Prev Next

API / APIGEE Gateway Interview Questions

1. What is Apigee and what problem does it solve for organisations? 2. What are the deployment models available in Apigee? 3. What is an API proxy in Apigee and what are its main components? 4. What are Flows in Apigee and what is the request/response processing pipeline? 5. What are Apigee Policies and what categories are available? 6. What is the VerifyAPIKey policy and how does basic API key security work in Apigee? 7. How does OAuth 2.0 work in Apigee and what grant types are supported? 8. What is the difference between Quota and SpikeArrest policies in Apigee? 9. What is an API Product in Apigee and how does it differ from an API Proxy? 10. What is the Apigee organisation hierarchy and what are Environments? 11. What are Shared Flows in Apigee and when do you use them? 12. What is response caching in Apigee and how do you configure the ResponseCache policy? 13. What is the AssignMessage policy and what can it do? 14. What is the ExtractVariables policy and how does it work with flow variables? 15. What is the ServiceCallout policy and when would you use it? 16. What are Key Value Maps (KVMs) in Apigee and how do you use them? 17. How does fault handling and error management work in Apigee? 18. What is Target Server configuration in Apigee and why is it used instead of hardcoding backend URLs? 19. What analytics capabilities does Apigee provide? 20. What is the Apigee Developer Portal and how does it support the developer experience? 21. How does JWT validation work in Apigee? 22. What is the MessageLogging policy in Apigee and how is it used for audit and debugging? 23. How does Apigee handle CORS (Cross-Origin Resource Sharing)? 24. What is the Apigee hybrid architecture in more depth, including its components? 25. What are Environment Groups and how does routing work in Apigee? 26. How does TLS and mutual TLS (mTLS) work in Apigee? 27. What is the Access Control policy in Apigee and how do you allowlist/denylist IPs? 28. How do the JSONToXML and XMLToJSON policies work in Apigee? 29. What is GraphQL proxy support in Apigee? 30. What is Apigee CI/CD and how do you deploy proxies in a pipeline? 31. What is RBAC (Role-Based Access Control) in Apigee and what are the built-in roles? 32. What is Advanced API Security in Apigee and how does it detect bot attacks? 33. What is Apigee API Hub and how does it relate to Apigee gateway? 34. How does load balancing and health checking work on Apigee TargetEndpoints? 35. What is the Apigee Debug / Trace tool and how do you use it for troubleshooting? 36. How do you import an OpenAPI specification into Apigee to generate a proxy? 37. What is Apigee monetisation and how does it work? 38. What are Apigee flow variables and how do you work with them? 39. How does Apigee compare to other API gateways such as Kong, AWS API Gateway, and MuleSoft? 40. What are common Apigee anti-patterns and best practices for production deployments?

1. What is Apigee and what problem does it solve for organisations?

Apigee is Google Cloud's native, full-lifecycle API management platform. It sits between backend services and the clients that consume them, acting as a secure, observable, and policy-enforcing proxy layer.

Read full answer

2. What are the deployment models available in Apigee?

Apigee offers three deployment models to accommodate different infrastructure requirements, data residency rules, and latency constraints. Apigee deployment models Model Management plane Runtime plane Best for Apigee (SaaS / cloud-native) Google-managed Google-managed Cloud-first; simplest to ope

Read full answer

3. What is an API proxy in Apigee and what are its main components?

An API proxy is the primary unit of deployment in Apigee. It creates an abstraction layer between API consumers and backend services, so backend URLs, authentication schemes, and data formats can change without affecting consumers....

Read full answer

4. What are Flows in Apigee and what is the request/response processing pipeline?

A Flow is an ordered sequence of policy steps that Apigee executes as a request travels from client to backend and back. Understanding the flow pipeline is fundamental to knowing where to attach each policy....

Read full answer

5. What are Apigee Policies and what categories are available?

Policies are the processing building blocks of an Apigee proxy. Each policy is a pre-built, reusable, XML-configured processing step that you attach to a flow....

Read full answer

6. What is the VerifyAPIKey policy and how does basic API key security work in Apigee?

The VerifyAPIKey policy is Apigee's most fundamental security mechanism. It validates that an incoming request contains a valid API key that was issued by Apigee to a registered developer application....

Read full answer

7. How does OAuth 2.0 work in Apigee and what grant types are supported?

Apigee implements the complete OAuth 2.0 specification via the OAuthV2 policy . Apigee can act as an authorisation server (issuing tokens) or as a resource server (validating tokens), or both....

