API Gateway Performance & Configuration Optimization
Diagnose and Optimize API Gateway Performance & Security
What You Can Do
Analyze your API gateway metrics and logs to identify performance bottlenecks, then receive targeted optimization recommendations for throughput, latency, and request handling. You'll also get a comprehensive security configuration audit to identify misconfigurations and vulnerabilities in your gateway setup, with step-by-step remediation guidance.
Features
Analyze request flows, identify latency sources, and pinpoint throughput constraints
Get specific tuning recommendations for connection pooling, buffer sizes, and request batching
Validate OAuth/JWT setup, TLS/mTLS, rate limiting, and access control policies
Inspect headers, payloads, and error patterns to reveal hidden performance or security issues
Create and validate rate limiting rules that protect your backend while allowing legitimate traffic
Design cache headers, TTLs, and cache-busting strategies for maximum hit ratios
Assess algorithm selection, health check behavior, and failover strategies
Build observability strategies tailored to your gateway's critical metrics
Example Output
Performance Analysis Results
Identified Bottleneck: Database connection pool exhaustion
- Current pool size: 50 connections
- Peak concurrent requests: 42
- Recommendation: Increase pool to 75–100, implement connection queuing
Latency Breakdown:
- Gateway processing: 5ms ✓ (healthy)
- Upstream service: 450ms ✗ (bottleneck)
- Solution: Implement circuit breaker, add timeout failover to cache
Security Audit Findings
Critical Issues:
- JWT secret exposed in configuration file → Rotate immediately, use secret manager
- Missing CORS origin validation → Implement strict allowlist
Medium Priority:
- Rate limiting not enforced on
/admin/*endpoints → Apply 100 req/min threshold - No mTLS configured for backend connections → Generate certificates and enable
What's Included
- SKILL.md: Complete skill with analysis workflows, decision trees, and verification checklists
- Performance Analysis Template: Structured framework for bottleneck diagnosis
- Security Configuration Audit Checklist: Validation guide for OAuth, TLS, rate limiting, and access control
- Optimization Playbook: Step-by-step remediation workflows for common gateway issues
- Monitoring Design Worksheet: Template for alerting on critical metrics and SLOs
- Request Flow Mapper: Tool for analyzing and optimizing multi-hop request paths
Who It's For
- DevOps Engineers — Diagnose and resolve production gateway performance issues
- Platform Engineers — Design scalable, secure API gateway infrastructure for teams
- SRE Teams — Optimize reliability and performance of shared API platforms
- API Architects — Validate security and performance of gateway configurations
- Backend Engineering Leads — Guide teams on gateway tuning and best practices
Best For
- Production bottleneck investigation — Identify root causes of latency spikes or throughput limits
- Gateway performance tuning — Implement configuration changes for measurable throughput/latency gains
- Security hardening initiatives — Audit and remediate misconfigurations during compliance sprints
- Capacity planning and scaling — Model growth forecasts and recommend infrastructure upgrades
- Post-incident optimization — Prevent recurrence by addressing underlying configuration weaknesses







