Perimattic

API Modernization Services That Open Your Systems to the Modern Ecosystem

We replace SOAP, RPC, and proprietary integration interfaces with REST, GraphQL, and event-driven APIs behind a managed API gateway — with contract-first design, OAuth 2.0 security, and a developer portal delivered as standard.

Since 2018
Delivering API modernization and integration architecture engagements
4.75/5
Verified Clutch rating across API and integration modernization projects
6–16 weeks
Typical API modernization timeline from audit to production

API Standards and Gateway Technologies We Use — REST, GraphQL, OpenAPI 3.0, Kong, AWS API Gateway, OAuth 2.0, gRPC

REST API DesignGraphQLOpenAPI 3.0API GatewayOAuth 2.0SOAP to RESTgRPCAPI VersioningRate LimitingKongAWS API GatewaySwaggerREST API DesignGraphQLOpenAPI 3.0API GatewayOAuth 2.0SOAP to RESTgRPCAPI VersioningRate LimitingKongAWS API GatewaySwagger
Overview

Why Legacy APIs Constrain Your Business — And How We Modernise Them

Legacy API layers accumulate over years of tactical integration decisions. SOAP services built in the 2000s are still carrying business-critical data. Undocumented REST endpoints with no versioning strategy break partner applications every time a developer makes a schema change. Proprietary integration middleware becomes a single point of failure and a barrier to every digital initiative that depends on connecting systems. The cost is not just technical — it is measured in partner onboarding timelines measured in months, mobile applications that cannot consume data in the format they need, and AI integrations that cannot reach the data they require.

Perimattic approaches API modernization contract-first: before a single endpoint is built or refactored, we produce an OpenAPI 3.0 specification that defines the target API — resources, operations, request and response schemas, error models, and versioning strategy. This contract is reviewed with consumers before implementation begins. We then introduce an API gateway as the controlled entry point for all API traffic, configure OAuth 2.0 security, and build the new REST or GraphQL implementation alongside the legacy interface — allowing existing consumers to migrate at their own pace.

The business value of a modern API layer extends beyond technical cleanliness. A well-documented, versioned, gateway-managed API layer enables partner ecosystems to onboard in days rather than months. Mobile and web applications can consume precisely the data they need via GraphQL without over-fetching. AI and data platform integrations can reach operational data through authenticated, rate-limited APIs without requiring database-level access. The API layer becomes a strategic asset — a platform that multiplies the value of every system behind it.

Legacy API Layer vs Modern API Architecture — Perimattic

Legacy API Layer
Modern API Architecture — Perimattic

Developer experience

Undocumented SOAP WSDL interfaces with no interactive documentation or developer portal

Developer experience

OpenAPI 3.0 specification published to a developer portal with interactive try-it-now sandbox

Security model

API keys, Basic authentication, or IP allowlisting with no delegated authorisation

Security model

OAuth 2.0 and OpenID Connect with scoped access tokens, token expiry, and per-client policies

Partner onboarding

Manual credential provisioning with weeks-long onboarding requiring engineering involvement

Partner onboarding

Self-service developer portal registration with automated credential provisioning and sandbox access

Observability

No API-level usage analytics, error rate visibility, or latency SLO tracking

Observability

Per-endpoint analytics, per-consumer quota dashboards, and error rate alerting configured from day one

Versioning and backwards compatibility

Breaking changes deployed without versioning, forcing all consumers to update simultaneously

Versioning and backwards compatibility

Semantic API versioning with deprecation timelines, migration guides, and parallel version support

The API layer is not a technical detail — it is the interface between your systems and every partner, mobile application, and integration that depends on them. Modernising it unlocks the value of everything behind it.

Core Services

API Modernization Services We Deliver

Seven specialist service lines covering every layer of your enterprise API modernization programme.

SOAP to REST and GraphQL Migration

Replace verbose SOAP/WSDL services with lightweight REST and GraphQL APIs. We maintain full backwards compatibility for legacy clients throughout the migration with parallel-run routing at the gateway layer.

OpenAPI 3.0 Contract Design and Documentation

Contract-first API design using OpenAPI 3.0 specification. We define resources, schemas, error models, and versioning before writing implementation code — ensuring consistency across all API consumers.

