# Custom Lambda Authorizer returning blank error message

**URL:** <https://forum.serverless.com/t/custom-lambda-authorizer-returning-blank-error-message/9233>\
**Category:** Serverless Framework\
**Tags:** lambda, api-gateway\
**Created:** [September 5, 2019, 8:31pm UTC](https://forum.serverless.com/t/custom-lambda-authorizer-returning-blank-error-message/9233 "2019-09-05T20:31:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sciguy](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@sciguy](https://forum.serverless.com/u/sciguy)\
**Post date:** [September 5, 2019, 8:31pm UTC](https://forum.serverless.com/t/custom-lambda-authorizer-returning-blank-error-message/9233/1 "2019-09-05T20:31:05Z")

</div>

The Custom lambda authorizer works fine. But when the token fails validation, i get the following along with status code 500.  
{  
“message”: null  
}

How can i add a more custom error message

---

<div class="post-metadata">

**Author:** ![Julien](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/julien/32/3480_2.png) [@Julien](https://forum.serverless.com/u/Julien)\
**Post date:** [September 6, 2019, 1:37pm UTC](https://forum.serverless.com/t/custom-lambda-authorizer-returning-blank-error-message/9233/2 "2019-09-06T13:37:12Z")

</div>

Hello,

I don’t think you can send a custom message. However, you can send a 401 HTTP status code by returning “Unauthorized” or 403 by returning a policy with effect “Deny” (instead of “Allow”).

You can find more details here : [https://docs.aws.amazon.com/apigateway/latest/developerguide/apigateway-use-lambda-authorizer.html](https://docs.aws.amazon.com/apigateway/latest/developerguide/apigateway-use-lambda-authorizer.html)

Hope it helps

---

<div class="post-metadata">

**Author:** ![walterdl](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/walterdl/32/3865_2.png) [@walterdl](https://forum.serverless.com/u/walterdl)\
**Post date:** [January 8, 2020, 1:49am UTC](https://forum.serverless.com/t/custom-lambda-authorizer-returning-blank-error-message/9233/3 "2020-01-08T01:49:06Z")

</div>

If I throw an error like `throw new Error("blabla")` from the lambda-authorizer, why the response is not `{message: "blabla"}`?
