FAQ
Questions platform leaders actually ask
Straight answers on deployment, standards, security, support, and pricing. If your question isn't here, an API architect will answer it directly.
Frequently asked questions
Forgepath platform components deploy into infrastructure you control — your Kubernetes clusters, cloud accounts, or managed container services. The governance runtime sits in your request path; the catalog, portal, and observability components connect to your systems through scoped, audited access. For regulated environments we support air-gapped and single-tenant topologies, and every deployment pattern is documented during the Align stage so your security reviewers see the full architecture before implementation begins.
OpenAPI 3.x is our default contract format, with AsyncAPI for event-driven interfaces and JSON Schema for shared payloads. We work comfortably with REST, GraphQL, and gRPC estates — the design system layer enforces your conventions across all of them. Versioning strategy, pagination patterns, and error contracts are defined per organization rather than imposed from a template, because standards only survive if they fit how your teams already work.
Security is enforced at runtime, not by convention: OAuth 2.x and mTLS patterns for authentication, least-privilege scope libraries tied to business purposes, rate limits and schema validation at the gateway, and mandatory expiry on access grants. Every grant, revocation, and policy change is recorded in an immutable audit trail searchable by application, scope, and reviewer. Our Principal Security Engineer reviews every major release, and we publish our own threat-modeling practices for customer security teams to review.
Both paths are supported. Most customers launch on the Forgepath portal — branded, with versioned docs, search, changelogs, and self-serve key issuance — because it removes months of frontend work. Teams with strong design systems of their own can consume our documentation pipeline and APIs directly to build a custom portal experience. Either way, docs are generated from live contracts, so they cannot drift from production behavior.
Your first week establishes the basics: a named support contact, an escalation map, environment capture, and a working session on filing effective requests. The engagement itself typically opens with a two-to-four-week Assess — discovery workshops, estate inventory, and a baseline readout. From there the sequence follows the stage model on our Services page: Assess, Align, Implement, Enable, Improve, with defined artifacts and exit criteria at every step.
Three tiers: Standard (business-hours coverage, first response within one to two business days), Priority (extended coverage, four-business-hour response for Priority severity, a named support engineer), and Mission Critical (24×7 coverage, 30-minute response for production outages, a dedicated escalation line, and quarterly reliability reviews). Severity definitions and the full escalation process are published on our Support page — including the post-incident review commitment.
Forgepath connects to what exists rather than demanding replacement: identity providers via standard federation, CI/CD pipelines through contract checks and policy gates, logging and metrics stacks via standard formats, and ticketing systems for incident routing. Legacy protocols — SOAP services, EDI feeds, batch file transfers — are wrapped with adapter patterns during Integration Modernization and retired incrementally behind governed interfaces.
Per-endpoint and per-consumer latency, error rates, and traffic volume; SLO and error-budget tracking with alerting routed to owning teams; consumer health scoring for partner-facing APIs; and dependency signals that show which downstream services an endpoint relies on. The goal is operational, not decorative: every dashboard maps to an owner and an action, and usage evidence feeds deprecation, capacity, and migration decisions.
Engagements are scoped and fixed-price per stage — you approve Assess, then decide on Align with evidence in hand, and so on. Platform components are licensed by estate size and usage profile rather than per-seat, because API platforms serve whole organizations, not individual desks. Ongoing Improve engagements and support tiers are annual. We publish what each stage delivers before you commit, and we will tell you during Assess if a smaller engagement (or none) is the right answer.
Yes — that is the common case, not the exception. Discovery tooling maps traffic and dependencies to build the inventory without requiring every original author to be available. Documentation is reconstructed from live contracts and observed behavior, then brought under the design system incrementally, prioritized by business criticality. Customers typically reach full documentation coverage of critical endpoints within two quarters; the long tail follows as teams touch each service.
Usually, yes. The governance layer is designed to complement incumbent gateways: policy definitions, audit trails, and lifecycle controls can run on top of the traffic infrastructure you already operate. Where the existing gateway is the constraint — unsupported policy hooks, no audit export — we plan its progressive replacement inside the same incremental model, dual-running until traffic fully shifts.
Discovery and analysis run against your estate under your access controls; we request read-only, scoped access and never retain production payloads. Engagement artifacts — inventories, blueprints, dashboards — belong to you and are handed over in open formats at Enable. Our website data handling is described in our Privacy Policy, and engagement-specific data terms are agreed in writing before Assess begins.
Still unresolved? Talk to an API Architect — real answers, not a routing queue.
Next step
Schedule an architecture conversation
Bring your current API landscape — the sprawl, the ownership gaps, the audit questions. A Forgepath API architect will walk through what a governed, observable foundation looks like for your organization. No slideware, just a practical working session.