This section compares API Security platform from ten
API gateway providers. Industry API security platforms are
provided by API gateway which is part of API management
[30]. Error! Reference source not found. compares the
main API security features and their pricing models provided
by ten API gateway providers.
In Error! Reference source not found., all API gateway
providers support two-factor API security, most of them also
support three-factor API security which is enterprise-strength
security. Moreover, the XACML [36] is the short name of
"eXtensible Access Control Markup Language", which is an
OASIS language standard implemented in XML for defining
declarative access control policy and a process model
describing how to evaluate access requests based on the rules
defined in policies. The standard promotes common
terminology and interoperability between access control
implementations by different vendors. Recently, REST
profile and JSON profile described by XACML are
developed, which is very helpful at describing access control
policies of REST/JSON API security.