Validate third-party OAuth tokens with an API Gateway Lambda authorizer

Answer Correct answer: A — Integrate the third-party IdP with API Gateway through a Lambda authorizer that validates its tokens, required on all routes.

A company is using AWS to develop and manage its production web application. The application includes an Amazon API Gateway HTTP API that invokes an AWS Lambda function. The Lambda function processes and then stores data in a database. The company wants to implement user authorization for the web application in an integrated way. The company already uses a third-party identity provider that issues OAuth tokens for the company’s other applications. Which solution will meet these requirements?

  1. Integrate the company’s third-party identity provider with API Gateway. Configure an API Gateway Lambda authorizer to validate tokens from the identity provider. Require the Lambda authorizer on all API routes. Update the web application to get tokens from the identity provider and include the tokens in the Authorization header when calling the API Gateway HTTP API. Correct Answer
  2. Integrate the company's third-party identity provider with AWS Directory Service. Configure Directory Service as an API Gateway authorizer to validate tokens from the identity provider. Require the Directory Service authorizer on all API routes. Configure AWS IAM Identity Center as a SAML 2.0 identity Provider. Configure the web application as a custom SAML 2.0 application.
  3. Integrate the company’s third-party identity provider with AWS IAM Identity Center. Configure API Gateway to use IAM Identity Center for zero-configuration authentication and authorization. Update the web application to retrieve AWS Security Token Service (AWS STS) tokens from IAM Identity Center and include the tokens in the Authorization header when calling the API Gateway HTTP API.
  4. Integrate the company’s third-party identity provider with AWS IAM Identity Center. Configure IAM users with permissions to call the API Gateway HTTP API. Update the web application to extract request parameters from the IAM users and include the parameters in the Authorization header when calling the API Gateway HTTP API.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An API Gateway Lambda authorizer can validate tokens from an external OAuth provider, so the company reuses the tokens it already issues without standing up a new user directory or changing how its other applications sign users in.

A company's web application runs behind an API Gateway HTTP API that invokes a Lambda function, and it already uses a third-party identity provider that issues OAuth tokens for its other applications. The company wants user authorization implemented in an integrated way for this application as well.

Rerouting the application's identity through IAM Identity Center or Directory Service. Identity Center issues AWS STS tokens for AWS console and application access rather than validating the third party's OAuth tokens, and Directory Service is a directory service rather than an API Gateway authorizer, so neither can consume the tokens the applications already hold.

Community Discussion (7 comments)

AzureDP900 👍 3 Selected: A
A is right, to implement user authorization for the web application, you can integrate the company’s third-party identity provider with API Gateway using an API Gateway Lambda authorizer to validate tokens from the identity provider. By requiring this authorizer on all API routes, you ensure that only authenticated and authorized users can access the application. Finally, update the web application to retrieve tokens from the identity provider and include them in the Authorization header when making requests to the API Gateway HTTP API. This ensures a seamless and integrated user experience across all applications using the same third-party identity provider.
0b43291 👍 3 Selected: A
By integrating the third-party identity provider with API Gateway and using a Lambda authorizer to validate OAuth tokens, Option A provides a seamless and integrated solution for user authorization in the web application, while leveraging the company's existing identity management infrastructure. The other options have drawbacks or do not fully meet the requirements: Option B: Integrating with AWS Directory Service and configuring it as an API Gateway authorizer may be unnecessary since the company already has a third-party identity provider. Option C: Requiring the web application to retrieve AWS STS tokens may be unnecessary since the company already has OAuth tokens issued by the third-party identity provider. Option D: Creating IAM users and extracting request parameters can be more complex and may not leverage the existing third-party identity provider and OAuth token issuance process.
Daniel76 👍 3 Selected: A
https://aws.amazon.com/blogs/security/use-aws-lambda-authorizers-with-a-third-party-identity-provider-to-secure-amazon-api-gateway-rest-apis/
Daniel76 👍 1 Selected: A
Building a Lambda authorizer allows users to access API Gateway resources by using their third-party credentials without having to configure additional services, such as Amazon Cognito. This can be particularly useful if your organization is using the third-party identity provider for single sign-on (SSO). on.com/blogs/security/use-aws-lambda-authorizers-with-a-third-party-identity-provider-to-secure-amazon-api-gateway-rest-apis/
gfhbox0083 👍 1 Selected: A
A, for sure. Lambda authorizers can integrate with external identity providers, including OAuth2, OpenID Connect, and others, to validate tokens or credentials.
vip2 👍 2 Selected: A
A API GW + integrated Lambda Authorizor for Authen. and Author.
kupo777 👍 2
A It is reasonable to configure the API Gateway Lambda authorizer to validate tokens from identity providers.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The company already has an identity provider issuing OAuth tokens, and the requirement is to authorise users in an integrated way rather than introduce a parallel system. An API Gateway Lambda authorizer is invoked on each API request and can validate the token issued by the external provider, returning an IAM policy that allows or denies the request, so the existing tokens become the basis for authorisation. Requiring the authorizer on all API routes ensures every endpoint is protected, and the web application change is limited to obtaining a token from the identity provider and passing it in the Authorization header. Because the authorizer is just a Lambda function, the validation logic can call whatever SDK or introspection endpoint the provider exposes, which is why this works with any third-party OAuth provider.

Why the Other Options Are Wrong

B: AWS Directory Service is a directory service, and it is not an API Gateway authorizer, so the described configuration does not exist. Adding SAML configuration for IAM Identity Center and registering the web application as a custom SAML application also forces the company onto AWS federation for a user base that already authenticates through the third-party provider, which is the opposite of an integrated approach. C: IAM Identity Center is integrated with API Gateway but it validates AWS STS tokens issued by AWS, not the third party's OAuth tokens, so the web application would have to obtain AWS tokens instead of the ones it already has, which changes the authentication model rather than integrating with it. D: IAM users with permissions to call the API are AWS credentials, not end-user identities, and extracting request parameters from IAM users and putting them in an Authorization header provides no authentication at all since the header content is attacker-controlled.

Community Comment Notes

The community voted 100 to 0 for A, and the top-voted comments linked the AWS blog on using Lambda authorizers with a third-party identity provider to secure API Gateway APIs, and noted that this pattern lets users access API Gateway resources with their third-party credentials without configuring additional services such as Amazon Cognito. Another commenter pointed out that Lambda authorizers can integrate with external providers including OAuth 2.0 and OpenID Connect.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide