ZuploZuplo
LoginStart for Free
  • Documentation
  • API Reference
Introduction
Getting Started
    Develop using the Portal
      1 - Setup Your Gateway2 - Rate Limiting3 - API Key Auth4 - Deploy5 - Dynamic Rate LimitingMCP - Quick start
    Develop Locally
      1 - Setup Your Gateway2 - Rate Limiting3 - API Key Auth
Concepts
Development
Policies
    Policy Catalog
    Authentication
    Authorization
    Security & Validation
    Metrics, Billing & Quotas
    Testing
    Request Modification
    Response Modification
    Upstream Authentication
    Archival
    GraphQL
    Other
    Guides
Handlers
API Keys
MCP Server
MCP Gateway
AI Gateway
Developer Portal
Monetization
Deploying & Source Control
Observability
Networking & Infrastructure
Account Management
Programming API
Build with AI
Zuplo CLI
Migration Guides
Platform LimitsSecuritySupportTrust & ComplianceChangelog
powered by Zudoku
Policies

Policy Catalog

Zuplo includes policies for any solution you need for securing and sharing your API. See the policy introduction to learn about using policies.

In addition to the built-in policies, Zuplo is fully programmable so developers can simply write code to customize any aspect of Zuplo.

Plan:

Inbound Policies

A/B Test Inbound
Access Control List
Add or Set Query Parameters
Add or Set Request Headers
Akamai Firewall for AI
Amberflo Metering / Billing
API Key Authentication
Archive Request to AWS S3
Archive Request to Azure Storage
Archive Request to GCP Storage
Add-On
Audit Logs
Auth0 JWT Auth
Add-On
AuthZEN Authorization
AWS Cognito JWT Auth
Add-On
Axiomatics Authorization
Basic Auth
Add-On
Bot Detection
Brown Out
Caching
Change Method
Clear Request Headers
Clerk JWT Auth
Add-On
Complex Rate Limiting
Composite Inbound (Group Policies)
Curity Phantom Token Auth
Custom Code Inbound
Firebase JWT Auth
Form Data to JSON
Geo-location filtering
GraphQL Complexity Limit
GraphQL Disable Introspection
HMAC Auth
IP Restriction
JWT Auth
JWT Scope Validation
Add-On
LDAP Auth
Mock API Response
Moesif Analytics & Billing
Monetization
Add-On
mTLS Auth
Add-On
Okta FGA Authorization
Okta JWT Auth
Add-On
OpenFGA Authorization
OpenMeter
PropelAuth JWT Auth
Query Parameter to Header
Quota
Rate Limiting
RBAC Authorization
Readme Metrics
Remove Query Parameters
Remove Request Headers
Request Size Limit
Request Validation
Require Origin
Set Body
Set Upstream API Key
Sleep / Delay
Stripe Webhook Auth
Supabase JWT Auth
Transform Request Body
Add-On
Upstream Azure AD Service Auth
Upstream Firebase Admin Auth
Upstream Firebase User Auth
Add-On
Upstream GCP Federated Auth
Add-On
Upstream GCP Self-Signed JWT
Add-On
Upstream GCP Service Auth
Add-On
Upstream Zuplo JWT
Web Bot Auth

Outbound Policies

A/B Test Outbound
Akamai Firewall for AI
Archive Response to AWS S3
Archive Response to Azure Storage
Clear Response Headers
Composite Outbound (Group Policies)
Custom Code Outbound
GraphQL Introspection Filter
HTTP Deprecation
Remove Response Headers
Replace String in Response Body
Secret Masking
Set Headers
Set Status Code
Transform Response Body
XML to JSON
Edit this page
Last modified on October 3, 2025
GitHub Action AutomationAPI Key Authentication Policy