I have been around API gateways long enough to have watched them get sold as the answer to every problem in the space, over and over, for more than a decade. And I have come to a somewhat unpopular conclusion: the gateway is a tired concept, not because the technology is bad — it is often fine — but because the gateway has almost never really been about the technology. The gateway is about power. It is the place an organization goes to centralize, to aggregate, to put a single chokepoint between everyone and everything, and the appeal of that chokepoint has always been at least as much political as it has been technical. Once you see the gateway as a power move wearing an architecture diagram, a lot of the tired debates about it suddenly make sense.
Think about what the gateway actually promises when a vendor or an internal platform team pitches it. One place all traffic flows through. One place all policy is enforced. One place all visibility accrues. One place all control lives. Stated as architecture, that sounds like tidiness. Stated honestly, that is centralization of power, and the team that runs the gateway becomes the team that everyone else has to go through, negotiate with, and wait on. I am not saying that is always malicious — sometimes centralizing control is genuinely the right call for a real reason. I am saying that the gateway’s core value proposition is centralization, and centralization is a question about who holds power, not a question about how bytes move. When adopting a gateway feels like it is mostly about tidiness, it is worth asking who is quietly accumulating the control, because someone always is.
This is exactly why I keep landing on federation as the healthier posture, the same way I have argued it for MCP and for governance, and why I keep insisting there is no platform for API governance that saves you — because “the platform” and “the gateway” are usually the same centralizing instinct with different labels. The centralized gateway becomes the bottleneck it promised to eliminate. It becomes the thing every team is blocked on, the single point of failure, the internal monopoly that no longer has to be responsive because it has no competition. Federation is the opposite bet: keep control close to the teams who own the capabilities, coordinate through discovery and shared rules rather than through a chokepoint, and refuse to let one team become the toll booth that everyone else pays. Federation distributes the power the gateway was designed to concentrate, and distributed power is more robust, more responsive, and frankly more honest about how large organizations actually work.
I want to be careful, because there are real functions people reach for a gateway to get, and I am not pretending those needs are fake. You do need auth, rate limiting, observability, and policy enforcement somewhere. The mistake is assuming those functions require a single central gateway that everything routes through, when most of them can live at the edges, close to the services, coordinated by shared standards rather than concentrated in one box. The authorization can be enforced by properly scoped tokens at each service. The rules can be a federated registry every team pulls from, not a central engine every request passes through. The visibility can be aggregated from distributed telemetry without funneling every byte through one chokepoint first. The functions are real. The requirement that they all live in one central, power-concentrating gateway is the part that was always more about control than about need.
And this is why the gateway feels tired to me in the agent era specifically. We are moving into a world of federated capabilities, distributed MCP servers, and agents composing across many providers, and the whole shape of that world is at odds with the one-chokepoint model. Trying to force the agentic, federated future through a centralized gateway is trying to fight the grain of where everything is actually going. The organizations that thrive are not going to be the ones with the biggest, most powerful central gateway. They are going to be the ones that got comfortable with federated control — that let power stay distributed, coordinated by shared standards and discovery instead of concentrated in a box that everyone resents and no one can route around.
So when someone pitches you the gateway as the clean technical answer, my advice is to translate the pitch. Ask what is really being centralized, and who ends up holding the power once it is. Sometimes the honest answer is that centralizing genuinely serves the mission, and then fine, do it deliberately, with your eyes open. But far more often the gateway is a power accumulation dressed as an architecture decision, and the tired old chokepoint is being sold to you as modernization. Embrace the federated posture instead. Keep control close to the people doing the work, coordinate through standards, and stop treating the single central gateway as the sophisticated answer. It was never really about the technology. It was always about who gets to be the toll booth, and in a federated, agentic world, the answer should increasingly be: no one.
