As
discussed before, we’ve been building out some services using
AWS API Gateway.
We have an OAuth 2.0 infrastructure that predates API Gateway, and we’ve had a
lot of problems with third parties being able to use the APIs behind API Gateway. Almost any mistake that can be made with the Authorization header set leads to an unhelpful message from Amazon CloudFront (which technically underpins API Gateway): “not a valid key=value pair” pointing to the access token in the Authorization header.
As it turns out, one of these error cases is a response that should generate a
404 Not Found response, because the URL doesn’t exist in API Gateway.
There’s a workaround to fake 404 messages: build fake endpoints into the API definition.