Authentication and APIs
Use Cognito and API Gateway to authenticate users and authorize backend requests.
Amazon Cognito manages sign-up and sign-in. API Gateway exposes the backend endpoints and checks authentication before routing requests to Lambda functions.
Cognito user pools
A user pool stores user accounts and attributes. It supports password policies, multi-factor authentication, tokens, and federation with external identity providers. A managed login interface can reduce the amount of authentication UI the application needs to build.
User groups can distinguish organizers from participants. Authentication establishes who a user is; the application must still enforce which records and operations that user may access. Group claims or scopes can inform that decision, but they do not replace authorization in the backend. See Cognito user pools.
Managed and custom authentication
| Responsibility | Custom implementation | Cognito |
|---|---|---|
| Accounts | Build and maintain account storage and flows | Managed user directory and account flows |
| Passwords | Implement secure storage, recovery, and policies | Configurable policies and recovery flows |
| Tokens and MFA | Implement and maintain the mechanisms | Managed token issuance and MFA options |
| Social sign-in | Integrate each identity provider | Configure supported identity providers |
| Maintenance | Operate the authentication infrastructure | Configure and integrate the managed service |
| Customization | Full control, with implementation responsibility | Work within the service’s features and extension points |
API Gateway’s role
API Gateway presents REST endpoints, routes requests to the appropriate function, and integrates with Cognito authorizers to validate tokens. Throttling helps control request rates; CloudWatch logs and metrics help diagnose failures and understand usage.
An authenticated request can ask the backend for an upload URL or retrieve a processing result. The function must verify ownership or organizer permissions before returning either. Keep file transfers in S3 rather than sending large media files through the API.