Govern Third-Party Provider APIs
After connecting to a third-party API gateway provider, you can govern discovered APIs through the same governance workflow used for Anypoint Platform APIs. This enables unified governance across multiple gateway platforms.
Follow these steps to govern APIs from third-party providers:
-
Connect and create a scanner. When the scanner runs, it discovers and catalogs APIs and their read-only policies. See Viewing Service Details in the Portfolio
-
Go to Portfolio > APIs and verify that discovered APIs appear, each labeled with its provider (for example, AWS). APIs are automatically added to the portfolio as they are discovered.
-
Create control rules to track the policies that you want to enforce across providers. You create these rules using developer skills rather than the UI. For guidance on creating policy subcategory rules, review the Author a Governance Ruleset skill in the MuleSoft Developer Hub. For example, use a prompt such as
create a rule to track that each API has a JWT policy applied to it. -
Create a governance strategy and select the control rules or automated policies to apply. The strategy evaluates conformance for all in-scope APIs, including those discovered from third-party providers.
-
Track conformance status for provider-hosted APIs through the governance strategy dashboard. Use the Any provider filter in the Governed Services tab of your governance strategy to focus on a subset of your cross-gateway environment.



