Build AppSync GraphQL API schema configurations with types, queries, mutations, subscriptions, and auth providers.
Build AppSync GraphQL API schema configurations with types, queries, mutations, subscriptions, and auth providers.
Required Fields
ApiNameAuthenticationTypeSchema.TypesOutput will appear here...Build an AppSync GraphQL API definition combining a primary AuthenticationType with AdditionalAuthenticationProviders, letting different clients authenticate differently against the same API (Cognito user pools for logged-in app users, an API key for limited public read access, IAM for server-to-server calls), each provider's access scoped further by @aws_auth-style directives on individual schema fields, not a single blanket permission model for the whole API. An API key (as configured via ApiKeyConfig) has a hard maximum lifetime of 365 days and must be manually rotated before expiry, since AppSync doesn't auto-renew API keys, a key silently expiring is a common self-inflicted outage for any client still relying on it.
Track API key expiration dates actively, an expiring, unrotated API key is a completely preventable outage that catches teams off guard because nothing alerts on it by default, set a calendar reminder or automated check well before the 365-day maximum.
Field-level auth directives are what actually make multi-provider authentication useful, just listing multiple AdditionalAuthenticationProviders without corresponding field-level directives means every provider effectively has access to everything the primary auth type would, verify the directives are actually scoping access as intended.
XrayEnabled adds useful request tracing for debugging resolver performance issues but has a small cost and overhead, it's usually fine to leave on for production APIs given the debugging value, but confirm your X-Ray sampling and cost expectations rather than assuming it's free.
The builder validates that ApiName, AuthenticationType, and Schema.Types resolve before accepting the JSON as a valid combined API definition (spanning what would actually be several separate AppSync API calls to create the API, set its schema, and configure logging); it can't verify the schema's GraphQL syntax is fully valid or that referenced Resolver names correspond to actually-configured data sources, those checks happen only when the schema is applied against a live API.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.