Which are the leading API security platforms available today, and how do they differ in terms of capabilities such as real-time threat detection and mitigation for APIs, integration with CI/CD and DevOps toolchains, support for authentication and authorization standards (like OAuth/OpenID), automated vulnerability scanning and fuzz testing, analytics and reporting dashboards, ease of deployment and use, scalability for small to enterprise environments, API-centric compliance support, policy automation and enforcement, and overall effectiveness in protecting API ecosystems from attacks?