---
# === IDENTITY ===
id: business/erp-integration/mulesoft-anypoint-capabilities/2026
canonical_question: "What are MuleSoft Anypoint Platform capabilities - pricing, Mule Flows/Messages, CloudHub 2.0 workers?"
aliases:
  - "MuleSoft Anypoint Platform pricing tiers and limits"
  - "CloudHub 2.0 worker sizes and replica specifications"
  - "MuleSoft usage-based pricing Mule Flows Messages throughput"
  - "MuleSoft integration platform capabilities and quotas"
entity_type: erp_integration
domain: business > erp-integration > mulesoft-anypoint-capabilities
region: global
jurisdiction: global
temporal_scope: 2025-2026

# === SYSTEM PROFILE ===
systems:
  - name: "MuleSoft Anypoint Platform"
    vendor: "Salesforce (MuleSoft)"
    version: "2025-2026 (CloudHub 2.0, Mule Runtime 4.x)"
    edition: "Integration Starter, Integration Advanced, API Management"
    deployment: "cloud"
    api_surface: "REST, RAML/OAS, DataWeave, Anypoint MQ, Connectors"

# === VERIFICATION ===
last_verified: 2026-03-02
confidence: 0.88
version: 1.0
first_published: 2026-03-02

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: volatile
  last_breaking_change: "2024 — transition from vCore-based to usage-based (Flows/Messages) pricing model"
  next_review: 2026-08-29
  change_sensitivity: high

# === CONSTRAINTS ===
constraints:
  - "Integration Starter: 50 Mule Flows, 5M Messages, 10,000 GB throughput per year"
  - "Integration Advanced: 200 Mule Flows, 20M Messages, 40,000 GB throughput per year"
  - "CloudHub 2.0 max HTTP request size: 1 GB; max request timeout: 300 seconds"
  - "CloudHub 2.0 API rate limit: 15 requests/second per remote IP address"
  - "Object Store v2 base: 10 TPS per store, 26M API requests/month; premium: 100 TPS, 100M requests/month"
  - "CloudHub 2.0 max application size: 350 MB; max 300 application properties"
  - "Mule Flow count multiplied by replicas — 1 flow on 3 replicas counts as 3 flows"

# === SKIP CONDITIONS ===
skip_this_unit_if:
  - condition: "User needs a specific ERP system API reference (Salesforce, SAP, Oracle)"
    use_instead: "business/erp-integration/{system}-api-capabilities/2026"
  - condition: "User needs MuleSoft RPA or IDP capabilities"
    use_instead: "business/erp-integration/mulesoft-automation-rpa/2026"
  - condition: "User needs to compare MuleSoft vs Boomi vs Workato"
    use_instead: "business/erp-integration/ipaas-comparison-mulesoft-boomi-workato/2026"

# === AGENT HINTS ===
inputs_needed:
  - key: integration_pattern
    question: "What integration pattern do you need?"
    type: choice
    options:
      - "API-led connectivity (system/process/experience layers)"
      - "event-driven (Anypoint MQ, pub/sub)"
      - "batch processing (scheduled ETL)"
      - "real-time sync (webhook/polling)"
  - key: deployment_target
    question: "Where will you deploy?"
    type: choice
    options:
      - "CloudHub 2.0 (fully managed)"
      - "Runtime Fabric (self-managed Kubernetes)"
      - "Hybrid (on-premise + cloud)"
  - key: scale
    question: "What's your expected scale?"
    type: choice
    options:
      - "< 50 flows, < 5M messages/month"
      - "50-200 flows, 5M-20M messages/month"
      - "> 200 flows, > 20M messages/month"

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/business/erp-integration/mulesoft-anypoint-capabilities/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-03-02)"

# === RELATED UNITS ===
related_kos:
  depends_on: []
  related_to: []
  solves: []
  alternative_to: []
  often_confused_with: []

# === SOURCES ===
sources:
  - id: src1
    title: "Anypoint Platform Pricing"
    author: MuleSoft
    url: https://docs.mulesoft.com/general/pricing
    type: official_docs
    published: 2025-12-01
    reliability: authoritative
  - id: src2
    title: "Usage and Pricing Metrics Reference"
    author: MuleSoft
    url: https://docs.mulesoft.com/general/usage-metrics
    type: official_docs
    published: 2025-12-01
    reliability: authoritative
  - id: src3
    title: "Limits in CloudHub 2.0"
    author: MuleSoft
    url: https://docs.mulesoft.com/cloudhub-2/ch2-limits
    type: official_docs
    published: 2025-11-01
    reliability: authoritative
  - id: src4
    title: "CloudHub 2.0 Architecture"
    author: MuleSoft
    url: https://docs.mulesoft.com/cloudhub-2/ch2-architecture
    type: official_docs
    published: 2025-11-01
    reliability: authoritative
  - id: src5
    title: "Object Store v2 Rate Limiting and Billing"
    author: MuleSoft
    url: https://docs.mulesoft.com/object-store/osv2-usage
    type: official_docs
    published: 2025-10-01
    reliability: authoritative
  - id: src6
    title: "Connected Apps in Anypoint Platform"
    author: MuleSoft
    url: https://docs.mulesoft.com/access-management/connected-apps-overview
    type: official_docs
    published: 2025-10-01
    reliability: authoritative
  - id: src7
    title: "MuleSoft Pricing: Implementation Cost and Pricing Details"
    author: Cloud Consultings
    url: https://cloudconsultings.com/mulesoft-pricing/
    type: technical_blog
    published: 2026-01-15
    reliability: moderate_high
  - id: src8
    title: "MuleSoft Anypoint Platform Pricing"
    author: Salesforce
    url: https://www.salesforce.com/mulesoft/anypoint-platform/pricing/
    type: official_docs
    published: 2025-12-01
    reliability: authoritative
---

