WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [Event Gateway](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Engineering
  4. Centralized Kong Management with Active Directory/LDAP
[Engineering](/blog/engineering)Engineering
April 24, 2020
5 min read

# Centralized Kong Management with Active Directory/LDAP

Felderi Santiago
Vice President Solutions Engineering - Americas

Kong Enterprise provides customers with the fastest, most scalable and flexible API management solution in the market. One of Kong's main advantages is the ability to quickly deploy and integrate with a customer's ecosystem of already-deployed solutions for identity management and monitoring.

As customers choose Kong to drive the decentralization of their applications, it’s critical to empower teams for end-to-end deployment while maintaining security and compliance. To do this, application groups should have enough access to accomplish their goals of rapid/automated deployments without granting too much access which could impact other teams.

Kong's Workspaces, fine-grained [role-based access control (RBAC)](https://konghq.com/blog/learning-center/what-is-rbac)role-based access control (RBAC) and concepts of Teams and Groups allow customers to accomplish this goal while integrating with the most prevalent identity management systems like Active Directory (AD) to drive proper security and compliance.

If you're new to Kong, a Kong Workspace is the ability to segment a single Kong installation into micro Kong environments that can be used by multiple teams.

For this blog post, we will look at Engineering Manager Fel Santiago and how we can use Active Directory to provide Fel the access he needs to manage his applications with Kong.

In particular, we will look at how Kong Workspaces, Teams and RBAC capabilities allow centralized access to be driven by the corporate Active Directory environment. This blog post equally applies to any Enterprise LDAP directory. In particular, we will accomplish the following:

  • - Integrate Kong with Active Directory
  • - Confirm AD user Fel can authenticate to Kong Manager
  • - Create a new Workspace for the Engineering group
  • - Assign an AD group a Kong role in the Engineering Workspace to confirm AD groups can be used to drive access to Kong

To follow along and perform this integration your environment, you'll need:

  • - Kong Enterprise installed and Kong Manager enabled. See Kong's installation [instructions](https://docs.konghq.com/enterprise/1.3-x/deployment/installation/overview)instructions.
  • - An AD environment to integrate with
  • - A service account and password to bind to AD
  • - One AD group

Let's get started.

## **Step 1 – Confirm Kong Is Installed Correctly and the Kong Nodes Can Communicate with AD**

Confirm Kong Enterprise is properly installed and Kong Manager is enabled by opening a browser and visiting http://<your_host>:8002 where <your_host> is the IP or hostname/fqdn of the host where Kong Manager is running.

If Kong is running and Kong Manager is properly configured, you will see Kong Manager load successfully.

Next, let's confirm the Kong nodes can communicate with the AD environment to authenticate and look up users/groups. There are a number of ways to do this, but a simple ping to the domain, if your environment allows, should confirm. The AD environment I will be using is kongad.com.

$ ping kongad.com
PING kongad.com (192.168.125.149) 56(84) bytes of data.
64 bytes from kongad.com (192.168.125.149): icmp_seq=1 ttl=128 time=0.490 ms
64 bytes from kongad.com (192.168.125.149): icmp_seq=2 ttl=128 time=0.610 ms

## **Step 2 – Set Up the Access Model**

The next step is to configure Admins, Groups and Roles in Kong to drive the appropriate level of access.

In this environment, we will set up the following access model:

  • - Create a new Workspace for our Engineering group named Engineering
  • - Create a mapping between the Kong Workspace admin role and the AD group to allow the AD group to drive access
  • - Create a new Kong Admin that maps to an AD user that should have access to Kong

The end result is the AD user should be able to authenticate to Kong Manager with AD credentials and have access to only the Engineering Workspace as a Workspace admin.

**Create a Workspace**

Let's create a Workspace by clicking on the New Workspace button, providing the name Engineering and picking our preferred color.

Once completed, Kong will open the Engineering Workspace.

**Mapping Groups to Kong Roles**

Let's now map a group in Kong to an AD group. To do this, we select Teams in the navigation bar, select the Groups tab and click New Group. Give the group the same name as the AD group you want to map, click Add/Edit Roles and select the Engineering Workspace-Admin role.

