We have developed APIs in GCP VPC that need to be protected via Google Cloud Endpoint or Apigee. Apigee is expensive. Is Apigee more secure than Cloud Endpoint?
Kong is typically a lot less expensive than apigee and leverages a plugin architecture allowing you to leverage OIDC or mutual TLS - https://docs.konghq.com/hub/kong-inc/openid-connect/
Cloud endpoints is secure -- the better question is does its security features meet your operational requirements?
What strategic & tactical capabilities are you leveraging with your API’s in GCP? Are you looking to accelerate data ingestion, storage, analysis or integration capabilities? Are you planning on leveraging API monetization / metering capabilities? Are you looking to leverage full-lifecycle API Management? If yes than Apigee may be a great fit.