# MuleSoft Anypoint Platform Capabilities — Pricing, Flows/Messages, CloudHub 2.0

## TL;DR

- **Bottom line**: MuleSoft Anypoint Platform uses usage-based pricing measured by Mule Flows (max concurrent per hour), Mule Messages (total monthly), and data throughput (GB/month). Two tiers: Integration Starter (50 flows, 5M messages) and Integration Advanced (200 flows, 20M messages). CloudHub 2.0 provides managed Mule runtime replicas from 0.1 to 4 vCores.
- **Key limit**: Flow count is multiplied by replicas — 1 flow deployed on 3 replicas counts as 3 flows against your allotment. [src2]
- **Watch out for**: The pricing model shift from vCore-based to usage-based (Flows/Messages) in late 2023/2024. Legacy contracts may still use vCore allocations. Confirm which model your contract uses before capacity planning. [src1]
- **Best for**: Enterprise API-led integration requiring 1,500+ pre-built connectors, full API lifecycle management, and multi-cloud deployment with DataWeave transformation.
- **Authentication**: Connected Apps with OAuth 2.0 (client credentials for M2M, authorization code for user-context). [src6]

## System Profile

MuleSoft Anypoint Platform is Salesforce's enterprise integration platform-as-a-service (iPaaS) providing a unified environment for designing, building, deploying, and managing APIs and integrations. It follows an "API-led connectivity" architecture with three layers: system APIs (connect to backends), process APIs (orchestrate business logic), and experience APIs (serve consumers). The platform includes Anypoint Studio (desktop IDE), Anypoint Code Builder (cloud IDE), API Designer, API Manager, Runtime Manager, and Exchange (asset marketplace).

This card covers the platform-level capabilities, pricing model, and infrastructure limits. It does NOT cover specific connector APIs (Salesforce Connector, SAP Connector, etc.) or the MuleSoft Automation suite (RPA, IDP) which have separate pricing.

| Property | Value |
|---|---|
| **Vendor** | Salesforce (MuleSoft) |
| **System** | Anypoint Platform (Mule Runtime 4.x, CloudHub 2.0) |
| **API Surface** | REST APIs (Platform APIs), RAML/OAS design, DataWeave 2.x, 1,500+ connectors |
| **Current Version** | CloudHub 2.0, Mule 4.x (2025-2026 releases) |
| **Editions Covered** | Integration Starter, Integration Advanced, API Management Solution |
| **Deployment** | Cloud (CloudHub 2.0), Self-managed (Runtime Fabric on K8s), Hybrid |
| **API Docs URL** | [MuleSoft Documentation](https://docs.mulesoft.com/) |
| **Status** | GA |

## API Surfaces & Capabilities

MuleSoft is an integration platform, not an ERP — it provides the middleware layer. Its "API surfaces" are the platform management APIs and integration runtime capabilities.

| Capability | Protocol | Best For | Limits | Real-time? | Bulk? |
|---|---|---|---|---|---|
| **Anypoint Platform APIs** | HTTPS/JSON REST | Managing deployments, APIs, users programmatically | 15 req/s per IP (CloudHub 2.0 API) | Yes | No |
| **HTTP/HTTPS Connector** | HTTP/1.1, HTTP/2 | Consuming/exposing REST/SOAP APIs | 1 GB max request, 300s timeout | Yes | No |
| **Anypoint MQ** | HTTPS/JSON | Async messaging, event-driven integration | 100K msg/s throughput (enterprise) | Yes | Yes |
| **Batch Module** | Internal | ETL, scheduled data loads, large datasets | Configurable batch size | No | Yes |
| **DataWeave 2.x** | Transformation language | Data mapping between any formats (JSON, XML, CSV, flat file) | Memory-bound by replica size | N/A | N/A |
| **Object Store v2** | HTTPS/JSON REST | State persistence, idempotency, caching | 10 TPS base / 100 TPS premium per store | Yes | No |
| **Anypoint Connectors** | Various (JDBC, SOAP, REST, proprietary) | Pre-built connectivity to 1,500+ systems | Per-connector limits vary | Both | Both |
| **Flex Gateway** | HTTP/HTTPS | Lightweight API gateway (managed or self-managed) | Per API policy limits | Yes | No |

