Skip to content
Cloud Efficiency Hub

REST APIs Used Where HTTP APIs Suffice in API Gateway

The short version

Amazon API Gateway offers two RESTful API products.

PointFive Research

Cloud cost research at PointFive

AWS service
AWS API Gateway
Category
Networking
Reference
CER-0355
Type
Suboptimal Tier or SKU

Explanation

Why the waste happens and who it affects.

REST APIs carry the full feature set, while HTTP APIs are, in AWS's own words, designed with minimal features so they can be offered at a lower price. Many teams still create REST APIs by default, often because older tutorials, frameworks and IaC templates predate HTTP APIs, and then front simple Lambda proxy or HTTP proxy backends with them without using any REST-only capability.

The cost gap scales with request volume. AWS pricing examples show REST API calls at $3.50 per million for the first 333 million requests a month (US East, N. Virginia) and HTTP API calls at $1.00 per million for the first 300 million, so a high-volume API that only needs routing, authorization and CORS pays about 3.5 times more per request than it has to.

Billing model

The pricing dimensions that drive this cost.

Both products bill per API call received plus data transferred out, with no hourly charge for the API itself.

REST API requests
Billed per million API calls received, in volume tiers, at a higher per-request rate than HTTP APIs
HTTP API requests
Billed per million API calls received at a lower rate, with each request metered in 512 KB increments
REST API cache
Optional cache billed per hour by provisioned cache size, available only on REST APIs
Data transfer out
Billed per GB at EC2 data transfer rates for both products

How to detect

4 checks to find it in your estate.

  • List REST APIs with apigateway get-rest-apis and rank them by the CloudWatch Count metric (AWS/ApiGateway namespace, ApiName and Stage dimensions) to find the highest-volume APIs
  • For each high-volume REST API, check whether it uses any feature HTTP APIs lack: API keys and usage plans, per-client throttling, AWS WAF, resource policies, private or edge-optimized endpoints, request validation, request body transformation, caching, mock integrations, response streaming, canary deployments, execution logs or X-Ray tracing
  • Flag APIs whose integrations are all Lambda proxy or HTTP proxy and whose authorization is IAM, a Lambda authorizer or Cognito, since these map directly to HTTP API features
  • Review API Gateway spend in Cost Explorer grouped by usage type to see how much of the bill comes from REST API request charges

How to fix

5 ways to remove the waste.

  • Export the eligible REST API as an OpenAPI 3.0 definition and import it as an HTTP API with apigatewayv2 import-api, then review the import info and warnings for properties HTTP APIs ignore
  • Replace REST-only constructs where equivalents exist, for example use a JWT authorizer for Cognito or OIDC tokens and parameter mapping instead of simple request parameter transformations
  • Move the custom domain API mapping to the new HTTP API, run both in parallel while you compare errors and latency, then delete the old REST API stage
  • Keep REST APIs where a REST-only feature is a real requirement, such as private APIs, WAF on the API, usage plans with API keys, or response caching, and document the reason so the choice is not revisited each review
  • Default new serverless APIs to HTTP APIs in templates and IaC modules unless a REST-only feature is needed

Documentation

Vendor references for pricing and configuration.