# Vendor facets — Azure API Management. A gateway plus an auto-generated developer portal with sign-up, # products, subscription keys and a try-it console, and a built-in "expose REST API as MCP server" that # publishes selected operations as tools on the APIM gateway host. What it cannot reach: rate-limit # headers by default (each header name is opt-in on the policy), a served protected-resource document # (only GitHub samples), public pricing, SDKs. vendor: microsoft-azure-api-management name: Azure API Management website: https://azure.microsoft.com/products/api-management areas: - developer-portal - api-gateway registry_keys: - azure-apim rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Azure API Management earns the portal set once declared — developer portal, OpenAPI-driven reference, Try-it console, sign-up — and can publish selected operations as an MCP server. By default that MCP endpoint sits on .azure-api.net, a Microsoft host, so it grades `platform` (0.25) unless the provider maps a custom domain. rate-limit-by-key emits only Retry-After unless the provider names the remaining/total headers (and the score reads either only when declared in the provider's OpenAPI), and OAuth protected-resource metadata exists only in samples, so the agent-auth dimensions stay out of reach. features: - id: developer-portal name: Managed developer portal description: >- Auto-generated, customizable portal (default https://.portal.azure-api.net, custom domain supported) populated with published APIs and products, with pages, layouts, visibility by group, and per-user usage reports. source: https://learn.microsoft.com/en-us/azure/api-management/developer-portal-overview tier: paid - id: try-it-console name: Interactive test console description: Try-it on API reference pages supporting no auth, subscription keys or OAuth 2.0 user authorization. source: https://learn.microsoft.com/en-us/azure/api-management/developer-portal-overview tier: paid - id: portal-signup name: Developer sign-up, sign-in and product subscriptions description: >- Basic-auth or Entra ID / External ID sign-up and sign-in, or delegation to an existing site; developers subscribe to products and receive subscription keys. source: https://learn.microsoft.com/en-us/azure/api-management/developer-portal-overview tier: paid - id: rate-limit-by-key name: rate-limit-by-key policy description: >- Per-key call-rate limiting returning 429 with Retry-After by default; remaining-calls-header-name and total-calls-header-name add headers only when the provider names them. source: https://learn.microsoft.com/en-us/azure/api-management/rate-limit-by-key-policy tier: all - id: rest-as-mcp name: Expose REST API as MCP server description: >- Selected operations of a managed REST API become MCP tools (no resources or prompts), served at https://.azure-api.net/-mcp/mcp, with APIM policies and product subscriptions applied. source: https://learn.microsoft.com/en-us/azure/api-management/export-rest-mcp-server tier: paid - id: mcp-security name: MCP inbound security (subscription key or Entra ID tokens) description: >- Inbound MCP access via Ocp-Apim-Subscription-Key or validate-azure-ad-token; Protected Resource Metadata is offered only through linked GitHub samples and labs. source: https://learn.microsoft.com/en-us/azure/api-management/secure-mcp-servers tier: paid - id: portal-reports name: Per-user usage reports in the portal description: Signed-in developers see their own API usage, data transfer and response times. source: https://learn.microsoft.com/en-us/azure/api-management/developer-portal-overview tier: paid maps: - feature: developer-portal check: portal_present layer: composite provider_must: Declare the portal URL (ideally on a custom domain) as a DeveloperPortal entry in apis.yml common[]. catalog_pass_rate: 0.228 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.633 - feature: developer-portal check: api_reference_present layer: composite provider_must: Declare the portal's API reference pages as an APIReference entry in apis.yml common[]. catalog_pass_rate: 0.222 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.942 saturated: true saturated_note: >- 94% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: try-it-console check: console_or_sandbox layer: composite provider_must: Enable CORS for the console and declare it as a Console entry in apis.yml common[]. catalog_pass_rate: 0.089 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.332 - feature: portal-signup check: sign_up_present layer: composite provider_must: Leave self sign-up enabled and declare /signup or /signin as SignUp or Login in apis.yml common[]. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: rate-limit-by-key check: rate_limit_signal layer: agent_readiness grade: documented partial: true partial_note: >- `verified` reads response headers declared in the provider's OpenAPI, matched by score.rb's /\A(x-)?ratelimit|\Aretry-after\z/i — so the Retry-After APIM emits by default would qualify, and remaining/total headers only if the provider names them X-RateLimit-*. Nothing fetched shows APIM adding them to the exported definition, so the vendor alone reaches only the `documented` fallback via a published rate_limits artifact; a provider that declares Retry-After on its 429s earns `verified`. points: 7 baseline_pass_rate: 0.381 - feature: rest-as-mcp check: mcp_server layer: agent_readiness grade: platform note: >- The default endpoint is on .azure-api.net, a Microsoft-owned domain serving the same generated shape for every customer — `platform` (0.25) in 0.22.0. With a custom gateway domain the same server would argue for `templated` (0.6); the profile maps the default. points: 12 baseline_pass_rate: 0.22 earns_nothing: - feature: mcp-security check: protected_resource_metadata why: >- The product docs validate Entra tokens; protected-resource metadata appears only in linked samples and labs, which a provider would have to build and serve itself. - feature: portal-reports why: Per-developer usage reports are useful and no check reads them. - feature: portal-signup check: plans_present why: >- Products are access bundles with subscription keys, not published price plans; the plans artifact is harvested from public pricing pages and APIM ships no pricing page. - feature: rate-limit-by-key check: rate_limits_documented why: >- Configuring a limit in policy XML is not publishing it; the check counts limits the provider writes down. out_of_reach: checks: - sdk_count_1 - sdk_count_3 - cli_present - idempotency - dry_run_mode - reversibility_documented - auth_clarity - delegated_identity - dynamic_client_registration - well_known_published - agent_card - pricing_link - llms_txt_published note: >- APIM validates tokens from Entra ID rather than serving discovery documents on the provider's host, ships no pricing page or llms.txt, and SDKs and API behaviours are the provider's. unscored_practice: - feature: rest-as-mcp why: >- MCP servers attached to APIM products inherit subscription-key access control and policy (rate limiting, tracing of agent IDs); the rubric grades hosting and authorship, not governance of the tools. surface: developer_ergonomics: reachable: 10.0 total: 42 access_clarity: reachable: 5.0 total: 38 agent_readiness: reachable: 6.5 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://learn.microsoft.com/en-us/azure/api-management/developer-portal-overview - https://learn.microsoft.com/en-us/azure/api-management/export-rest-mcp-server - https://learn.microsoft.com/en-us/azure/api-management/rate-limit-by-key-policy - https://learn.microsoft.com/en-us/azure/api-management/secure-mcp-servers measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8775 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 4.3 p75: 6.0 p90: 7.4 max: 7.5 mean_among_movers: 4.5 agent_readiness_lift: median: 2.2 p75: 2.5 p90: 4.7 max: 5.5 mean_among_movers: 2.8 facet_lift_median_among_movers: developer_ergonomics: 16.6 access_clarity: 13.1 composite_band_moves: thin -> developing: 1716 developing -> strong: 659 emerging -> thin: 337 strong -> exemplar: 140 minimal -> emerging: 3 agent_readiness_band_moves: agent-aware -> agent-ready: 969 agent-ready -> agent-native: 105 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written