apihub

A full-cycle platform for APIs

You bring a working service.
We take care of the rest.

Catalogue, keys, limits, invoices, debugging and monitoring — what every provider rebuilds from scratch and always half-finishes. We built it once and in full, including the parts people remember in month three: reconciliation to the kopeck, a per-stage request trace, and a breaking-change detector.

0 ppm

reconciliation divergence

Over a million-call run. Reconciliation recomputes the period independently and compares it to the ledger.

4 ms

gateway overhead, p99

Everything the platform adds to your response time: key, quota, metering.

739 ms

from “found an API” to working code

Machine time for the whole path: catalogue, mock call, sign-up, key, real call.

12 s

to a leaked-key alert

From the first foreign call to throttling the key and notifying its owner.

1

The consumer calls one address

One key instead of a dozen bespoke auth schemes, one domain instead of a dozen. A public API can be tried with no key at all: the gateway answers with an example from the spec, and says so in a response header.

2

The gateway checks, counts and records

Key, plan, quota, rate — and a record of the call with its own id. All of it costs 4 ms at the 99th percentile; that is the price of having someone stand between you.

3

Everything else grows from those records

Invoices and payouts, charts, a per-stage trace of a call, uptime observation, a leaked-key signal. None of it is counted separately — one source, so two numbers cannot disagree.

The public catalogue is only one channel. An API can stay private and be granted by name, opened to partners, or published to everyone: the provider chooses visibility, and the billing model follows from it.

Money is computed once and verified another way

Whole kopecks, double-entry, immutable postings. Every day an independent reconciliation recomputes the period — and if it does not agree, no invoice is issued until we know why. Rounding always favours whoever pays.

0 ppm over a million calls

We compute the numbers, and providers cannot touch them

Uptime, latency, error rate — from our own probes and our own log. They cannot be hidden and there is nothing to game. Next to them we state plainly how many vantage points we watch from: one, for now.

one vantage point, and we say so

Debugging instead of correspondence

The “your API is broken” versus “your request is malformed” argument ends in thirty seconds: the trace shows the request body, the response body and the timing by stage — key, quota, upstream, and our own work as a separate number.

request body, response body, timing by stage

Updates that do not break someone else’s code

A new specification is compared with the old one by meaning. A field gone from a response or a new required parameter will not ship as a minor version, and subscribers get a separate warning.

specs compared by meaning, not by text

How money works

Everything is whole kopecks. There is no fractional money anywhere: not in the database, not in the calculation, not in reports. Rounding goes down, in favour of whoever pays; the platform has no way to profit from rounding.

  • Every call through the gateway emits an event with a request id. Charging works from those events, and a duplicate event is harmless: the idempotency key will not let one operation post twice.
  • Double-entry bookkeeping: the postings of every transaction sum to zero, and the database enforces that, not the application. Entries are immutable — a correction is a reversing operation, not an edit.
  • Reconciliation runs daily: it recomputes the period from scratch with an independent query and compares it to the ledger. Any divergence is a reason to investigate rather than to invoice.
  • Work the provider did not do is not billed: a rejection on our side, an upstream 5xx, an answer served from the mock. A consumer’s own bad request (4xx) does count — the upstream handled it.

Charging is monthly. The subscription fee is always taken, even with no calls: it pays for the platform holding the infrastructure, not for volume. If the plan changed mid-month, each plan takes its share by days — and the quota is split the same way, otherwise changing plans would double the free allowance.

What we measure and show

The numbers on an API card are computed by us and the provider cannot influence them — otherwise they would mean nothing. The “our measurements” section stands apart from general statistics: it is what the platform verified itself, with its own probes.

  • Latency percentiles are taken at the histogram bucket boundary rather than interpolated inside it: interpolation would look more precise, but the precision would be invented.
  • Monitoring is from a single location, and that is stated plainly. A map from several regions needs several machines, which we do not have yet.
  • “Not enough data” is a status of its own, not blank space: silence would read as “bad”.
  • Monitoring can only be reset when a new API version is released. We see the release ourselves, so nobody has to be taken at their word.

What we store, and what we do not

Request headers and bodies are recorded only if the provider enabled capture. It is off by default — the one place where “off” is the right default: capture on by default would mean the platform started storing the provider’s customers’ data without asking anyone.

  • Authorization headers are always stripped and never reach the record. A provider can add their own fields to the strip list — stripping happens before writing, not at display time.
  • Bodies are compressed and then encrypted, in that order: ciphertext is indistinguishable from random bytes, and random bytes do not compress.
  • Retention is set by the provider in the plan — from an hour to a year — and stamped into the record when it is written. An hour by default: quietly extending that would mean deciding, on the provider’s behalf, how long someone else’s data is kept. Changing plans later does not touch what is already written.
  • We do not store the API key, only its fingerprint. Showing a key twice is impossible, and it is not filled into the exported curl command: saying so is more honest than inserting a placeholder.

What we do not do

The list is short and gets updated. It is here because a promise that is not kept costs more than a missing feature.

  • The platform’s own services are marked as ours in the catalogue. We run a catalogue in which we compete with those we admit; the price is the same, but who built a service is something the consumer should know before choosing, not after.
  • We do not compare our prices with providers’ direct prices. Only the provider can state such a price, and they will not enter a number that makes us look expensive. The calculator compares plans within the platform, and the page says so.
  • We do not monitor from several regions — one location for now.
  • We do not publish generated SDKs to npm or PyPI: the client can be downloaded as an archive.
  • We do not proxy gRPC. SSE and WebSocket are in progress.
  • We do not keep secrets in a dedicated vault: they are stored encrypted next to the database. That covers a leaked dump or replica, but not someone already inside.

You can try it right now

A public API in the catalogue answers from its mock — no key, no sign-up. If you like the shape of the response, issue a key and repeat the same call against the real service.