[src1, src3, src4]

## Rate Limits & Quotas

### Usage-Based Pricing Metrics (Per Year)

| Metric | Integration Starter | Integration Advanced | Overage Increment | Counting Method |
|---|---|---|---|---|
| **Mule Flows** | 50 | 200 | Contact sales | Max Concurrent — highest number of flows in any single hour of the month |
| **Mule Messages** | 5,000,000 | 20,000,000 | 1M increments | Total — sum of all messages triggered by event sources per month |
| **Data Throughput** | 10,000 GB | 40,000 GB | 100 GB increments | Total — all data in/out of Mule infrastructure per month |

[src1, src2, src7]

### CloudHub 2.0 Infrastructure Limits

| Limit Type | Value | Notes |
|---|---|---|
| **Max HTTP request size** | 1 GB | Per request |
| **Max HTTP request timeout** | 300 seconds | Read-request timeout |
| **Max HTTP header length** | 32 KB | All headers combined |
| **Max ingress URI size** | 4 KB | URL path + query string |
| **API rate limit** | 15 req/s per remote IP | CloudHub 2.0 management API |
| **Max application size** | 350 MB | Deployment artifact |
| **Max application properties** | 300 | Key/value pairs |
| **Max property key/value** | 1,024 characters each | Per entry |
| **Environments per business group** | 200 | Organizational limit |
| **Private spaces per org** | 100 | Network isolation |
| **VPNs per private space** | 10 | Site-to-site |
| **Firewall rules (inbound)** | 300 | Per private space |
| **Firewall rules (outbound)** | 300 | Per private space |
| **Custom TLS contexts** | 50 | Per private space |

[src3]

### CloudHub 2.0 Replica Sizes

| Replica Size | vCores | Total Memory | Heap Memory | Storage | CPU Bursting |
|---|---|---|---|---|---|
| **0.1 vCore** | 0.1 | 1.2 GB | 480 MB | 8 GB | Yes |
| **1 vCore** | 1 | 4 GB | 2 GB | 12 GB | No |
| **2 vCores** | 2 | 8 GB | 4 GB | 20 GB | No |
| **4 vCores** | 4 | 15 GB | 7.5 GB | 20 GB | No |

Metaspace limit: 256 MB (fixed, all sizes). Initial metaspace: 128 MB. Replicas under 1 vCore support CPU bursting for faster startup. All replicas include minimum 8 GB storage (approximately 3 GB used by OS and Mule runtime). [src4]

### Object Store v2 Limits

| Limit Type | Base | Premium Add-on | Notes |
|---|---|---|---|
| **TPS per store** | 10 | 100 | 429 on exceed |
| **Monthly API requests** | 26M | 100M per add-on | Per organization, all environments |
| **Max value size** | 10 MB (Base64) | 10 MB (Base64) | Per entry |
| **Max key size** | 1,024 bytes | 1,024 bytes | UTF-8 |
| **Max TTL** | 30 days | 30 days | 2,592,000 seconds |
| **Max keys per GET** | 25 | 25 | Pagination required |
| **Billing unit** | 1 per 100 KB | 1 per 100 KB | Payload-based billing |

[src5]

## Authentication

### Platform-Level Authentication (Anypoint Platform APIs)

| Flow | Use When | Token Lifetime | Refresh? | Notes |
|---|---|---|---|---|
| **Connected App — Client Credentials** | M2M automation, CI/CD pipelines, no user context | Access token: configurable (default ~30 min) | New token per expiry | Recommended for integrations. App scoped to org where created. |
| **Connected App — Authorization Code** | User-context operations, third-party apps | Access token: configurable | Yes (refresh token) | Requires redirect URI |
| **Connected App — JWT Bearer** | Server-to-server with user impersonation | Access token: configurable | New JWT per request | App acting on behalf of user |
| **Username/Password (Basic Auth)** | Legacy, testing only | Session-based | No | Deprecated for production use — no MFA support |

[src6]

### Runtime-Level Authentication (APIs Built on MuleSoft)

MuleSoft APIs you build can use any authentication the HTTP Connector supports: OAuth 2.0 (all grant types), Basic Auth, NTLM, Digest, API Key, mTLS. Authentication policies (OAuth 2.0 Token Enforcement, Client ID Enforcement, JWT Validation) are applied via API Manager.

