API Manager policies are governance rules applied to APIs deployed on Anypoint Platform — controlling authentication, authorisation, traffic management, threat protection, and header manipulation. Policies are applied to an API instance in API Manager and enforced by the Anypoint Gateway or Mule runtime, without modifying the Mule application code. This means security and rate limiting are applied consistently across all API instances, can be updated centrally without redeploying the Mule application, and are visible in Anypoint Analytics for monitoring. We configure OAuth 2.0, JWT validation, client ID enforcement, SLA-tiered rate limiting, TLS, and custom policies for every API.