Amazon API Gateway authentication with the Amazon Cognito client credentials flow

Client → Amazon Cognito → Amazon API Gateway → AWS Lambda

Secure service-to-service calls to an Amazon API Gateway API with an Amazon Cognito user pool, using the OAuth 2.0 client credentials grant.

The sample project demonstrates how to use a Cognito User Pool as an Authorizer for an API hosted on API Gateway. The API is invoked using using an access token that is generated using the user pool app client credentials. If the token is valid, the returns a 200 response. For any invalid tokens, the API response with 401 error.

< Back to all patterns

GitHub icon View this pattern on GitHub


Clone repo

git clone https://github.com/aws-samples/serverless-patterns/cd serverless-patterns/cdk-cognito-apigateway-lambda

Deploy

See the GitHub repo for detailed deployment instructions.


Testing

See the GitHub repo for detailed testing instructions.

Cleanup

cdk destroy

Additional resources

Created by:

Suhasini Krishnan Udayar

Suhasini Krishnan Udayar

Cloud Application Architect