Who this is for
Teams with a working API and no user management in front of it
Data providers who want to sell access, not build a billing system
Companies whose internal API now has to face paying customers
What we solve for you
Your API works. Everything around it doesn't. You have endpoints; you do not have accounts, roles, tenants, plans, quotas, rate limits, IP allow-lists or a documentation portal. That is months of work your customers never asked for. Every piece of it also has to be maintained for as long as the product lives.
What you get
Access control on every route
Each path in your OpenAPI document gets its own named permission. The permissions sit in a tree that you grant by user, group or role. Access is decided before the request reaches you.
Plans, quotas and rate limits
Attach the relay to a product and define subscription plans. The gateway enforces quotas and rate limits at the edge, so an over-quota request never costs you compute.
Your own route prefix
Routes publish under /eps/{your-prefix}/…: one endpoint per OpenAPI path, not a catch-all proxy. That is why permissions and usage metering work per route, not just per API.
Upstream credentials stay with you
UniCore injects the upstream credential on the way out and supports rotation. Your API key lives on your infrastructure and is never handed to a caller.
A documentation portal per relay
Every relay gets its own Swagger UI with the bearer scheme already wired in, so a new customer can read the docs and make their first call without talking to you.
Routes your spec doesn't advertise
Add manual endpoints with their own path overrides and their own auth, for the parts of your API that your OpenAPI document doesn't cover.
How it works
Point us at your spec
Give the relay your upstream base URL and your OpenAPI document. If that document is itself protected, UniCore applies the upstream credential to fetch it.
Choose a route prefix
Pick the prefix your customers will call. It is unique across the whole deployment, so no other tenant can claim the same public path.
The relay publishes your routes
UniCore parses the spec and publishes one route per path, creating a named permission for each as it goes.
Define a product and its plans
Attach the relay to a product, then set up the plans you want to sell with their quotas and rate limits.
Grant access
Assign permissions by user, group or role, or let a subscription do it: buying a plan then grants the routes that plan includes.
Go live
Callers authenticate against UniCore, quotas are enforced automatically, and usage is recorded per user for billing.
What ships with UniCore and what you write
Everything on the left already exists, is tested and is maintained by us. Everything on the right is yours to write.
Ships with UniCore
Accounts, sessions and session renewal
Email and password sign-in
Google, Microsoft and Apple sign-in
Roles, groups and named permissions
Per-route access control
Tenants and tenant isolation
Products and subscription plans
Quotas and rate limits
IP allow-lists
Per-user usage metering
Upstream credential injection and rotation
A Swagger portal per relay
Audit logging
An admin console
You write
Your API
Before you ask
Does my API have to change?
No. The relay sits in front of it and forwards to your upstream base URL. Your API is unaware of UniCore, and nothing about its code or deployment has to change.
What if my OpenAPI document is incomplete?
Three modes are supported: spec only, spec plus manual endpoints (the default), or manual only. You are never blocked by a spec that doesn't describe everything.
Where does it run?
On your infrastructure. UniCore is self-hosted: one compose file, PostgreSQL or SQL Server. It fits comfortably on a 4 GB server. There is no managed hosting option today, by design, so that data sovereignty stays with you.
Can two customers collide on the same public path?
No. The route prefix is unique across the entire deployment, not just per tenant. That way one tenant cannot break another's routes with an ambiguous match.
See it applied to your own case
Thirty minutes, screen-shared, with your API or your product idea on the table. No slide deck.