# Replacing Mashery With Azure API Management

> Moving from on-premises TIBCO Mashery to Azure API Management trades server upkeep for a managed gateway. What APIM does well, and its limits.

Canonical: https://mikereams.com/writing/replacing-mashery-with-azure-api-management

Published: May 3, 2023  
Author: Mike Reams (https://mikereams.com/about)  
Topics: [Cloud Computing](https://mikereams.com/writing/topics/cloud), [API](https://mikereams.com/writing/topics/api), [Web Development](https://mikereams.com/writing/topics/web-development)  
Tags: API, APIM, Azure  
Project: [Replaced Mashery With Azure API Management](https://mikereams.com/work/replaced-mashery-with-azure-api-management)

![Replacing Mashery With Azure API Management](https://mikereams.com/writing/dd0206fde334022b1d937531be53c42e67e392d9-600x315.webp)

*Written in 2023 and updated in 2026. Two things have moved since: Boomi bought Mashery from TIBCO in May 2024 (it is now Boomi Cloud API Management), and Azure API Management added its v2 tiers.*

## The decision

The client ran Mashery on-premises and had to move off it. The vendor's path forward was TIBCO Cloud API Management, its hosted version. I recommended Azure API Management (APIM) instead, on cost and on how well it met the client's requirements.

## How the two compare

Both products sit in the same category — full API lifecycle management plus a gateway — so the choice comes down to fit rather than a feature checklist. Mashery's strengths were around its developer community: an API explorer, matching developers with API projects, and a public API status monitor.

APIM is Azure's managed API platform. It fronts services wherever they run — on-premises, in containers or in any cloud — and has three parts:

- **Management plane (Azure portal):** define or import API specs, package APIs into products, set policies such as quotas and transformations, manage users, and read analytics.
- **Gateway:** routes calls to backends; checks API keys, JWTs and certificates; enforces quotas and rate limits; transforms requests and responses without code changes; caches responses; and logs call metadata.
- **Developer portal:** documentation, an interactive console, self-service sign-up and subscription keys, and per-developer usage analytics.

## What APIM does well

- **Policies.** Most of the power is here: convert XML to JSON and back, rewrite headers, restrict parameters, or route to different backends based on the message body — all without touching backend code.
- **API structure.** Products, APIs and versions are well thought out. New APIs stand up quickly, versioning is built in, and the analytics help find bottlenecks and unusual usage.
- **Developer portal.** It works out of the box: developers register, request and manage their own subscriptions, and the sign-up emails are customizable. Deeper customization takes real effort.

## What to plan around

- **Access is per API, not per operation.** A subscription can be scoped to a product, a single API, or all APIs — never one operation. If a GET and a POST on the same API need different access, split them into separate APIs or enforce the difference in policy, for example by checking JWT claims per operation. Still true in 2026.
- **Cost at scale.** APIM is cheap to start, but the jumps between tiers are steep; moving from classic Standard to Premium multiplied the cost. Set budget alerts from day one, and price the newer v2 tiers, which change the math.

## Alternatives worth a look

- **Apigee** (Google Cloud): a full lifecycle API platform with strong analytics and security.
- **Kong:** an open-source gateway for layer 4 and 7 traffic, extended through plugins, with an enterprise edition.
- **Ocelot:** a lightweight open-source .NET gateway for microservice back ends. It works with anything that speaks HTTP.
- **Boomi Cloud API Management:** Mashery itself, under new ownership. If you're still on it, re-evaluate.
