Course in AWS Skill Tree

AWS API Gateway and Cognito for Beginners

Build an HTTP order API, connect a real browser with CORS, add Cognito sign-in and protect private routes with JWT authorization while testing actual data and rejected requests.

AWS

Introduction

Build an order API that accepts validated requests, supports a browser client and requires application sign-in for private data. Connect API Gateway, Lambda, DynamoDB and Cognito through observable requests and stored results.

Five guided labs lead from an HTTP API to browser CORS, Cognito authentication and JWT route protection. The independent challenge repairs a private API that exposes an order while preserving its public health endpoint.

What You Will Learn

  • Expose a Lambda function through an HTTP API
  • Validate order input and compute DynamoDB-backed results
  • Configure browser origin, method and header CORS behavior
  • Sign in with Cognito and refresh application credentials
  • Protect private routes with a JWT authorizer
  • Test that rejected requests leave business data unchanged
  • Repair private access without breaking public health requests

Who This Course Is For

This course is for learners with a Lambda and data-access foundation who want to build and protect an application API.

Prerequisites: Start with Lambda deployment and configuration (FN01/FN02), including IAM roles and CloudWatch Logs. Before the order API, complete Lambda–DynamoDB access (FN03). Follow each lab’s specific prerequisites: CORS and sign-in can both follow the order API; JWT route protection needs sign-in. Complete JWT protection before the challenge.

Learning environment: All activities run in a provided browser-based LabEx Linux environment. Use Terminal for AWS CLI commands and AWS View, next to Terminal, to inspect the same resource and application state. Tools and the connection are prepared; you do not need a personal AWS account or access keys. Each lab starts independently in a fresh VM. The CORS lab supplies a Browser Client entry in AWS View for actual browser requests. Identity views show safe metadata without passwords or bearer tokens.

Frequently Asked Questions

Is CORS an authentication mechanism?

No. CORS controls browser access behavior; it does not establish user identity. Application sign-in is separate from IAM resource permissions, and a valid JWT alone does not establish ownership of an order.

How are private routes tested?

HTTP requests must execute the intended function and read or write stored items. Rejected authorization must stop before Lambda and leave business data unchanged. Compare gateway decisions, function event/response logs and records. Use only supplied synthetic identities and keep authentication files private.

Which API and sign-in features are covered?

The course uses HTTP APIs, the $default AutoDeploy stage, Python payload 2.0 integration and a focused Cognito password/refresh and RS256/JWKS JWT flow. Route scopes use the Cognito user self-service scope; custom business scopes, per-user order isolation, hosted OAuth/MFA, production signing-key rotation and deployment automation are outside scope.

Can I continue into a project after this course?

Yes. These capabilities support the private API project after its Secrets Manager and Parameter Store prerequisites. Each unit starts fresh; complete functional checks before deleting owned resources and preserve unrelated references.

Teacher

labby
Labby
Labby is the LabEx teacher.