ZuploZuplo
LoginStart for Free
  • Documentation
  • API Reference
Getting Started
    Develop in the portal
      1 - Setup Your Gateway2 - Rate Limiting3 - API Key Auth4 - Deploy5 - Dynamic Rate LimitingDynamic MCP Server - Quickstart
    Develop locally with the CLI
      1 - Setup Your Gateway2 - Rate Limiting3 - API Key Auth4 - Deploy5 - Dynamic Rate LimitingDynamic MCP Server - Quickstart
Concepts
API Management
    Overview
    API Keys
    Rate Limiting
    Caching
    GraphQL
    Monetization
    Policies
      Overview
      Authentication
      Authorization
      Security & Validation
      Metrics, Billing & Quotas
      Testing
      Request Modification
      Response Modification
      Upstream Authentication
      GraphQL
      Caching
      Other
      Guides
    Handlers
AI Gateway
MCP Gateway
MCP Server
Developer Portal
Development
Deploying & Source Control
Analytics
Observability
Networking & Infrastructure
Account Management
Programming API
Build with AI
Zuplo CLI
Migration Guides
Platform LimitsVersion Support PolicySecuritySupportTrust & ComplianceChangelog
powered by Zudoku
Policies

Policies overview

Zuplo includes policies for any solution you need for securing and sharing your API. See Policy Fundamentals to learn how to use policies.

In addition to the built-in policies, Zuplo is fully programmable so developers can simply write code to customize any aspect of Zuplo.

Plan:

Inbound Policies

Add or Set Query Parameters
Add or Set Request Headers
AI Gateway Authentication
AI Gateway Configuration Executor
AI Gateway Configuration Loader
AI Gateway Fallback Model
AI Gateway Metering
AI Gateway Model Filtering
Add-On
AI Gateway Semantic Cache
Akamai AI Firewall
Akamai Firewall for AI
Amberflo Metering / Billing
API Key Authentication
Add-On
Audit Logs
Auth0 JWT Auth
Add-On
AuthZEN Authorization
AWS Cognito JWT Auth
Add-On
Axiomatics Authorization
Basic Auth
Add-On
Bot Detection
Brown Out
Caching
Change Method
Clear Request Headers
Clerk JWT Auth
Comet Opik Tracing
Add-On
Complex Rate Limiting
Composite Inbound (Group Policies)
Curity Phantom Token Auth
Custom Code Inbound
Data Loss Prevention
Data Loss Prevention (DLP)
Firebase JWT Auth
Form Data to JSON
Galileo Tracing
Geo-location filtering
GraphQL Cache
GraphQL Complexity Limit
GraphQL Disable Introspection
IP Address Restriction
JWT Auth
JWT Scope Validation
Add-On
LDAP Auth
MCP Amazon Cognito OAuth
MCP Auth0 OAuth
MCP Capability Filter
MCP Clerk OAuth
MCP Google OAuth
MCP Keycloak OAuth
MCP Logto OAuth
MCP Microsoft Entra OAuth
MCP OAuth
MCP Okta OAuth
MCP OneLogin OAuth
MCP Ping OAuth
MCP Token Exchange
MCP WorkOS OAuth
Mock API Response
Moesif Analytics & Billing
Monetization
Add-On
mTLS Auth
Add-On
Okta FGA Authorization
Okta JWT Auth
Add-On
OpenFGA Authorization
OpenMeter
PropelAuth JWT Auth
Query Parameter to Header
Quota
Rate Limiting
Readme Metrics
Remove Query Parameters
Remove Request Headers
Request Size Limit
Request Validation
Require Origin
Require User Claims
Add-On
Semantic Cache
Set Body
Set Upstream API Key
Sleep / Delay
Smart Router
Stripe Webhook Auth
Supabase JWT Auth
Traffic Splitting
Add-On
Upstream AWS Federated Auth
Add-On
Upstream AWS Service Auth
Add-On
Upstream Azure AD Service Auth
Upstream Firebase Admin Auth
Upstream Firebase User Auth
Add-On
Upstream GCP Federated Auth
Add-On
Upstream GCP Self-Signed JWT
Add-On
Upstream GCP Service Auth
Upstream OAuth 2.0 Client Credentials Auth
Add-On
Upstream Zuplo JWT
Web Bot Auth

Outbound Policies

Akamai Firewall for AI
CDN Cache Control
Clear Response Headers
Composite Outbound (Group Policies)
Custom Code Outbound
Data Loss Prevention
GraphQL Analytics
GraphQL Introspection Filter
HTTP Deprecation
Add-On
Prompt Injection Detection
Remove Response Headers
Replace String in Response Body
Set Headers
Set Status Code
XML to JSON
Edit this page
Last modified on August 28, 2026
Custom MonetizationAPI Key Authentication