# Configure ApiGateway v2 authorizers

**URL:** <https://forum.serverless.com/t/configure-apigateway-v2-authorizers/11376>\
**Category:** Serverless Framework\
**Tags:** api-gateway\
**Created:** [May 6, 2020, 8:13pm UTC](https://forum.serverless.com/t/configure-apigateway-v2-authorizers/11376 "2020-05-06T20:13:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SavelevArtemD](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/savelevartemd/32/4222_2.png) [@SavelevArtemD](https://forum.serverless.com/u/SavelevArtemD)\
**Post date:** [May 6, 2020, 8:13pm UTC](https://forum.serverless.com/t/configure-apigateway-v2-authorizers/11376/1 "2020-05-06T20:13:49Z")

</div>

I’m trying to setup simple authorizer based on this [doc](https://www.serverless.com/framework/docs/providers/aws/events/http-api/). Also using serverless plugin [serverless-pseudo-parameters](https://www.npmjs.com/package/serverless-pseudo-parameters).

My serverless configuration for authorizer:

```auto
provider:
...
  logs:
    httpApi: true
  httpApi:
    cors: true
    authorizers:
      simpleAuthorizer:
        identitySource: $request.header.Authorization
        issuerUrl:
          - Fn::Join:
              - '/'
              - - https://cognito-idp.#{AWS::Region}.amazonaws.com
                - "#{CognitoUserPool}"
        audience:
          - "#CognitoUserPoolClient"

```

My configuration for simple lambda:

```auto
functions:
  ping:
    name: ${self:provider.stage}-ping
    handler: test.handler
    events:
      - httpApi:
          method: GET
          path: /test
          authorizer:
            name: simpleAuthorizer

```

My configuration of user pool and user pool client:

```auto
resources:
  Resources:
    CognitoUserPool:
      Type: AWS::Cognito::UserPool
      Properties:
        UserPoolName: ${self:service}-${self:provider.stage}-user
        UsernameAttributes:
          - email
        Policies:
          PasswordPolicy:
            MinimumLength: 6
            RequireLowercase: False
            RequireNumbers: True
            RequireSymbols: False
            RequireUppercase: True
        Schema:
          - Name: email
            Required: false
            DeveloperOnlyAttribute: false
            Mutable: true
            AttributeDataType: String

    CognitoUserPoolClient:
      Type: AWS::Cognito::UserPoolClient
      Properties:
        ClientName: cognito-example-client
        GenerateSecret: False
        UserPoolId: "#{CognitoUserPool}"

```

User pool, user pool client, HTTP API, lambda successfully created, **but I can’t see a authorizer at the AWS console of API Gateway service.** Thanks for any help.

---

<div class="post-metadata">

**Author:** ![orndorffgrant](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/orndorffgrant/32/4110_2.png) [@orndorffgrant](https://forum.serverless.com/u/orndorffgrant)\
**Post date:** [May 7, 2020, 1:44pm UTC](https://forum.serverless.com/t/configure-apigateway-v2-authorizers/11376/2 "2020-05-07T13:44:51Z")

</div>

Hey @SavelevArtemD! I just deployed the following serverless.yaml. I think the only difference is putting curly braces around `CognitoUserPoolClient` for the audience.

```auto
service: test

plugins:
  - serverless-pseudo-parameters

provider:
  name: aws
  runtime: nodejs12.x
  logs:
    httpApi: true
  httpApi:
    cors: true
    authorizers:
      simpleAuthorizer:
        identitySource: $request.header.Authorization
        issuerUrl: "https://cognito-idp.#{AWS::Region}.amazonaws.com/#{CognitoUserPool}"
        audience:
          - "#{CognitoUserPoolClient}"

functions:
  ping:
    name: ${self:provider.stage}-ping
    handler: test.handler
    events:
      - httpApi:
          method: GET
          path: /test
          authorizer:
            name: simpleAuthorizer

resources:
  Resources:
    CognitoUserPool:
      Type: AWS::Cognito::UserPool
      Properties:
        UserPoolName: ${self:service}-${self:provider.stage}-user
        UsernameAttributes:
          - email
        Policies:
          PasswordPolicy:
            MinimumLength: 6
            RequireLowercase: False
            RequireNumbers: True
            RequireSymbols: False
            RequireUppercase: True
        Schema:
          - Name: email
            Required: false
            DeveloperOnlyAttribute: false
            Mutable: true
            AttributeDataType: String

    CognitoUserPoolClient:
      Type: AWS::Cognito::UserPoolClient
      Properties:
        ClientName: cognito-example-client
        GenerateSecret: False
        UserPoolId: "#{CognitoUserPool}"

```

And everything seemed to get deployed. Looking at the stack in the CloudFormation Console I see this:

 ![teststack](https://canada1.discourse-cdn.com/flex036/uploads/serverless/original/2X/6/6cb6aad0345c48425f5e4e25d36314a39c575d81.png)

Then if I click the link in the row for HttpApi and then navigate to the “Authorization” section and select the endpoint I see this

 ![authsection](https://canada1.discourse-cdn.com/flex036/uploads/serverless/original/2X/3/3c89b650edd5c7f0099ddadbca0baa60a8af36ae.png)

So it looks like everything is deploying successfully on my end.

Running `sls --version` I get:

```auto
Framework Core: 1.69.0
Plugin: 3.6.11
SDK: 2.3.0
Components: 2.30.10

```

Hopefully this helps. Let me know if you can’t get it working.

Best,  
Grant

* * *

Plug: The complexity of getting Cognito working with serverless is the reason I founded JustAuthenticateMe. It’s a super simple authentication-as-a-service that’s straightforward to set up. Check it out at [https://www.justauthenticate.me/](https://www.justauthenticate.me/)

---

<div class="post-metadata">

**Author:** ![SavelevArtemD](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/savelevartemd/32/4222_2.png) [@SavelevArtemD](https://forum.serverless.com/u/SavelevArtemD)\
**Post date:** [May 7, 2020, 6:13pm UTC](https://forum.serverless.com/t/configure-apigateway-v2-authorizers/11376/3 "2020-05-07T18:13:44Z")

</div>

Thanks a lot!  
I solved my problem by simple updating servreless (completely forgot I used the version 1.63.0)
