API Management & Security

CloudThat · Account 915062473651 · ap-south-1 (Mumbai) · LIVE
checking AWS…

Publishing & Monetization

Secured REST API, commercial tiers with per-customer limits, and metered usage turned into a priced invoice.

Demo
📈 Live Metrics & Logs
Published API — access control
API Gateway apimgmtsec-api open ↗ Backend apimgmtsec-backend-fn
ⓘ
An API key identifies the customer; API Gateway checks it before the backend. No key → 403. Valid key → 200.
request · GET /prod/data
// Click to call the live API…
Policy-based throttling
apimgmtsec-free-plan · apimgmtsec-premium-plan open ↗

Free tier

trial consumers
  • 5 req/sec
  • 100 req/day
  • exceed → 429

Premium tier

paying customers
  • 50 req/sec
  • 10,000 req/day
  • absorbs → 200
ⓘ
A usage plan ties a key to a rate limit (req/sec) and quota (req/day). Exceed → 429 Too Many Requests.
Runtime monetization — invoice
apimgmtsec-billing-fn open ↗
ⓘ
Metering counts billable calls. First 100 free, then ₹0.50/call. The billing Lambda returns a customer invoice.
lambda · apimgmtsec-billing-fn
// Invoice output…
Live API Gateway metrics (CloudWatch)
Real CloudWatch data for apimgmtsec-api, timestamps in IST.

AI/ML-Enabled Security

AWS WAF with a rate-based rule, AWS managed rules, and the AI/ML layer — Bot Control with machine learning.

Demo
📈 Live WAF Metrics
📜 Live WAF Logs
Bot Control (AI/ML) — bot vs human
apimgmtsec-waf-acl open ↗
ⓘ
Bot Control uses ML to tell bots from browsers via the User-Agent & behaviour. Bot → 403 even with a key; browser → 200.
waf · Bot Control (ML)
// Run both to see 403 → 200…
WAF flood protection
aws-waf-logs-apimgmtsec open ↗
ⓘ
The rate-based rule blocks any IP over 100 req / 5 min → 403. Security layer (403), vs usage-plan throttle (429).
Live WAF metrics
Blocked vs Allowed requests on apimgmtsec-waf-acl, IST.
Live WAF log events
Real records from aws-waf-logs-apimgmtsec, newest first (IST).
Click Refresh to load live WAF logs…

Centralized Security Operations

Threat detection, vulnerability management, compliance, incident response and posture — one pane, automated response.

Operations services
Automated incident response — flow
GuardDuty finding → apimgmtsec-guardduty-response → apimgmtsec-secops-alerts → Email → security team

Deployed Resources

Live resources backing this platform. Click any card to open its AWS console.

LIVE ACTIVITY LOG · real AWS calls (IST)
// every button triggers a real AWS call — it is logged here with an IST timestamp, the endpoint, and the live result.