Api Management Platform Competition Concerns IN UK
API Management Platform Competition Concerns in the UK
1. Introduction
API management platforms sit between API providers and API consumers. They typically perform functions such as API authentication, authorisation, traffic management, rate limiting, monitoring, analytics, billing, developer access, security and API discovery.
Examples include enterprise API gateways and management layers operated by cloud providers, software vendors, financial-infrastructure firms and digital platforms.
From a UK competition-law perspective, an API management platform can become strategically important where competitors, downstream businesses or complementary service providers depend upon it. The central concern is therefore not merely the existence of an API, but whether control over the API-management layer becomes a mechanism for market power, exclusion or dependency.
The UK framework is particularly relevant because the CMA is increasingly addressing interoperability, data portability, cloud switching and platform access. Its cloud-services investigation identified competition concerns and recommended consideration of Strategic Market Status investigations for Microsoft and AWS; in 2026 the CMA also reported steps by Microsoft and Amazon concerning interoperability and cloud egress.
2. Applicable UK Legal Framework
A. Competition Act 1998 — Chapter II
Section 18 prohibits an undertaking with a dominant position from abusing that position.
For an API-management platform, potential abuses include:
- refusal to provide API access;
- discriminatory access conditions;
- excessive API-management fees;
- discriminatory rate limits;
- degrading API performance for competing services;
- self-preferencing the platform's own applications;
- tying API-management services to cloud or software products;
- technical interoperability restrictions;
- withholding essential technical documentation;
- discriminatory authentication requirements;
- unreasonable suspension or termination;
- using API data to disadvantage dependent businesses.
B. Digital Markets, Competition and Consumers Act 2024
The DMCC Act provides the CMA with a specialised regime for firms designated with Strategic Market Status (SMS).
This is particularly important for API management because interoperability, access to platform functionality, data portability and switching can be addressed through conduct requirements rather than relying exclusively upon traditional abuse-of-dominance doctrine.
For example, the CMA's mobile-platform work has expressly addressed interoperable access, including mechanisms through which developers can request access to platform functionality.
C. Competition Act 1998 — Chapter I
API-management firms can also create competition concerns through agreements or coordinated conduct involving:
- API access restrictions;
- exclusivity;
- customer allocation;
- standard-setting;
- information exchange;
- common API pricing;
- restrictions on interoperability.
D. Cloud and digital-market regulation
API management is increasingly intertwined with cloud infrastructure. Consequently, competition analysis may extend beyond the API gateway itself to:
cloud infrastructure → identity layer → API gateway → API marketplace → analytics → billing → downstream applications.
The CMA's cloud investigation found an adverse effect on competition and recommended consideration of SMS investigations into the largest cloud providers.
3. Principal Competition Concerns
3.1 API Gateway Dominance
An API gateway can become a critical intermediary between:
- developers and applications;
- applications and databases;
- fintechs and banking infrastructure;
- merchants and payment systems;
- cloud services and enterprise customers;
- AI applications and foundation models.
If one provider controls a sufficiently important gateway, it may acquire intermediation power.
The relevant question is whether competitors can reasonably bypass the gateway.
If switching requires extensive:
- code rewriting;
- authentication changes;
- security reconfiguration;
- monitoring migration;
- data migration;
- contract renegotiation;
then the gateway may generate significant switching costs.
4. Refusal or Restriction of API Access
A dominant platform could refuse interoperability with competing applications.
The traditional UK/EU essential-facilities principles require careful analysis, particularly concerning indispensability, elimination of competition and objective justification.
Albion Water Ltd v Water Services Regulation Authority [2006] CAT 7
The Competition Appeal Tribunal examined access to infrastructure controlled by a dominant undertaking. Thames Water's approach to access pricing was scrutinised under Chapter II. The Tribunal set aside the regulator's conclusion concerning the initial access price.
Relevance to API management:
Where an API-management layer functions as an important infrastructure bottleneck, access conditions and pricing can become competition-law issues rather than merely contractual matters.
5. Discriminatory API Access
A platform may technically provide access while giving different commercial or technical treatment to:
- its own applications;
- affiliated companies;
- preferred partners;
- independent competitors.
Examples include:
| Conduct | Competition concern |
|---|---|
| Higher rate limits for own apps | Self-preferencing |
| Lower latency for affiliates | Discriminatory access |
| Faster API approvals for subsidiaries | Foreclosure |
| Better documentation for internal products | Information advantage |
| Competitor-specific throttling | Raising rivals' costs |
| Different authentication requirements | Unequal access |
The distinction between legitimate technical differentiation and discriminatory exclusion is critical.
6. API Degradation
A particularly sophisticated form of exclusion can occur without formally denying access.
The API remains available but its:
- latency increases;
- request quotas decrease;
- uptime deteriorates;
- response quality changes;
- documentation becomes less complete;
- authentication process becomes more burdensome.
