{"_id":"@aligent/cdk-secure-rest-api","_rev":"6-fe953cc274f210e607ebad90bd393286","name":"@aligent/cdk-secure-rest-api","dist-tags":{"latest":"1.3.0"},"versions":{"1.1.0":{"name":"@aligent/cdk-secure-rest-api","version":"1.1.0","license":"MIT","_id":"@aligent/cdk-secure-rest-api@1.1.0","maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-danielvanderploeg","email":"daniel.vanderploeg@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"dist":{"shasum":"64987fb10045013f65f01854963c2d4a877a15ce","tarball":"https://registry.npmjs.org/@aligent/cdk-secure-rest-api/-/cdk-secure-rest-api-1.1.0.tgz","fileCount":13,"integrity":"sha512-cFFyryJrhw9QQPsN/1VWa4z9Or0fuNBoyoqgR4K+Bl0bZenuhx5UI2u3eJaTT329fbDLxWCQXoR8FtOYBDbGng==","signatures":[{"sig":"MEYCIQCI/ObOwpHodBqwUbN+D1UZIdCwyjvqGMmgZ7Fc9a7EtQIhAJbSw2bGjeAf5vcF9wsGGRcLOR8n2mdlEJOPNYleeMk8","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30137},"main":"index.js","types":"index.d.ts","gitHead":"648fb79cdda142bf7b409fbc033eb762270c8bf8","scripts":{"lint":"npx nx lint secure-rest-api","test":"npx nx test secure-rest-api","build":"tsc"},"_npmUser":{"name":"aligent-danielvanderploeg","email":"daniel.vanderploeg@aligent.com.au"},"repository":{"url":"git+https://github.com/aligent/cdk-constructs.git","type":"git"},"_npmVersion":"10.9.2","description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","directories":{},"_nodeVersion":"22.14.0","dependencies":{"source-map-support":"^0.5.21"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","aws-cdk":"^2.1120.0","ts-jest":"^29.4.9","ts-node":"^10.9.1","typescript":"^5.3.2","@types/jest":"^29.5.10","@types/node":"^20.19.39"},"peerDependencies":{"constructs":"^10.5.0","aws-cdk-lib":"^2.113.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk-secure-rest-api_1.1.0_1777867640109_0.23405499948414032","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@aligent/cdk-secure-rest-api","version":"1.1.2","license":"MIT","_id":"@aligent/cdk-secure-rest-api@1.1.2","maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-danielvanderploeg","email":"daniel.vanderploeg@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"dist":{"shasum":"ed72332dc314fda0d299e3c118cd02735dc8f886","tarball":"https://registry.npmjs.org/@aligent/cdk-secure-rest-api/-/cdk-secure-rest-api-1.1.2.tgz","fileCount":7,"integrity":"sha512-lH08jkh1rMtk7mvH+yB5GSmVwTqTa7hyg1I9/PQ/aKoKv+baoqTHFy3dfj1PyF2QXIJ1G1we1PWeBKZo2/06Wg==","signatures":[{"sig":"MEUCICxf1MgmfqqjKIKYOnoe+GnkSIgWC6bQXt0IlC7oeAG7AiEA4wSwLsesMB7/b7Uh3EE/cd8c0w2HRkzHFnLoI8r4C/Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aligent%2fcdk-secure-rest-api@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":19523},"main":"index.js","types":"index.d.ts","gitHead":"25ddb05db9c89c8855395a9097a6adcc536d9d31","scripts":{"lint":"npx nx lint secure-rest-api","test":"npx nx test secure-rest-api","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f4ee7437-3080-4ada-8374-3072390239d2"}},"repository":{"url":"git+https://github.com/aligent/cdk-constructs.git","type":"git"},"_npmVersion":"11.15.0","description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","directories":{},"_nodeVersion":"24.15.0","dependencies":{"source-map-support":"^0.5.21"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","aws-cdk":"^2.1124.1","ts-jest":"^29.4.9","ts-node":"^10.9.1","typescript":"^5.3.2","@types/jest":"^29.5.10","@types/node":"^24.12.4"},"peerDependencies":{"constructs":"^10.5.0","aws-cdk-lib":"^2.113.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk-secure-rest-api_1.1.2_1779424565894_0.9589373167099502","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@aligent/cdk-secure-rest-api","version":"1.2.0","license":"MIT","_id":"@aligent/cdk-secure-rest-api@1.2.0","maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"dist":{"shasum":"7452e753d6dc1081314c9d59f2b99e96d2372edf","tarball":"https://registry.npmjs.org/@aligent/cdk-secure-rest-api/-/cdk-secure-rest-api-1.2.0.tgz","fileCount":7,"integrity":"sha512-185zBj9MjBUz1q+Cog35Ej9nSMdBQ9IbSvcWFCnOwYOP34PSQI1DOfoS02FcSWeVenI+wSHEiFiQcdDAXSL0wg==","signatures":[{"sig":"MEQCIGCgFQ4EtSTijN66ptCTi4ahp1Quo1YITMOqLH9zvhHNAiBbk1VhubXnGiNL5h7jH9vLyojVdbZi/seRXIkI06Aejg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aligent%2fcdk-secure-rest-api@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":22289},"main":"index.js","types":"index.d.ts","gitHead":"62089f061e6000652f9743e9782ec8bec11163d4","scripts":{"lint":"npx