### Authentication Gotchas

- Connected Apps using Client Credentials are scoped to the organization where they are created — they cannot access resources in other organizations. [src6]
- The client secret has no expiration by default, but admins can set expiration — ensure monitoring of secret rotation. [src6]
- Rate limiting on Anypoint Platform Access Management API calls can cause authentication failures during high-volume CI/CD runs — implement token caching. [src3]

## Constraints
<!-- Agents: read this section before recommending any integration approach from this unit.
     These are hard constraints that must not be violated. -->

- **Flow counting is per-replica**: A single Mule application with 5 flows deployed on 3 replicas = 15 flows against your allotment. This is the #1 surprise in capacity planning. [src2]
- **Integration Starter caps at 50 flows/year**: For anything beyond a few simple integrations, you will need Integration Advanced (200 flows) or overages. [src1]
- **CloudHub 2.0 max request timeout is 300 seconds**: Long-running synchronous operations (large file processing, complex orchestrations) must be designed asynchronously. [src3]
- **Object Store v2 TTL max is 30 days**: Cannot be used for permanent state storage — use an external database for persistent data. [src5]
- **No dollar pricing on website**: MuleSoft does not publish list prices. All pricing requires a Salesforce sales engagement. Budget $100K-$250K/year minimum for Integration Starter based on industry reports. [src7, src8]
- **CloudHub 2.0 replicas share a global vCore pool**: Starting additional applications may fail if the pool is exhausted — applications cannot start until vCores are freed. [src4]
- **Premium connectors (SAP, Oracle EBS) are add-ons**: Not included in base tiers — budget separately. [src8]

## Integration Pattern Decision Tree

```
START — User needs MuleSoft Anypoint Platform
├── What's the primary use case?
│   ├── API-led connectivity (expose + orchestrate + consume APIs)
│   │   ├── < 50 integrations? → Integration Starter
│   │   ├── 50-200 integrations? → Integration Advanced
│   │   └── > 200 integrations? → Integration Advanced + overage packs
│   ├── API management only (gateway, policies, governance)
│   │   └── API Management Solution (pay per API requests/managed/governed)
│   ├── Automation (RPA, IDP, Flow Orchestration)
│   │   └── MuleSoft Automation suite (separate pricing)
│   └── Event-driven messaging
│       └── Anypoint MQ add-on + Integration tier
├── Where to deploy?
│   ├── Fully managed cloud → CloudHub 2.0
│   │   ├── Dev/test → 0.1 vCore replicas (CPU bursting, cheapest)
│   │   ├── Production, moderate load → 1 vCore replicas
│   │   ├── Production, high memory → 2 or 4 vCore replicas
│   │   └── HA required? → minimum 2 replicas (auto multi-AZ)
│   ├── Self-managed Kubernetes → Runtime Fabric
│   │   └── You manage K8s cluster, MuleSoft manages Mule runtime
│   └── On-premise + cloud hybrid → Hybrid deployment
│       └── Mule runtime on-premise, managed via Anypoint Platform
├── How to count capacity?
│   ├── Count flows (max concurrent per hour)
│   │   └── Remember: flows × replicas = total flow count
│   ├── Count messages (total per month from event sources)
│   │   └── Only initial event source triggers count — internal flow-ref does not
│   └── Count data throughput (total GB in/out per month)
│       └── Includes monitoring/logging overhead, not just business data
└── Need state persistence?
    ├── Temporary (< 30 days) → Object Store v2
    ├── Permanent → External database (Salesforce, PostgreSQL, etc.)
    └── Message queuing → Anypoint MQ
```

## Quick Reference

### Pricing Tier Comparison

| Feature | Integration Starter | Integration Advanced | API Management |
|---|---|---|---|
| **Mule Flows** | 50/year | 200/year | N/A |
| **Mule Messages** | 5M/year | 20M/year | N/A |
| **Data Throughput** | 10,000 GB/year | 40,000 GB/year | N/A |
| **CloudHub 2.0** | Included | Included | Not included |
| **API Designer** | Included | Included | Included |
| **API Manager** | Limited | Full | Full |
| **API Governance** | Not included | Not included | Included |
| **Flex Gateway** | Not included | Not included | Included |
| **Anypoint Exchange** | Included | Included | Included |
| **Monitoring** | Basic | Advanced (Titanium) | Basic |
| **HA Clustering** | Not included | Included | N/A |
| **Multi-cloud** | Not included | Included | N/A |
| **Automation Credits** | Included | Included | Not included |
| **Premium Connectors** | Add-on | Add-on | N/A |
| **Estimated Annual Cost** | $100K-$150K | $200K-$400K+ | Contact sales |

[src1, src7, src8]

