Build APIM subscription and product configs with rate limiting, quotas, approval workflows, and named values from Key Vault.
Build APIM subscription and product configs with rate limiting, quotas, approval workflows, and named values from Key Vault.
Required Fields
serviceNameproductsproducts[0].productIdproducts[0].displayNameproducts[0].subscriptionRequiredsubscriptionsOutput will appear here...Build Azure API Management products and subscriptions where a product's rateLimiting (calls per renewalPeriod) and quota (a longer-window cap, often monthly, plus optional bandwidth limit) are two independent throttling layers, not the same control at different granularity, a subscriber can be well under their monthly quota while still getting rate-limited on a short burst exceeding the per-minute call rate. approvalRequired: true on a product means a new subscription request sits pending until an API publisher manually approves it, while subscriptionsLimit caps how many active subscriptions a single developer/group can hold to that product at once, both gates operate independently of each other and independently of the rate/quota policies applied once a subscription is actually active.
Design rateLimiting and quota together as complementary, not redundant, controls, a product needs both a short-window burst protection and a longer-window volume cap to actually cover both abuse patterns they're each meant to address.
Always set an explicit expirationDate on time-bounded partner or trial subscriptions, an indefinite subscription for a relationship with a known end date is a common source of stale, unrevoked access that persists long after it should have lapsed.
Prefer Key Vault-backed namedValues for any credential used in an APIM policy, a plaintext secret embedded directly in policy XML or configuration is both a security exposure and an operational headache to rotate compared to a centrally-managed Key Vault reference.
The builder validates that serviceName, products, the first product's productId/displayName/subscriptionRequired, and subscriptions all resolve before accepting the JSON as a valid combined product and subscription specification; it can't verify the referenced API IDs actually exist in the APIM instance or that the Key Vault secret ID is reachable with correct permissions, those are only confirmed against the live APIM resource provider.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.