Amazon API Gateway
API Gateway
You need a secure, public entry point to route HTTP traffic and WebSocket connections to your backend services.
Reach for it when
- Exposing a set of serverless Lambda functions as a public REST API for mobile clients.
- Implementing rate limiting, API key verification, and CORS headers at the network edge.
- Creating a proxy interface that translates legacy XML payloads into JSON before routing them to internal services.
Do not reach for it when
- Routing high-throughput internal microservice traffic within a private VPC network — use Private ALB instead.
- Streaming large file uploads or downloads exceeding 10 megabytes — stream directly to and from S3 instead.
- Serving simple HTTP requests for static assets and web pages — use CloudFront and S3 instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| Application Load Balancer | Choose it when routing high volumes of standard HTTP traffic directly to EC2 instances or ECS containers. |
| AppSync | Choose it when building GraphQL APIs that require real-time data synchronization and subscriptions. |
How you pay
- The model
- Pay per million API requests received, plus data transfer fees out of AWS.
- The line item that surprises people
- Using REST APIs instead of HTTP APIs can more than double your API gateway request bill for identical traffic profiles.
What trips people up
- Timeouts vary by API type: HTTP APIs allow at most 30 seconds; Regional and private REST API integration timeouts can be raised beyond the 29-second default, potentially at the cost of a lower throttling quota.
- Failing to configure CORS options correctly on the gateway will cause browsers to block client requests with preflight errors.
- Default request throttling limits are account-wide; a single runaway API endpoint can starve all other APIs in that region.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.