### Key Platform Components

| Component | Purpose | Included In |
|---|---|---|
| **Anypoint Studio** | Desktop IDE (Eclipse-based) for Mule app development | All tiers |
| **Anypoint Code Builder** | Cloud IDE (VS Code-based) with AI assist | All tiers |
| **API Designer** | RAML/OAS API specification authoring | All tiers |
| **API Manager** | API proxy management, policies, SLA tiers | Starter (limited), Advanced, API Mgmt |
| **Runtime Manager** | Deploy and manage Mule apps on CloudHub/RTF/Hybrid | All integration tiers |
| **Anypoint Exchange** | Asset marketplace (APIs, connectors, templates, examples) | All tiers |
| **Anypoint Monitoring** | Application and API performance dashboards | Basic in Starter, Advanced in Advanced |
| **Anypoint MQ** | Cloud messaging service (pub/sub, queues) | Add-on |
| **DataWeave 2.x** | Data transformation language (JSON, XML, CSV, flat file, etc.) | All tiers |
| **Anypoint Visualizer** | Application network topology visualization | Integration Advanced |
| **Flow Designer** | Low-code integration builder | All integration tiers |
| **Flex Gateway** | Lightweight, high-performance API gateway | API Management tier |

[src1, src8]

## Step-by-Step Integration Guide

### 1. Authenticate to Anypoint Platform API

Create a Connected App (client credentials) and obtain an access token. [src6]

```bash
# Input:  Connected App client_id and client_secret
# Output: Bearer access token

curl -X POST "https://anypoint.mulesoft.com/accounts/api/v2/oauth2/token" \
  -H "Content-Type: application/json" \
  -d '{
    "grant_type": "client_credentials",
    "client_id": "YOUR_CLIENT_ID",
    "client_secret": "YOUR_CLIENT_SECRET"
  }'
```

**Verify**: Response includes `"access_token"` field and `"token_type": "bearer"`.

### 2. List Environments in Your Organization

Retrieve environment IDs needed for deployment operations. [src1]

```bash
# Input:  Bearer token, organization ID
# Output: List of environments (id, name, type)

curl -X GET "https://anypoint.mulesoft.com/accounts/api/organizations/{orgId}/environments" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
```

**Verify**: Response includes array of environments with `id`, `name`, and `type` (production/sandbox).

### 3. Deploy an Application to CloudHub 2.0

Use the Runtime Manager API to deploy a Mule application. [src4]

```bash
# Input:  Bearer token, org ID, env ID, application JAR
# Output: Deployment status

curl -X POST "https://anypoint.mulesoft.com/amc/application-manager/api/v2/organizations/{orgId}/environments/{envId}/deployments" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "my-app",
    "target": {
      "provider": "MC",
      "targetId": "{targetId}",
      "replicas": 2,
      "replicaSize": "1"
    },
    "application": {
      "ref": {
        "groupId": "{groupId}",
        "artifactId": "my-app",
        "version": "1.0.0",
        "packaging": "jar"
      }
    }
  }'
```

**Verify**: `curl -X GET "https://anypoint.mulesoft.com/amc/application-manager/api/v2/organizations/{orgId}/environments/{envId}/deployments/{deploymentId}"` returns `"status": "RUNNING"`.

### 4. Check Usage Metrics

Monitor your flow and message consumption against allotments. [src2]

```bash
# Input:  Bearer token, org ID
# Output: Usage data (flows, messages, throughput)

curl -X GET "https://anypoint.mulesoft.com/accounts/api/cs/organizations/{orgId}/usage-reports" \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
```

**Verify**: Response includes current period flow count, message count, and throughput against allotment.

## Code Examples

### Python: Authenticate and List Deployments

```python
# Input:  Connected App client_id and client_secret
# Output: List of deployed applications in an environment

import requests  # requests==2.31+

CLIENT_ID = "your_client_id"
CLIENT_SECRET = "your_client_secret"
ORG_ID = "your_org_id"
ENV_ID = "your_env_id"
BASE_URL = "https://anypoint.mulesoft.com"

# Step 1: Get access token
token_resp = requests.post(
    f"{BASE_URL}/accounts/api/v2/oauth2/token",
    json={
        "grant_type": "client_credentials",
        "client_id": CLIENT_ID,
        "client_secret": CLIENT_SECRET,
    },
)
token_resp.raise_for_status()
access_token = token_resp.json()["access_token"]

# Step 2: List deployments
headers = {"Authorization": f"Bearer {access_token}"}
deployments = requests.get(
    f"{BASE_URL}/amc/application-manager/api/v2/organizations/{ORG_ID}/environments/{ENV_ID}/deployments",
    headers=headers,
)
deployments.raise_for_status()
for app in deployments.json().get("items", []):
    print(f"{app['name']}: {app['status']} ({app.get('target', {}).get('replicas', '?')} replicas)")
```

### JavaScript/Node.js: Deploy and Monitor Application

```javascript
// Input:  Connected App credentials, application reference
// Output: Deployment ID and status

const axios = require("axios"); // axios@1.6+

const BASE_URL = "https://anypoint.mulesoft.com";
const CLIENT_ID = process.env.MULESOFT_CLIENT_ID;
const CLIENT_SECRET = process.env.MULESOFT_CLIENT_SECRET;

async function getToken() {
  const { data } = await axios.post(`${BASE_URL}/accounts/api/v2/oauth2/token`, {
    grant_type: "client_credentials",
    client_id: CLIENT_ID,
    client_secret: CLIENT_SECRET,
  });
  return data.access_token;
}

async function deployApp(orgId, envId, appConfig) {
  const token = await getToken();
  const headers = { Authorization: `Bearer ${token}` };
  const { data } = await axios.post(
    `${BASE_URL}/amc/application-manager/api/v2/organizations/${orgId}/environments/${envId}/deployments`,
    appConfig,
    { headers }
  );
  console.log(`Deployed: ${data.id} — Status: ${data.status}`);
  return data.id;
}
```

### cURL: Quick Platform Health Check

```bash
# Input:  Connected App credentials
# Output: Organization info confirming access

# 1. Authenticate
TOKEN=$(curl -s -X POST "https://anypoint.mulesoft.com/accounts/api/v2/oauth2/token" \
  -H "Content-Type: application/json" \
  -d '{"grant_type":"client_credentials","client_id":"'$CLIENT_ID'","client_secret":"'$CLIENT_SECRET'"}' \
  | jq -r '.access_token')

# 2. Get org info
curl -s "https://anypoint.mulesoft.com/accounts/api/me" \
  -H "Authorization: Bearer $TOKEN" | jq '.user.organization.name'

# 3. Check CloudHub 2.0 runtime status
curl -s "https://anypoint.mulesoft.com/amc/application-manager/api/v2/organizations/$ORG_ID/environments/$ENV_ID/deployments" \
  -H "Authorization: Bearer $TOKEN" | jq '.items[] | {name, status}'
```

## Data Mapping

### Mule Message Structure

| Component | Description | Access Pattern | Gotcha |
|---|---|---|---|
| **payload** | Main data body (any type: JSON, XML, Java, stream) | `payload` or `#[payload]` in DataWeave | Payload is consumed on first read for streaming — use `repeatableStream` |
| **attributes** | Metadata about the message (HTTP headers, query params, URI params) | `attributes.headers`, `attributes.queryParams` | Read-only after message creation |
| **vars** | Flow variables — persist across processors within a flow | `vars.myVar` | Not propagated to `flow-ref` targets by default in some versions |
| **error** | Error object when exception occurs | `error.description`, `error.errorType` | `error` only available inside error handlers |

### DataWeave Common Transforms

| Source Format | Target Format | Transform | Gotcha |
|---|---|---|---|
| JSON object | XML | `output application/xml --- payload` | JSON arrays need wrapper element in XML |
| CSV | JSON array | `output application/json --- payload` | CSV headers become field names — spaces/special chars cause issues |
| Flat file (fixed-width) | JSON | `output application/json --- payload` using schema | Must define FFD (flat file definition) schema file |
| Java POJO | JSON | `output application/json --- payload` | Private fields without getters are invisible |
| XML with namespaces | JSON | Use `ns` declaration | Namespaces stripped in JSON — can lose distinction between elements |

### Data Type Gotchas

- DataWeave auto-coerces types aggressively — `"123"` (string) becomes `123` (number) in some contexts without explicit format. Always use explicit type coercion: `payload.amount as Number`. [src2]
- Streaming payloads (large files) are consumed on first read. Enable `repeatableFileStoreStream` to allow re-reading, but watch memory/disk usage. [src4]
- Date/time handling: DataWeave uses ISO 8601 by default. When integrating with systems using epoch timestamps, use `payload.date as Number {unit: "milliseconds"}`. [src2]

## Error Handling & Failure Points

### Common Error Codes

| Code | Meaning | Cause | Resolution |
|---|---|---|---|
| **429** | Rate limit exceeded | Too many requests to CloudHub 2.0 API (>15/s per IP) or Object Store (>10 TPS) | Exponential backoff: wait 2^n seconds, max 5 retries |
| **503** | Service unavailable | CloudHub 2.0 replica restarting or scaling | Retry after 30s; check Runtime Manager for app status |
| **408** | Request timeout | Operation exceeded 300s CloudHub limit | Redesign as async pattern with correlation ID |
| **413** | Payload too large | Request body > 1 GB | Chunk large payloads; use streaming |
| **MULE:CONNECTIVITY** | Connection refused/timeout | Target system down or network issue | Check firewall rules (300 max), VPN status, private space config |
| **MULE:RETRY_EXHAUSTED** | All retries failed | Persistent downstream failure | Dead letter queue pattern; alert operations team |
| **MULE:EXPRESSION** | DataWeave evaluation error | Null payload, wrong type, missing field | Add null-safe operators (`payload.field default ""`) |
| **MULE:STREAM_MAXIMUM_SIZE_EXCEEDED** | In-memory buffer overflow | Streaming payload exceeds configured buffer | Increase `maxInMemorySize` or switch to file-based streaming |