Read full answer

8. What is the difference between Quota and SpikeArrest policies in Apigee?

Both policies limit traffic, but they operate on very different time scales and serve different purposes. Confusing them is a common interview question because both say 'rate limiting' but do fundamentally different jobs....

Read full answer

9. What is an API Product in Apigee and how does it differ from an API Proxy?

An API Product is a curated bundle of API proxy resources combined with a usage plan. It is the unit that developers subscribe to, and it represents how you monetise or control access to your APIs....

Read full answer

10. What is the Apigee organisation hierarchy and what are Environments?

Apigee uses a clear hierarchical structure to organise all resources. Understanding this hierarchy is essential for managing multi-team and multi-environment API programmes.

Read full answer

11. What are Shared Flows in Apigee and when do you use them?

A Shared Flow is a reusable sequence of policies that can be called from any API proxy using the FlowCallout policy. Shared flows solve the problem of duplicating the same policy logic across dozens of proxies -- a change to...

Read full answer

12. What is response caching in Apigee and how do you configure the ResponseCache policy?

The ResponseCache policy stores successful backend responses in Apigee's in-memory cache. When an identical subsequent request arrives within the cache TTL, Apigee serves the cached response directly without contacting the backend at all....

Read full answer

13. What is the AssignMessage policy and what can it do?

The AssignMessage policy is one of the most-used policies in Apigee. It lets you create, modify, or remove HTTP message components (headers, query parameters, form parameters, body, verb, path) on either the request or the response....

Read full answer

14. What is the ExtractVariables policy and how does it work with flow variables?

The ExtractVariables policy extracts content from HTTP messages (headers, query parameters, URI path, JSON body, XML body, form parameters) and stores the values in named flow variables . These variables can then be referenced in conditions and other policies throughout...

Read full answer

15. What is the ServiceCallout policy and when would you use it?

The ServiceCallout policy allows an Apigee proxy to make an additional HTTP call to an external service within the same request/response pipeline . The response from that external call is stored in a variable and can be used by subsequent...

Read full answer

16. What are Key Value Maps (KVMs) in Apigee and how do you use them?

Key Value Maps (KVMs) are encrypted, persistent key-value stores that allow Apigee proxies to read configuration values at runtime without hardcoding them. KVMs are ideal for storing environment-specific configuration like backend URLs, API keys, feature flags, and whitelists that need...

Read full answer

17. How does fault handling and error management work in Apigee?

Apigee provides a structured fault handling mechanism through FaultRules and DefaultFaultRule . When a policy raises an error, Apigee exits the normal flow and enters the error flow, where you can customise the error response returned to the client....

Read full answer

18. What is Target Server configuration in Apigee and why is it used instead of hardcoding backend URLs?

A Target Server is a named, environment-scoped configuration object that defines a backend service endpoint (host, port, SSL settings). Instead of hardcoding the backend URL in the proxy's TargetEndpoint XML, you reference a Target Server by name....

Read full answer

19. What analytics capabilities does Apigee provide?

Apigee includes a built-in analytics engine that automatically captures data about every API request passing through the gateway. No additional instrumentation is needed in the backend.

Read full answer

20. What is the Apigee Developer Portal and how does it support the developer experience?

The Developer Portal is a self-service website that Apigee generates and hosts for API producers. It is the primary channel through which external developers discover APIs, read documentation, register for API access, and manage their applications....

Read full answer

21. How does JWT validation work in Apigee?

Apigee provides a dedicated JWT policy (separate from OAuthV2) for validating, generating, and decoding JSON Web Tokens. The JWT policy is useful when your authentication scheme uses JWTs issued by an external identity provider such as Google Identity, Auth0, Okta,...

Read full answer

22. What is the MessageLogging policy in Apigee and how is it used for audit and debugging?

The MessageLogging policy sends log messages to an external syslog endpoint or Google Cloud Logging during or after request/response processing. Unlike debug trace (which is ephemeral), MessageLogging persists request/response data to an external system for audit trails, debugging, and compliance

Read full answer

23. How does Apigee handle CORS (Cross-Origin Resource Sharing)?

CORS must be handled by Apigee when web browser clients make API calls cross-origin. Apigee deals with two types of CORS requests: simple requests (handled in the response flow) and preflight OPTIONS requests (which must be responded to immediately, before...

Read full answer

24. What is the Apigee hybrid architecture in more depth, including its components?

Apigee hybrid splits responsibilities between Google-managed and customer-managed infrastructure. Understanding the component split is important for architects and operations engineers.

Read full answer

25. What are Environment Groups and how does routing work in Apigee?

Environment Groups define the hostnames that route incoming API traffic to a set of environments. They are the mechanism by which Apigee maps a public URL hostname to one or more environments for request routing....

Read full answer

26. How does TLS and mutual TLS (mTLS) work in Apigee?

Apigee supports TLS on both the northbound (client-to-Apigee) and southbound (Apigee-to-backend) connections. Mutual TLS adds client certificate verification, enabling strong two-way authentication without API keys or tokens.

Read full answer

27. What is the Access Control policy in Apigee and how do you allowlist/denylist IPs?

The AccessControl policy enforces IP-based allowlisting or denylisting. It inspects the client IP address from the request and either permits or blocks the request based on configured CIDR rules....

Read full answer

28. How do the JSONToXML and XMLToJSON policies work in Apigee?

The JSONToXML and XMLToJSON policies enable Apigee to act as a protocol bridge between clients and backends that use different message formats. This is common in enterprise environments where legacy backends speak SOAP/XML but modern clients expect JSON REST APIs....

Read full answer

29. What is GraphQL proxy support in Apigee?

Apigee supports GraphQL APIs through the GraphQL policy , which validates incoming GraphQL requests against a schema and enforces limits on query depth and field count. This prevents common GraphQL-specific attacks such as deeply nested queries that could overwhelm a...

Read full answer

30. What is Apigee CI/CD and how do you deploy proxies in a pipeline?

Apigee supports full CI/CD integration for proxy deployments using the Apigee Maven Plugin , apigeecli (the official CLI tool), and the Apigee Management API . This allows proxy bundles to be imported, deployed, and tested as part of a standard...

Read full answer

31. What is RBAC (Role-Based Access Control) in Apigee and what are the built-in roles?

Apigee integrates with Google Cloud IAM for access control. Every Apigee operation is controlled by IAM roles assigned to users or service accounts at the Google Cloud project or organisation level....

Read full answer

32. What is Advanced API Security in Apigee and how does it detect bot attacks?

Advanced API Security (formerly known as Apigee Sense) is an AI/ML-powered add-on that analyses API traffic patterns to detect and block bots, credential stuffing attacks, and API abuse -- without any policy configuration from the developer. Advanced API Security capabilities...

Read full answer

33. What is Apigee API Hub and how does it relate to Apigee gateway?

Apigee API Hub is Google Cloud's centralised API registry and governance platform. It is distinct from the Apigee gateway -- while the gateway handles runtime traffic, API Hub provides design-time governance: a searchable catalogue of all APIs across an organisation,...

Read full answer

34. How does load balancing and health checking work on Apigee TargetEndpoints?

Apigee supports client-side load balancing across multiple backend Target Servers directly within the TargetEndpoint configuration. This provides basic resilience and failover without requiring an external load balancer between Apigee and the backend.

Read full answer

35. What is the Apigee Debug / Trace tool and how do you use it for troubleshooting?

The Debug (Trace) tool in the Apigee UI captures a real-time, step-by-step view of a request as it flows through the proxy pipeline. It shows which policies executed, the values of flow variables at each step, and any errors raised....

Read full answer

36. How do you import an OpenAPI specification into Apigee to generate a proxy?

Apigee can auto-generate an API proxy skeleton directly from an OpenAPI Specification (OAS 3.x or Swagger 2.0). This generates the proxy's flow structure, conditional flows for each operation, and basic passthrough routing - saving significant scaffolding time....

Read full answer

37. What is Apigee monetisation and how does it work?

Apigee Monetisation is a feature that enables API producers to charge developers for API consumption. It builds on the API Product model to attach pricing plans, enforce payment-based quotas, and generate revenue reports....

Read full answer

38. What are Apigee flow variables and how do you work with them?

Flow variables are runtime key-value pairs that carry contextual information through the Apigee request/response pipeline. They are the primary means by which policies share data with each other....

Read full answer

39. How does Apigee compare to other API gateways such as Kong, AWS API Gateway, and MuleSoft?

Apigee sits in the enterprise API management tier alongside Kong Enterprise, AWS API Gateway, and MuleSoft Anypoint. Each has distinct strengths that make them better suited for different organisations and architectures....

Read full answer

40. What are common Apigee anti-patterns and best practices for production deployments?

Knowing what NOT to do is as important as knowing the policies. These anti-patterns are commonly asked about in senior Apigee interviews and architecture reviews....

Read full answer

«
»

Comments & Discussions