2.1.2.2. API Gateway Authorization (IAM, Cognito)
2.1.2.2. API Gateway Authorization (IAM, Cognito)
First Principle: API Gateway authorization secures your APIs by controlling who can access them, protecting your application's backend logic and data.
Access control is a critical aspect of securing your APIs. Amazon API Gateway offers various mechanisms to authorize API calls, ensuring only authenticated and authorized users or services can interact with your backend.
- IAM Authorization: Uses AWS Identity and Access Management (IAM) roles and policies to control access. Ideal for internal APIs accessed by other AWS services or IAM users who have AWS credentials.
- Amazon Cognito User Pool Authorizers: Integrates with Amazon Cognito User Pools(a managed user directory). Ideal for external facing APIs (web, mobile apps) where you manage users and their authentication. Cognito handles user sign-up, sign-in, and tokens. The client sends the ID token in the
Authorizationheader; if the method is configured with OAuth scopes, it must send the access token instead (never the refresh token). Because a user pool can federate a corporate SAML identity provider, a Cognito authorizer can protect an API for corporate users with no custom authorizer code. - Lambda Authorizers (formerly Custom Authorizers): A Lambda function that you provide, which processes incoming requests and returns an IAM policy document to allow or deny the request. Offers highly flexible and custom authorization logic.
- A token-based authorizer receives a bearer token (OAuth 2.0 or JWT), which clients send as
Authorization: Bearer <token>. Possession of a bearer token is all it takes to use it, so send it only over HTTPS and keep it short-lived. - For a REST API, the function must return an IAM policy (with a
principalId) whoseEffect: Allowcovers the requested method ARN; a 200 status or a baretrueis not enough. An HTTP API authorizer with simple responses enabled may instead return{"isAuthorized": true}. - Authorizer result caching (TTL 300 seconds by default, up to 3,600) lets API Gateway reuse the returned policy for repeat requests with the same token instead of invoking the authorizer, and its expensive validation, every time.
- A token-based authorizer receives a bearer token (OAuth 2.0 or JWT), which clients send as
- API Keys: (A simple method where clients must include an API key in the request header.) Provides a basic level of access control, often used for usage plans and throttling. Not a strong authentication mechanism alone.
Scenario: You're developing a public-facing API for a mobile application, and you need to manage user authentication (sign-up, sign-in) and authorize access to your API endpoints based on authenticated user identities. Additionally, you have some internal APIs that should only be accessible by specific IAM roles.
⚠️ Exam Trap: Cognito User Pools handle authentication (who are you?). Cognito Identity Pools handle authorization (what AWS resources can you access?). The exam frequently tests this distinction.