# Get API key IDs or actual keys

**URL:** <https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180>\
**Category:** Serverless Framework\
**Tags:** aws\
**Created:** [November 24, 2017, 9:44am UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180 "2017-11-24T09:44:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![henrik](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/henrik/32/1325_2.png) [@henrik](https://forum.serverless.com/u/henrik)\
**Post date:** [November 24, 2017, 9:44am UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180/1 "2017-11-24T09:44:12Z")

</div>

Hey,

I would like to protect some of my AWS Lambda functions exposed via HTTP with a simple API key mechanism.

Serverless has the apiKeys section which will automatically generate the keys in AWS and print them after deployment.  
However, only the name of the key can be set in the configuration.

In my Lambda function I need to check, which of the generated keys has been used. The HTTP Lambda proxy gives me the ID and value of the API key. The only problem is, in my application I do not have access to the keys.

I tried passing them as an environment variable like so:

```
provider:
  environment:
    APIKEY_ADMIN: Ref: ApiGatewayApiKey1
    APIKEY_PUBLIC: Ref: ApiGatewayApiKey2

```

Which results in a circular dependency. Is there any other way to get they API key value or ID without hardcoding it? Or will I have to write a custom authorizer?

Thanks

---

<div class="post-metadata">

**Author:** ![el-feo](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/el-feo/32/2346_2.png) [@el-feo](https://forum.serverless.com/u/el-feo)\
**Post date:** [August 20, 2018, 6:37pm UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180/2 "2018-08-20T18:37:27Z")

</div>

Hi Henrik, did you ever solve this issue?  
I am trying to do something similar.

Thanks!

---

<div class="post-metadata">

**Author:** ![henrik](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/henrik/32/1325_2.png) [@henrik](https://forum.serverless.com/u/henrik)\
**Post date:** [August 20, 2018, 6:56pm UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180/3 "2018-08-20T18:56:52Z")

</div>

Hey,

I’m afraid not. I resorted to using JSON Web Tokens instead.

---

<div class="post-metadata">

**Author:** ![el-feo](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/el-feo/32/2346_2.png) [@el-feo](https://forum.serverless.com/u/el-feo)\
**Post date:** [August 23, 2018, 9:17pm UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180/4 "2018-08-23T21:17:12Z")

</div>

Henrik, thanks for responding to my question.

For anyone finding this in the future my solution was to create an `api-key-authorizer` module and look up the key based upon the key name. This relies on you being able to define the key name in the serverless.yml file:

```javascript
const aws = require("aws-sdk");

let apiGateway = new aws.APIGateway({
  region: process.env.REGION
});

function findApiKey(apiKeyName) {
  let apiParams = {
    includeValues: true,
    nameQuery: apiKeyName
  };
  let authorizedKey;
  apiGateway.getApiKeys(apiParams, function (err, data) {
    if (err) console.log(err, err.stack);
    else {
      authorizedKey = data.items[0].value;
    }
  });
  return authorizedKey;
}

exports.verifyAccess = (headers, apiKeyName) => {
  let requestKey = headers["x-api-key"];
  let validKey = findApiKey(apiKeyName);
  let isAuthorized = validKey === requestKey;
  return isAuthorized;
};

```

There’s probably a better way to do this and it’d be great to be able to reference a specific key in `process.env` but I could not find a way.

---

<div class="post-metadata">

**Author:** ![taystu](https://avatars.discourse-cdn.com/v4/letter/t/f9ae1b/32.png) [@taystu](https://forum.serverless.com/u/taystu)\
**Post date:** [January 14, 2019, 12:01pm UTC](https://forum.serverless.com/t/get-api-key-ids-or-actual-keys/3180/5 "2019-01-14T12:01:25Z")

</div>

Hi is there any update or better way to access the generated API Keys?