This can make a competing service commercially inferior.
The competition question becomes whether the degradation reflects legitimate:
- cybersecurity;
- capacity management;
- reliability;
- fraud prevention;
or instead constitutes exclusionary conduct.
7. Self-Preferencing
An API-management provider may operate both:
- the infrastructure layer; and
- competing downstream applications.
It may therefore have an incentive to favour its own services.
Potential mechanisms include:
API gateway → privileged routing → superior latency → better application performance → customer migration → strengthened gateway dominance.
This resembles broader digital-platform concerns examined by the CMA.
For example, the CMA has imposed a fair-ranking conduct requirement on Google's general-search services requiring objective and non-discriminatory ranking criteria.
The principle is potentially relevant by analogy where an API-management platform controls the technical conditions through which competing applications reach users.
8. API Tying and Bundling
An API-management provider could require customers purchasing one service to purchase another.
Examples:
- API gateway + cloud hosting;
- API management + identity services;
- API gateway + analytics;
- API access + proprietary database;
- API access + proprietary authentication;
- API management + payment processing.
Tying becomes particularly problematic if the provider has significant market power in the tying product and uses that power to foreclose competitors in the tied market.
9. Switching Costs and Lock-In
API-management platforms can generate substantial technological switching costs.
A customer may need to replace:
- API policies;
- authentication systems;
- access tokens;
- rate-limit rules;
- developer portals;
- monitoring dashboards;
- API specifications;
- logging systems;
- billing integrations;
- security policies.
Consequently, even a technically substitutable API-management platform may not constitute an effective competitive substitute.
The CMA's work on cloud services is especially relevant because it identified structural competition concerns surrounding cloud services and switching-related conditions.
10. Data and Analytics Advantages
API-management platforms receive valuable information concerning:
- API calls;
- customer demand;
- transaction frequency;
- latency;
- failed transactions;
- application behaviour;
- developer activity;
- geographic demand;
- usage patterns.
If the platform also competes downstream, this information can create a potential data advantage.
For example:
Independent application → API gateway → gateway collects usage data → gateway's affiliated application uses aggregated intelligence → independent competitor faces informational disadvantage.
The CMA's recent work on smart data specifically identifies limited interoperability, data-transfer difficulties and absence of real-time API mechanisms as potential barriers to effective data mobility.
11. API Pricing and Excessive Charges
API-management platforms can impose:
- per-call fees;
- bandwidth charges;
- minimum commitments;
- premium authentication charges;
- egress fees;
- developer-access fees;
- API marketplace commissions.
Competition concerns may arise where a dominant provider imposes excessive or discriminatory access charges.
The analysis would normally consider:
- market power;
- cost structure;
- comparable prices;
- profitability;
- competitive constraints;
- customer alternatives;
- technical necessity;
- objective justification.
12. API Documentation as a Competitive Bottleneck
API documentation may appear insignificant but can be commercially crucial.
A platform could disadvantage competitors by:
- delaying documentation;
- withholding technical specifications;
- changing specifications without adequate notice;
- providing incomplete sandbox environments;
- restricting testing;
- withholding error codes;
- imposing disproportionate certification requirements.
The CMA's interoperability work emphasises transparent and objective processes for requests for access to platform functionality.
13. Security Justifications
API providers will often argue that restrictions are necessary to protect:
- cybersecurity;
- consumer privacy;
- fraud prevention;
- system stability;
- intellectual property;
- authentication integrity.
These can constitute legitimate justifications.
The important competition-law issue is proportionality.
A platform should not be able to invoke "security" as a blanket justification for conduct that unnecessarily excludes competitors.
Recent European digital-platform jurisprudence is particularly relevant to this reasoning. The Court of Justice has considered whether refusal to make a digital platform interoperable may constitute abuse and recognised legitimate security and technical justifications where supported by evidence.
Although that is EU rather than UK authority, it provides useful comparative reasoning for UK analysis.
14. Six Key Case Laws / Authorities
Because there is no large body of UK reported litigation specifically about modern API-management platforms, the following authorities should be divided between directly relevant UK digital cases and analogous access/interoperability cases.
1. Albion Water Ltd v Water Services Regulation Authority [2006] CAT 7
Principle: access to infrastructure controlled by a dominant undertaking can raise Chapter II concerns, including questions concerning access pricing.
API relevance: API gateways may constitute digital infrastructure where competitors materially depend on access.
2. Albion Water Ltd v Water Services Regulation Authority [2006] CAT 36
The Tribunal considered dominance in a highly constrained infrastructure market, including the absence of effective potential competition and substantial barriers to entry.
API relevance: useful for analysing whether an API-management layer has sufficient market power to constitute a bottleneck.
3. Streetmap.EU Ltd v Google Inc [2016] EWHC 253 (Ch)
This is particularly relevant to API economics. The judgment records that Streetmap's API was an important part of its business and that Google's free Maps API affected Streetmap's ability to compete for business customers.