nx lint secure-rest-api","test":"npx nx test secure-rest-api","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f4ee7437-3080-4ada-8374-3072390239d2"}},"repository":{"url":"git+https://github.com/aligent/cdk-constructs.git","type":"git"},"_npmVersion":"11.18.0","description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","directories":{},"_nodeVersion":"24.15.0","dependencies":{"source-map-support":"^0.5.21"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","aws-cdk":"^2.1124.1","ts-jest":"^29.4.9","ts-node":"^10.9.1","typescript":"^5.3.2","@types/jest":"^29.5.10","@types/node":"^24.13.2"},"peerDependencies":{"constructs":"^10.5.0","aws-cdk-lib":"^2.113.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk-secure-rest-api_1.2.0_1782798571805_0.8320010031746325","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@aligent/cdk-secure-rest-api","version":"1.2.1","license":"MIT","_id":"@aligent/cdk-secure-rest-api@1.2.1","maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"dist":{"shasum":"3699f8d925eaf807f1c5b7d7e33f14928c458e3f","tarball":"https://registry.npmjs.org/@aligent/cdk-secure-rest-api/-/cdk-secure-rest-api-1.2.1.tgz","fileCount":7,"integrity":"sha512-jGxjbmaB6YutLs9ucEnXkKEpvtFASyFTvMOA/cYLq6rrHnAauYGBWGqhw6fezdCPiGBnc4WiijDy4wBEelhSNg==","signatures":[{"sig":"MEUCIQC524rutzPFjdhBI6XH4kpss7s2U9KVMS3sjWGdw3kapAIgLkv0TJAP3w480/7i4qtN9BS136g7QRyi4y8F1/Q/qFA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aligent%2fcdk-secure-rest-api@1.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":23578},"main":"index.js","types":"index.d.ts","gitHead":"45f128cfd2a9c2d54eea4e88f322e440e90b5c3f","scripts":{"lint":"npx nx lint secure-rest-api","test":"npx nx test secure-rest-api","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f4ee7437-3080-4ada-8374-3072390239d2"}},"repository":{"url":"git+https://github.com/aligent/cdk-constructs.git","type":"git"},"_npmVersion":"12.0.1","description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","directories":{},"_nodeVersion":"24.15.0","dependencies":{"source-map-support":"^0.5.21"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","aws-cdk":"^2.1132.0","ts-jest":"^29.4.11","ts-node":"^10.9.1","typescript":"^5.3.2","@types/jest":"^29.5.10","@types/node":"^24.13.3"},"peerDependencies":{"constructs":"^10.5.0","aws-cdk-lib":"^2.113.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk-secure-rest-api_1.2.1_1784685767926_0.404597165737679","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aligent/cdk-secure-rest-api","version":"1.3.0","description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","main":"index.js","types":"index.d.ts","license":"MIT","homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","repository":{"type":"git","url":"git+https://github.com/aligent/cdk-constructs.git"},"bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"scripts":{"build":"tsc","test":"npx nx test secure-rest-api","lint":"npx nx lint secure-rest-api"},"devDependencies":{"@types/jest":"^29.5.10","@types/node":"^24.13.3","aws-cdk":"^2.1132.0","jest":"^29.7.0","ts-jest":"^29.4.11","ts-node":"^10.9.1","typescript":"^5.3.2"},"dependencies":{"source-map-support":"^0.5.21"},"peerDependencies":{"aws-cdk-lib":"^2.113.0","constructs":"^10.5.0"},"gitHead":"ac1c251e4ac9ff9e2a035e08ceebca6dbe199d3d","_id":"@aligent/cdk-secure-rest-api@1.3.0","_nodeVersion":"24.15.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-8wz+F9nY1Xl8ZVJSS7tZHZOBMmybINRLPCOvs7uOxkRaWUnS5oNK9ezflnYZOOqBHbswYC7wpzuzzyiIUXIl5A==","shasum":"fd64c149c609f080b1aaae6e7c552a08189a6fd2","tarball":"https://registry.npmjs.org/@aligent/cdk-secure-rest-api/-/cdk-secure-rest-api-1.3.0.tgz","fileCount":7,"unpackedSize":27167,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aligent%2fcdk-secure-rest-api@1.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCb5N8TRAYHNn2WAqzIakfZIFn1zi6H1n+XOEuCOQLRlAIgA699KdDmJ1Gs4PyLMaQAGnmDRcEWbGtV1BIGq6E0doY="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f4ee7437-3080-4ada-8374-3072390239d2"}},"directories":{},"maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cdk-secure-rest-api_1.3.0_1788912175990_0.3846981211364955"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-04T04:07:20.023Z","modified":"2026-09-09T00:02:56.456Z","1.1.0":"2026-05-04T04:07:20.268Z","1.1.2":"2026-05-22T04:36:06.028Z","1.2.0":"2026-06-30T05:49:31.938Z","1.2.1":"2026-07-22T02:02:48.067Z","1.3.0":"2026-09-09T00:02:56.134Z"},"bugs":{"url":"https://github.com/aligent/cdk-constructs/issues"},"license":"MIT","homepage":"https://github.com/aligent/cdk-constructs/tree/main/packages/constructs/secure-rest-api#readme","repository":{"type":"git","url":"git+https://github.com/aligent/cdk-constructs.git"},"description":"A CDK construct for creating API Gateway REST APIs secured with API Key authentication and usage plan throttling","maintainers":[{"name":"jarrod.swift","email":"jarrod.swift@aligent.com.au"},{"name":"aligent-bot","email":"devops+npm@aligent.com.au"},{"name":"tom.thorogood","email":"tom.thorogood@aligent.com.au"}],"readme":"# Aligent AWS Secure REST API\n\n## Overview\n\n![TypeScript version](https://img.shields.io/github/package-json/dependency-version/aligent/cdk-constructs/dev/typescript?filename=packages/constructs/secure-rest-api/package.json&color=red) ![AWS CDK version](https://img.shields.io/github/package-json/dependency-version/aligent/cdk-constructs/dev/aws-cdk?filename=packages/constructs/secure-rest-api/package.json) ![NPM version](https://img.shields.io/npm/v/%40aligent%2Fcdk-secure-rest-api?color=green)\n\nA CDK construct for provisioning an API Gateway REST API secured with API Key authentication and usage plan throttling. Routes accept any CDK `Integration`, giving callers full control over how endpoints are wired.\n\n## Features\n\n- API Gateway REST API with API Key authentication (`apiKeyRequired: true` on all routes)\n- Usage plan with configurable throttle rate and burst limits\n- Configurable CORS preflight options\n- Accepts any CDK `Integration` per route (Lambda, HTTP, Mock, Step Functions, etc.)\n- Supports nested, multi-segment route paths (e.g. `rewards/accounts/{accountId}/redeem`)\n- Supports alias paths so a route can be exposed under an additional path (e.g. renaming an endpoint without breaking existing consumers)\n- Configurable deployment stage via `deployOptions` (stage name defaults to `prod`)\n\n## Installation\n\n```bash\nnpm install @aligent/cdk-secure-rest-api\n```\n\nOr with yarn:\n\n```bash\nyarn add @aligent/cdk-secure-rest-api aws-cdk-lib constructs\n```\n\n### Peer Dependencies\n\n- `aws-cdk-lib` (^2.113.0)\n- `constructs` (^10.5.0)\n\n## Basic Usage\n\n```typescript\nimport { SecureRestApi } from '@aligent/cdk-secure-rest-api';\nimport { LambdaIntegration } from 'aws-cdk-lib/aws-apigateway';\nimport { HttpMethod } from 'aws-cdk-lib/aws-apigatewayv2';\n\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  routes: [\n    {\n      path: 'items',\n      methods: [HttpMethod.GET],\n      integration: new LambdaIntegration(myFunction),\n    },\n  ],\n});\n\n// Access created resources\nconst { api, apiKey, usagePlan } = api;\n```\n\n## Configuration Examples\n\n### Multiple routes and methods\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  routes: [\n    {\n      path: 'items',\n      methods: [HttpMethod.GET, HttpMethod.POST],\n      integration: new LambdaIntegration(itemsFunction),\n    },\n    {\n      path: 'orders',\n      methods: [HttpMethod.GET],\n      integration: new LambdaIntegration(ordersFunction),\n    },\n  ],\n});\n```\n\n### Nested route paths\n\nMulti-segment paths create the intermediate resources automatically. Routes\nsharing a common prefix resolve to the same parent resource.\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'rewards-api',\n  routes: [\n    {\n      path: 'rewards/accounts/{accountId}/redeem',\n      methods: [HttpMethod.POST],\n      integration: new LambdaIntegration(redeemFunction),\n    },\n    {\n      path: 'rewards/reversal', // reuses the shared `rewards` resource\n      methods: [HttpMethod.POST],\n      integration: new LambdaIntegration(reversalFunction),\n    },\n  ],\n});\n```\n\n### Alias paths\n\nExpose a route under one or more additional paths, useful when renaming an\nendpoint without breaking existing consumers: keep the old path as an alias\nuntil callers migrate to the new one, then drop `aliasPaths` once it's safe.