# Deploy the APIs - Access Denied Error

**URL:** <https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237>\
**Category:** General\
**Created:** [May 26, 2018, 12:55am UTC](https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237 "2018-05-26T00:55:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chrisbnyc](https://avatars.discourse-cdn.com/v4/letter/c/a5b964/32.png) [@chrisbnyc](https://discourse.sst.dev/u/chrisbnyc)\
**Post date:** [May 26, 2018, 12:55am UTC](https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237/1 "2018-05-26T00:55:45Z")

</div>

Hi,

I’ve gotten to this step and I’m trying to figure out where my IAM has gone south.

To recap:

- I can locally execute all the API calls with no problems
- They deploy fine to /dev

But when I run npx I get:

```
Authenticating with User Pool
Getting temporary credentials
Making API request
{ status: 500,
  statusText: 'Internal Server Error',
  data: { status: false } }

```

- I verified that the account created in the User Pool has access
- In Cloudwatch logs I see

`AccessDeniedException: User: arn:aws:sts::[trimmed user id]:assumed-role/notes-app-api-dev-us-west-2-lambdaRole/notes-app-api-dev-create is not authorized to perform: dynamodb:PutItem on resource: arn:aws:dynamodb:us-west-2:[trimmed user id]:table/notes`

I have a hunch it is a role issue but I believe the authenticated role noted in the Federated Identity Pool has the correct permissions per the article.

Am I missing something obvious?

Thanks  
Chris

---

<div class="post-metadata">

**Author:** ![chrisbnyc](https://avatars.discourse-cdn.com/v4/letter/c/a5b964/32.png) [@chrisbnyc](https://discourse.sst.dev/u/chrisbnyc)\
**Post date:** [May 26, 2018, 10:55pm UTC](https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237/2 "2018-05-26T22:55:16Z")

</div>

Self - solved… the serverless.yml was malformed (the iamRoleStatements block was not indented enough and was ignored by the deploy statement)… wish it complained about that!

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 27, 2018, 10:10pm UTC](https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237/3 "2018-05-27T22:10:01Z")

</div>

Yeah sadly it doesn’t do that. We try to add little pointers in the various spots in the tutorial to help people catch it but it can be tricky.

---

<div class="post-metadata">

**Author:** ![chrisbnyc](https://avatars.discourse-cdn.com/v4/letter/c/a5b964/32.png) [@chrisbnyc](https://discourse.sst.dev/u/chrisbnyc)\
**Post date:** [May 27, 2018, 11:24pm UTC](https://discourse.sst.dev/t/deploy-the-apis-access-denied-error/237/4 "2018-05-27T23:24:05Z")

</div>

Thanks for the reply, yeah, I felt silly when I finally figured it out!
