# Vendor facets — Gravitee. API Management (v4 gateway, Developer Portal, plans and subscriptions, an MCP # entrypoint that generates one tool per OpenAPI operation) plus Gravitee Access Management, a full # OAuth/OIDC server with a discovery document and dynamic client registration. The one vendor in this set # that can put a served authorization server on the provider's own infrastructure — but path-scoped per # security domain. What it cannot reach: rate-limit headers the rubric recognises (off by default, and # named X-Rate-Limit-*, which score.rb's header pattern does not match), pricing, SDKs. vendor: gravitee name: Gravitee website: https://www.gravitee.io areas: - api-gateway registry_keys: - gravitee rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Gravitee reaches further into agent auth than the other gateways, but only through Access Management: a provider running AM serves an OIDC discovery document that advertises authorization_code and a registration_endpoint, which can earn auth_clarity `served`, delegated_identity `served` and dynamic_client_registration — conditional because AM scopes discovery under /{domain}/oidc/, not the host root. On API Management it earns the portal set once declared, and the MCP entrypoint serves OpenAPI-generated tools on the provider's own gateway (`templated`, 0.6). Its rate-limit headers are off by default and named X-Rate-Limit-*, a spelling score.rb's /\A(x-)?ratelimit/ header test does not match. features: - id: rate-limit-policies name: Rate Limit, Quota and Spike Arrest policies description: >- Three limiting policies with error keys RATE_LIMIT_TOO_MANY_REQUESTS / QUOTA_TOO_MANY_REQUESTS / SPIKE_ARREST_TOO_MANY_REQUESTS and overridable response templates. source: >- https://documentation.gravitee.io/apim/create-and-configure-apis/apply-policies/policy-reference/rate-limit tier: open-source - id: rate-limit-headers name: addHeaders option (X-Rate-Limit-Limit / -Remaining / -Reset) description: >- When addHeaders is true (default false) the policy adds X-Rate-Limit-Limit, X-Rate-Limit-Remaining, X-Rate-Limit-Reset and Retry-After on rejection. source: https://github.com/gravitee-io/gravitee-policy-ratelimit tier: open-source - id: mcp-entrypoint name: MCP entrypoint — Generate Tools from OpenAPI description: >- On a v4 proxy API, enabling the MCP entrypoint (path /mcp) and pasting the OpenAPI generates one tool per operation — name from operationId, description from summary and description, input and output schemas from parameters and 2xx responses. source: https://documentation.gravitee.io/apim/ai-agent-management/convert-your-apis-to-mcp-servers tier: unknown - id: developer-portal name: Developer Portal description: >- Catalog where consumers discover APIs, read documentation, test endpoints, generate access tokens, view analytics and manage subscriptions; applications subscribe to API plans. source: >- https://documentation.gravitee.io/apim/configure-and-manage-the-platform/manage-organizations-and-environments/developer-portal tier: open-source - id: access-management-oidc name: Gravitee Access Management — OIDC provider with DCR description: >- OAuth 2.0 / OIDC authorization server supporting the authorization code flow, with a registration_endpoint (POST https:///{domain}/oidc/register) advertised in the OpenID discovery document. source: https://documentation.gravitee.io/am/guides/auth-protocols/openid-connect tier: open-source maps: - feature: developer-portal check: portal_present layer: composite provider_must: Declare the portal URL as a DeveloperPortal entry in apis.yml common[]. catalog_pass_rate: 0.228 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.633 - feature: developer-portal check: documentation_present layer: composite provider_must: Publish documentation pages in the portal and declare them as Documentation in apis.yml common[]. catalog_pass_rate: 0.453 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.95 saturated: true saturated_note: >- 95% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: developer-portal check: console_or_sandbox layer: composite provider_must: Declare the portal's endpoint-testing view as a Console entry in apis.yml common[]. catalog_pass_rate: 0.089 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.332 - feature: developer-portal check: sign_up_present layer: composite provider_must: Allow consumer sign-up and declare the page as SignUp or Login in apis.yml common[]. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: developer-portal check: plans_present layer: composite conditional: true condition: >- Only if the provider's plans are visible publicly and describe commercial tiers — Gravitee plans are security/access plans (keyless, API key, JWT, OAuth2, mTLS) without prices, and the plans artifact is harvested from public pages. catalog_pass_rate: 0.172 facet: access_clarity points: 8 baseline_pass_rate: 0.44 - feature: rate-limit-headers check: rate_limit_signal layer: agent_readiness grade: documented partial: true partial_note: >- `verified` reads response headers declared in the provider's OpenAPI, matched by score.rb's /\A(x-)?ratelimit|\Aretry-after\z/i. Gravitee's X-Rate-Limit-* spelling does NOT match that pattern (the hyphen after "rate" breaks it); only the Retry-After it adds on rejection would. The headers are off by default and not written into the spec, so the vendor alone reaches only the `documented` fallback via a published rate_limits artifact. points: 7 baseline_pass_rate: 0.381 - feature: mcp-entrypoint check: mcp_server layer: agent_readiness grade: templated note: >- Tools are generated from the provider's own OpenAPI and served by the provider's gateway at the API's /mcp path — `templated` (0.6); `verified` only when the catalog probe of the provider's mcp/ manifest passes. Edition not stated on the fetched page. points: 12 baseline_pass_rate: 0.22 - feature: access-management-oidc check: auth_clarity layer: agent_readiness grade: served conditional: true condition: >- Only if the provider runs AM on its own host and the catalog's discovery probe reaches AM's path-scoped document (/{domain}/oidc/.well-known/openid-configuration) with its `issuer`; a probe of the host root will not find it. points: 10 baseline_pass_rate: 0.474 - feature: access-management-oidc check: delegated_identity layer: agent_readiness grade: served conditional: true condition: >- Same discovery-path condition; AM supports the authorization code flow, which the served grade needs listed in grant_types_supported. points: 6 baseline_pass_rate: 0.209 - feature: access-management-oidc check: dynamic_client_registration layer: agent_readiness conditional: true condition: >- Only if DCR is enabled in the AM security domain and the discovery document carrying registration_endpoint is reachable by the catalog probe. points: 6 baseline_pass_rate: 0.134 earns_nothing: - feature: rate-limit-policies check: rate_limits_documented why: >- Policies enforce limits; the check counts limits the provider publishes in a harvested rate_limits artifact. - feature: developer-portal check: pricing_link why: The portal lists access plans, not prices; there is no pricing page to point at. out_of_reach: checks: - sdk_count_1 - sdk_count_3 - cli_present - idempotency - dry_run_mode - reversibility_documented - protected_resource_metadata - well_known_published - llms_txt_published - agent_card - error_semantics note: >- Nothing fetched shows Gravitee serving an oauth-protected-resource document for MCP entrypoints, and SDKs, llms.txt and API behaviours are the provider's. unscored_practice: - feature: rate-limit-headers why: >- X-Rate-Limit-* is a real, deployed spelling; score.rb's RATELIMIT_HEADER_RE matches only (x-)ratelimit* and Retry-After, so a Gravitee customer who faithfully declares the headers its gateway emits still misses `verified` unless it also declares Retry-After. Rubric input, not a mapping. - feature: developer-portal why: >- The Developer Portal also catalogs A2A agent proxies with subscribable plans; no check reads a portal-level agent catalog. surface: developer_ergonomics: reachable: 11.0 total: 42 access_clarity: reachable: 13.0 total: 38 agent_readiness: reachable: 31.7 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://documentation.gravitee.io/am/guides/auth-protocols/openid-connect - https://documentation.gravitee.io/apim/ai-agent-management/convert-your-apis-to-mcp-servers - >- https://documentation.gravitee.io/apim/configure-and-manage-the-platform/manage-organizations-and-environments/developer-portal - >- https://documentation.gravitee.io/apim/create-and-configure-apis/apply-policies/policy-reference/rate-limit - https://github.com/gravitee-io/gravitee-policy-ratelimit measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8866 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 4.0 p75: 5.9 p90: 6.0 max: 7.9 mean_among_movers: 4.2 agent_readiness_lift: median: 5.2 p75: 6.0 p90: 7.7 max: 9.0 mean_among_movers: 5.4 facet_lift_median_among_movers: developer_ergonomics: 16.6 access_clarity: 13.1 composite_band_moves: thin -> developing: 1577 developing -> strong: 574 emerging -> thin: 325 strong -> exemplar: 133 minimal -> emerging: 3 agent_readiness_band_moves: agent-aware -> agent-ready: 2456 agent-ready -> agent-native: 209 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written