Prowl
53/100
prowl
Benchmarked Sep 19, 2026

Otoroshi Admin API

Admin API of the Otoroshi reverse proxy

api platform_profile
Benchmark Your API

Score Breakdown

Token Efficiency7/10
Parseability7/10
Documentation6/10
Auth Simplicity6/10
Error Clarity4/10
First-Try Success4/10
Consistency3/10
Latency2/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
{
  "service_type": "platform",
  "base_url": "https://maif.local:otoroshi",
  "auth_method": "unknown",
  "auth_config": {
    "notes": "Otoroshi Admin API typically requires authentication via an admin API key header (e.g., Otoroshi-Admin-Api-Key) or session-based auth for the UI. The provided description does not specify credentials or key location.",
    "likely_headers": [
      "Otoroshi-Admin-Api-Key",
      "Authorization: Bearer <token>"
    ]
  },
  "endpoints": [],
  "pricing_model": {
    "type": "free",
    "details": {
      "license": "Apache License 2.0 (open source)",
      "maintainer": "MAIF (French mutual insurance company)",
      "cost": "Free, self-hosted; no SaaS pricing for the OSS edition"
    }
  },
  "rate_limits": {
    "notes": "Rate limiting is not a hard-coded constraint of the Admin API itself; Otoroshi's own rate-limiting features apply to managed routes, not to the Admin API. Concurrency and performance depend on the deployment.",
    "configured_via": "Otoroshi plugins / administration configuration"
  },
  "capabilities": [
    "Reverse proxy and API gateway management",
    "Dynamic service/route registration and configuration",
    "API key and authentication/authorization management",
    "Plugin and extension management",
    "Monitoring, analytics, and audit log access",
    "Certificate and TLS management",
    "Traffic shaping, retries, and circuit breaking",
    "Multi-tenant (organizations/teams) administration",
    "UI/Admin dashboard backed by the Admin API"
  ],
  "raw_analysis": "Otoroshi is an open-source reverse proxy and API gateway developed and maintained by MAIF. The 'Admin API' refers to the HTTP interface exposed by an Otoroshi instance that powers its administration UI and allows programmatic control over the gateway. The given URL (https://maif.local:otoroshi) is clearly an internally deployed instance, likely using an internal DNS name (maif.local) and a non-standard port. This is not a public SaaS endpoint; it is self-hosted infrastructure.\n\nPurpose and audience: Otoroshi targets platform engineers, DevOps, and API teams who need to expose, secure, and govern HTTP services at scale. It supports dynamic reconfiguration, plugin-based extension, multi-tenant team management, and detailed analytics.\n\nMaturity: Otoroshi is a mature, production-used project (Apache 2.0) with an established ecosystem (Otoroshi Cloud / Cloud APIM commercial offering by MAIF). It has been under development since around 2018 and is used in French public-sector and enterprise contexts.\n\nAdmin API characteristics: The Admin API is the same interface backing the admin dashboard. It exposes CRUD operations over entities such as services, routes, apikeys, certificates, plugins, groups, organizations, and more. Authentication on the Admin API is typically enforced with an admin API key sent in a dedicated header; when the admin UI is not enabled, the Admin API can still be secured via a token. Because the description does not include a key or auth method, the auth_method here is set to 'unknown' rather than 'none'.\n\nIntegrations: Common integrations include OAuth/OIDC providers, JWT validation, Kafka, Elasticsearch for analytics/audit, LDAP, Prometheus, and generic HTTP backends. The Admin API itself can be driven by Terraform providers, CLI tools, and custom scripts (as well as the official Otoroshi command line and dashboard).\n\nPricing: Open-source and free; a commercial offering (Cloud APIM) exists but is independent of this specific instance.\n\nRate limits: No public documented rate limits for the Admin API; limits would stem from the deployment, reverse proxies in front of it, or configured policies.\n\nAssessment for platform catalog: This is a self-hosted, non-public admin interface. It should typically not be exposed beyond the internal network. For cataloging purposes, it is best treated as an internal admin platform rather than a public API. No public endpoints could be enumerated from the provided description alone."
}
Execute

0/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /None66ms
robots_txtGET /robots.txtNone16ms
llms_txtGET /llms.txtNone15ms
Interpret
{
  "overall": 42,
  "dimensions": {
    "token_efficiency": 7.0,
    "first_try_success": 4.0,
    "response_parseability": 7.0,
    "error_clarity": 4.0,
    "doc_quality": 6.0,
    "auth_simplicity": 6.0,
    "latency": 2.0,
    "consistency": 3.0
  },
  "pricing_normalized": {
    "model": "free",
    "license": "Apache-2.0",
    "self_hosted": true,
    "saas_available": false
  },
  "issues": [
    "All three probes failed with 'Invalid port: otoroshi' — the target URL is malformed or unreachable, blocking all technical verification",
    "Uptime, robots.txt, and llms.txt could not be validated; no security headers confirmed",
    "No SaaS/managed offering — agents recommending it must account for self-hosting burden (infra, ops, upgrades)",
    "No llms.txt or agent-oriented discovery surface confirmed",
    "Latency measured at 66ms but only against a failing request, so true performance is unknown"
  ],
  "recommendations": [
    "Fix the probe target URL (likely needs explicit scheme and port, e.g. https://maif.github.io/otoroshi/) before re-scoring",
    "Confirm whether a hosted/managed Otoroshi exists; if not, agents should caveat recommendations with self-hosting requirements",
    "Publish an llms.txt describing the Admin API surface and auth model for agent consumption",
    "Document the Admin API auth flow (API keys vs JWT) front and center in the getting-started guide",
    "Add a status page or health endpoint so agents can verify operational state"
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
No
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/otoroshi-admin-api">
  <img src="https://prowl.world/badge/otoroshi-admin-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard