Is IAM role inside yml file is enough for authorisation?

I am using cognito for authentication of my API.
According to my understanding, we defined IAM role in serverless.yml file to limit access to aws resource from API. So, do we still need to create identity pool and link with user pool.

What I want to do is that, I want to create different level of user to access the API? According to this resource (, creating cognito identity pool is the solution. Is there any other way we can do that?

Much of what your are doing is implemented in the aws-amplify library.

1 Like