# Vendor facets — Tyk. An open-source gateway with a licensed Developer Portal (API products, subscription # plans, self-registration, OAuth DCR provisioning) and, since Gateway 5.15 Enterprise, MCP proxies # generated from Tyk OAS APIs. Headers: X-RateLimit-Limit/Remaining/Reset, populated from quotas by # default and from rate limits only when rate_limit_response_headers says so. What it cannot reach: those # headers inside the provider's OpenAPI, served OAuth discovery or protected-resource documents, pricing. vendor: tyk name: Tyk website: https://tyk.io areas: - api-gateway registry_keys: - tyk rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Tyk's portal earns the usual set once declared — portal, OpenAPI documentation, self-registration — and its subscription plans can become published plans when the provider shows them publicly, though the portal has no built-in payments or pricing page. Tyk emits X-RateLimit-* headers, by default only when a quota is configured, and the `verified` grade reads them from the provider's OpenAPI, which Tyk does not write. The Enterprise MCP proxy derives one tool per OpenAPI operation on the provider's own gateway (`templated`, 0.6). features: - id: rate-limit-headers name: X-RateLimit-* response headers description: >- X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset; rate_limit_response_headers (5.13+) chooses quotas (default) or rate_limits as the data source; 429 on exceed. source: https://tyk.io/docs/api-management/rate-limit tier: open-source - id: api-to-mcp name: REST API to MCP proxy description: >- A Tyk OAS API with the x-tyk-mcp-server extension that derives an MCP tool per chosen operation (operationId as tool name), re-derived on gateway reload; Dashboard wizard to pick operations and override names. source: https://tyk.io/docs/ai-management/mcps/api-to-mcp tier: enterprise - id: developer-portal name: Tyk Developer Portal description: >- Licensed CMS-style portal with API products, catalogs per audience, subscription plans (rate limit/quota policies), developer self-registration, app provisioning with OAuth DCR, and OpenAPI documentation. source: https://tyk.io/docs/portal/overview/intro tier: enterprise - id: monetization-integrations name: Monetization via external billing description: >- No built-in payments; usage-based billing from gateway traffic logs, tiered plans, and integrations such as Moesif and Stripe. source: https://tyk.io/docs/portal/overview/intro tier: enterprise maps: - feature: developer-portal check: portal_present layer: composite provider_must: Declare the portal URL as a DeveloperPortal entry in apis.yml common[]. catalog_pass_rate: 0.228 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.633 - feature: developer-portal check: api_reference_present layer: composite provider_must: Declare the published OpenAPI reference pages as an APIReference entry in apis.yml common[]. catalog_pass_rate: 0.222 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.942 saturated: true saturated_note: >- 94% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: developer-portal check: documentation_present layer: composite provider_must: Write tutorials and guides in the portal CMS and declare them as Documentation in apis.yml common[]. catalog_pass_rate: 0.453 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.95 saturated: true saturated_note: >- 95% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: developer-portal check: sign_up_present layer: composite provider_must: Enable developer self-registration and declare the page as SignUp or Login in apis.yml common[]. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: developer-portal check: plans_present layer: composite conditional: true condition: >- Only if the provider's subscription plans are visible on a public page — Tyk plans are rate-limit/quota policies with no price field, and the plans artifact is harvested from public pages. catalog_pass_rate: 0.172 facet: access_clarity points: 8 baseline_pass_rate: 0.44 - feature: rate-limit-headers check: rate_limit_signal layer: agent_readiness grade: documented partial: true partial_note: >- The headers Tyk emits are exactly the X-RateLimit-* family the `verified` grade names, but the grade reads them from the provider's OpenAPI responses; nothing fetched shows Tyk writing them into the spec, so only the `documented` fallback via a published rate_limits artifact is reachable. points: 7 baseline_pass_rate: 0.381 - feature: api-to-mcp check: mcp_server layer: agent_readiness grade: templated note: >- Derived from the provider's own OpenAPI and served by the provider's own gateway — `templated` (0.6); Enterprise-only; `verified` only when the catalog probe of the provider's mcp/ manifest passes. points: 12 baseline_pass_rate: 0.22 earns_nothing: - feature: developer-portal check: dynamic_client_registration why: >- The portal uses DCR to provision apps at the customer's IdP; the check reads a registration_endpoint in a discovery document the provider serves, which Tyk does not. - feature: monetization-integrations check: pricing_link why: The portal has no pricing page of its own; pricing is whatever the provider publishes elsewhere. - feature: api-to-mcp check: protected_resource_metadata why: >- The fetched MCP page says the proxy is a distinct consumer with its own credential and policy, and documents no /.well-known/oauth-protected-resource document. out_of_reach: checks: - sdk_count_1 - sdk_count_3 - cli_present - idempotency - dry_run_mode - reversibility_documented - auth_clarity - delegated_identity - well_known_published - llms_txt_published - agent_card - error_semantics note: >- Nothing fetched shows Tyk serving discovery documents or llms.txt on the provider's host, and SDKs and API behaviours are the provider's. unscored_practice: - feature: rate-limit-headers why: >- The quota-by-default header behaviour means a provider that only configures rate limits ships no headers at all until it flips rate_limit_response_headers; no check reads runtime headers to notice. surface: developer_ergonomics: reachable: 11.0 total: 42 access_clarity: reachable: 13.0 total: 38 agent_readiness: reachable: 10.7 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://tyk.io/docs/ai-management/mcps/api-to-mcp - https://tyk.io/docs/api-management/rate-limit - https://tyk.io/docs/portal/overview/intro measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8762 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 3.3 p75: 5.2 p90: 6.0 max: 7.9 mean_among_movers: 4.0 agent_readiness_lift: median: 5.2 p75: 6.0 p90: 7.7 max: 9.0 mean_among_movers: 5.4 facet_lift_median_among_movers: developer_ergonomics: 13.1 access_clarity: 13.1 composite_band_moves: thin -> developing: 1423 developing -> strong: 460 emerging -> thin: 318 strong -> exemplar: 103 minimal -> emerging: 3 agent_readiness_band_moves: agent-aware -> agent-ready: 2456 agent-ready -> agent-native: 209 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written