This blog post is the second part of a series about Amazon Verified Permissions, focusing on integration strategies for serverless applications. It covers Lambda Authorizers for both Amazon API Gateway and Amazon AppSync, explaining how each handles authorization logic differently. The post discusses three authorization APIs: IsAuthorized, IsAuthorizedWithToken, and BatchIsAuthorized, with the latter allowing up to 30 authorization decisions in a single request, reducing costs and latency. Pricing considerations are addressed, noting that smart caching strategies can help manage expenses. The post also highlights the importance of mapping request data to authorization requests, which is critical for both role-based and attribute-based access control. The next article in the series will cover Amazon Cognito integration and how Amazon simplifies the mapping process.

Want to be the hero of cloud?

Great, we are here to help you become a cloud services hero!

Let's start!
Book a meeting!