Amazon Cognito customers can secure access to APIs using Amazon Verified Permissions
Share
Services
AWS has launched a feature for Amazon Cognito customers to reduce the time spent securing Amazon API Gateway APIs with fine-grained access control, from weeks to days. The feature leverages Amazon Verified Permissions to manage and evaluate granular security policies that reference user attributes and groups. With a few clicks, you can enforce that only users in authorized Amazon Cognito groups have access to the application’s APIs. For example, say you are building a loan processing application, you can secure your application by restricting access to the “approve\_loan” API to users in the “loan\_officers” group. You can implement more fine-grained authorization, without making any code changes, by updating the underlying Cedar policy, so that only “loan\_officers” above “Director” level can approve loans.
Amazon Verified Permissions is a scalable permissions management and fine-grained authorization service for the applications that you build. Today, we launched a feature that streamlines implementing fine-grained authorization by combining Amazon Cognito, Amazon Verified Permissions, and Amazon API Gateway. It automatically generates an authorization model based on your APIs and policies that allows only authorized Amazon Cognito groups access to your APIs. Additionally, it deploys an AWS Lambda authorizer which you attach to the APIs you want to secure. Once the authorizer is attached, all API requests are authorized by Verified Permissions.
To get started, visit the Verified Permissions console, and create a policy store by selecting “Setup with API Gateway and Cognito”. Learn more by watching a [quick overview and demo video](https://www.youtube.com/watch?v=OBrSrzfuWhQ). For more information visit [Verified Permissions product page](https://aws.amazon.com/verified-permissions/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share