AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is building a web application that uses Amazon API Gateway to expose a REST API. The API needs to invoke an AWS Lambda function. The Lambda function's execution role has the necessary permissions to perform its tasks. However, when testing the API, the developer receives a '500 Internal Server Error' from API Gateway, and CloudWatch Logs show 'Missing Authentication Token' errors originating from API Gateway, even though the Lambda function itself runs successfully when invoked directly. What is the MOST likely cause of this issue?

  1. AThe API Gateway deployment is outdated and needs to be redeployed.
  2. BThe Lambda function's execution role does not have permission to be invoked by API Gateway.
  3. CThe API Gateway method's integration request is incorrectly configured.
  4. DThe Lambda function does not have a resource-based policy allowing API Gateway to invoke it.
Show answer & explanation

Correct answer: D. The Lambda function does not have a resource-based policy allowing API Gateway to invoke it.

API Gateway requires explicit permission to invoke a Lambda function. This permission is granted via a resource-based policy attached directly to the Lambda function, allowing the API Gateway service principal to invoke it. The 'Missing Authentication Token' error from API Gateway, despite the Lambda working directly, indicates API Gateway itself lacks permission to call Lambda.

Why the other options are wrong

  • A. An outdated deployment might cause issues, but not typically a 'Missing Authentication Token' directly from API Gateway when trying to invoke Lambda.
  • B. The Lambda execution role defines what Lambda can do, not what can invoke Lambda. This is a common misconception.
  • C. Incorrect integration request configuration might lead to payload mapping issues or other errors, but 'Missing Authentication Token' specifically points to an authorization problem for API Gateway to invoke Lambda.

Lambda Resource-Based Policy

An IAM policy attached directly to an AWS Lambda function, granting other AWS services (like API Gateway, S3, SNS) permission to invoke that specific function.

  • Separate from the Lambda execution role.
  • Defines 'who can invoke me' for the function.
  • Crucial for service-to-service integration with Lambda.

Memory trick: API Gateway needs a special pass to knock on Lambda's door.

More Development with AWS Services questions