API relevance: demonstrates that API access, pricing and distribution can materially affect competitive conditions.
4. Infederation Ltd v Google Inc & Others
This UK Competition Appeal Tribunal litigation concerned alleged abuse of dominance under section 18 Competition Act 1998 and the Google Shopping decision. Although ultimately withdrawn following settlement in 2026, the litigation illustrates the continuing importance of platform-discrimination theories in UK digital competition litigation.
API relevance: platform operators that control an intermediation layer can face scrutiny concerning preferential treatment of their own services.
5. Google Android / Google Play CMA investigation
The CMA investigated Google's requirement that certain Android app developers use Google Play's billing system. The investigation was conducted under Chapter II of the Competition Act 1998.
API relevance: illustrates the competition-law significance of controlling an intermediary layer between applications and consumers, particularly where technical or commercial rules restrict alternative routes.
6. CMA Mobile Platforms / Apple-Google interoperability measures
The CMA's mobile-platform regime now expressly addresses interoperability. In 2026, the CMA reported commitments involving mechanisms allowing developers to request interoperable access to platform functionality and requiring fairer, more transparent consideration of such requests.
API relevance: highly relevant to modern API ecosystems because interoperability is effectively the ability of an external service to communicate with and use functionality controlled by another platform.
15. Cloud Services as an API Competition Issue
API management cannot realistically be separated from cloud competition.
A simplified dependency chain is:
Cloud provider → compute/storage → identity → API gateway → API management → application → customer
If the same firm controls several layers, it can potentially use power at one level to reinforce another.
The CMA's cloud investigation concluded in 2025 that competition in UK public-cloud infrastructure was not working as well as it could and recommended consideration of SMS investigations concerning Microsoft and AWS.
In March 2026, the CMA announced that Microsoft and Amazon had taken material steps concerning interoperability and cloud egress fees following CMA engagement, subject to continuing review.
This makes API portability + cloud portability + data portability an increasingly connected competition-law issue.
16. API Management and Strategic Market Status
Under the UK's DMCC framework, the most significant firms may face conduct requirements specifically designed to address persistent competition problems.
The CMA has already used this framework for Google's mobile platform and search services. Google's mobile platform was designated as having SMS in October 2025, with subsequent work concerning app certainty, steering and interoperability.
The same regulatory logic could potentially become relevant to API-controlled ecosystems where a platform possesses substantial entrenched market power and external businesses depend upon access.
17. Potential Remedies
Possible UK competition remedies could include:
Structural remedies
- separation of API-management and downstream businesses;
- divestiture in exceptional circumstances.
Behavioural remedies
- non-discriminatory API access;
- transparent eligibility requirements;
- reasonable API pricing;
- interoperability obligations;
- objective rate-limit policies;
- prohibition of discriminatory degradation;
- transparent API-change notifications.
Portability remedies
- API configuration portability;
- data portability;
- export of API-management policies;
- migration tools;
- standardised authentication interfaces.
Governance remedies
- independent interoperability review;
- complaint mechanisms;
- audit trails;
- publication of access criteria;
- regulatory monitoring.
18. Competition-Law Test for an API Management Platform
A practical UK analysis can be structured as follows:
1. Define the market
↓
2. Determine whether the API-management provider has substantial market power
↓
3. Identify the dependency created by the API layer
↓
4. Identify exclusionary conduct
↓
5. Examine effects on competitors and customers
↓
6. Consider objective justification
↓
7. Examine proportionality
↓
8. Consider Competition Act / DMCC intervention
↓
9. Determine appropriate interoperability, access or portability remedy
19. Emerging Competition Risks
The most significant future issues are likely to involve:
- AI-agent APIs and access to foundation-model functionality;
- API gateways controlling autonomous AI agents;
- cloud-to-AI API bundling;
- API marketplace self-preferencing;
- proprietary authentication systems;
- API usage-data advantages;
- dynamic algorithmic rate limiting;
- API access discrimination;
- API degradation against competitors;
- cross-platform interoperability;
- API switching and migration costs;
- data portability;
- API security standards used as exclusionary mechanisms;
- API billing and revenue-sharing arrangements.
The CMA's current digital-market agenda already shows increasing attention to interoperability, data portability, fair ranking, steering and cloud switching conditions, making these highly relevant directions for UK competition analysis.
Conclusion
API management is increasingly capable of becoming a competition-law bottleneck rather than merely a technical service. The key UK concern arises where a platform controls an important interoperability layer and uses that control to restrict access, discriminate between users, favour its own downstream services, increase switching costs, exploit API-generated data or reinforce dependence on its wider cloud or software ecosystem.
The strongest analytical combination is therefore:
dominance + technical dependency + discriminatory/exclusionary API conduct + competitive effects + absence of proportionate objective justification.

comments