# Set header value for proxied request programatically

**URL:** <https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078>\
**Category:** Serverless Framework\
**Tags:** cloudformation, api-gateway\
**Created:** [April 24, 2019, 8:48am UTC](https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078 "2019-04-24T08:48:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DrColza](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/drcolza/32/2838_2.png) [@DrColza](https://forum.serverless.com/u/DrColza)\
**Post date:** [April 24, 2019, 8:48am UTC](https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078/1 "2019-04-24T08:48:09Z")

</div>

I’m using an API Gateway endpoint as a proxy to a 3rd party service.

_Given_ I authenticate to the proxy endpoint using the value in the Authorization header

_When_ the proxy makes the request to the 3rd party

_Then_ it should be using the 3rd party api-key (pulled from SSM) as the value in the forwarded Authorization header

_But_ the request to the 3rd party is using the original request Authorization header value

The function definition in my serverless.yml:

```
functions:
  3rd_party_proxy_v1:
    handler: handler.hello
    events:
      - http:
          path: /v1/{proxy+}
          method: ANY
          integration: HTTP_PROXY
          authorizer: ${self:custom.authorizer_arn}
          cors: true
          request:
            uri: ${self:custom.3rd_party_base_url}/api/v1/{proxy}
            parameters:
              paths:
                proxy: true
              querystrings:
                data: true
              headers:
                Authorization: "'SSWS ${ssm:3RD_PARTY_API_KEY~true}'"

```

When I test this functionality via the console it works as expected, using the value pulled from SSM.

However, when I test it by hitting the api gateway directly it just passes through the auth header value.

The only way I can get it to work is by manually setting the header value via the console but I’d like to have this happen programmatically, can serverless support this?

---

<div class="post-metadata">

**Author:** ![DrColza](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/drcolza/32/2838_2.png) [@DrColza](https://forum.serverless.com/u/DrColza)\
**Post date:** [May 2, 2019, 8:12am UTC](https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078/2 "2019-05-02T08:12:01Z")

</div>

I couldn’t find a solution using HTTP\_PROXY so I had to switch to using a LAMBDA\_PROXY. I will update here if I find an HTTP\_PROXY solution.

---

<div class="post-metadata">

**Author:** ![DrColza](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/drcolza/32/2838_2.png) [@DrColza](https://forum.serverless.com/u/DrColza)\
**Post date:** [May 7, 2019, 10:13am UTC](https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078/3 "2019-05-07T10:13:12Z")

</div>

I’ve found an approach to being able to use the serverless framework and be able to hard code integration request header values and utilise HTTP\_PROXY instead of maintaining a LAMBDA\_PROXY.

I had to write an intermediary python script to programmatically edit the Cloudformation that the serverless tool creates.

Deployment steps as follows:

1. Use the yml fucntion configuration defined in the original post.
2. Create a package, `sls package --package <YOUR_PACKAGE_NAME> --stage <STAGE>`
3. Run the python script to change the `integration.request.header.Authorization` value in the `<YOUR_PACKAGE_NAME>/cloudformation-template-update-stack.json` and `<YOUR_PACKAGE_NAME>/serverless-state.json` files
4. Deploy the package `sls deploy --package <YOUR_PACKAGE_NAME> --stage <STAGE>`

I bundled these commands together in a Makefile so I could call a single command for packaging, updating and deploying:

`make deploy-<STAGE>`

---

<div class="post-metadata">

**Author:** ![VillaCebras](https://avatars.discourse-cdn.com/v4/letter/v/ee59a6/32.png) [@VillaCebras](https://forum.serverless.com/u/VillaCebras)\
**Post date:** [December 13, 2019, 11:15am UTC](https://forum.serverless.com/t/set-header-value-for-proxied-request-programatically/8078/4 "2019-12-13T11:15:32Z")

</div>

Have you tried to override cloudformation template directly from serverless.yml?

> **[Serverless Framework - AWS Lambda Guide - AWS Infrastructure Resources](https://serverless.com/framework/docs/providers/aws/guide/resources/)**
>
> How to deploy and manage AWS infrastructure to use with your AWS Lambda functions with the Serverless Framework

Then you can override request integration header sending third-party authorization token instead of AWS Apigateway token.

```
resources:
  Resources:
    ApiGatewayMethodYourMethod:
      Type: AWS::ApiGateway::Method
      Properties:
        Integration:
          RequestParameters:
            integration.request.header.User-Agent: 'token'

```

Hope this helps!
