Ocelot review
A focused, self-hosted gateway for ASP.NET Core service architectures.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
Ocelot is an open-source API gateway implemented as ASP.NET Core middleware. It forwards client requests to downstream services through configuration and route-based request forwarding, making it a fit for teams building .NET microservice architectures. The gateway supports HTTP, HTTPS, WebSocket, and WebSocket Secure traffic, and it is installed as a NuGet package inside an ASP.NET Core application. Its audience is therefore developers and platform teams already working within the ASP.NET Core ecosystem.
Its strongest area is the breadth of gateway behavior available within that focused environment. Ocelot supports authentication and authorization through configurable ASP.NET Core schemes, including JWT bearer and IdentityServer bearer-token support. Teams can apply rate limiting globally or per route, transform claims, headers, query strings, paths, and HTTP methods, and use request aggregation, caching, load balancing, and quality-of-service middleware. WebSocket, WebSocket Secure, and SignalR proxying extend its usefulness beyond straightforward HTTP forwarding. Service discovery integrations for Consul, Kubernetes, Eureka, and Service Fabric also support deployments where downstream services are managed dynamically.
The main trade-off is its deployment and ecosystem focus. Ocelot is self-hosted and operates inside an ASP.NET Core application, so it is best suited to teams comfortable managing a .NET-based gateway and its configuration. Buyers seeking a gateway that fits outside ASP.NET Core or want a different deployment model should consider an alternative. Ocelot is a strong match when routing, authentication, transformations, rate controls, discovery, and service-proxy capabilities need to sit close to .NET services; it is less suitable when the priority is a broader platform approach rather than a focused ASP.NET Core implementation.
Ocelot pros and cons
- Where it wins
- Broad routing, security, throttling, transformation, and proxy features
- Supports Consul, Kubernetes, Eureka, and Service Fabric discovery
- Handles HTTP(S), WebSocket, WSS, and SignalR proxying
- Where it doesn't
- Self-hosted deployment requires an ASP.NET Core application
- Designed primarily for .NET microservice architectures
- Configuration and route forwarding require application-level setup
Ocelot fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update