You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AWS API Gateway导入Swagger定义时Bearer认证配置报错求助

AWS API Gateway导入Swagger配置JWT认证的正确方式

你的问题核心在于AWS API Gateway对Swagger/OpenAPI的安全认证配置有特定要求,不能直接套用标准OpenAPI规范的写法,以下是具体分析和解决方案:

错误原因分析

  1. 第一次使用type: http报错:AWS API Gateway目前导入Swagger时不支持标准OpenAPI 3.0的http类型Bearer认证定义,必须结合AWS专属的扩展字段来配置。
  2. 第二次缺name和in报错:符合OpenAPI规范要求,apiKey类型的安全定义必须指定这两个属性,分别标识认证参数的名称和位置。
  3. 第三次配置仍报错:一是name需要大写开头的Authorization(AWS默认识别这个Header名);二是缺少AWS专属的扩展配置,无法让API Gateway识别这是JWT认证关联的授权器,因此被忽略。

正确配置示例

根据你使用的授权类型,选择对应配置:

场景1:使用Cognito用户池作为JWT授权器

openapi: 3.0.1
info:
  title: 你的API名称
  version: 1.0.0
components:
  securitySchemes:
    bearerAuth:
      type: apiKey
      name: Authorization  # 必须大写开头
      in: header
      bearerFormat: JWT
      # AWS专属扩展配置
      x-amazon-apigateway-authtype: cognito_user_pools
      x-amazon-apigateway-authorizer:
        type: cognito_user_pools
        providerARNs:
          - arn:aws:cognito-idp:你的区域:你的账号ID:userpool/你的用户池ID
security:
  - bearerAuth: []  # 全局启用该认证,也可在单个接口配置
paths:
  /你的接口路径:
    get:
      responses:
        '200':
          description: 成功响应

场景2:使用自定义Lambda授权器

openapi: 3.0.1
info:
  title: 你的API名称
  version: 1.0.0
components:
  securitySchemes:
    bearerAuth:
      type: apiKey
      name: Authorization  # 必须大写开头
      in: header
      bearerFormat: JWT
      # AWS专属扩展配置
      x-amazon-apigateway-authtype: custom
      x-amazon-apigateway-authorizer:
        type: token
        authorizerUri: arn:aws:apigateway:你的区域:lambda:path/2015-03-31/functions/你的Lambda授权器ARN/invocations
        authorizerResultTtlInSeconds: 300  # 缓存授权结果的时间(可选)
security:
  - bearerAuth: []
paths:
  /你的接口路径:
    get:
      responses:
        '200':
          description: 成功响应

关键注意点

  • 必须添加x-amazon-apigateway-authtype和x-amazon-apigateway-authorizer这两个AWS扩展字段,明确授权类型和对应的资源信息。
  • name字段固定为Authorization,不能用小写的authorization,否则AWS无法识别。
  • 如果不需要全局启用认证,可以把security块移到单个接口的配置下。

内容的提问来源于stack exchange,提问作者Sandyx

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 19:25:20