HTTP in front of your code · Chapter 1 of 1
How API Gateway protects your backend
An API Gateway is the entry point that manages HTTP routing, security, and throttling before your serverless code ever executes.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
The roles of a managed API gateway
Why should you place an API Gateway in front of your Lambda functions?
API Gateway receives the client request, terminates the TLS connection, and matches the route path.
- 01
Exposing serverless code to the internet
A Lambda function has no public URL by default. An API Gateway acts as an HTTP server that terminates TLS connections, manages routes, and invokes the function on behalf of clients.
- 02
Offloading common application tasks
Instead of writing authentication, request validation, and rate limiting logic inside your code, you configure these rules at the gateway level to save execution cost.
- 03
The CORS enforcement reality
Cross-Origin Resource Sharing is a browser security mechanism, not a server security boundary. The gateway must be configured to return correct access control headers, or the client browser will block the response.
Check yourself
Where is CORS security policy actually enforced?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
Comparing REST and HTTP APIs under the hood
How do integration timeouts and gateway types affect application cost?
API Gateway receives the client request, terminates the TLS connection, and matches the route path.
- 01
REST versus HTTP gateway types
HTTP APIs are designed to be fast and cost-effective, providing routing and basic authorization. REST APIs offer features like request transformation, response caching, and schema validation but cost more.
- 02
Protecting backends with token bucket throttling
API Gateway uses a token bucket algorithm to throttle traffic. If a client exceeds the request limit, the gateway rejects the request immediately, protecting your backend from exhaustion.
- 03
The integration timeout ceiling
When API Gateway forwards a request, it waits for a response. If the backend does not return a response within the timeout limit, the gateway closes the connection and returns a 504 Gateway Timeout.
The numbers
- Integration timeout
- Depends on API typeREST APIs default to at most 29 seconds; Regional and private REST API limits can be raised. HTTP APIs allow at most 30 seconds.
- Default throttling limit
- 10,000 requests per secondThe default steady-state rate limit, with a burst limit of 5,000 requests.
- REST API pricing per million
- $3.50The cost per million requests for the first 333 million requests.
- HTTP API pricing per million
- $1.00The cost per million requests, which is significantly cheaper than REST APIs.
Check yourself
A report takes 45 seconds, but its HTTP API integration allows only 30 seconds. Why does the client see a timeout?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →