AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building an API using Amazon API Gateway that needs to securely expose an endpoint to a partner company. The partner company requires that all requests to the API be authenticated using their existing custom authentication system, which provides a JWT token. The developer needs to validate this JWT token before forwarding requests to the backend Lambda function. Which API Gateway authorization method should the developer implement?
- AResource policy
- BLambda authorizer (formerly custom authorizer)
- CIAM authorization
- DAmazon Cognito User Pool authorizer
Show answer & explanationAnswer & explanation
Correct answer: B. Lambda authorizer (formerly custom authorizer)
A Lambda authorizer (formerly custom authorizer) allows a developer to use a custom Lambda function to perform arbitrary authorization logic. This is ideal for integrating with existing custom authentication systems that issue JWT tokens, as the Lambda function can validate the token and return an IAM policy.
Why the other options are wrong
- A. Resource policies control access to the API Gateway itself based on IP addresses, VPCs, principals, etc., but do not perform token validation for custom authentication systems.
- C. IAM authorization is for AWS IAM users/roles, not external custom authentication systems.
- D. Cognito User Pool authorizers are specifically for JWT tokens issued by Amazon Cognito User Pools, not arbitrary custom JWTs.
API Gateway Lambda Authorizer
An API Gateway Lambda authorizer is a Lambda function that controls access to API Gateway API methods. It's used to implement custom authorization schemes, including validating JWT tokens from external identity providers.
- Allows custom authorization logic.
- Can validate any JWT token or other custom authentication.
- Returns an IAM policy to permit or deny access.
Memory trick: Lambda Authorizer Validates Custom Tokens.