\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  routes: [\n    {\n      path: 'customers',\n      methods: [HttpMethod.GET],\n      integration: new LambdaIntegration(customersFunction),\n      aliasPaths: ['people'], // old path, kept working during migration\n    },\n  ],\n});\n```\n\nAlias paths work with nested routes too, as long as the parameter names match:\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  routes: [\n    {\n      path: 'customers/{id}/addresses',\n      methods: [HttpMethod.GET],\n      integration: new LambdaIntegration(addressesFunction),\n      aliasPaths: ['people/{id}/addresses'],\n    },\n  ],\n});\n```\n\n### Custom throttling\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  throttle: {\n    rateLimit: 50,   // requests per second\n    burstLimit: 100,\n  },\n  routes: [...],\n});\n```\n\n### Custom stage name\n\nBy default the API deploys to a `prod` stage. Pass `deployOptions` to override\nthe stage name (or any other CDK `StageOptions`, e.g. logging or tracing).\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  deployOptions: { stageName: 'staging' },\n  routes: [...],\n});\n```\n\n### Custom CORS configuration\n\n```typescript\nconst api = new SecureRestApi(this, 'Api', {\n  apiName: 'my-api',\n  corsOptions: {\n    allowOrigins: ['https://example.com'],  // overrides default (all origins)\n    additionalMethods: ['POST'],            // appended to GET, OPTIONS\n    additionalHeaders: ['Authorization'],   // appended to Content-Type, X-Api-Key\n  },\n  routes: [...],\n});\n```\n\n## Configuration Reference\n\n### `apiName` (string) — required\n\nThe name of the REST API and the base for generated resource names.\n\n### `description` (string)\n\nDescription for the API Gateway REST API.\n\nDefault: `REST API for {apiName} service`\n\n### `routes` (SecureRestApiRoute[]) — required\n\nRoutes to register on the API. Each route requires:\n\n| Property | Type | Description |\n|----------|------|-------------|\n| `path` | `string` | The resource path; may be nested/multi-segment (leading slash is stripped automatically) |\n| `methods` | `HttpMethod[]` | HTTP methods to register on the resource |\n| `integration` | `Integration` | Any CDK API Gateway integration |\n| `aliasPaths` | `string[]` | Optional. Additional paths that register the same `methods` and `integration` |\n\n### `deployOptions` (StageOptions)\n\nStage options for the API's default deployment, passed through to the underlying\nCDK `RestApi`. Use `stageName` to override the deployed stage name.\n\nDefault: CDK default (`prod` stage).\n\n### `throttle` (object)\n\nThrottling limits applied to the usage plan.\n\n| Property | Type | Default |\n|----------|------|---------|\n| `rateLimit` | `number` | `100` |\n| `burstLimit` | `number` | `200` |\n\n### `corsOptions` (object)\n\nCORS preflight configuration applied to all resources.\n\n| Property | Type | Behaviour |\n|----------|------|-----------|\n| `allowOrigins` | `string[]` | Overrides the default (all origins) |\n| `additionalMethods` | `string[]` | Appended to the defaults: `GET`, `OPTIONS` |\n| `additionalHeaders` | `string[]` | Appended to the defaults: `Content-Type`, `X-Api-Key` |\n\n### `apiKeyName` (string)\n\nOverride the name of the generated API key.\n\nDefault: `{apiName}-api-key`\n\n### `usagePlanName` (string)\n\nOverride the name of the generated usage plan.\n\nDefault: `{apiName}-usage-plan`\n\n## Local Development\n\n[NPM link](https://docs.npmjs.com/cli/v7/commands/npm-link) can be used to develop the module locally:\n\n1. Pull this repository locally\n2. `cd` into this repository\n3. Run `npm link`\n4. `cd` into the downstream repo and run `npm link '@aligent/cdk-secure-rest-api'`\n\nThe downstream repository should now include a symlink to this module, allowing local changes to be tested before pushing.\n","readmeFilename":"README.md"}