Your APIs.Your AI.
Your security.
One platform.
Managed Otoroshi clusters, serverless API management, an AI gateway for every LLM and threat protection. Built by the team that created Otoroshi.
- Managed · Serverless · Open source
- No lock-in, it's plain Otoroshi
- Made in France
- Otoroshi in production, created at MAIF
- Since 2017
- for managed clusters, worldwide
- 7 regions
- LLM providers behind one API
- 50+
- of the OWASP CRS v4 regression tests passed
- 100%
The platform
One platform.
Your way.
Run it on your own Otoroshi — managed by us or self-hosted — or go serverless and run nothing at all. Same building blocks, same people behind them.
On your Otoroshi
managed by us or self-hosted
Serverless
nothing to run
Otoroshi · Managed
Your Otoroshi cluster.
Ready in seconds.
Fully managed Otoroshi clusters, perfectly configured and optimized. Every Otoroshi feature, every extension, none of the operations: we handle setup, upgrades, backups, scaling and monitoring.
- Always up to date
- Backed up, encrypted at rest
- Clustered & auto-scaled
- Monitored 24/7
- No lock-in: it's plain Otoroshi
- 7 regions worldwide
acme-prod
Otoroshi cluster · Paris
3
nodes
99.9%
uptime
auto
scaling
Deploy in
Otoroshi · Serverless
git push.
Your API is live.
Describe your API with OpenAPI, add routes, JavaScript plugins and portal pages in a git repository. Every branch is an environment with its own domain and API keys. Deploy, preview, roll back: it's just git.
- One branch per environment
- API keys, quotas, dev portal
- OpenAPI first
- Zero server to manage
$ git commit -m "add orders api"
$ git push origin main
Deploying my-api@main…
✓ deployed to prod
→ live: GET /orders 200 · 41ms
my-api/
- openapi.jsonyour routes
- entities/routes & backends
- modules/JavaScript plugins
- docs/portal pages
- dev-portal.jsonportal & plans
One branch per environment
Open source · Otoroshi LLM extension
Every model.
One API.
Connect, secure and govern all your LLMs behind a single OpenAI-compatible API. Route by cost or performance, cache semantically, enforce guardrails and budgets, and know the cost and CO₂ of every call. AI Studio gives your teams a console for it all.
- OpenAI-compatible API
- Guardrails
- Budgets & quotas
- Semantic cache
- Cost & CO₂ per call
- MCP servers & agents

- OpenAI
- Anthropic
- Mistral AI
- Gemini
- Ollama
- Azure AI
- Groq
- DeepSeek
- Scaleway
- OVHcloud
- Cohere
- Hugging Face
- Cloudflare AI
- ElevenLabs
- + many more, local models too
Open source · Threat Protection
Every threat.
One score.
A JVM-native WAF running the OWASP Core Rule Set, IP reputation feeds, CrowdSec, bot and AI-crawler control, honeypots: every detector adds up into one threat score, and the response is graded — from log to cluster-wide ban. Dry run first, then arm.
- WAF · OWASP Core Rule Set
- IP reputation & CrowdSec
- Bots & AI crawlers
- Cluster-wide bans
POST /login?user=admin'--
from 203.0.113.42 · hosting network
- IP reputation+40
- Hosting network (ASN)+15
- WAF · OWASP CRS+45
- Bots & AI crawlers—
- CrowdSec—
- Honeypots—
100
threat score
Serverless · Nothing to install
No gateway to run?
Go serverless.
The power of our Otoroshi extensions, as fully managed services you plug in front of your apps in minutes. Pay as you grow, start for free.
AI Gateway
Every LLM behind one OpenAI-compatible endpoint, with quotas, budgets, semantic cache and guardrails.
AI Studio, serverless
Discover AI GatewayWebShield
A web application firewall in front of any app or API. OWASP rules, bot mitigation, real-time analytics.
Threat Studio, serverless
Discover WebShieldAuthify
Authentication enforced in front of any app in a few clicks. Bring your own identity provider.
OpenID Connect · Keycloak · Auth0
Discover AuthifyOur story
Founded by the
creator of Otoroshi.
Open source at heart: Otoroshi and our extensions are Apache 2.0. Cloud APIM is by far the biggest contributor to Otoroshi, and the people who support you are the people who write the code.
Explore our open-source projects- 2017
Otoroshi is born
Created by Mathieu Ancelin at MAIF, open source from day one.
- 2021
Cloud APIM is founded
In Poitiers, France, by the people behind Otoroshi.
- 2023
Otoroshi, managed
Dedicated clusters, perfectly configured, ready in seconds.
- 2024
Serverless & AI
GitOps APIs, the LLM extension, AI Gateway and Authify.
- 2026
Security & studios
Threat Protection, AI Studio and Threat Studio.
Support · Training · Consulting
Backed by the people
who wrote the code.
🇫🇷 Made in France · English & French speaking
Support
Up to 24/7, 30-minute response
Professional support for mission-critical Otoroshi infrastructures, on Cloud APIM or on-premise.
See support plansTraining
Tailor-made sessions for your team
Learn how to make the best of Otoroshi, managed by Cloud APIM or in your own datacenters.
Book a sessionConsulting
Install, configure, build on Otoroshi
Architecture reviews, migrations, custom plugins and extensions: rock-solid from day one.
Talk to an expertFrom the blog
News, deep dives
and tutorials.

