Roadmap
Important Note: Plans in the Roadmap may change. Priorities are updated based on user feedback, regulatory requirements and technical assessment. No version or date commitment is given for the items on this page.
Completed
The full list of features available in released versions is kept in the release notes: Release Notes 2026, Release Notes 2025 and Change Log.
Priority Plan
Security and Compliance
- Multi-factor authentication — one-time code and MFA support for API Manager and API Portal
- Expanded SIEM module — logging a wider set of security events and profile-based forwarding of traffic logs; for example an informational profile forwards everything while a security profile forwards only blocked requests
- Password visibility auditing — recording who viewed a secret value on screen as a security event
- Security compliance profiles and API Governance report — compliance scoring and reporting, primarily against OWASP
- Vault integration — external secret management support for API Gateway credentials
- ASN-based IP blocking — blocking by autonomous system number in IP lists
API Gateway and Development
- Per-environment policies — different policy configuration per environment for the same API
- Connector API — per-endpoint connection definition under API Creator
- Moving SOAP to REST conversion to method level
- Endpoint-level mock response definition
- Spec editor — manual editing of OpenAPI and WSDL definitions, publishing the edited version and regenerating it from the source definition on demand
API Proxy Group
- Cross-gateway endpoint grouping — collecting endpoints from different gateways into a single group
- Group-level analytics tabs
- Endpoint-level access control within groups
Analytics and Reporting
- Geolocation report — geographic distribution of requests
API Portal and Interface
- Portal certificate management and rating system
- Migrating the interface infrastructure to the current version
Management APIs
- Expanding Management API and APIops coverage — making all administrative functions available programmatically
AI Module — Next Phase
The following items are planned on top of the AI Gateway's existing capabilities.
Protection and Security
- Retrieved context inspection — scanning content retrieved through RAG against indirect prompt injection before it reaches the model
- Approval gate for high-risk tool calls — classifying MCP tools by risk tier and requiring approval
- Output sanitization — cleaning the model response before it reaches downstream systems
- Concurrent stream and maximum token ceiling — protection against denial-of-service attempts
- Built-in OWASP LLM Top 10 policy pack — a protection set deployable as a single bundle, with guardrail hit indicators
- External guardrail provider adapters — enabling on-premises or cloud-based protection services
- Model supply chain auditing — drift detection in the model catalog and allowed model list metrics
Routing and Model Management
- Semantic routing offered as a load balancing algorithm
- Model canary and A/B promotion flow — experiment definition, comparison view, promotion and rollback
- Regular model catalog expansion — periodic addition of new and open-weight models
- Streaming tool call loop — multi-turn tool use on streaming responses as well
- Request coalescing in the semantic cache — collapsing concurrent requests for the same key into a single call
Compliance, Cost and Quality
- Compliance dashboard and built-in regulatory profile
- Audit trail replay
- Token usage forecasting — projection based on historical usage
- Quality telemetry — controlled sampling, human or automated scoring and distribution drift monitoring
- Prompt lifecycle governance — immutable revision records, diff view and optional reviewer approval
- File management endpoint — file upload constrained by purpose allowlist, size and count quotas
Feature Request Process
Submitting a Request
The Apinizer team reviews user feedback and feature requests regularly. You can submit your request through these channels:
- Email — you can write to support@apinizer.com
- API Portal Support Tickets — if API Portal is used in your installation, you can open a ticket directly from the portal, exchange messages on it and track its status
Evaluation Criteria
Requests are evaluated according to the following criteria:
- User need — how many organizations need this feature
- Business value — the contribution the feature provides
- Technical feasibility — whether it can be built with the current architecture
- Platform fit — alignment with Apinizer's overall vision and architecture
- Resource requirement — the effort required for development
Request Statuses
- Under review — request received and being evaluated
- Planned — request accepted and added to the Roadmap
- In development — development has started
- Released — feature is released and available
- Out of scope — not taken up for technical or strategic reasons
Deprecated Features
The current, version-based list of deprecated and removed features is kept on a separate page.
The deprecation process has four steps:
- Announcement — the feature is marked as deprecated and announced in the release notes
- Warning period — transition to the alternative solution is recommended
- Migration support — migration guides and any required scripts are provided
- Removal — the feature is removed in the stated version
You can reach the current list on the Deprecated and Removed page.
Release Cadence
Apinizer publishes approximately three major versions per year. Major versions include new features, architectural changes and, where needed, data model updates.
Patch versions are published between major versions as needed. Patch versions include improvements, minor features and bug fixes.
A data model update may be required when moving to a major version. Before upgrading, always review the upgrade warnings in that version's release notes and any log table update scripts.
Roadmap Updates
This page is updated when each major version is released, on significant scope changes, and based on user feedback.