[src3, src4]

### Failure Points in Production

- **Flow count surprise at renewal**: Organization deploys more replicas for HA, tripling flow count beyond contract. Fix: `Audit flow counts monthly with Usage Reports API; right-size replica counts per app`. [src2]
- **Object Store TTL expiry during long batch jobs**: Batch state stored in Object Store expires mid-job (30-day max). Fix: `Use external database for batch state; Object Store only for short-lived idempotency keys`. [src5]
- **CloudHub 2.0 vCore pool exhaustion**: New deployments fail silently because all vCores are allocated. Fix: `Monitor vCore usage via Platform APIs; set up alerts when >80% allocated; stop unused sandbox apps`. [src4]
- **Streaming payload consumed twice**: HTTP Listener payload read once by logger, then null in next processor. Fix: `Enable repeatableFileStoreStream in HTTP Listener config; or explicitly set payload to a variable before logging`. [src4]
- **Connected App secret rotation failure**: CI/CD pipeline breaks because secret expired (admin set expiration). Fix: `Monitor secret expiration via Platform API; rotate secrets on schedule before expiry; use multiple connected apps for rolling rotation`. [src6]
- **Private space firewall rule limit**: Complex network topology exceeds 300 inbound/outbound rules. Fix: `Use CIDR aggregation; consolidate rules by subnet; consider network peering instead of individual rules`. [src3]

## Anti-Patterns

### Wrong: Counting flows without considering replicas

```
// BAD — assumes 10 flows = 10 against allotment
// Reality: 10 flows x 3 replicas = 30 flows
App has 10 flows, deployed on 3 replicas for HA
Expected flow count: 10
Actual flow count: 30 (10 x 3)
```

### Correct: Factor replicas into capacity planning

```
// GOOD — plan with replica multiplier
Total flows = sum(app_flows x app_replicas) for all apps
Example: App A (5 flows x 2 replicas) + App B (3 flows x 1 replica)
Total = 10 + 3 = 13 flows against allotment

Rule: Minimize replicas in non-production environments (use 1 replica for sandbox)
```

### Wrong: Synchronous processing for large payloads

```
// BAD — blocks for 5+ minutes, hits 300s timeout
HTTP Listener → Transform 500MB file → POST to target system
Result: 408 timeout after 300 seconds
```

### Correct: Async pattern with Anypoint MQ

```
// GOOD — async with status tracking
HTTP Listener → Validate → Publish to Anypoint MQ queue → Return 202 Accepted
Separate flow: MQ Subscriber → Chunk file → Process chunks → Update status in Object Store
Client polls status endpoint for completion
```

### Wrong: Using Object Store as a database

```
// BAD — data disappears after 30 days
Store customer preferences in Object Store v2
Result: All preferences silently deleted after TTL expiry
```

### Correct: Use Object Store for transient state only

```
// GOOD — Object Store for idempotency, external DB for permanent data
Object Store: deduplication keys (TTL: 24h), batch watermarks (TTL: 7d)
External DB: customer data, configuration, audit logs
```

## Common Pitfalls

- **"Sandbox is free" assumption**: CloudHub 2.0 sandbox environments consume from the same vCore pool as production. Running full replicas in sandbox reduces production capacity. Fix: `Use 0.1 vCore single-replica deployments in sandbox; stop apps when not testing`. [src4]
- **Ignoring data throughput metric**: Teams focus on flow and message counts but forget that data throughput (including monitoring overhead) counts toward allotment. Fix: `Monitor throughput via Usage Reports; reduce logging verbosity in production; optimize payload sizes`. [src2]
- **Not pinning connector versions**: Upgrading connectors mid-project can introduce breaking changes. Fix: `Pin connector versions in pom.xml; test upgrades in sandbox first; maintain a connector upgrade runbook`. [src1]
- **Underestimating message volume**: Event sources that fire frequently (polling every 5s, HTTP Listener on high-traffic API) accumulate millions of messages quickly. Fix: `Calculate monthly message estimate: triggers_per_minute x 60 x 24 x 30. Use watermark-based polling to reduce frequency`. [src2]
- **Deploying without HA planning**: Single-replica deployments have no failover — replica restart means downtime. Fix: `Production apps: minimum 2 replicas (auto-distributed across data centers 60+ miles apart). Accept single-replica only for non-critical workloads`. [src4]
- **Premium connector surprise**: SAP, Oracle EBS, and other premium connectors are not included in base tiers. Budget can increase 20-40% when these are needed. Fix: `Identify all required connectors during evaluation; get add-on pricing from Salesforce before contract signing`. [src8]

