You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS IAM用户凭证调用API Gateway始终提示匿名未授权问题

问题诊断与解决方案

你的问题核心出在请求认证参数配置错误和API Gateway未启用IAM校验两个关键环节,导致请求被识别为匿名用户。

1. 修正Python请求的认证参数

你的AWSRequestsAuth配置存在两处错误:

  • aws_host需填写API Gateway的实际域名,而非ec2.amazonaws.com
  • aws_service应指定为execute-api(API Gateway对应的AWS服务标识),不是api

修正后的代码:

import requests
from aws_requests_auth.aws_auth import AWSRequestsAuth

url = 'https://<apig id>.execute-api.us-west-2.amazonaws.com/beta/query/'

auth = AWSRequestsAuth(
    aws_access_key='<my key id>',
    aws_secret_access_key='<my secret key>',
    aws_host='<apig id>.execute-api.us-west-2.amazonaws.com',  # 替换为你的API Gateway域名
    aws_region='us-west-2',
    aws_service='execute-api'  # 修正为正确的服务名称
)

response = requests.get(url, auth=auth)

2. 启用API Gateway的IAM认证校验

即使IAM用户和资源策略配置正确,若API Gateway方法未开启IAM认证,系统不会校验请求中的IAM凭证,直接将请求标记为匿名。

配置步骤:

  • 进入AWS控制台的API Gateway服务,打开目标API
  • 找到beta阶段下的/query方法,点击方法请求
  • 在设置区域的认证类型中选择AWS IAM
  • 保存配置后,重新部署API到beta阶段

3. 额外验证项

  • 确认IAM用户的Access Key/Secret Key未过期、权限未被撤销
  • 检查资源策略的Resource ARN:arn:aws:execute-api:us-west-2:<my account id>:<my api g id>/*已覆盖/beta/query路径,无需调整
  • Postman中配置时,选择AWS Signature认证类型,填写正确的Access Key、Secret Key、Region,以及Service Name(execute-api)

完成以上操作后,重新发起请求即可通过认证。

内容的提问来源于stack exchange,提问作者piano-antinomy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 08:56:07