IP Library › Granted Patent US 12,647,331
Granted Patent B2
US 12,647,331 · App. 18/793,140 · Granted Jun 2, 2026

Measuring and enforcing API usage in a multi-tenant computing environment

Inventors: Matthew Banks (Livermore, CA); Niall Tierney (Dublin, IE)
Assignee: WORKDAY, INC.
H04L41/5009H04L63/08H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,331
App. No.
18/793,140
Granted
Jun 2, 2026
Kind
B2
Abstract

In some implementations, the techniques described herein relate to a method including: receiving, at an API gateway, an API request from an API client; extracting, by the API gateway, a client identity associated with the API request; checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity; determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.

Claims (37)

1 . A method comprising:

receiving, at an API gateway, an API request from an API client;

extracting, by the API gateway, a client identity associated with the API request;

checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;

determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and

applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.

2 . The method of claim 1 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.

3 . The method of claim 1 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.

4 . The method of claim 1 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.

5 . The method of claim 1 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.

6 . The method of claim 1 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.

7 . The method of claim 1 , further comprising: updating API Level Indicator (ALI) metrics associated with the client, the ALI metrics representing one or more of actual usage metrics including a number of requests made, a total response bandwidth, a number of errors encountered, and a latency of the requests; and storing the ALI metrics in a distributed cache for monitoring and analyzing API usage.

8 . A non-transitory computer-readable storage medium for tangibly storing computer program instructions capable of being executed by a computer processor, the computer program instructions defining steps of:

receiving, at an API gateway, an API request from an API client;

extracting, by the API gateway, a client identity associated with the API request;

checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;

determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and

applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.

9 . The non-transitory computer-readable storage medium of claim 8 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.

10 . The non-transitory computer-readable storage medium of claim 8 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.

11 . The non-transitory computer-readable storage medium of claim 8 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.

12 . The non-transitory computer-readable storage medium of claim 8 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.

13 . The non-transitory computer-readable storage medium of claim 8 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.

14 . The non-transitory computer-readable storage medium of claim 8 , the steps further comprising: updating API Level Indicator (ALI) metrics associated with the client, the ALI metrics representing one or more of actual usage metrics including a number of requests made, a total response bandwidth, a number of errors encountered, and a latency of the requests; and storing the ALI metrics in a distributed cache for monitoring and analyzing API usage.

15 . A device comprising:

a processor; and

a non-transitory computer-readable medium storing program instructions that, when executed by the processor, cause the processor to perform steps of:

receiving, at an API gateway, an API request from an API client;

extracting, by the API gateway, a client identity associated with the API request;

checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;

determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and

applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.

16 . The device of claim 15 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.

17 . The device of claim 15 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.

18 . The device of claim 15 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.

19 . The device of claim 15 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.

20 . The device of claim 15 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2024
From: BANKS, MATTHEW; TIERNEY, NIALL
To: WORKDAY, INC.
Reel/Frame 068165/0992 →
Continuity (1)
Related Publication 20260039566A1 · Feb 5, 2026
References Cited (11)
US 10148493B1 · Ennis, Jr. · 2018 [cited by examiner]
US 10552442B1 · Lusk · 2020 [cited by examiner]
US 11570182B1 · Tran · 2023 [cited by examiner]
US 20170171245A1 · Lee · 2017 [cited by examiner]
US 20200052957A1 · Tubillara · 2020 [cited by examiner]
US 20200174842A1 · Wang · 2020 [cited by examiner]
US 20230104787A1 · Hassan · 2023 [cited by examiner]
US 20230124166A1 · Mohanty · 2023 [cited by examiner]
US 20230176918A1 · Aronovich · 2023 [cited by examiner]
US 20230300135A1 · Krishnan · 2023 [cited by examiner]
US 20230367608A1 · Ross · 2023 [cited by examiner]