AZ-DEV-180: API Management for Developers
About This Course
Learn Azure API Management from a developer's perspective: import APIs, author policies across all scopes, secure with JWT and mutual TLS, apply rate limits and quotas, compose backends, version APIs, brand a developer portal, and deploy a self-hosted gateway. By the end you will run a complete enterprise API program on Standard v2 / Premium v2 APIM.
Course Curriculum
20 Lessons
AZ-DEV-180 M1L1 - APIM fundamentals - tiers, topology, and developer portal
APIM tiers (Consumption, Developer, Basic v2, Standard v2, Premium v2), gateway topology (management vs data plane), developer portal, API catalog, products.
AZ-DEV-180 M1L2 - Provision Standard v2 APIM and import your first API - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Provision a Standard v2 APIM instance, import an ASP.NET Core 10 minimal-API OpenAPI spec, and verify a 200 response from the imported API through the APIM test console.
AZ-DEV-180 M2L3 - Importing APIs from many sources
OpenAPI (v2 + v3), WSDL, Function Apps, Logic Apps, GraphQL passthrough, gRPC, Azure OpenAI. Replace vs merge on re-import.
AZ-DEV-180 M2L4 - Import three API flavors into one APIM - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Import three APIs into one APIM instance: an ASP.NET Core 10 OpenAPI, an Azure Function App, and a GraphQL API. Verify each is callable through APIM.
AZ-DEV-180 M3L5 - Policy fundamentals - scopes, sections, and inheritance
Policy XML structure, the four sections (inbound / backend / outbound / on-error), scopes (global / product / API / operation) and the <base /> inheritance pattern, common policies.
AZ-DEV-180 M3L6 - Author four policies: rewrite, header, log-to-eventhub, mock - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Write four policies at three scopes: rewrite a URI path, add a request header at operation scope, log every response to Event Hubs at API scope, mock a specific operation.
AZ-DEV-180 M4L7 - Security policies - JWT, mTLS, OAuth, subscription keys
Subscription keys, <validate-jwt> for Entra ID + custom, OAuth 2.0 flows with APIM, mutual TLS via client certificates, IP filtering.
AZ-DEV-180 M4L8 - Enforce Entra ID JWT validation on an API - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Add <validate-jwt> to an API. Require the correct audience and the Orders.Read scope. Verify 200 for a valid token, 401 for missing/wrong-audience, and 403 for missing-scope tokens.
AZ-DEV-180 M5L9 - Rate limits, quotas, and circuit breakers
<rate-limit-by-key>, <quota-by-key>, circuit-breaker policy, retry policy. Multi-tier subscription designs.
AZ-DEV-180 M5L10 - Ship a tiered subscription and rate-limit design - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Configure three subscription tiers with distinct quotas — Free (1000/mo), Standard (100k/mo), Premium (unlimited) — plus a 10 req/s rate limit. Load-test each tier and verify enforcement.
AZ-DEV-180 M6L11 - Transformation and composition patterns
Rewriting bodies, <send-request> for backend composition, <send-one-way-request>, JSON/XML conversion, <choose> and <set-variable> for conditional logic.
AZ-DEV-180 M6L12 - Compose a fan-out customer-summary endpoint - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Build /api/customer-summary — a composed endpoint that fans out to Orders, Payments, and Support APIs in parallel via <send-request> and merges responses. Verify sub-500ms p95 across 100 concurrent calls.
AZ-DEV-180 M7L13 - Versioning and revisions
Version sets (path, query-string, header), revisions for non-breaking iteration, deprecation workflows.
AZ-DEV-180 M7L14 - Ship v1 and v2 side-by-side with revisions - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Version an API path-based (v1 / v2). Ship v2 with a renamed field. Support both simultaneously with per-version policy transformations. Iterate on v2 with revisions and stage-promote.
AZ-DEV-180 M8L15 - Developer portal customization and identity
Portal architecture (React-based), visual designer + code customization, external identity providers (Entra ID, External ID, custom OIDC), visibility rules.
AZ-DEV-180 M8L16 - Brand the developer portal and wire External ID sign-in - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Customize the developer portal with Anchorline branding — logo, colors, home page. Wire Entra External ID as the sign-in provider. Verify a new developer can sign up, subscribe to a product, and receive a subscription key.
AZ-DEV-180 M9L17 - Self-hosted gateway on Kubernetes
Self-hosted gateway architecture, deploying on Kubernetes, connectivity back to APIM management plane, offline mode, edge / on-prem / sovereignty use cases.
AZ-DEV-180 M9L18 - Deploy a self-hosted gateway to AKS - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 20 minutes for the environment to become ready before beginning the exercises.
Deploy a self-hosted APIM gateway to AKS via Helm, register it with the APIM instance, route one API through it, and verify traffic hits the self-hosted gateway while management stays on the APIM control plane.
AZ-DEV-180 M10L19 - Capstone - Enterprise API program design
API program design: product taxonomy, subscription tiers, developer onboarding, deprecation policy, API-first culture, APIM cost planning at scale.
AZ-DEV-180 M10L20 - Capstone - Ship the Anchorline API program end-to-end - Lab Exercises
⚠️ Provisioning note: This lab pre-deploys Azure API Management, which may take 45 minutes or more before the lab is ready to use. Please be patient during startup — the lab will move to Ready as soon as the APIM instance is fully provisioned. This is Azure-side provisioning time and cannot be reduced.
Note: This lab pre-provisions Azure resources at start — allow up to 20 minutes for the environment to become ready before beginning the exercises.
Build the Anchorline API program: 5 APIs (Orders, Customers, Payments, Support, Analytics), 3 subscription tiers (Free / Standard / Premium), JWT tenant isolation, branded developer portal with External ID, and one API routed through a self-hosted AKS gateway. Verify a new tenant developer signs up, subscribes, and makes their first call in under 5 minutes.