API Gateway Implementation (Kong, AWS, Azure APIM)

Deploy and configure Kong Gateway, AWS API Gateway, or Azure API Management as the single controlled entry point for all API traffic — with rate limiting, logging, request transformation, and analytics built in.

OAuth 2.0 and OpenID Connect Security

Replace API keys and Basic authentication with OAuth 2.0 authorisation flows and OIDC identity federation. We design token scopes, expiry policies, and per-client access controls from day one.

API Versioning Strategy and Backwards Compatibility

Define and implement an API versioning strategy that allows the API to evolve without breaking existing consumers. We manage deprecation timelines, migration guides, and compatibility layers.

Event-Driven API Design (Webhooks, AsyncAPI)

Replace polling integrations with event-driven APIs using AsyncAPI specification, webhook infrastructure with delivery guarantees, and message broker integration for high-throughput asynchronous data exchange.

API Analytics, Rate Limiting, and Monetisation

Instrument the API layer with usage analytics, per-consumer quota enforcement, SLO tracking, and monetisation metering — giving full visibility into how partners and clients consume your APIs.

Technology Stack

Technologies We Use to Modernise Enterprise APIs

API Gateways

6 tools
Kong GatewayAWS API GatewayAzure API ManagementGoogle ApigeeNginxTraefik

API Design and Standards

6 tools
OpenAPI 3.0GraphQLgRPCAsyncAPISwaggerPostman

Security and Auth

6 tools
OAuth 2.0OpenID ConnectKeycloakAuth0AWS CognitoJWT

Observability and Testing

6 tools
DatadogGrafanak6PostmanInsomniaAWS CloudWatch
How We Engage

Our API Modernization Delivery Process

A structured six-stage process from free API portfolio audit to production API gateway deployment and lifecycle governance.

01

API Portfolio Audit and Contract Mapping (Free)

We inventory every API, integration endpoint, and data exchange — SOAP services, REST endpoints, file transfers, and proprietary middleware — mapping consumers, SLAs, and security posture.

02

Target API Design and OpenAPI Specification

We design the target API contract using OpenAPI 3.0 — defining resources, operations, schemas, error models, and versioning strategy before a single line of implementation code is written.

03

Gateway Selection and Security Architecture

We select and configure the API gateway and design the OAuth 2.0 and OpenID Connect security architecture — including scopes, token lifetimes, and per-client access control policies.

04

API Migration and Client Migration Support

We build the new REST and GraphQL APIs alongside legacy interfaces, route traffic through the gateway, and support each client team through their migration with documentation and compatibility layers.

05

Developer Portal and Documentation Delivery

We publish the OpenAPI 3.0 specification to a developer portal with interactive documentation, authentication guides, code samples, and sandbox environments for internal and partner developers.

06

Monitoring, Analytics, and Lifecycle Governance

We configure API analytics dashboards, error rate alerting, latency SLO tracking, and a deprecation governance process so the API layer continues to serve consumers reliably as it evolves.

Use Cases

API Modernization Across Every Industry

Select an industry to see how we modernise legacy APIs and integration layers with contract-first design and managed API gateways.

Financial institutions modernising their API layers must satisfy PSD2, Open Banking, and GDPR obligations while exposing payment initiation, account data, and product catalogue APIs to authorised third-party providers — all through a managed API gateway with robust OAuth 2.0 security.

  • Open Banking API implementation compliant with PSD2 and FCA Open Banking standards with OAuth 2.0 PKCE flows
  • SOAP-to-REST migration of core banking integration layers with full backwards compatibility for existing client applications
  • API gateway implementation with rate limiting, fraud detection hooks, and per-partner access control policies
  • Payment initiation and account information service APIs designed to OpenAPI 3.0 specification with developer portal documentation
  • Legacy FIX protocol and proprietary trading APIs modernised to REST and WebSocket for real-time market data distribution

Healthcare organisations modernising clinical integrations must adopt HL7 FHIR R4 API standards while retiring legacy HL7 v2 and proprietary vendor interfaces — enabling patient data exchange with EHR systems, payer platforms, and patient-facing applications through a secure, standards-based API layer.

  • HL7 FHIR R4 API implementation replacing legacy HL7 v2 and proprietary EHR integration interfaces
  • SMART on FHIR authorisation framework implemented with OAuth 2.0 and OpenID Connect for patient-facing application access
  • Clinical data exchange APIs designed for interoperability with NHS Digital, Epic, Cerner, and Meditech EHR systems
  • Patient consent management APIs implemented with GDPR and HIPAA-compliant data access audit trails
  • Medical device and IoT sensor data ingestion APIs built on AsyncAPI specification for real-time clinical telemetry

SaaS companies building partner ecosystems and marketplace integrations require a well-documented, versioned API layer that enables third-party developers to build on their platform — replacing ad-hoc webhook implementations and undocumented internal APIs with a managed, monetisable API product.

  • Public API product design with OpenAPI 3.0 specification, developer portal, and SDK generation for partner onboarding
  • Webhook infrastructure replaced with AsyncAPI-specified event-driven APIs with delivery guarantees and retry policies
  • API versioning strategy implemented to allow backwards-compatible evolution without forced client migrations
  • API monetisation and rate limiting configured on Kong or AWS API Gateway with per-plan usage metering
  • Internal microservice APIs consolidated behind a unified API gateway with service mesh observability and distributed tracing

Retail organisations modernising their integration layers must replace point-to-point EDI and SOAP integrations with composable REST and GraphQL APIs that enable headless commerce, real-time inventory, and partner marketplace connectivity across a growing ecosystem of channels and fulfilment providers.

  • Product catalogue and inventory APIs redesigned to GraphQL for flexible headless commerce and mobile application consumption
  • EDI and SOAP order management integrations replaced with REST APIs and webhook-based fulfilment event notifications
  • Payment gateway integrations modernised with PCI-DSS-compliant API design and tokenisation service abstraction
  • Partner marketplace and drop-ship supplier APIs implemented with OpenAPI 3.0 specification and automated onboarding
  • Loyalty and personalisation APIs exposed through a managed API gateway with customer identity federation via OAuth 2.0

Logistics operators modernising supply chain integrations must replace legacy EDI, FTP, and proprietary carrier APIs with real-time REST and event-driven APIs that provide live shipment tracking, automated booking, and partner connectivity across multi-carrier fulfilment networks.

  • Carrier and 3PL integration APIs modernised from legacy EDI and FTP to real-time REST with webhook event notifications
  • Shipment tracking and visibility APIs designed to OpenAPI 3.0 specification with multi-carrier data normalisation
  • Warehouse management system APIs exposed through an API gateway with per-partner rate limiting and access control
  • Cross-border trade and customs documentation APIs integrated with HMRC, CBP, and EU customs APIs via REST
  • IoT and telematics data ingestion APIs built on AsyncAPI for real-time fleet and cold chain monitoring

Government departments modernising public-facing and inter-agency APIs must adopt GOV.UK API standards and data sovereignty requirements while replacing legacy SOAP services and proprietary middleware with accessible, documented REST APIs that enable third-party public service delivery.

  • Citizen-facing service APIs designed to GOV.UK API standards with accessibility compliance and GDPR-lawful data sharing
  • Inter-agency data sharing APIs implemented with attribute-based access control and full audit trail for data governance
  • Legacy SOAP and WSDL government service interfaces replaced with REST APIs and OpenAPI 3.0 documentation
  • API gateway implementation on government-approved cloud infrastructure with sovereign data residency and IL compliance
  • Open data APIs published to data.gov.uk with developer portal, usage analytics, and automated onboarding for approved consumers
Results and Proof

Typical Outcomes From Our API Modernization Engagements

0–16 wks
typical API modernization from audit to production deployment
0+ yrs
delivering API and integration modernization engagements
0.75/5
verified Clutch rating across API and integration projects
0+
industries served including financial services, healthcare, and SaaS
0
specialised API services from SOAP migration to gateway monetisation
Client Testimonials

What Clients Say About Our Integration Work

Verified on ClutchIndependently verified client reviews.

“Their professional behavior was impressive.”

Perimattic's work resulted in stable production systems. The team was helpful, easily accessible, and communicative through email. Their professionalism was impressive.

Quality

4.5

Schedule

5.0

Cost

5.0

Willing to Refer

4.5

Alexander Belozerov

Team Lead, Leasing Automation Company

Wilmington, Delaware · 11–50 employees

DevOps Managed Services · Oct 2023 – Aug 2024

24/7 monitoring and support for production environments plus Linux server administration for a leasing automation company.

