Back to blog
Learn

Lambda vs. API Gateway: Who Does the Heavy Lifting?

Confused about where your logic belongs? Learn the architectural split between AWS Lambda and API Gateway.

The architectural crossroads

When building serverless APIs on AWS, you often hear ‘Lambda’ and ‘API Gateway’ mentioned in the same breath. It is easy to assume they are just two parts of the same machine, but they serve distinct purposes. Choosing where to handle authentication, validation, or transformation can be the difference between a clean, scalable system and a maintenance nightmare.

The contenders

AWS Lambda is your compute engine. It executes code in response to events. It is essentially a function-as-a-service (FaaS) that doesn’t care about HTTP headers or status codes—it just processes input and returns output.

Amazon API Gateway is your traffic controller. It is a managed service that sits in front of your backend, handling the ‘plumbing’ of HTTP requests. It manages traffic, security, throttling, and API versioning before a single line of your custom code even runs.

Dimensions that matter

  • Offloading logic: API Gateway can perform request validation and parameter mapping without invoking Lambda. This saves money and latency.
  • Security: API Gateway handles OAuth, JWT verification, and API keys. Keeping this out of your Lambda code keeps your functions focused on business logic.
  • Cost: API Gateway has a per-request cost, while Lambda charges for execution time and memory. Moving logic to the gateway can reduce your Lambda bill.
  • Complexity: Using Gateway features (like VTL mapping templates) adds configuration complexity that some developers find harder to debug than standard code.

Side-by-side takeaways

  • Use API Gateway for: Authentication, request validation (JSON schema), rate limiting, and traffic shaping.
  • Use Lambda for: Business logic, database interactions, complex data processing, and integration with other cloud services.

Trade-offs & gotchas

Marketing materials often make ‘serverless’ look like a single bucket, but the ‘Gateway-first’ approach has a learning curve. If you put all your logic in the Gateway, you lose the ability to unit test your logic in a standard IDE, as you are now testing infrastructure configuration rather than code. Conversely, if you put everything in Lambda, you are paying for compute time to do simple tasks like checking if a required field exists.

Closing takeaway

Keep your Lambda functions ‘dumb’ regarding HTTP protocols. Use API Gateway as the gatekeeper for all incoming requests, and let your Lambda functions focus purely on the business domain.

Inquire about my experience

Consulting

Planning a build or modernization? Ask how consulting engagements work.