No more typing reviews! Try our Samantha, our new voice AI agent.
it_user17886 - PeerSpot reviewer
Manager, IT Security & IT Office of the CIO at a engineering company with 1,001-5,000 employees
Real User
Dec 6, 2015
It provides a simple endpoint for applications to call and for customers to call, so it reduces a lot of the complication of API services. But, in order to get OAUTH, we had to buy the MAG product.
Pros and Cons
  • "It provides a simple endpoint for applications to call and for customers to call, so it reduces a lot of the complications of API services."
  • "One item that we’ve had discussions – and they’ve fixed some of it – you had to buy extra products, specifically the CA Mobile API Gateway, to get certain types of token support even though you didn’t need that product for anything else."

What is most valuable?

It’s a way for us to secure our externally-sourced API calls that come into the organization. The two things are 1) protocol translation where we can let a REST call come in and get converted to some legacy protocol, and 2) security token translation support because we need to convert a standard industry token to something an internal system will understand.

How has it helped my organization?

It provides a simple endpoint for applications to call and for customers to call, so it reduces a lot of the complications of API services. Most of these APIs the user never sees, like a mobile app that does something below the water line, or another partner is calling our application – such as an order purchasing system at another customer, whose app calls our app. It eliminates the need to deal with users in a lot of cases, so if users don’t have to deal with the system it’s convenient for them. It helps us automate as well.

What needs improvement?

One item that we’ve had discussions – and they’ve fixed some of it – you had to buy extra products, specifically the CA Mobile API Gateway, to get certain types of token support even though you didn’t need that product for anything else.

So, foundational token support should be part of the base product and you shouldn’t have to buy the mobile feature to get those features. For example, in order to get OAUTH we had to buy the MAG product, but I think they’ve fixed that now. But we’re not sure they’ve fixed everything.

What do I think about the stability of the solution?

I think it’s a solid product. We’ve had some issues with the proprietary hardware that we’re running it on, but we’re getting rid of that and going to VMs, so the issue will probably go away. At one point in order to do certain types of upgrades to not only do it through a web interface, but we had to get deep into the system – multiple things we had to do in order to upgrade so it wasn’t as seamless as we had hoped.

Buyer's Guide
Layer7 API Management
June 2026
Learn what your peers think about Layer7 API Management. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.

What do I think about the scalability of the solution?

It's not been an issue.

How are customer service and support?

I think they’ve got really sharp people. When there’s a serious problem, they’re quick to triage and get an authoritative person to respond quickly.

How was the initial setup?

Pretty straightforward; the biggest issue was the initial hardware that we purchased. CA sold the product on a certain kind of UNIX box, but those boxes weren’t appropriate for the solution – it was well before CA took over.

What's my experience with pricing, setup cost, and licensing?

We knew we needed some kind of API security gateway to basically sit on the edge of our network and police what could get in, and do other things like translate API calls. We wanted a simple API call to be translatable to multiple backend system. Before we were just using traditional web proxy servers, not really API focused.

Which other solutions did I evaluate?

We knew we needed some kind of API security gateway to basically sit on the edge of our network and police what could get in, and do other things like translate API calls. We wanted a simple API call to be translatable to multiple backend system. Before we were just using traditional web proxy servers, not really API focused.

We used IBM DataPower at the time. Both HP and Oracle were OEMing the Layer7 product at the time, and the fact that HP was OEMing it was certainly a factor. We were looking for someone that’s innovative; someone we can trust to be a long-term partner.

What other advice do I have?

It fits in well with our other security middleware. We’re also a SiteMinder customer so there are some synergies there. When CA bought Layer 7, that was a good thing for us, and we sort of fell into those kinds of synergies.

They should make sure they find a product that supports industry security standards, and has good management capabilities, good manageability.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user345549 - PeerSpot reviewer
IT Mobile/Web Solution Delivery Manager at a insurance company with 5,001-10,000 employees
Real User
Dec 6, 2015
It allows you to much more rapidly expose enterprise services to front-end applications, but the user experience for developers to discover and develop APIs needs work.
Pros and Cons
  • "It allows you to much more rapidly expose enterprise services to front-end applications, such as mobile and web."
  • "The products developer portals can be better."

What is most valuable?

I'd say the API gateway that routes traffic in REST-to-SOAP conversions is a feature we find most valuable. SOAP is a type of web service, and REST is another.

How has it helped my organization?

It allows you to much more rapidly expose enterprise services to front-end applications, such as mobile and web.

What needs improvement?

The products developer portals can be better. It needs a better look and feel.

Also, the user experience for developers to discover and develop APIs needs work.

For how long have I used the solution?

We've been using it for two years.

What do I think about the stability of the solution?

It's very good.

What do I think about the scalability of the solution?

We've just started so there's not a lot of traffic yet.

How are customer service and technical support?

They've been responsive, but they're pricey.

Which solution did I use previously and why did I switch?

This is the first API gateway product we’ve used, and we looked for a vendor who has a reputation for establishing long-term partnerships.

How was the initial setup?

Initial setup was pretty straightforward.

Which other solutions did I evaluate?

We also looked at Axway, IBM, and Mashery. We went through a long evaluation and CA's number one strength was the built-in security management features.

What other advice do I have?

As part of your evaluation, make sure that the companies can set up a proof of concept to check real situations.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Layer7 API Management Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Product Categories
API Management
Buyer's Guide
Download our free Layer7 API Management Report and get advice and tips from experienced pros sharing their opinions.