# Express Gateway > Express Gateway is an open-source (Apache-2.0) microservices and serverless API > gateway built on Express.js and Node.js. It is self-hosted software, not a > hosted service: an operator installs it, points a YAML config at their > downstream services, and composes policies (auth, rate limiting, transforms, > proxying) into pipelines. Its own HTTP API is the Admin API, which by default > listens on http://localhost:9876 and is not intended for public exposure. Generated by API Evangelist on 2026-09-07 from this repository's apis.yml and artifacts. Express Gateway does not publish an llms.txt of its own; a probe of https://www.express-gateway.io/llms.txt returned 404. ## Project status Express Gateway is dormant. The npm runtime last published 1.16.11 on 2021-04-29, the last tagged GitHub release was v1.16.9 on 2019-09-22, the official Docker `latest` tag was pushed 2021-04-29, and the documentation site is versioned v1.16.3 and carries a 2021 copyright. The repository is not archived and was last pushed 2024-05-14; the npm package still serves roughly 6,300 downloads a month. ## Admin API The Admin API is an HTTP interface for administering a running gateway. It manages users, applications, credentials, scopes, schemas, policies, service endpoints, API endpoints and pipelines. Express Gateway publishes no OpenAPI, Swagger, GraphQL, AsyncAPI, gRPC or WSDL contract for it — the API Evangelist OpenAPI in this repository was written from the published Admin API Reference and is not a provider-published document. - Admin API Reference: https://www.express-gateway.io/docs/admin/ - Users: https://www.express-gateway.io/docs/admin/users/ - Apps: https://www.express-gateway.io/docs/admin/apps/ - Credentials: https://www.express-gateway.io/docs/admin/credentials/ - Scopes: https://www.express-gateway.io/docs/admin/scopes/ - Schemas: https://www.express-gateway.io/docs/admin/schemas/ - Policies: https://www.express-gateway.io/docs/admin/policies/ - Service Endpoints: https://www.express-gateway.io/docs/admin/service-endpoints/ - API Endpoints: https://www.express-gateway.io/docs/admin/api-endpoints/ - Pipelines: https://www.express-gateway.io/docs/admin/pipelines/ ## Authentication The Admin API itself ships unauthenticated on localhost. The documented way to expose it safely is to front it with Express Gateway and apply the key-auth policy, then send `Authorization: apikey {keyId}:{keySecret}`. - Securing the Admin API: https://www.express-gateway.io/docs/admin/ - Key Authorization policy: https://www.express-gateway.io/docs/policies/key-authorization/ - OAuth 2.0 policy (RFC 6749): https://www.express-gateway.io/docs/policies/oauth2/ - OAuth 2.0 Introspection (RFC 7662): https://www.express-gateway.io/docs/policies/oauth2-introspection/ - JWT Verification: https://www.express-gateway.io/docs/policies/jwt/ - Basic Authorization: https://www.express-gateway.io/docs/policies/basic-authorization/ ## Getting started - Getting Started: https://www.express-gateway.io/getting-started/ - Installation: https://www.express-gateway.io/docs/installation/ - Core Concepts: https://www.express-gateway.io/docs/core-concepts/ - Configuration (gateway.config.yml): https://www.express-gateway.io/docs/configuration/gateway.config.yml/ - CLI Reference (the `eg` command): https://www.express-gateway.io/docs/cli/ - FAQ: https://www.express-gateway.io/docs/faq/ ## Distribution - npm: https://www.npmjs.com/package/express-gateway (1.16.11, 2021-04-29) - Docker Hub: https://hub.docker.com/r/expressgateway/express-gateway - Source: https://github.com/ExpressGateway/express-gateway (Apache-2.0) - Releases / changelog: https://github.com/ExpressGateway/express-gateway/releases ## Project - Website: https://www.express-gateway.io/ - Documentation: https://www.express-gateway.io/docs/ - Blog: https://www.express-gateway.io/blog/ - Roadmap: https://www.express-gateway.io/docs/roadmap/ - Resources and community: https://www.express-gateway.io/resources/ - Issue queue: https://github.com/ExpressGateway/express-gateway/issues - Contributing: https://github.com/ExpressGateway/express-gateway/blob/master/Contributing.md ## Not published Express Gateway serves no /.well-known/ documents, no llms.txt, no A2A agent card, no MCP server, no status page, no pricing page (the software is free and open source), no security.txt and no vulnerability-disclosure policy. Those absences are recorded in this repository rather than filled in.