker Compose only)
STS/assumed role session; leave empty for long-lived IAM user keys
CLOUDWATCH_READ_BATCH_SIZE
Keep default (5) unless tuning needed
Connector tuning value
LOG_GROUP_NAME
API Gateway execution/access log group name (Use comma-separated names to suppport more than one log group)
CloudWatch Logs console (for your API Gateway stage)
AWS_REGION
Region of API Gateway + CloudWatch log group
AWS region (example: ap-south-1)
DATABASE_ABSTRACTOR_TOKEN
Database abstractor token
Akto Dashboard > Quick Start > Hybrid SaaS > Runtime Service Command section
DISCOVER_OPENAPI_SPEC
"true" to enable OpenAPI discovery
Connector feature flag
OPENAPI_DISCOVERY_INTERVAL_MINUTES
Discovery interval (default 15)
Connector tuning value
Notes:
To create AWS CLI credentials, you can take reference from the official AWS docs.
For AWS IAM policy permissions for cloudwatch, you can refer here.
Get Support for your Akto setup
There are multiple ways to request support from Akto. We are 24X7 available on the following:
In-app
intercomsupport. Message us with your query on intercom in Akto dashboard and someone will reply.Join our discord channel for community support.
Contact
help@akto.iofor email support.Contact us here.
Last updated