Any AD user that's a member of this group will be a Workspace Admin in the Engineering Workspace.

**Create Kong Admins**

The next step is to create Kong Admins that match the names of the users AD that will administer Kong.

In my AD environment, I have a user with samAccountName of Fel that's a member of the AD group Kong_Engineering_Workspace_Admins.

To create a Kong Admin, click on Teams, the Admins tab and click +Invite Admin. Enter an email address, set the username and custom_id to the AD user's samAccountName - Fel in my case. To enable access for this user to the Kong Admin API, check the box Enable RBAC token.

Note we will not select any Roles for the Admin(s) since the user's role will be inherited by the roles their AD group membership is mapped to.

## **Step 3 – Integrate Kong With the Existing AD Environment**

For the purpose of this blog post, we will be conducting a rather simple integration with no TLS.

Log on into the Kong node(s) where Kong Manager is enabled, edit /etc/kong/kong.conf and set the parameters below with the settings specific for your environment.

admin_gui_auth_conf = { "anonymous":"", \
  "attribute":"sAMAccountName", \
  "bind_dn":"cn=svc_kong,ou=Users,ou=kongad,dc=kongad,dc=com", \
  "base_dn":"ou=kongad,dc=kongad,dc=com", \
  "group_base_dn":"ou=groups,ou=kongad,dc=kongad,dc=com", \
  "group_name_attribute":"cn", \
  "cache_ttl":2, \
  "header_type":"Basic", \
  "keepalive":60000, \
  "ldap_host":"kongad.com", \
  "ldap_password":"<BIND_USER_PASSWORD>", \
  "ldap_port":389, \
  "start_tls":false, \
  "timeout":10000, \
  "verify_ldap_host":true, \
  "consumer_by":["username", "custom_id"] \
}

Let me explain the key parameters to make this integration work. For complete details on these parameters, see the Kong advanced ldap plug-in [page](https://docs.konghq.com/hub/kong-inc/ldap-auth-advanced)page.

  • - attribute – This is the user attribute Kong will look for in AD to authenticate the user
  • - bind_dn – The distinguished name (DN) of the service account used to bind to the directory to authenticate and look up identities
  • - base_dn – The distinguished name (DN) used to search for users
  • - group_base_dn – The distinguished name (DN) to use to search for groups
  • - group_name_attribute – This is the group attribute Kong will search for groups in AD
  • - ldap_host – The name of the AD domain
  • - ldap_password – The password of the bind user configured in bind_dn

Save your configuration and restart Kong:

/usr/local/bin/kong restart

Once Kong is integrated with Active Directory, you can use AD principals to drive access in Kong.

## **Step 4 – Validate the Integration**

Now it's time to validate the integration. Open a new private/incognito window and visit Kong Manager at http://<your_host>:8002.

Log on with the Kong Admin(s) configured in Step 2 with the Active Directory password and confirm the user can only access the Engineering Workspace. In my case, the username is fel and entering a correct AD password allows the user to login.

Let's click on the default Workspace to validate if the user has access. As expected, the user has insufficient access.

Go back to Workspaces and click on Engineering Workspace, and this time the user fel has full access to the Engineering Workspace. Success!

Note: The default user for Kong is kong_admin. Once you enable LDAP authentication, the kong_admin user will not be able to authenticate unless you a) create an AD user with samAccountName of kong_admin or b) you change the name of kong_admin to match an AD user. Instructions to accomplish the latter can be found [here](https://docs.konghq.com/enterprise/1.3-x/kong-manager/service-directory-mapping/#set-up-a-directory-user-as-the-first-super-admin)here.

I hope you found this blog post helpful! In summary, we've looked at how integrating Kong with Active Directory helps customers accelerate the move to decentralized applications by empowering teams for end-to-end delivery while maintaining security and compliance. In a future blog post, we will cover how Kong can deliver these same benefits with any OpenID Connect compatible solution.

