Skip to content
NewThreat Protection & Threat Studio for Otoroshi

Your APIs.Your AI.
Your security.
One platform.

Managed Otoroshi clusters, serverless API management, an AI gateway for every LLM and threat protection. Built by the team that created Otoroshi.

  • Managed · Serverless · Open source
  • No lock-in, it's plain Otoroshi
  • Made in France
Web & mobile appsREST · GraphQL · WSPartnersAPI keys · OAuth2AI agentsMCP · tool callsBots & attackersSQLi · scrapersCloud APIM gatewayOtoroshi inside · managed, serverless or self-hostedEVERY CALL · EVERY POLICYAuthenticationRate limitsWAF · CRSGuardrailsAnalyticsblockedYour APIsmicroservices · legacyLLM providers50+, local models tooMCP serverstools for your agentsSaaS & eventsanywhere, any cloud
OtoroshiPowered byOtoroshiOpen source · Apache 2.0 · #OSSbyMAIF
Otoroshi in production, created at MAIF
Since 2017
for managed clusters, worldwide
7 regions
LLM providers behind one API
50+
of the OWASP CRS v4 regression tests passed
100%

The platform

One platform. Your way.

Run it on your own Otoroshi — managed by us or self-hosted — or go serverless and run nothing at all. Same building blocks, same people behind them.

Otoroshi · Managed

Your Otoroshi cluster.
Ready in seconds.

Fully managed Otoroshi clusters, perfectly configured and optimized. Every Otoroshi feature, every extension, none of the operations: we handle setup, upgrades, backups, scaling and monitoring.

  • Always up to date
  • Backed up, encrypted at rest
  • Clustered & auto-scaled
  • Monitored 24/7
  • No lock-in: it's plain Otoroshi
  • 7 regions worldwide

acme-prod

Otoroshi cluster · Paris

Ready

3

nodes

99.9%

uptime

auto

scaling

Requests / slast 24h

Deploy in

ParisRoubaixGravelinesWarsawMontrealSingaporeSydney

Otoroshi · Serverless

git push.
Your API is live.

Describe your API with OpenAPI, add routes, JavaScript plugins and portal pages in a git repository. Every branch is an environment with its own domain and API keys. Deploy, preview, roll back: it's just git.

  • One branch per environment
  • API keys, quotas, dev portal
  • OpenAPI first
  • Zero server to manage
~/my-api

$ git commit -m "add orders api"

$ git push origin main

Deploying my-api@main…

✓ deployed to prod

→ live: GET /orders 200 · 41ms

my-api/

  • openapi.jsonyour routes
  • entities/routes & backends
  • modules/JavaScript plugins
  • docs/portal pages
  • dev-portal.jsonportal & plans

One branch per environment

devsandbox
main prod

Open source · Otoroshi LLM extension

Every model.
One API.

Connect, secure and govern all your LLMs behind a single OpenAI-compatible API. Route by cost or performance, cache semantically, enforce guardrails and budgets, and know the cost and CO₂ of every call. AI Studio gives your teams a console for it all.

  • OpenAI-compatible API
  • Guardrails
  • Budgets & quotas
  • Semantic cache
  • Cost & CO₂ per call
  • MCP servers & agents
ai-studio · Overview
AI Studio overview: quickstart, spend, requests and tokens of the week
  • OpenAI
  • Anthropic
  • Mistral AI
  • Gemini
  • Ollama
  • Azure AI
  • Groq
  • DeepSeek
  • Scaleway
  • OVHcloud
  • Cohere
  • Hugging Face
  • Cloudflare AI
  • ElevenLabs
  • + many more, local models too

Open source · Threat Protection

Every threat.
One score.

A JVM-native WAF running the OWASP Core Rule Set, IP reputation feeds, CrowdSec, bot and AI-crawler control, honeypots: every detector adds up into one threat score, and the response is graded — from log to cluster-wide ban. Dry run first, then arm.

  • WAF · OWASP Core Rule Set
  • IP reputation & CrowdSec
  • Bots & AI crawlers
  • Cluster-wide bans

POST /login?user=admin'--

from 203.0.113.42 · hosting network

suspicious
  • IP reputation+40
  • Hosting network (ASN)+15
  • WAF · OWASP CRS+45
  • Bots & AI crawlers—
  • CrowdSec—
  • Honeypots—

100

threat score

logtarpitchallengedenyban Banned on every node

Our story

Founded by the creator of Otoroshi.

Open source at heart: Otoroshi and our extensions are Apache 2.0. Cloud APIM is by far the biggest contributor to Otoroshi, and the people who support you are the people who write the code.

Explore our open-source projects
  1. 2017

    Otoroshi is born

    Created by Mathieu Ancelin at MAIF, open source from day one.

  2. 2021

    Cloud APIM is founded

    In Poitiers, France, by the people behind Otoroshi.

  3. 2023

    Otoroshi, managed

    Dedicated clusters, perfectly configured, ready in seconds.

  4. 2024

    Serverless & AI

    GitOps APIs, the LLM extension, AI Gateway and Authify.

  5. 2026

    Security & studios

    Threat Protection, AI Studio and Threat Studio.

Support · Training · Consulting

Backed by the people who wrote the code.

🇫🇷 Made in France · English & French speaking

From the blog

News, deep dives and tutorials.

All articles

FAQ

Frequently asked questions

Still have a question? Talk to our team.

What is Otoroshi?

Otoroshi is a battle-tested, open-source (Apache 2.0) HTTP reverse proxy with API management features, from the #OSSbyMAIF ecosystem. It was created by one of the founders of Cloud APIM, and Cloud APIM is by far its biggest contributor.

Managed or serverless: which one should I choose?

Otoroshi Managed gives you a dedicated, fully configurable Otoroshi cluster with full admin access: ideal for complex or regulated environments. Serverless is GitOps driven, there is nothing to run and you pay as you grow: ideal for dev-first teams. Compare both offers.

Am I locked in?

No. A managed instance is plain Otoroshi with every feature available, and you can export your data at any time. Our extensions are open source, so you can run the very same stack on your own infrastructure.

Where can I deploy my Otoroshi instances?

Cloud APIM offers Otoroshi deployments in 7 regions all over the globe: Paris, Roubaix, Gravelines, Warsaw, Montreal, Singapore, Sydney.

Which AI providers can I use?

The Otoroshi LLM extension supports 50+ providers through one OpenAI-compatible API, including OpenAI, Anthropic, Mistral, Gemini, Azure OpenAI, Groq, DeepSeek, Scaleway, OVHcloud AI Endpoints, Cohere, Hugging Face, and local models with Ollama.

Can you support our own, on-premise Otoroshi?

Yes. We offer professional support (up to 24/7 with a 30-minute response time), training and consulting for Otoroshi clusters running anywhere, by the people that created Otoroshi. See support plans.

Ready to build?Start in minutes.

Spin up a managed Otoroshi cluster or a serverless project for free, or ask us for a live demo of the whole platform.