AWS Amplify Graph API that can be accessed without authorization (login)

Viewed 656

I am new to Amplify and I am building a simple list of items (votes) with GraphQL. While the items visibility should be public (read access) without authentication, creating, updating and deleting should be done authenticated via Cognito user pool.

The model can be seen in following AWS Amplify Admin UI screenshot:

AWS Amplify Admin UI Data

I am not able to set the read access to Anyone (since this option is greyed out). Furthermore following statement in the AWS docs puzzles me a bit:

While the API endpoints are publicly reachable, they never allow unauthorized access.
GraphQL API Security with AWS AppSync and mplify

Am I on the wrong track when I want to publish a Graph API with Amplify to the public without authentication? Did I misconfigure my API or is there a way to bypass authentication? Honestly I am not sure if I understand the concept behind this.

For me it is hardly imaginable that only authenticated users can access the API. Respectively I assume there are many other cases (beside my one) where accessing the API without authentication is a requirement.

Thanks in advance for your feedback.

PS: #52601860 seems to be a similar question.

1 Answers

For me, restricting the public access to read operations in the schema file (amplify/backend/api/<name>/schema.graphql) was sufficient:

type SomeModel @model @auth(rules: [{allow: public, operations: [read]}]) {
  id: ID!
  # ...
}

You can check those permissions via amplify status api -acm SomeModel.

Do not forget to provision those changes by running amplify push.

Related