Exposing Kubernetes Applications with Otoroshi and the Gateway API on Clever Cloud
There's a certain feeling you get when you've just finished setting up a new piece of infrastructure and it actually works. The kind of satisfaction that makes you reach for your c

Building a JVM-Native WAF: A Journey from WASM to Pure Scala
For the past two years, Otoroshi has had a Web Application Firewall powered by Coraza, the excellent Go implementation of ModSecurity. To achieve that, we compiled Coraza to WebAss

Introducing the Otoroshi LLM Extension by Cloud APIM
🔍 What Is the Otoroshi LLM Extension? The Otoroshi LLM Extension by Cloud APIM is a groundbreaking module that enhances the capabilities of the open-source API Gateway Otoroshi, t
FAQ
Frequently asked questions
Still have a question? Talk to our team.
What is Otoroshi?
Otoroshi is a battle-tested, open-source (Apache 2.0) HTTP reverse proxy with API management features, from the #OSSbyMAIF ecosystem. It was created by one of the founders of Cloud APIM, and Cloud APIM is by far its biggest contributor.
Managed or serverless: which one should I choose?
Otoroshi Managed gives you a dedicated, fully configurable Otoroshi cluster with full admin access: ideal for complex or regulated environments. Serverless is GitOps driven, there is nothing to run and you pay as you grow: ideal for dev-first teams. Compare both offers.
Am I locked in?
No. A managed instance is plain Otoroshi with every feature available, and you can export your data at any time. Our extensions are open source, so you can run the very same stack on your own infrastructure.
Where can I deploy my Otoroshi instances?
Cloud APIM offers Otoroshi deployments in 7 regions all over the globe: Paris, Roubaix, Gravelines, Warsaw, Montreal, Singapore, Sydney.
Which AI providers can I use?
The Otoroshi LLM extension supports 50+ providers through one OpenAI-compatible API, including OpenAI, Anthropic, Mistral, Gemini, Azure OpenAI, Groq, DeepSeek, Scaleway, OVHcloud AI Endpoints, Cohere, Hugging Face, and local models with Ollama.
Can you support our own, on-premise Otoroshi?
Yes. We offer professional support (up to 24/7 with a 30-minute response time), training and consulting for Otoroshi clusters running anywhere, by the people that created Otoroshi. See support plans.
Ready to build?Start in minutes.
Spin up a managed Otoroshi cluster or a serverless project for free, or ask us for a live demo of the whole platform.