You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制AWS API端点访问权限?防止Lambda函数调用链接公开可访问

Hey there! Great question—securing your Lambda-invoking API endpoint is super important to keep random public access out. Let’s walk through the most practical, effective methods you can use, based on your specific use case:

1. Use IAM Authentication for API Gateway

If your API is only meant to be accessed by AWS services, or authenticated IAM users/roles, this is the most straightforward built-in option.

  • Attach an IAM policy to the entity (user, role, or service) that needs access, granting permission for the execute-api:Invoke action on your API’s specific ARN.
  • Example policy snippet:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": "execute-api:Invoke",
          "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/STAGE/*"
        }
      ]
    }
    
  • Only requests signed with valid AWS credentials will be allowed through—no random public calls can bypass this.
2. Implement API Keys + Usage Plans

Perfect if you need to grant access to third-party developers or specific client apps.

  • Enable the "API key required" setting on your API methods. Clients will need to send a valid key in the x-api-key header with every request.
  • Pair this with usage plans to set rate limits and request quotas—this prevents abuse even if a key accidentally leaks.
  • Important: Always enforce HTTPS for your API to avoid interception of the API key in transit.
3. Build a Custom Lambda Authorizer

For full control over authentication logic (like validating custom tokens, JWTs from OAuth providers, or even IP checks), use a Lambda authorizer.

  • This authorizer Lambda runs before your target Lambda function. It validates the request’s credentials (e.g., a token in the Authorization header) and returns an IAM policy allowing or denying access.
  • Common use cases: Validating tokens from Auth0, checking if the request comes from a trusted IP range, or verifying custom internal auth tokens.
4. Restrict Access by IP Address

If you only want specific IPs or IP ranges to access your API, set up a resource policy on API Gateway.

  • Example policy that allows only a single IP range:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": "*",
          "Action": "execute-api:Invoke",
          "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/STAGE/*",
          "Condition": {
            "IpAddress": {
              "aws:SourceIp": ["192.168.1.0/24"]
            }
          }
        }
      ]
    }
    
  • Any request from an IP outside the specified range will be blocked immediately.
5. Integrate AWS Cognito User Pools

Ideal if your API is accessed by end-users (like a mobile or web app).

  • Users sign up or log in via Cognito, which issues JWT tokens. Clients send these tokens in the Authorization header of API requests.
  • API Gateway automatically validates the tokens, so you don’t have to build custom auth logic from scratch. You can also configure fine-grained permissions based on user groups.

Pro Tip

Layer multiple security methods for extra protection—for example, combine API keys with IP restrictions, or use Cognito plus a Lambda authorizer for additional validation checks. Also, enable CloudWatch logging for your API Gateway to monitor access attempts and spot suspicious activity early.

内容的提问来源于stack exchange,提问作者zegulas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:14:52