# Cognito authorizer not being set for API gateway

**URL:** <https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109>\
**Category:** Serverless Framework\
**Tags:** lambda\
**Created:** [July 17, 2018, 6:18pm UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109 "2018-07-17T18:18:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kgoedecke](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/kgoedecke/32/2251_2.png) [@kgoedecke](https://forum.serverless.com/u/kgoedecke)\
**Post date:** [July 17, 2018, 6:18pm UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/1 "2018-07-17T18:18:00Z")

</div>

I’m currently having issues on adding a simple cognito userpool as the authorizer function. The serverless file specifies the authorizer but yet it is not being set in the AWS Gateway as the authorizer (confirmed by AWS console dashboard).

My serverless file looks like this:

```
functions:
  create:
    handler: handler.createSite
    events:
      - http:
          path: sites
          method: post
        integration: lambda-proxy
        authorizer: cognitoAuthorizer
        cors:
          origins:
            - '*'
          headers:
            - Content-Type
            - X-Amz-Date

```

And under resources I have this:

```
resources:
apiGatewayAuthorizer: 
      Type: AWS::ApiGateway::Authorizer
      Properties: 
        Name: cognitoAuthorizer
        Type: COGNITO_USER_POOLS
        IdentitySource: method.request.header.Authorization
        RestApiId: 
          Ref: ApiGatewayRestApi
        ProviderARNs: 
          - 'arn:aws:cognito-idp:us-east-1:2xxxxxx8:userpool/us-east-1_5kKNNXXX'

```

Am I doing anything wrong here? I feel like this should be very easy thing to do, yet I’m having massive issues using Cognito with serverless.

---

<div class="post-metadata">

**Author:** ![buggy](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/buggy/32/177_2.png) [@buggy](https://forum.serverless.com/u/buggy)\
**Post date:** [July 18, 2018, 1:26am UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/2 "2018-07-18T01:26:36Z")

</div>

Your indentation looks incorrect.

Based on the docs I don’t think you need the resources section at all.

```auto
functions:
  create:
    handler: handler.createSite
    events:
      - http:
          path: sites
          method: post
          authorizer:
            arn: arn:aws:cognito-idp:us-east-1:2xxxxxx8:userpool/us-east-1_5kKNNXXX

```

---

<div class="post-metadata">

**Author:** ![kgoedecke](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/kgoedecke/32/2251_2.png) [@kgoedecke](https://forum.serverless.com/u/kgoedecke)\
**Post date:** [July 18, 2018, 1:37am UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/3 "2018-07-18T01:37:36Z")

</div>

@buggy Would that create the resources then, or would I have to do that manually through the AWS console?

---

<div class="post-metadata">

**Author:** ![buggy](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/buggy/32/177_2.png) [@buggy](https://forum.serverless.com/u/buggy)\
**Post date:** [July 19, 2018, 4:08am UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/4 "2018-07-19T04:08:15Z")

</div>

@kgoedecke You still need to create the User Pool which can be done manually or in the resources section.

---

<div class="post-metadata">

**Author:** ![kgoedecke](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/kgoedecke/32/2251_2.png) [@kgoedecke](https://forum.serverless.com/u/kgoedecke)\
**Post date:** [July 19, 2018, 10:01am UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/5 "2018-07-19T10:01:43Z")

</div>

Issue has been resolved, it was just an indention problem! Thanks guys!

---

<div class="post-metadata">

**Author:** ![JosephCanete](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/josephcanete/32/7614_2.png) [@JosephCanete](https://forum.serverless.com/u/JosephCanete)\
**Post date:** [August 18, 2023, 4:39am UTC](https://forum.serverless.com/t/cognito-authorizer-not-being-set-for-api-gateway/5109/6 "2023-08-18T04:39:36Z")

</div>

Hey bro, by any chance do you know why my cognito authorizer only honors id\_token from Header.Authorization: "Bearer " + id\_token? - I cannot find a way to change this into "Bearer " + access\_token.

from login response I am getting  
id\_token  
access\_token  
refresh\_token

Can you enlighthen me please?