“The team's turnaround between when we greenlight tasks and when Perimattic implements them is phenomenal.”

The new architecture is scalable and highly efficient, saving a lot of money in fees. Perimattic provides high-quality IT consulting and cloud development work promptly and at great value. The team remains involved from the planning stage to providing support, showing diligence and proactiveness.

Quality

5.0

Schedule

5.0

Cost

4.5

Willing to Refer

5.0

Alwyn Joy

Solutions Architect, Rezcomm

United Kingdom · 11–50 employees

AWS Migration (Legacy → Microservices) · Nov 2018 – Ongoing

Transitioned a travel systems company's legacy server system to an AWS-based microservices architecture with ongoing maintenance.

Why Perimattic

Why Teams Choose Perimattic to Modernise Their API Layer

Four structural advantages that separate a modern, developer-friendly API platform from an expensive API rewrite that breaks consumers.

01

Contract-First Design Before Writing a Single Endpoint

We design the OpenAPI 3.0 contract and get consumer sign-off before writing implementation code. This prevents the most common cause of API rework: building the wrong interface.

02

Legacy Clients Supported During Migration — No Forced Cutover

Existing SOAP and proprietary API consumers continue to work throughout the migration. We run new and legacy interfaces in parallel, shifting clients incrementally on their own timelines.

03

Security Redesigned With OAuth 2.0 and OIDC From Day One

We do not carry legacy API keys or Basic authentication into the modern API layer. OAuth 2.0 flows and OpenID Connect identity federation are designed into the architecture from the start.

04

Developer Portal Delivered as Part of Every Engagement

Every API modernization engagement includes a developer portal: interactive OpenAPI documentation, authentication guides, sandbox environments, and a changelog — not treated as an optional add-on.

“The difference between a successful API modernization and an expensive API rewrite is not the technology — it is designing the contract with consumers before writing the implementation.”

FAQ

API Modernization: Frequently Asked Questions

What is API modernization?

API modernization is the process of replacing legacy integration interfaces — SOAP services, undocumented RPC endpoints, proprietary middleware, and point-to-point integrations — with standards-based, versioned APIs built to modern specifications such as REST, GraphQL, and AsyncAPI. A modernized API layer introduces an API gateway as the single controlled entry point for all API traffic, enforces OAuth 2.0 security, provides usage analytics and rate limiting, and publishes OpenAPI 3.0 documentation through a developer portal. The result is a system that is easier for partners, mobile applications, and internal teams to consume, and far easier to govern and evolve over time.

What is the difference between SOAP, REST, and GraphQL?

SOAP (Simple Object Access Protocol) is an XML-based protocol that uses WSDL contracts to describe service operations. It is verbose, strongly typed, and was the enterprise integration standard of the 2000s. REST (Representational State Transfer) is an architectural style that uses standard HTTP methods and JSON payloads, making APIs lightweight, cacheable, and easy to consume from any client. REST is the dominant standard for modern web and mobile API design. GraphQL is a query language for APIs that allows clients to request exactly the data they need — no more, no less — in a single request. GraphQL is particularly well suited for consumer-facing APIs where multiple clients (mobile, web, partner) have different data requirements. Most enterprise API modernization projects involve migrating SOAP to REST, and many then add GraphQL as a consumer-facing layer on top of REST microservices.

When should we use GraphQL instead of REST?

GraphQL is the right choice when you have multiple client types — mobile, web, third-party partners — that each need different subsets of the same data. GraphQL eliminates the over-fetching and under-fetching problems that occur when a single REST endpoint serves clients with different data requirements. It is also effective when you are aggregating data from multiple backend services into a single API response, as GraphQL resolvers can fan out to multiple data sources and compose the result. REST remains the better choice for simple resource-oriented APIs, APIs exposed to external public developers who expect RESTful conventions, and high-throughput APIs where HTTP caching provides significant performance benefits. In practice, many organisations adopt both: REST for backend service-to-service APIs and GraphQL as an experience layer for consumer-facing clients.

What are the benefits of an API gateway?

