# Make a Serverless API which can work with or without Authentication

**URL:** <https://forum.serverless.com/t/make-a-serverless-api-which-can-work-with-or-without-authentication/12356>\
**Category:** Serverless Framework\
**Tags:** lambda, api-gateway\
**Created:** [August 22, 2020, 3:29pm UTC](https://forum.serverless.com/t/make-a-serverless-api-which-can-work-with-or-without-authentication/12356 "2020-08-22T15:29:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeevantk](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@Jeevantk](https://forum.serverless.com/u/Jeevantk)\
**Post date:** [August 22, 2020, 3:29pm UTC](https://forum.serverless.com/t/make-a-serverless-api-which-can-work-with-or-without-authentication/12356/1 "2020-08-22T15:29:09Z")

</div>

Hi,  
I have a usecase where I want to give varying responses if the user is not authenticated / not authenticated . I am using cognito for authentication .

**getProfile:**  
\*\* handler: profileController.getProfileDetails\*\*  
\*\* events:\*\*  
\*\* - http:\*\*  
\*\* path: profile/{profileName}\*\*  
\*\* method: get\*\*  
\*\* cors: true\*\*  
\*\* authorizer:\*\*  
\*\* arn: COGNITO ARN GOES HERE\*\*

if I call this API without passing and Authorization Header, I am getting a response stating

**{**  
\*\* “message”: “Unauthorized”\*\*  
**}**

and the control doesn’t even go to my lambda function . What I want is something like this  
export async function getProfileDetails(event,context){

**if(!event.requestContext.authorizer){**  
\*\* // go to unauthorized flow\*\*  
**}else{**  
\*\* // go to authorized flow\*\*  
**}**  
**}**

Please let me know if it is possible to do the same with serverless, API Gateway , lambda and cognito .

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![davidlng8](https://avatars.discourse-cdn.com/v4/letter/d/e47c2d/32.png) [@davidlng8](https://forum.serverless.com/u/davidlng8)\
**Post date:** [September 10, 2020, 8:05pm UTC](https://forum.serverless.com/t/make-a-serverless-api-which-can-work-with-or-without-authentication/12356/2 "2020-09-10T20:05:39Z")

</div>

I noticed there hasn’t been a reply yet so i figured i’d ask a question (i’m also looking for a solution to this): What about switching to a custom authorizer that redirects to a separate lambda method when authentication fails? Would that be a worthwhile approach?
