WSO2 has been named a Leader in Gartner’s 2026 Magic Quadrant for API Management, published on September 28, 2026.
The company described how it rebuilt its API platform over the past year, but the short version is that APIs now have a second type of customer, AI agents, and WSO2 wants to manage both with the same tools.
The WSO2 API Platform is open source and modular. It manages APIs, AI services and Model Context Protocol (MCP) servers. WSO2 says it handles more than 63 trillion transactions a year for thousands of enterprises and governments, including hundreds of Fortune 1000 companies.
Instead of one big product, it is split into separate pieces you can adopt individually:
- API Gateway
- AI Gateway
- Event Gateway
- API Control Plane
- AI Workspace
- Dev Portal and MCP Hub
- Monetization
A company can start with only the AI Gateway, the MCP Hub or the Dev Portal and add the rest later. WSO2 says there are no forced migrations and no hard cutoff dates.
Making APIs Usable by Agents
An agent can’t use an API the way a developer does, by reading docs and experimenting. WSO2 says agents need a few specific artifacts: an llms.txt index, api.md endpoint descriptions, published Arazzo workflows (which describe multi-step API sequences) and an MCP Registry API.
READ: WSO2 Says Kenyan Businesses Must Make Systems Ready for AI Agents
According to WSO2, the platform generates all of these automatically, and developers can control per API what agents are allowed to see. It can also take a REST API defined in OpenAPI and expose it as a governed MCP service.
One Control Plane for API, AI and MCP Traffic
The AI Gateway applies policy to large language model (LLM) traffic and to MCP servers. WSO2 lists MCP authentication and authorization, rate limiting at the level of individual tools, and built-in guardrails. A separate AI Workspace gives AI teams their own control plane.
The goal is that every LLM and MCP call going through the platform is visible and governed.
Derric Gilling, WSO2’s VP and general manager for the API Platform, said governance has to be added where AI traffic already runs, one piece at a time, without making enterprises replace their existing API platform.
“We view our placement as a Leader in the 2026 Gartner Magic Quadrant as validation of our approach in meeting enterprises’ demands for AI governance they can trust to work at scale.”
Monetization
WSO2 draws a line between counting usage and charging for it. Its monetization component attributes usage to the team, customer or agent that generated it. That covers API calls, AI traffic and MCP traffic, including token consumption.
The attribution works across gateways from more than 14 vendors, not just WSO2’s own, so costs can be traced back even when traffic is spread across different gateways. The same data can drive usage-based billing.
READ: WSO2 Hosts First WSO2Con Africa in Nairobi
Every component is licensed under Apache 2.0 and free to run indefinitely, except monetization, which is offered through SaaS. WSO2 says this helps organizations that have sovereignty or open-source requirements.
Where It Runs
Customers can choose from four deployment models:
- Fully vendor-managed SaaS
- Hybrid
- Self-managed
- Air-gapped
Data residency is supported. In the hybrid setup, the control plane is in SaaS while the gateways stay self-hosted, so traffic stays inside infrastructure the customer controls. Private single-tenant data planes are available on AWS, Azure and GCP.
WSO2 also makes two commitments worth noting. Features are meant to be the same across all deployment models, and on-premises pricing for the gateway, portal and control plane matches cloud pricing.
The numbers back this up, as on-premises deployments are currently 67% of WSO2’s installed base. The SaaS offering handled 423 million transactions in February 2026, and its public cloud service has a SOC 2 Type 2 attestation.



