## Diagnostic Commands

```bash
# Authenticate and get access token
TOKEN=$(curl -s -X POST "https://anypoint.mulesoft.com/accounts/api/v2/oauth2/token" \
  -H "Content-Type: application/json" \
  -d '{"grant_type":"client_credentials","client_id":"'$CLIENT_ID'","client_secret":"'$CLIENT_SECRET'"}' \
  | jq -r '.access_token')

# Check organization info and entitlements
curl -s "https://anypoint.mulesoft.com/accounts/api/me" \
  -H "Authorization: Bearer $TOKEN" | jq '.user.organization'

# List all environments
curl -s "https://anypoint.mulesoft.com/accounts/api/organizations/$ORG_ID/environments" \
  -H "Authorization: Bearer $TOKEN" | jq '.data[] | {id, name, type}'

# List all deployments in an environment
curl -s "https://anypoint.mulesoft.com/amc/application-manager/api/v2/organizations/$ORG_ID/environments/$ENV_ID/deployments" \
  -H "Authorization: Bearer $TOKEN" | jq '.items[] | {name, status, target: .target.replicas}'

# Check specific deployment status and replica health
curl -s "https://anypoint.mulesoft.com/amc/application-manager/api/v2/organizations/$ORG_ID/environments/$ENV_ID/deployments/$DEPLOYMENT_ID" \
  -H "Authorization: Bearer $TOKEN" | jq '{status, target: .target, replicas: .replicas}'

# Check usage/consumption metrics
curl -s "https://anypoint.mulesoft.com/accounts/api/cs/organizations/$ORG_ID/usage-reports" \
  -H "Authorization: Bearer $TOKEN" | jq '.'
```

## Version History & Compatibility

| Version/Milestone | Release Date | Status | Key Changes | Notes |
|---|---|---|---|---|
| **CloudHub 2.0 GA** | 2023 | Current | Kubernetes-based, replicas replace workers, private spaces | Successor to CloudHub 1.0 |
| **Usage-based pricing** | Late 2023/2024 | Current | Flows/Messages/Throughput replaces vCore-based pricing | New contracts only; legacy contracts grandfathered |
| **Mule Runtime 4.6.x** | 2025 | Current | Performance improvements, Java 17 support | Mule 3.x EOL reached |
| **Flex Gateway GA** | 2023 | Current | Lightweight API gateway alternative to Mule Gateway | Separate from CloudHub runtime |
| **Anypoint Code Builder GA** | 2024 | Current | Cloud-based VS Code IDE with AI assist | Replaces Design Center flow designer for new projects |
| **MuleSoft MCP Server** | 2025 | Current | AI agent integration — develop/deploy via natural language | Part of Agentforce platform |

[src1, src4, src8]

### Deprecation Policy

CloudHub 1.0 (legacy) is in maintenance mode with migration to CloudHub 2.0 recommended. Mule 3.x has reached end of extended support — all new development must use Mule 4.x. MuleSoft follows Salesforce's release cadence with three major releases per year. API version changes are communicated through release notes, with backward-compatible changes preferred. [src1, src4]

## When to Use / When Not to Use

| Use When | Don't Use When | Use Instead |
|---|---|---|
| Enterprise needs 1,500+ pre-built connectors for complex multi-system integration | Simple point-to-point integration between 2-3 SaaS apps | Workato, Zapier, or native integrations |
| API-led connectivity architecture with system/process/experience layers | Budget under $100K/year for integration | Open-source (Apache Camel) or lower-cost iPaaS |
| Salesforce-centric organization wanting tight CRM integration | Need only API gateway without integration runtime | Kong, Apigee, or AWS API Gateway |
| Regulated industry requiring full API governance and policy enforcement | Lightweight event streaming only | Apache Kafka, AWS EventBridge, or Confluent |
| Hybrid deployment required (on-premise + cloud) | Serverless/function-based integration only | AWS Step Functions, Azure Logic Apps |
| Need visual DataWeave transformation for complex data mapping | Simple webhook-to-webhook forwarding | n8n, Make, or simple proxy |

## Important Caveats

- MuleSoft does not publish list prices. All estimates in this card ($100K-$400K+/year) are based on industry reports and may vary significantly based on contract negotiation, Salesforce relationship, and volume discounts. Always get a formal quote. [src7, src8]
- Usage-based pricing (Flows/Messages) applies to new contracts. Organizations on legacy vCore-based contracts may see different limits. Confirm your contract model before capacity planning. [src1]
- CloudHub 2.0 limits are subject to change with each release. The 15 req/s API rate limit and 300s timeout are current as of early 2026 but should be verified against latest release notes. [src3]
- Sandbox environments consume from the same resource pool as production. There is no "free tier" — all deployed replicas count toward your vCore allocation and flow count. [src2, src4]
- Object Store v2 billing counts based on payload size (1 unit per 100 KB), not just request count. A single GET retrieving 500 KB of data counts as 5 units. [src5]
- Premium connectors (SAP, Oracle, Workday) require separate licensing and can significantly increase total cost of ownership. [src8]

## Related Units
<!-- Generated from related_kos frontmatter -->
