# API Gateway and Cognito Authorization in Lambda Function

**URL:** <https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357>\
**Category:** Serverless Architectures\
**Tags:** aws\
**Created:** [February 20, 2017, 7:24am UTC](https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357 "2017-02-20T07:24:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tsch](https://avatars.discourse-cdn.com/v4/letter/t/76d3ee/32.png) [@Tsch](https://forum.serverless.com/u/Tsch)\
**Post date:** [February 20, 2017, 7:24am UTC](https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357/1 "2017-02-20T07:24:06Z")

</div>

Hello,

I am currently working on a web application that has the following setup:

- Backend written with Serverless, using API Gateway and Lambda functions that access DynamoDB
- Frontend with Angular2 hosted on S3 bucket consuming REST webservice exposed by API Gateway
- AWS Cognito for user management (and Cognito authorizer)

Now I was wondering if I really have to use the AWS Cognito Identity JS SDK for login/register/etc on the clientside. I think when providing additional endpoints via the REST API with API Gateway to allow login, register, etc. would result in a more consistent API without the need to include Cognito SDK in every application. My frontend would then just send userdata (username and password) to a public HTTPS endpoint _/login_ within my API Gateway and the lambda functions forwards the userdata to cognito. On positive authorization I can return a JWT token generated from Cognito from my Lambad function that can be used for any further authorized requests (added to authorization headers on client side).

Does this approach leads to any security concerns compared to client side Cognito authentication directly in the frontend? So far, I have not found anything related using a lambda function to get JWT token from Cognito.

Thanks in advance for your opinions

---

<div class="post-metadata">

**Author:** ![outmarch](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/outmarch/32/1259_2.png) [@outmarch](https://forum.serverless.com/u/outmarch)\
**Post date:** [March 7, 2017, 4:16am UTC](https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357/2 "2017-03-07T04:16:47Z")

</div>

you able to find answer for your question ? I had same question.

Below URL says _The password features use the Secure Remote Password (SRP) protocol to avoid sending cleartext passwords over the wire._ so SDK uses SRP protocol which is more secure …

> **[amazon-archives/amazon-cognito-identity-js](https://github.com/amazon-archives/amazon-cognito-identity-js)**
>
> Amazon Cognito Identity SDK for JavaScript. Contribute to amazon-archives/amazon-cognito-identity-js development by creating an account on GitHub.

what is the best practice?

---

<div class="post-metadata">

**Author:** ![Tsch](https://avatars.discourse-cdn.com/v4/letter/t/76d3ee/32.png) [@Tsch](https://forum.serverless.com/u/Tsch)\
**Post date:** [March 7, 2017, 5:56am UTC](https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357/3 "2017-03-07T05:56:38Z")

</div>

Still not sure on this. And you are right, the quote with SRP makes me wondering if my approach is really a good idea to go.

---

<div class="post-metadata">

**Author:** ![outmarch](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/outmarch/32/1259_2.png) [@outmarch](https://forum.serverless.com/u/outmarch)\
**Post date:** [March 9, 2017, 5:30am UTC](https://forum.serverless.com/t/api-gateway-and-cognito-authorization-in-lambda-function/1357/4 "2017-03-09T05:30:58Z")

</div>

I have opened below issue with AWS lets see what they suggest …

> <https://github.com/amazon-archives/amazon-cognito-identity-js/issues/319#issuecomment-285171455>
>
> I am planning to use Cognito user pool, federated identities with APIG and lambda.
> In my case I am planning to use...
