The gateway and the application handle different checks
A gateway can manage access, throttle requests and enforce technical rules. Whether a specific user is allowed to read a particular order must additionally be decided in the responsible service. We plan token validation, service identities, tenant assignment and logging along this boundary. For write calls, we clarify how repeated requests are handled. Old versions follow a clear deprecation process, so that changes do not unexpectedly break partner connections.


