SYSTEM Cited by 6 sources
Amazon API Gateway¶
What it is¶
Amazon API Gateway is AWS's managed API ingress — fronts a REST, HTTP, or WebSocket API, handles routing, throttling, authz, request transformation, and caching, forwards requests to a backend (Lambda, ECS, EC2, VPC endpoint, etc.).
Why it appears in Verified Permissions architectures¶
In the lambda-authorizer pattern, API Gateway invokes a Lambda authorizer before each request, the authorizer returns an IAM policy (Allow / Deny), API Gateway enforces that policy and forwards or rejects.
API Gateway adds two things beyond the authorizer itself:
- Authorization-decision cache. When a Lambda authorizer returns an IAM policy, API Gateway can cache that decision keyed by token (or token + route), so subsequent requests from the same principal hit the cached IAM policy without re-invoking the authorizer. Cache TTL is per-authorizer-configured. This is the outer half of the two-level cache that delivers submillisecond authorization in Convera's architecture.
- Built-in 403 / deny response handling — API Gateway returns the HTTP 4xx directly without touching the backend on deny.
The inner half of the two-level cache is application-level caching of Cognito tokens; together they mean that for repeat calls neither Cognito nor AVP is on the hot path. (Source: sources/2026-02-05-aws-convera-verified-permissions-fine-grained-authorization)
Caveats¶
- Cache invalidation on policy change isn't discussed in the Convera source; in general the authorizer-cache TTL becomes the policy-change propagation floor.
- API Gateway has its own request-rate and account-level service quotas that are not discussed in the Convera source.
Seen in¶
- sources/2026-09-18-aws-how-csiro-built-scalable-cost-optimized-genomic-variant-querying-on-aws
— API Gateway as the sole public entry point and zero-trust
authentication boundary for sBeacon. Every request must
carry a valid JWT from an Amazon Cognito user pool;
the
COGNITO_USER_POOLSauthorizer validates signature/expiry/audience before any Lambda is invoked, so unauthenticated requests get a401without reaching a handler. All other services (S3, DynamoDB, Athena, SNS) have no public resource policies — API Gateway is the only ingress. It also enforces the whole-genome-range-query timeout (an accidental genome-wide range query times out at the API Gateway level). Onboarding (submitDataset) sits behind the same authorizer plus ansbeacon-admingroup check. (Source: sources/2026-09-18-aws-how-csiro-built-scalable-cost-optimized-genomic-variant-querying-on-aws) - sources/2026-09-10-aws-building-resilient-real-time-streaming-workers-with-amazon-dynamodb-leases — API Gateway as the control-plane event ingress (a REST API) for a WebSocket worker fleet: external systems POST START / STOP events that a Lambda event router turns into DynamoDB connection-state writes + SQS notifications. Note the layering — the managed WebSocket connections the fleet holds are outbound to upstream sources, so API Gateway here fronts only the control API, not the data-plane sockets. (Source: sources/2026-09-10-aws-building-resilient-real-time-streaming-workers-with-amazon-dynamodb-leases)
- sources/2026-08-19-aws-how-clario-detects-phi-pii-in-dicom-images-using-bedrock — API Gateway is the edge choke point for Clario's DICOM PHI/PII detection service: TLS in transit, IAM-backed authorization, per-consumer API-key validation, and rate limiting are all handled at the edge, then the request is forwarded to the EKS detection backend — keeping the backend focused purely on detection (see gateway-strips-auth-dispatches-cached-backend).
- sources/2026-02-05-aws-convera-verified-permissions-fine-grained-authorization — API Gateway as the ingress + authorizer-decision cache across all four Convera authorization flows; explicit role in the two-level cache delivering submillisecond latency.
- sources/2026-04-21-aws-oldcastle-infor-aurora-quicksight-real-time-analytics
— API Gateway as the signed-embed-URL minting endpoint for
embedded QuickSight dashboards inside Infor OS. REST API with
Lambda integration; Lambda validates Infor session tokens,
maps Infor roles → QuickSight permissions + RLS filters, and
calls
GenerateEmbedUrlForRegisteredUser. CORS configured per-Infor-domain; rate-limiting at the API Gateway tier. The canonical wiki instance of signed-embed-url-with-role-mapping.
Related¶
- lambda-authorizer — the pattern API Gateway's authorizer hook was built for.
- systems/aws-lambda — most common backend + the authorizer compute.
- systems/amazon-verified-permissions — policy engine the Lambda authorizer calls.
- authorization-decision-caching — the cache design space.
Bosch L.OS vehicle-tracking ingress¶
Bosch L.OS uses API Gateway as the unified consumer ingress for discovery, tracking, and termination requests before its ECS/Fargate Tracking Connector authenticates, authorizes, normalizes, and routes them. The source does not disclose API type, authorizer configuration, throttling limits, or caching policy. (Source: sources/2026-08-14-aws-serverless-vehicle-tracking-at-scale-bosch-los-on-aws)