Validate third-party OAuth tokens with an API Gateway Lambda authorizer
A company is using AWS to develop and manage its production web application. The application includes an Amazon API Gateway HTTP API that invokes an AWS Lambda function. The Lambda function processes and then stores data in a database. The company wants to implement user authorization for the web application in an integrated way. The company already uses a third-party identity provider that issues OAuth tokens for the company’s other applications. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An API Gateway Lambda authorizer can validate tokens from an external OAuth provider, so the company reuses the tokens it already issues without standing up a new user directory or changing how its other applications sign users in.
A company's web application runs behind an API Gateway HTTP API that invokes a Lambda function, and it already uses a third-party identity provider that issues OAuth tokens for its other applications. The company wants user authorization implemented in an integrated way for this application as well.
Rerouting the application's identity through IAM Identity Center or Directory Service. Identity Center issues AWS STS tokens for AWS console and application access rather than validating the third party's OAuth tokens, and Directory Service is a directory service rather than an API Gateway authorizer, so neither can consume the tokens the applications already hold.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The company already has an identity provider issuing OAuth tokens, and the requirement is to authorise users in an integrated way rather than introduce a parallel system. An API Gateway Lambda authorizer is invoked on each API request and can validate the token issued by the external provider, returning an IAM policy that allows or denies the request, so the existing tokens become the basis for authorisation. Requiring the authorizer on all API routes ensures every endpoint is protected, and the web application change is limited to obtaining a token from the identity provider and passing it in the Authorization header. Because the authorizer is just a Lambda function, the validation logic can call whatever SDK or introspection endpoint the provider exposes, which is why this works with any third-party OAuth provider.Why the Other Options Are Wrong
B: AWS Directory Service is a directory service, and it is not an API Gateway authorizer, so the described configuration does not exist. Adding SAML configuration for IAM Identity Center and registering the web application as a custom SAML application also forces the company onto AWS federation for a user base that already authenticates through the third-party provider, which is the opposite of an integrated approach. C: IAM Identity Center is integrated with API Gateway but it validates AWS STS tokens issued by AWS, not the third party's OAuth tokens, so the web application would have to obtain AWS tokens instead of the ones it already has, which changes the authentication model rather than integrating with it. D: IAM users with permissions to call the API are AWS credentials, not end-user identities, and extracting request parameters from IAM users and putting them in an Authorization header provides no authentication at all since the header content is attacker-controlled.Community Comment Notes
The community voted 100 to 0 for A, and the top-voted comments linked the AWS blog on using Lambda authorizers with a third-party identity provider to secure API Gateway APIs, and noted that this pattern lets users access API Gateway resources with their third-party credentials without configuring additional services such as Amazon Cognito. Another commenter pointed out that Lambda authorizers can integrate with external providers including OAuth 2.0 and OpenID Connect.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →