Skip to content
Docs
English
Esc
↑↓navigate↵open⌘Jpreview
On this page

Authentication and APIs

Use Cognito and API Gateway to authenticate users and authorize backend requests.

Amazon Cognito manages sign-up and sign-in. API Gateway exposes the backend endpoints and checks authentication before routing requests to Lambda functions.

Cognito user pools

A user pool stores user accounts and attributes. It supports password policies, multi-factor authentication, tokens, and federation with external identity providers. A managed login interface can reduce the amount of authentication UI the application needs to build.

User groups can distinguish organizers from participants. Authentication establishes who a user is; the application must still enforce which records and operations that user may access. Group claims or scopes can inform that decision, but they do not replace authorization in the backend. See Cognito user pools.

Managed and custom authentication

Responsibility Custom implementation Cognito
Accounts Build and maintain account storage and flows Managed user directory and account flows
Passwords Implement secure storage, recovery, and policies Configurable policies and recovery flows
Tokens and MFA Implement and maintain the mechanisms Managed token issuance and MFA options
Social sign-in Integrate each identity provider Configure supported identity providers
Maintenance Operate the authentication infrastructure Configure and integrate the managed service
Customization Full control, with implementation responsibility Work within the service’s features and extension points

API Gateway’s role

API Gateway presents REST endpoints, routes requests to the appropriate function, and integrates with Cognito authorizers to validate tokens. Throttling helps control request rates; CloudWatch logs and metrics help diagnose failures and understand usage.

An authenticated request can ask the backend for an upload URL or retrieve a processing result. The function must verify ownership or organizer permissions before returning either. Keep file transfers in S3 rather than sending large media files through the API.

Continue to EC2 and Lambda

Last updated on October 7, 2026

Was this page helpful?