@malinthaprasan malinthaprasan released this Feb 4, 2017 · 695 commits to master since this release

Assets 2

The WSO2 API Manager 2.1.0 Released!

The WSO2 API Manager team is pleased to announce the release of version 2.1.0 of the Open Source API Manager.

WSO2 API Manager is a platform for creating, managing, consuming and monitoring APIs. It employs proven SOA best practices to solve a wide range of API management challenges such as API provisioning, API governance, API security and API monitoring. It combines some of the most powerful and mature components of the WSO2's state-of-the-art Carbon platform to deliver a smooth and end-to-end API management experience while catering to both API publisher and API consumer requirements.

WSO2 API Manager is comprised of several modules.

  • API Provider: Define new APIs and manage them
  • API Store: Browse published APIs and subscribe to them
  • API Gateway: The underlying API runtime based on WSO2 ESB
  • API Key Manager: Performs Key Generation and Key Validation functionalities
  • API Traffic Manager: Performs Rate Limiting of API Requests

WSO2 API Manager is developed on top of the revolutionary WSO2 Carbon platform (Middleware a' la carte), an OSGi based framework that provides seamless modularity to your SOA via componentization. This release also contains many new features and a range of optional components (add-ons) that can be installed to customize the behavior of the API Manager. Further, any existing features of the product which are not required in your environment can be easily removed using the underlying provisioning framework of Carbon. In brief, WSO2 API Manager can be fully customized and tailored to meet your exact API management needs.

For more information on WSO2 API Manager please visit http://wso2.com/products/api-manager. Also take a look at the online product documentation.

How to Run

  1. Extract the downloaded zip
  2. Go to the bin directory in the extracted folder
  3. Run the wso2server.sh or wso2server.bat as appropriate
  4. Launch a web browser and navigate to https://localhost:9443/publisher to access the API provider webapp
  5. Navigate to https://localhost:9443/store to access the API store
  6. Navigate to https://localhost:9443/admin to access Admin Portal
  7. Use "admin", "admin" as the username and password to login as an admin

New Features in 2.1.0

Improvements in 2.1.0

  • [APIMANAGER-4527] - Upgrade Swagger Editor and UI
  • [APIMANAGER-4569] - Support updating an API with API import tool
  • [APIMANAGER-4610] - Support SSO without enabling single logout
  • [APIMANAGER-4863] - No message on workflow enabled App creation.
  • [APIMANAGER-4985] - No option to select scope for the first time token generation in api store
  • [APIMANAGER-5100] - Display Error message in UI when backend fails due to errors in the inline script in prototyped APIs
  • [APIMANAGER-5324] - Make the description field support rich text
  • [APIMANAGER-5336] - Change severity level from Error to Warn when logging access token related user errors
  • [APIMANAGER-5339] - Support SSO SAML Request Signing and Sending ACS in Publisher
  • [APIMANAGER-5351] - Update Swagger SDK Generation library
  • [APIMANAGER-5401] - Allow to define conditional groups with query parameter values as null
  • [APIMANAGER-5406] - Use different keystore for Data Bridge Configuration
  • [APIMANAGER-5443] - Provide "Get API" in store RESTapi's
  • [APIMANAGER-5446] - Need to add a method to check user existance within roles.
  • [APIMANAGER-5454] - Manage Alert Types UI is not intuitive to the user on entering email addresses.
  • [APIMANAGER-5455] - Improve "View In Store" link to open in a new tab
  • [APIMANAGER-5459] - Allowing a comma separated email list for subscribing to Alert Types.
  • [APIMANAGER-5496] - Advance throttling issue with adding query parameters
  • [APIMANAGER-5505] - Unlimited subscription tier returned from APIUtil.getTierFromCache() method doesn?t have a tier plan
  • [APIMANAGER-5517] - Provide an option to set JWT exp time when Token cache is enabled.
  • [APIMANAGER-5523] - Increasing size of VALUE column of AM_BLOCK_CONDITIONS table
  • [APIMANAGER-5524] - Remove ERROR stack trace for API authentication failures
  • [APIMANAGER-5537] - Save document contents in the local storage

Resolved Issues

Key Features of WSO2 API Manager

Following is a categorization of the core features supported by WSO2 API Manager based on the target user group.

  • Create a Store of all Available APIs:
    • Graphical experience similar to Android Marketplace or Apple App Store.
    • Browse APIs by provider, tags or name.
    • Self-registration to developer community to subscribe to APIs.
    • Subscribe to APIs and manage subscriptions on per-application basis.
    • Subscriptions can be at different service tiers based on expected usage levels.
    • Role based access to API Store; manage public and private APIs.
    • Manage subscriptions at a per-developer level.
    • Browse API documentation, download helpers for easy consumption.
    • Comment on and rate APIs.
    • Forum for discussing API usage issues (Available soon in future version).
    • Try APIs directly on the store front.
    • Internationalization (i18n) support.
  • Publishing and Governing API Use:
    • Publish APIs to external consumers and partners, as well as internal users.
    • Supports publishing multiple protocols including SOAP, REST, JSON and XML style services as APIs.
    • Manage API versions and deployment status by version.
    • Govern the API lifecycle (publish, deprecate, retire).
    • Attach documentation (files, external URLs) to APIs.
    • Apply Security policies to APIs (authentication, authorization).
    • Associate API available to system defined service tiers.
    • Provision and Manage API keys.
    • Track consumers per API.
    • One-click deployment to API Gateway for immediate publishing.
  • Route API Traffic:
    • Supports API authentication with OAuth2.
    • Extremely high performance pass-through message routing with sub-millisecond latency.
    • Enforce rate limiting and throttling policies for APIs by consumer.
    • Horizontally scalable with easy deployment into cluster using proven routing infrastructure.
    • Scales to millions of developers/users.
    • Capture all statistics and push to pluggable analytics system.
    • Configure API routing policies with capabilities of WSO2 Enterprise Service Bus.
    • Powered by WSO2 Enterprise Service Bus.
  • Manage Developer Community:
    • Self-sign up for API consumption.
    • Manage user account including password reset.
    • Developer interaction with APIs via comments and ratings.
    • Support for developer communication via forums (Available soon in future version).
    • Powered by WSO2 Identity Server.
  • Govern Complete API Lifecycle:
    • Manage API lifecycle from cradle to grave: create, publish, block, deprecate and retire.
    • Publish both production and sandbox keys for APIs to enable easy developer testing.
    • Publish APIs to partner networks such as ProgrammableWeb (Available soon in future version).
    • Powered by WSO2 Governance Registry.
  • Monitor API Usage and Performance:
    • All API usage published to pluggable analytics framework.
    • Out of the box support for WSO2 Business Activity Monitor and Google Analytics.
    • View metrics by user, API and more.
    • Customized reporting via plugging reporting engines.
    • Monitor SLA compliance.
    • Powered by WSO2 Business Activity Monitor.
  • Pluggable, Extensible and Themeable:
    • All components are highly customizable thru styling, theming and open source code.
    • Storefront implemented with Jaggery (jaggeryjs.org) for easy customization.
    • Pluggable to third party analytics systems and billing systems (Available soon in future version).
    • Pluggable to existing user stores including via JDBC and LDAP.
    • Components usable separately - storefront can be used to front APIs gatewayed via third party gateways such as Intel Expressway Service Gateway.
    • Support for Single Sign On (SSO) using SAML 2.0 for easy integration with existing web apps
  • Easily Deployable in Enterprise Setting:
    • Role based access control for managing users and their authorization levels.
    • Store front can be deployed in DMZ for external access with Publisher inside the firewall for private control.
    • Different user stores for developer focused store-front and internal operations in publisher.
    • Integrates with enterprise identity systems including LDAP and Microsoft Active Directory.
    • Gateway can be deployed in DMZ with controlled access to WSO2 Identity Server (for authentication/authorization) and governance database behind firewall.
  • Support for creating multi-tenanted APIs
    • Run a single instance and provide API Management to multiple customers
    • Share APIs between different departments in a large enterprise
  • Publishing and Governing API Use
    • Document an API using Swagger
    • Restrict API Access tokens to domains/IPs
    • Ability to block a subscription and restricting a complete application
    • Ability to revoke access tokens
    • Separate validity period configuration for Application Access Token
    • OAuth2 Authorization Code Grant Type Support
    • Configuring execution point of mediation extensions
  • Monitor API Usage and Performance
    • Improved dashboard for monitoring usage statistics (Filtering data for a date range, More visually appealing widgets)

Known Issues

All the open issues pertaining to WSO2 API Manager are reported at the following location:

How You Can Contribute

Mailing Lists

Join our mailing list and correspond with the developers directly.

Reporting Issues

We encourage you to report issues, documentation faults and feature requests regarding WSO2 API Manager through the public API Manager JIRA. You can use the Carbon JIRA to report any issues related to the Carbon base framework or associated Carbon components.


We are committed to ensuring that your enterprise middleware deployment is completely supported from evaluation to production. Our unique approach ensures that all support leverages our open development methodology and is provided by the very same engineers who build the technology.

For more details and to take advantage of this unique opportunity please visit http://wso2.com/support.

To learn more about WSO2 API Manager and WSO2 support offerings please visit http://wso2.com/products/api-manager.

-- The WSO2 API Manager Team --