API Gateway 403: User is not authorized to access this resource with an explicit deny
An API Gateway authorizer (Lambda/Cognito) or resource policy denied the request.
Seen on:
AWS
Meaning
Lambda authorizers return Allow/Deny policies; a Deny, a policy whose Resource ARN doesn’t cover the called method (common with cached authorizer results), or a resource policy restricting IPs/VPCs results in this 403.
Common causes
- Lambda authorizer returned Deny
- Cached authorizer policy only allows the first method/path called
- Resource policy restricts source IP/VPC endpoint
- Invalid/expired token treated as deny
⚡ Quick fix
- Return a policy covering all needed resources (e.g. arn:…/*) or disable authorizer caching
- Check the authorizer’s logs
- Review the API resource policy
Detailed fix by platform
Node.js
- javascript
return { principalId: user.id, policyDocument: { Version: "2012-10-17", Statement: [{ Action: "execute-api:Invoke", Effect: "Allow", Resource: event.methodArn.split("/").slice(0, 2).join("/") + "/*" }] } };
How to diagnose
- Authorizer — Logs/output policy
- Cache — TTL > 0 with per-method resource?
- Resource policy — IP/VPC conditions
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026