Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

API Product to mandate addition of atleast one proxy

Hi,

As per this document, https://docs.apigee.com/api-platform/publish/create-api-products

there is a warning saying that If you don't select an API proxy, any app associated with the product can make calls to any API in your entire organization.

Is there a way to mandate addition of atleast one proxy to the product so that if anybody misses to add a proxy to the product it does not expose all the APIs. If not, what is the best way to prevent this.

Solved Solved
0 4 520
1 ACCEPTED SOLUTION

As this is a situation that can bite you unexpectedly (this is the "skeleton key" mentioned by @wwitman in his excellent article here) -- it would be awesome to at least see a warning on the API Product page that warned when this condition exists. Silent superuser privilege seems dangerous...

View solution in original post

4 REPLIES 4