Skip to content

Your API is the product. UniCore ships the rest.

Put an existing REST API behind UniCore and it gains accounts, per-route permissions, subscription plans, quotas and a documentation portal, with no change to the API itself.

Who this is for

Teams with a working API and no user management in front of it

Data providers who want to sell access, not build a billing system

Companies whose internal API now has to face paying customers

What we solve for you

Your API works. Everything around it doesn't. You have endpoints; you do not have accounts, roles, tenants, plans, quotas, rate limits, IP allow-lists or a documentation portal. That is months of work your customers never asked for. Every piece of it also has to be maintained for as long as the product lives.

What you get

Access control on every route

Each path in your OpenAPI document gets its own named permission. The permissions sit in a tree that you grant by user, group or role. Access is decided before the request reaches you.

Plans, quotas and rate limits

Attach the relay to a product and define subscription plans. The gateway enforces quotas and rate limits at the edge, so an over-quota request never costs you compute.

Your own route prefix

Routes publish under /eps/{your-prefix}/…: one endpoint per OpenAPI path, not a catch-all proxy. That is why permissions and usage metering work per route, not just per API.

Upstream credentials stay with you

UniCore injects the upstream credential on the way out and supports rotation. Your API key lives on your infrastructure and is never handed to a caller.

A documentation portal per relay

Every relay gets its own Swagger UI with the bearer scheme already wired in, so a new customer can read the docs and make their first call without talking to you.

Routes your spec doesn't advertise

Add manual endpoints with their own path overrides and their own auth, for the parts of your API that your OpenAPI document doesn't cover.

How it works

  1. Point us at your spec

    Give the relay your upstream base URL and your OpenAPI document. If that document is itself protected, UniCore applies the upstream credential to fetch it.

  2. Choose a route prefix

    Pick the prefix your customers will call. It is unique across the whole deployment, so no other tenant can claim the same public path.

  3. The relay publishes your routes

    UniCore parses the spec and publishes one route per path, creating a named permission for each as it goes.

  4. Define a product and its plans

    Attach the relay to a product, then set up the plans you want to sell with their quotas and rate limits.

  5. Grant access

    Assign permissions by user, group or role, or let a subscription do it: buying a plan then grants the routes that plan includes.

  6. Go live

    Callers authenticate against UniCore, quotas are enforced automatically, and usage is recorded per user for billing.

What ships with UniCore and what you write

Everything on the left already exists, is tested and is maintained by us. Everything on the right is yours to write.

Ships with UniCore

Accounts, sessions and session renewal

Email and password sign-in

Google, Microsoft and Apple sign-in

Roles, groups and named permissions

Per-route access control

Tenants and tenant isolation

Products and subscription plans

Quotas and rate limits

IP allow-lists

Per-user usage metering

Upstream credential injection and rotation

A Swagger portal per relay

Audit logging

An admin console

You write

Your API

Before you ask

Does my API have to change?

No. The relay sits in front of it and forwards to your upstream base URL. Your API is unaware of UniCore, and nothing about its code or deployment has to change.

What if my OpenAPI document is incomplete?

Three modes are supported: spec only, spec plus manual endpoints (the default), or manual only. You are never blocked by a spec that doesn't describe everything.

Where does it run?

On your infrastructure. UniCore is self-hosted: one compose file, PostgreSQL or SQL Server. It fits comfortably on a 4 GB server. There is no managed hosting option today, by design, so that data sovereignty stays with you.

Can two customers collide on the same public path?

No. The route prefix is unique across the entire deployment, not just per tenant. That way one tenant cannot break another's routes with an ambiguous match.

See it applied to your own case

Thirty minutes, screen-shared, with your API or your product idea on the table. No slide deck.

See pricing