After creating and configuring a Lambda authorizer, the crucial next step is to associate it with the specific API Gateway methods that require authorization. This configuration tells API Gateway to invoke the designated Lambda authorizer function before forwarding the request to the backend integration, ensuring that the incoming request's identity or token is validated. Without this explicit link, the authorizer would exist but never be utilized by the API endpoint.
Why this answer
The API Gateway method must be explicitly configured to use the Lambda authorizer as the authorization mechanism. This is done by setting the method's Authorization type to the Lambda authorizer's logical name in the API Gateway console or via the REST API's `authorizationType` property set to `CUSTOM` and referencing the authorizer's ID. Without this configuration, API Gateway will not invoke the authorizer function for incoming requests.
Exam trap
The trap here is that candidates confuse the token validation logic inside the authorizer with the output format, mistakenly thinking the authorizer returns a JWT or API key, when in fact it must return an IAM policy document for API Gateway to enforce authorization.