All Products
Search
Document Center

API Gateway:Upload a plugin

Last Updated:Sep 21, 2026

After you develop a plug-in, you can upload the plug-in as a custom plug-in on the Plug-in page in the Cloud-native API Gateway console. You can view and use the uploaded plug-in by using your Alibaba Cloud account or the credentials of a Resource Access Management (RAM) user that has permissions on the cloud-native gateway. The built-in plug-ins and uploaded plug-ins are enabled in the same way.

Procedure

  1. Log on to the API Gateway console.

  2. In the left-side navigation pane, click Plug-in. In the top navigation bar, select a region.

  3. On the Plug-in page, click Publish Plug-in in the upper-right corner.

  4. In the Publish Plug-in panel, configure the plugin parameters and click Upload. The plugin takes about 30 seconds to publish.

  5. Parameter

    Description

    Select Language

    The programming language used to develop the plugin.

    Plug-in ID

    A unique English identifier for the plugin.

    Plug-in Name

    The display name of the plugin.

    Plug-in Description

    A description of the plugin's purpose. This description is displayed on the plugin card after the plugin is created.

    Version Description

    A description of this version of the plugin.

    WASM File

    Upload the plugin's locally compiled binary file. The filename must end with ".wasm".

    Execution Stage

    The stages are processed in the following order: Authorization > Authentication Phase > Statistics > Default phase. If the plugin's execution does not depend on other plugins, select Authorization.

    Execution Priority

    Controls the execution order within a stage. A larger value indicates a higher priority. If you customize the order, use multiples of 10 to leave space for future adjustments.

    Adapt to Gateway Version

    Select Any Version or Specified Version.

    Any Version: You can install the plugin on a gateway of any version.

    Specified Version: You can install the plugin only on a gateway of the specified version or later.

Plug-in and policy priorities

In the following table, the plug-in or policy that is listed higher up has a higher execution priority than those listed lower down.

Item

Type

Execution stage

Priority

Remarks

IP address blacklist or whitelist

Policy

RBAC Filter

http-real-ip

Plug-in

Authorization

980

Throttling

ModelRouter

Plug-in

Authorization

900

Built in an AI API

ModelMapper

Plug-in

Authorization

800

Built in an AI API

frontend-gray

Plug-in

Authorization

450

Transmission

geo-ip

Plug-in

Authorization

440

Transmission

DeGraphQL

Plug-in

Authorization

430

Transmission

cache-control

Plug-in

Authorization

420

Transmission

Request/Response conversion

Plug-in

Authorization

410

Transmission

oauth

Plug-in

Authorization

350

Authentication

jwt-auth

Plug-in

Authorization

340

Authentication

hmac-auth

Plug-in

Authorization

330

Authentication

basic-auth

Plug-in

Authorization

320

Authentication

key-auth

Plug-in

Authorization

310

Authentication

External authentication

Plug-in

Authorization

300

Authentication

OPA

Plug-in

Authorization

225

Authentication

Request validation

Plug-in

Authorization

220

Transmission

IP address block

Plug-in

Authorization

210

Security

JWT Logout

Plug-in

Authorization

50

Authentication

General response caching

Plug-in

Authorization

10

Transmission

CORS

Plug-in

Authentication

340

Security

waf

Plug-in

Authentication

330

Security

request-block

Plug-in

Authentication

320

Security

bot-detect

Plug-in

Authentication

310

Security

ai-data-masking

Plug-in

Default

991

AI

ai-statistics

Plug-in

Default

990

AI

ai-security-guard

Plug-in

Default

850

AI

ai-cache

Plug-in

Default

800

AI

ai-quota

Plug-in

Default

750

AI

ai-intent

Plug-in

Default

700

AI

ai-history

Plug-in

Default

650

AI

ai-token-ratelimit

Plug-in

Default

600

AI

ai-prompt-template

Plug-in

Default

500

AI

ai-prompt-decorator

Plug-in

Default

450

AI

ai-network-search

Plug-in

Default

440

AI

ai-transformer

Plug-in

Default

410

AI

ai-rag

Plug-in

Default

405

AI

traffic-tag

Plug-in

Default

400

Throttling

ai-json

Plug-in

Default

150

AI

ai-proxy

Plug-in

Default

110

AI

canary-header

Plug-in

Default

100

Throttling

cluster-key-rate-limit

Plug-in

Default

20

Throttling

key-rate-limit

Plug-in

Default

10

Throttling

Concurrency control/throttling/circuit breaking

Policy

Sentinel Filter

Timeout/retry/traffic replication/header modification/HTTP rewrite/CORS

Policy

Router Filter

FAQ

What are the possible causes of plug-in publish failures?

In most cases, plug-ins fail to be published because the .wasm file of the plug-in is in an invalid binary format. For a demo for loading the .wasm file to your on-premises environment, see Develop plug-ins in Go.