An API gateway provides a single controlled entry point for all API traffic, centralising concerns that would otherwise be duplicated in every backend service: authentication and authorisation, rate limiting and throttling, request and response transformation, SSL termination, logging, and analytics. Without a gateway, every service must implement its own security and throttling logic, creating inconsistency and security risk. The gateway also decouples clients from backend services: the backend can be refactored, scaled, or replaced without changing the API contract that clients depend on. Managed API gateways such as Kong, AWS API Gateway, and Azure API Management additionally provide developer portal capabilities, API key management, and monetisation metering.

How do you handle backwards compatibility during API modernization?

Backwards compatibility is managed through a combination of API versioning strategy, a parallel-run migration period, and traffic routing at the gateway layer. During migration, the legacy SOAP or proprietary API remains live and continues to serve existing clients. The new REST API is introduced alongside it. The API gateway routes requests to the appropriate backend based on the version specified in the request header or URL. Existing clients continue on v1 (legacy) until they have migrated to v2 (modern). We define a deprecation timeline, communicate it through the developer portal, and provide migration guides. No client is forced to cut over until they are ready, and no cutover requires a maintenance window.

What are the best practices for API security?

Modern API security is built on OAuth 2.0 and OpenID Connect rather than API keys or HTTP Basic authentication. OAuth 2.0 provides delegated authorisation — clients obtain short-lived access tokens scoped to specific operations, rather than sharing credentials. OpenID Connect adds identity federation, allowing users to authenticate via their organisation's identity provider. At the gateway layer, rate limiting prevents abuse and denial-of-service attacks. All API traffic should be encrypted in transit via TLS 1.2 or higher. Input validation should be performed at the gateway and at the backend service. Sensitive data should never be returned in API responses unless the caller has explicit authorisation. API access logs should be written to an immutable audit store for compliance and incident investigation.

How long does API modernization take?

The timeline depends on the number of APIs in scope, their complexity, and the number of dependent client applications that must migrate. A typical API modernization engagement runs six to sixteen weeks from the initial API portfolio audit to production deployment of the new API layer and developer portal. The audit and contract design phase typically takes two to four weeks. Gateway configuration and security architecture takes one to two weeks. API migration — building the new endpoints and parallel-running with the legacy layer — takes four to eight weeks depending on complexity. Developer portal delivery and client migration support adds one to two weeks. Large portfolios with dozens of SOAP services or hundreds of undocumented endpoints will take longer and are typically sequenced in waves.

Why is a developer portal important?

A developer portal is the interface between your API and the developers who consume it — internal teams, partner organisations, and third-party application builders. Without a portal, developers must read source code or ask colleagues to understand how an API works. A portal built on OpenAPI 3.0 specification provides interactive documentation, try-it-now sandbox environments, authentication guides, code samples in multiple languages, and changelog history. For external partner APIs and public APIs, the portal is also the onboarding mechanism: developers register, obtain credentials, and begin building without requiring manual intervention from your team. A well-maintained developer portal directly reduces integration support costs and accelerates partner and customer time-to-first-call.

What are the main API versioning strategies?

The three main API versioning strategies are URL path versioning, header versioning, and query parameter versioning. URL path versioning — /v1/orders, /v2/orders — is the most explicit and easiest for developers to understand, making it the most commonly used approach. Header versioning uses a custom request header (e.g., API-Version: 2024-01) to specify the version, keeping URLs clean but making versioning less visible. Query parameter versioning appends the version as a parameter (?version=2) and is the least favoured as it pollutes URLs and interferes with caching. Semantic versioning (major.minor.patch) is useful for communicating the impact of changes: major versions indicate breaking changes, minor versions indicate new backwards-compatible features, and patch versions indicate bug fixes. We recommend URL path versioning for public APIs and header versioning for internal service-to-service APIs.

How do we get started with API modernization?

The starting point is an API portfolio audit: an inventory of every API, integration endpoint, and data exchange in your system — SOAP services, REST endpoints, database-level integrations, file transfers, and proprietary middleware. We document the consumers of each interface, the data it carries, the SLA it must meet, and its current security posture. From this audit we produce a modernization roadmap: a sequenced plan that prioritises high-value, high-risk interfaces first, defines the target API specification for each, and identifies the gateway and security architecture. The first deliverable is a free audit report and roadmap produced in a discovery call — book one to begin.

Get Started

Ready to Modernise Your API Layer and Open Your Platform?

Tell us about your API estate — the SOAP services, undocumented endpoints, and integration pain points — and we will produce an API audit and modernization roadmap in a free discovery call.