AppSync Security

  • API_KEY
  • AWS_IAM: users, roles, cross-account access
  • OPENID_CONNECT: OpenID Connect provider / JSON Web Token
  • AMAZON_COGNITO_USER_POOLS

For HTTPS (Hypertext transfer protocol secure), we can use CloudFront in front of AppSync