How to configure a built-in JWT authorizer on an Amazon API Gateway HTTP API?
A developer is working on a new authorization mechanism for an application. The developer must create an Amazon API Gateway API and must test JSON Web Token (JWT) authorization on the API. The developer must use the built-in authorizer and must avoid managing the code with custom logic. The developer needs to define an API route that is available at /auth to test the authorizer configuration. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between HTTP APIs and WebSocket APIs regarding native JWT authorizer support, and between built-in JWT authorizers and custom Lambda authorizers.
Amazon API Gateway HTTP APIs support a built-in JWT authorizer that validates tokens issued by an OIDC or OAuth 2.0 provider without requiring custom code. WebSocket APIs do not support the native JWT authorizer, and Lambda authorizers require managing custom logic.
Candidates often choose option C (HTTP API with Lambda authorizer) because Lambda authorizers are widely used, but the requirement explicitly says to avoid managing custom code, which eliminates Lambda authorizers.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
The correct answer is D. The scenario has three key constraints: (1) test JWT authorization, (2) use the built-in authorizer, and (3) avoid managing custom logic. Amazon API Gateway HTTP APIs natively support a JWT authorizer that validates tokens issued by any OIDC- or OAuth 2.0-compliant identity provider. You simply configure the authorizer with the issuer URL and audience, then attach it to a route such as /auth. No code, no Lambda, no deployment of custom logic is required.
Why the other options are wrong:
- Option A uses a WebSocket API. WebSocket APIs in API Gateway do not support the built-in JWT authorizer; they only support Lambda authorizers for custom authentication. Therefore this option cannot meet the "built-in authorizer" requirement.
- Option B also uses a WebSocket API and a Lambda authorizer. This violates both constraints: WebSocket APIs lack native JWT support, and a Lambda authorizer requires you to write and manage custom code.
- Option C uses an HTTP API (correct API type) but attaches a Lambda authorizer. While functional, a Lambda authorizer requires you to author, deploy, and maintain a Lambda function that parses and validates the token — directly contradicting the requirement to avoid managing custom logic.
Official Reference
Exam Strategy
When a question says "built-in" and "no custom logic," immediately eliminate every option that mentions a Lambda authorizer. Then check whether the chosen API type (HTTP vs. WebSocket vs. REST) actually supports the native feature in question.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →