not authorized to access this resource ☁️ AWS

API Gateway 403: User is not authorized to access this resource with an explicit deny

An API Gateway authorizer (Lambda/Cognito) or resource policy denied the request.

Seen on: AWS

Meaning

Lambda authorizers return Allow/Deny policies; a Deny, a policy whose Resource ARN doesn’t cover the called method (common with cached authorizer results), or a resource policy restricting IPs/VPCs results in this 403.

Common causes

  • Lambda authorizer returned Deny
  • Cached authorizer policy only allows the first method/path called
  • Resource policy restricts source IP/VPC endpoint
  • Invalid/expired token treated as deny

⚡ Quick fix

  1. Return a policy covering all needed resources (e.g. arn:…/*) or disable authorizer caching
  2. Check the authorizer’s logs
  3. Review the API resource policy

Detailed fix by platform

Node.js

  1. javascript
    return {
      principalId: user.id,
      policyDocument: { Version: "2012-10-17", Statement: [{ Action: "execute-api:Invoke", Effect: "Allow", Resource: event.methodArn.split("/").slice(0, 2).join("/") + "/*" }] }
    };

How to diagnose

  1. Authorizer — Logs/output policy
  2. Cache — TTL > 0 with per-method resource?
  3. Resource policy — IP/VPC conditions

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.