Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Gateway 3.9: Extended AI Support and Enhanced Security
Product Releases
December 20, 2024
3 min read

Kong Gateway 3.9: Extended AI Support and Enhanced Security

Alex Drag
Head of Product Marketing
Topics
API SecurityAPI GatewayKong GatewayKong Gateway EnterpriseAI Gateway
Share on Social

More on this topic

eBooks

Becoming a Secure API-First Company

eBooks

API Infrastructure: ESB versus API Gateway

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo

Today we're excited to announce Kong Gateway 3.9! 

Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality around LLM support for AI governance and security and threat protection. Keep reading to learn more!

Make your organization even more AI-ready: Added support for 1M+ new AI models and agentic workflows

With the Kong Gateway 3.9 release, we also shipped new improvements to our AI Gateway. This new release ships with support for a new GenAI provider, Hugging Face, providing users with access to more than 1.1 million new AI models. You'll be able to easily secure, observe, and govern the Hugging Face models via the Kong AI Gateway in the same way you are currently able to do so for GCP Vertex, AWS BedRock, Azure AI, OpenAI, Mistral, Antrophic, Cohere, and more.

Support for AI agentic workflows has also been significantly improved by enhancing AI Gateway’s function-calling capabilities across every GenAI provider. Building chatbots, AI agents, and "copilot" capabilities has never been easier while ensuring governance, security, speed, and observability via the AI capabilities available through Kong's AI Gateway.

Enhanced security and threat protection: Injection protection and more advanced rate limiting

Given how mission-critical API security is from a tech and financial perspective, we decided to further our API security offering with new API security functionality: injection protection and service-level rate limiting. 

Injection protection (Enterprise only)

An injection attack is a type of security vulnerability where an attacker exploits flaws in a system to inject malicious data or code into a program, query, or request. The goal is to manipulate the system's behavior, often to gain unauthorized access, retrieve sensitive information, or execute malicious actions. 

There are several different kinds of injection attacks (SQL, XSS, etc.), and now you can use Kong to protect your organization from these malicious threat vectors.

Kong Gateway can now enforce injection protection policies, all powered by the new Injection Protection plugin. This new enterprise plugin is designed to cover a wide range of common injection patterns, such as SQL, XSS, Server-side include, XPath Syntax, and Java Exception — all out of the box. The plugin will extract information from request headers, path, query, or body payload parameters and evaluate that content against pre-defined regular expressions. If the content matches any of the patterns, the request is flagged as malicious and blocked.

If our default patterns don't meet your needs, you can define custom patterns and have the gateway validate requests against those as well. This gives you the power to customize the injection protection plugin to fit the unique API security needs of your organization.

Learn more about getting started with the Injection Protection plugin on the Kong blog, or head over to the plugin documentation.

Advanced rate limiting and service protection

Rate limiting is "bread-and-butter" API gateway functionality and is key in making sure that API traffic is secure, reliable, and performant.

Gateway 3.9 expands the scope of Kong rate limiting, allowing you to enforce fine-grained rate limits and access controls at the service level. While service-level rate limiting was already possible by combining the existing rate-limiting plugin with the advanced rate-limiting plugin, you can now do it with a single plugin dedicated to service-level protection. This enables you to enforce multiple rate limits for a single API at both the service and route or consumer levels when used in conjunction with other rate-limiting plugins.

The new Service protection plugin enables this. To learn more and get started, check out the plugin documentation.

Getting started with Kong Gateway 3.9 

Start with Kong Gateway 3.9 by signing up for Kong Konnect for free. Or, if you want to try Kong Gateway Enterprise 3.9, you can explore the options for getting started here. 

To explore the comprehensive list of features, fixes, and updates, please see the available CHANGELOG for Kong Gateway Enterprise here.

Power your APIs with Kong Gateway

Learn MoreGet a Demo
Topics
API SecurityAPI GatewayKong GatewayKong Gateway EnterpriseAI Gateway
Share on Social
Alex Drag
Head of Product Marketing

Recommended posts

Kong Gateway Enterprise 3.8.x.x EOL

Kong Logo
Product ReleasesSeptember 23, 2025

As of September 2025, Kong Gateway Enterprise 3.8 will enter its End Of Life (EOL) phase and will no longer be fully supported by Kong. Following this, Kong Gateway Enterprise 3.8 will enter a 12-month sunset support period, focused on helping cus

Andrew Jessup

Kong Mesh 2.12: SPIFFE/SPIRE Support and Consistent XDS Resource Names

Kong Logo
Product ReleasesSeptember 18, 2025

We're very excited to announce Kong Mesh 2.12 to the world! Kong Mesh 2.12 delivers two very important features: SPIFFE / SPIRE support, which provides enterprise-class workload identity and trust models for your mesh, as well as a consistent Kuma R

Justin Davies

Announcing terraform-provider-konnect v3

Kong Logo
Product ReleasesAugust 22, 2025

It’s been almost a year since we released our  Konnect Terraform provider . In that time we’ve seen over 300,000 installs, have 1.7 times as many resources available, and have expanded the provider to include data sources to enable federated managem

Michael Heap

Announcing the Kong Agentic AI Hackathon

Kong Logo
NewsAugust 12, 2025

Kong-quer the Agentic AI Hackathon 🚀 Calling all builders, tinkerers, and API innovators. The Kong Hackathon is back for  API Summit 2025 ! This year, we’re challenging developers worldwide to create projects that don’t just react, they  think ,  a

Juhi Singh

How to Build a Multi-LLM AI Agent with Kong AI Gateway and LangGraph

Kong Logo
EngineeringJuly 31, 2025

In the last two parts of this series, we discussed How to Strengthen a ReAct AI Agent with Kong AI Gateway and How to Build a Single-LLM AI Agent with Kong AI Gateway and LangGraph . In this third and final part, we're going to evolve the AI Agen

Claudio Acquaviva

How to Build a Single LLM AI Agent with Kong AI Gateway and LangGraph

Kong Logo
EngineeringJuly 24, 2025

In my previous post, we discussed how we can implement a basic AI Agent with Kong AI Gateway. In part two of this series, we're going to review LangGraph fundamentals, rewrite the AI Agent and explore how Kong AI Gateway can be used to protect an LLM

Claudio Acquaviva

Announcing Kubernetes Ingress Controller 3.5

Kong Logo
Product ReleasesJuly 17, 2025

We're happy to announce the 3.5 release of Kong Ingress Controller (KIC).  This release includes the graduation of combined services to General Availability, support for connection draining, as well as the start of deprecating support for some Ingre

Justin Davies

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

Platform
Kong KonnectKong GatewayKong AI GatewayKong InsomniaDeveloper PortalGateway ManagerCloud GatewayGet a Demo
Explore More
Open Banking API SolutionsAPI Governance SolutionsIstio API Gateway IntegrationKubernetes API ManagementAPI Gateway: Build vs BuyKong vs PostmanKong vs MuleSoftKong vs Apigee
Documentation
Kong Konnect DocsKong Gateway DocsKong Mesh DocsKong AI GatewayKong Insomnia DocsKong Plugin Hub
Open Source
Kong GatewayKumaInsomniaKong Community
Company
About KongCustomersCareersPressEventsContactPricing
  • Terms•
  • Privacy•
  • Trust and Compliance•
  • © Kong Inc. 2025