- [API Management](/blog/tag/api-management)API Management- [Kong Gateway](/blog/tag/kong-gateway)Kong Gateway- [Secrets Management](/blog/tag/secrets-management)Secrets Management

## More on this topic

_Videos_

## BMW’s Decentralized API Gateway at Scale

_Videos_

## From Alert to Action: AI-Driven API Outage Analysis

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [API Management](/blog/tag/api-management)API Management- [Kong Gateway](/blog/tag/kong-gateway)Kong Gateway- [Secrets Management](/blog/tag/secrets-management)Secrets Management
Felderi Santiago
Vice President Solutions Engineering - Americas

Recommended posts

# Announcing Standard Webhooks

[Engineering](/blog)EngineeringDecember 13, 2023

We're pleased to announce the launch of Standard Webhooks!  Kong has been part of the Technical Committee of this standard with other great companies like Svix (the initiator of the project), Ngrok, Zapier, Twillio, Lob, Mux, and Supabase. This was

Vincent Le Goff
[](https://konghq.com/blog/engineering/announcing-standard-webhooks)

# 4 Ways to Deploy Kong Gateway

[Engineering](/blog)EngineeringMay 23, 2023

There are many different ways to deploy Kong Gateway. In this post, Viktor Gamov (Principal Developer Advocate at Kong) walks through the four most popular ways. Depending on your particular use case, you may find that one or more of these is a goo

Viktor Gamov
[](https://konghq.com/blog/engineering/4-ways-to-deploy-kong-gateway)

# Securing your Services and Applications with Styra Declarative Authorization Service (DAS) & Kong Gateway Enterprise

[Engineering](/blog)EngineeringSeptember 26, 2022

Jeff Broberg, William Seaton and Peter Sullivan from Styra also contributed to this post API Gateway Authentication (AuthN) and Authorization (AuthZ) are important ways to control the data that is allowed to be transmitted using your APIs. Basically

Claudio Acquaviva
[](https://konghq.com/blog/engineering/kong-gateway-enterprise-and-styra-das)

# API Composition with StepZen and Kong

[Engineering](/blog)EngineeringSeptember 15, 2022

There are many pros and cons for both GraphQL and REST APIs, but one of the areas where GraphQL really shines is API composition. Taking data from multiple APIs and combining them to make something new is a key part of delivering a useful service.

Michael Heap
[](https://konghq.com/blog/engineering/api-composition-with-stepzen-and-kong)

# A Tour of Kong's Routing Capabilities

Kong Logo
[Engineering](/blog)EngineeringJanuary 8, 2019

Routing Tricks and Tips Kong is very easy to get up and running: start an instance, configure a service, configure a route pointing to the service, and off it goes routing requests, applying any plugins you enable along the way. But Kong can do a lo

Kong
[](https://konghq.com/blog/engineering/tour-kongs-routing-capabilities)

# Practical Strategies to Monetize AI APIs in Production

[Engineering](/blog)EngineeringMarch 27, 2026

Traditional APIs are, in a word, predictable. You know what you're getting: Compute costs that don't surprise you Traffic patterns that behave themselves Clean, well-defined request and response cycles AI APIs, especially anything that runs on LLMs

Deepanshu Pandey
[](https://konghq.com/blog/engineering/monetize-ai-apis)

# Modernizing Integration & API Management with Kong and PolyAPI

[Engineering](/blog)EngineeringFebruary 9, 2026

The goal of Integration Platform as a Service (iPaaS) is to simplify how companies connect their applications and data. The promise for the first wave of iPaaS platforms like Mulesoft and Boomi was straightforward: a central platform where APIs, sys

Gus Nemechek
[](https://konghq.com/blog/engineering/kong-and-polyapi)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo
Ask AI for a summary of Kong
  • [](https://chatgpt.com/s/t_69b981cfa37081919ce25ce107c431c1)
  • [](https://share.google/aimode/hyefOiNwl8pg8W99d)
  • [](https://www.perplexity.ai/search/what-solutions-does-kong-offer-VsYWPddxQjajgvLA4B9hjQ)
Stay connected

## step-0

    • Company
    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
    • Legal
    • [Terms](/legal/terms-of-use)Terms
    • [Privacy](/legal/privacy-policy)Privacy
    • [Trust and Compliance](https://trust.konghq.com)Trust and Compliance
    • Platform
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • Explore More
    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • Open Source
    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode