API Gateway REST APIs with zero requests in 30 days, a check that raises no findings today
What does ZopNight detect here?
ZopNight looks for Amazon API Gateway REST APIs whose CloudWatch `Count` metric shows zero requests over a 30-day window with at least 7 days of peak data. It raises no finding today: a finding needs a positive monthly cost for the API, and ZopNight currently prices every API Gateway API at $0.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-166 |
| Category | idle |
| Severity | medium |
| Metric | Count |
| Threshold | zero requests |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | apigateway:GET · cloudwatch:GetMetricStatistics |
Where it applies
An unused API costs little, unless something is provisioned behind it
API Gateway pricing says you only pay when your APIs are in use, with no minimum fees or upfront commitments; REST and HTTP APIs bill for the calls they receive and the data they send out. The exception is the optional stage cache, which is charged at an hourly rate set by the cache size, and which keeps charging with zero traffic.
So an abandoned API is mostly a hygiene problem: an exposed endpoint nobody owns. When it has a cache or other standing charge attached, it is also a cost problem worth checking by hand.
Checking request counts yourself
aws apigateway get-rest-apis --query 'items[].[id,name,createdDate]'aws apigatewayv2 get-apis --query 'Items[].[ApiId,Name,ProtocolType]'
aws cloudwatch get-metric-statistics --namespace AWS/ApiGateway --metric-name Count \ --dimensions Name=ApiName,Value=orders-api \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumREST API metrics use the
ApiName dimension;
HTTP and WebSocket APIs, which this check does not cover, use
ApiId.
aws apigateway get-stages --rest-api-id <id> shows whether a stage has cacheClusterEnabled.
What counts as a quiet API
The Count series for the API must be present, must include at least 7 days of peak data inside
the 30-day window, and must show a maximum of zero. Then ZopNight needs a positive monthly cost for the API.
Both parts are required. The check covers REST APIs only; HTTP and WebSocket APIs are not
evaluated.
Why no idle API shows up today
Because request charges fall to nothing when requests stop, ZopNight currently records no monthly
cost for API Gateway APIs, stage caches included, so the rule stays silent rather than show a $0
finding. It raises no findings today on any API. A missing or partial
Count series is also treated as unknown, not idle. If you want every abandoned API listed,
regardless of cost, run the commands above and look for APIs with no requests.
When there is a saving, it is the whole cost
saving = monthly cost ZopNight holds for the APIcost after deletion = 0Retiring an API nobody calls
- Check custom domain names and base path mappings:
aws apigateway get-domain-namesandaws apigateway get-base-path-mappings --domain-name api.example.com - Look for Route 53 records, client configs and partner docs that still reference the endpoint.
- Turn off any stage cache first if you want to stop the charge while you confirm.
- Delete the API:
aws apigateway delete-rest-api --rest-api-id a1b2c3d4e5for REST, oraws apigatewayv2 delete-api --api-id a1b2c3d4e5for HTTP and WebSocket APIs.