Gravitee.io AM 2.0

After months of work, we are pleased to announce that the 2.0 release of Gravitee.io Access Management is now available.

The Gravitee.io. Access Management project provides a unique centralized authentication and authorization solution to heterogeneous applications.


The version 2.0 release has been re-written from scratch and represents a major architecture change for the project.

We focused to make the Authorization Server fully reactive with the Vert.x toolkit and ReactiveX API with RxJava2 implementation.

Here are the new features we want to highlight :

Access Management is now reactive

The 1.x version of Gravitee.io Access Management was created to meet the need to secure APIs. The need was recurrent and the first versions of Gravitee.io have been released in a very short period of time.

The Access Management 1.x allowed us to provide a strong and complete solution for our first users. However the synchronous I/O Servlet architecture and core security framework used by the 1.x version showed their limits in terms of scalability and freedom due to a too restrictive framework driven model.

We decided to re-start from scratch and focus on creating a new fully reactive version. We have chosen Vert.x for its high-performance, its tool-kit, its flexibility, its simplicity and the experience we have gained with Gravitee.io API Management.

You’re using Gravitee.io Access Management 1.x and have written some custom plugins ? Want to upgrade ? You can read the major changes from the documentation.

Access Management Gateway and Management API are now distinct

Starting from 2.x version, the Access Management Gateway server and the Management API server have been split up and let you deploy these two servers into separate network zone.

See more details on how to install Access Management 2.x from the installation guide.

What next ?

Access Management 2.x was a pure technical evolution but allow us to develop the next big features :

  • OAuth 2.0/OpenID Connect full compliancy
  • Analytics, Monitoring
  • Better user/role management
  • More plugins
  • Policies

Ready to secure your APIs ?

You have set up Access Management 2.x ? You have discovered and tried the quickstarts ?

Ready to dive in for more complex scenario ?

You can discover the possibilities provided by the Gravitee.io API Platform (APIM and AM) to protect your sensible data with our Secure your APIs QuickStart.


Waiting for your feedbacks, we would be happy to talk and help you from Gitter channel.