Sketio

AWS Serverless REST API Architecture Diagram

Updated

A serverless REST API on AWS puts three managed services between a client and its data. Amazon API Gateway receives the HTTPS request, AWS Lambda runs your code once per request, and Amazon DynamoDB stores the data. There are no servers to patch and no capacity to size up front. With on-demand capacity you pay per request instead of for idle machines.

This template adds the two things most real APIs need next: Amazon Cognito to check who is calling, and Amazon CloudWatch to keep the logs. Rename the boxes, add routes or swap a service, and the diagram stays an ordinary editable board.

HTTPSinvokeread / writeClientAPI GatewayLambdaDynamoDBCognitoCloudWatchauthorizerlogs

Scroll sideways to see the whole diagram

AWS Serverless REST API Architecture Diagram. Open it in Sketio to change it.

Start from this diagram and edit it on your own board.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

What each part does

Client
A browser, a mobile app or another service. It sends HTTPS requests and, when the API is protected, includes the token it received when the user signed in.
API Gateway
The front door. It maps each method and path (for example GET /items/{id}) to an integration, turns away requests that fail the authorizer, and can throttle callers.
Cognito
A user pool that signs users in and issues tokens. API Gateway checks each token with an authorizer before the request can reach Lambda.
Lambda
Your handler code. API Gateway invokes it for each request with the method, path and body as the event. It runs the business logic and returns the response, and Lambda scales by running more copies at once.
DynamoDB
A key-value and document table that the function reads and writes by key. Model the table around your access patterns, because queries are by key rather than by arbitrary join.
CloudWatch
Collects the function's logs and metrics when its execution role allows it, so you can search errors, watch latency and set alarms.

How a request flows

  1. The client sends an HTTPS request to API Gateway, with its Cognito token when the route is protected.
  2. API Gateway checks the token against the Cognito user pool. A request that fails never reaches Lambda.
  3. API Gateway invokes the Lambda function and passes the request (method, path, headers and body) as the event.
  4. The function reads or writes DynamoDB items by key and builds a response.
  5. API Gateway returns that response to the client. The function writes its logs and metrics to CloudWatch.

When to use it

Common variations

Use an HTTP API instead of a REST API

API Gateway offers both. HTTP APIs have fewer features but cost less and add less latency, and they support JWT authorizers that work with Cognito. Choose a REST API when you need usage plans, API keys, request validation or AWS WAF.

One function per route, or one for the whole API

A function per route keeps deployments and permissions small. A single function behind a proxy route is simpler to write and shares its warm instances. Start with what your team can maintain and split later.

Move slow work to a queue

When a request triggers work that takes seconds, have the function put a message on a queue and answer straight away, then process it in a second function.

Add your own domain

Attach a custom domain name to the API with a certificate from AWS Certificate Manager and an alias record in Route 53. Where the certificate lives depends on the endpoint type: an edge-optimized API needs it in us-east-1, while a Regional API needs it in the same Region as the API.

Make it yours

Start with the routes: name the API Gateway box after your own resource, such as /orders, and replace DynamoDB with the store you actually use.

Opens this diagram as a board you can edit.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

All templates