A developer is building a serverless application using an API Gateway HTTP API and Lambda. The developer needs to authenticate users with a JWT token. Which API Gateway feature should be used?
An API Gateway JWT authorizer (also known as a native OIDC/OAuth 2.0 authorizer) is specifically designed to validate JSON Web Tokens (JWTs) issued by a third-party OpenID Connect (OIDC) or OAuth 2.0 compliant identity provider. It declaratively configures the issuer URL and audience, allowing API Gateway to automatically fetch public keys, verify the token's signature, expiration, and claims without custom code. This makes it the most direct and efficient solution for authenticating existing JWTs.
Why this answer
API Gateway HTTP APIs support JWT Authorizers natively. This feature allows API Gateway to validate JSON Web Tokens (JWTs) directly without invoking a Lambda function, verifying the token's signature, expiry, and issuer against a configured identity provider (such as Amazon Cognito or any OIDC-compliant provider). This is the most efficient and cost-effective way to handle JWT authentication in HTTP APIs.
Exam trap
The trap is that candidates often assume they need a custom Lambda Authorizer to validate JWTs, or confuse REST API authorizers with HTTP API authorizers. For HTTP APIs, a native JWT Authorizer should be used instead of a custom Lambda Authorizer to reduce latency and cost.
How to eliminate wrong answers
Option A is wrong because a Lambda Authorizer (formerly Custom Authorizer) is used when you need custom validation logic beyond simple JWT verification, such as calling an external identity provider or performing complex claims mapping; it introduces unnecessary latency and cost for straightforward JWT validation. Option B is wrong because IAM Authorizer uses AWS Signature Version 4 (SigV4) for request signing and is intended for AWS service-to-service or IAM user authentication, not for validating externally-issued JWTs. Option D is wrong because Amazon Cognito User Pools is a full identity provider that issues JWTs, but it is not an API Gateway authorizer feature; you would still need to use a JWT Authorizer or Lambda Authorizer to validate those tokens in API Gateway.