Extract a JWT token from the auth header into a new backend header

Extract a part of JWT token from the Authorization header and pass it on to the backend integrations as a separate header

This snippet can be used to extract a part of JWT token from the Authorization header and pass it on to the backend integrations as a separate header using Mapping template.
Integration request parameters, in the form of headers, can be mapped from any defined method request parameters and the payload.
One can make use of Method request header along with the mapping expression method.request.header.PARAM_NAME to achieve this use case.
1. Set up a Method Request by configuring an HTTP method (ANY, DELETE, GET, HEAD, OPTIONS, PATCH, POST, PUT) for your API Gateway resource with a backend integration.
2. In the Method Request tab, click edit and add a new HTTP request header name (e.g., clientId) that will be sent to the backend. Avoid restricted header names per AWS documentation.
3. After adding the header in Method Request settings, navigate to the Integration Request section where your backend integration endpoint is configured.
4. Expand URL request headers parameters and add a mapping entry using the expression method.request.header.clientId to forward the header to the integration.
5. This maps the incoming method request header value and passes it as a separate header to the backend integration endpoint.

To pass only a new header to the backend: Add the following mapping template body that fetches the header named Authorization from the request, validates if the header value starts with ‘Bearer’ and extracts a part of the value for the new clientId header. Then context.responseOverride.header.<header_name> is used for overriding the header. Use the content types as application/json.

#set($authHeaderValue = $input.params().header.get('Authorization'))
#if($authHeaderValue.startsWith('Bearer '))
  #set($clientId = $authHeaderValue.substring(7))
  #set($context.requestOverrideConfiguration.headers.clientId = $clientId)
$util.toJson($input.json('$'))
#else
$util.badRequest("Missing or invalid 'Authorization' header")
#end

{ 
  "method": "$context.httpMethod",
  "body" : $input.json('$'),
  "headers": { 
       "clientId": "$util.escapeJavaScript($clientId)"
  }
}
                                


To append the new header to the list of headers and send it along with all the headers to the backend, use the following template.

#set($authHeaderValue = $input.params().header.get('Authorization'))
#if($authHeaderValue.startsWith('Bearer '))
  #set($clientId = $authHeaderValue.substring(7))
  #set($allHeaders = $input.params().header)
  #set($entry = {})
  $util.qr($allHeaders.put('clientId', $clientId))
  $util.toJson($input.json('$'))
#else
  $util.badRequest("Missing or invalid 'Authorization' header")
#end

{
  "method": "$context.httpMethod",
  "body" : $input.json('$'),
  "headers": "$util.escapeJavaScript($allHeaders)"
}

                                


Invoke the API using the invoke URL along with an Authorization header. For example “Authorization: Bearer a1b2c3d4e5f6g7.h8i9j0k1l2m3n4o5p6.q7r8s9t0u1v2w3x4y5z” is being passed as the token header. Please ensure to use your API Gateway’s invoke URL.

curl --location 'https://abcde1234.execute-api.us-east-1.amazonaws.com/Stage/Resource-1’ \
--header 'Authorization: Bearer a1b2c3d4e5f6g7.h8i9j0k1l2m3n4o5p6.q7r8s9t0u1v2w3x4y5z' \
--header 'Cloud: AWS' \   
--header 'Content-Type: application/json' \
--data '{"Condition”:”Check the headers”}’

                                


Created by: