API gateways centralize cross-cutting concerns — until they become a single point of confusion.
Good reasons to introduce one
Unified auth, rate limiting, and edge routing across many backend services.
Bad reasons
Putting business logic in the gateway. That creates an unowned, hard-to-test mega-layer.
Operational basics
Timeouts, retries with jitter, and clear error mapping keep clients sane during partial outages.