Hey everyone, I'm trying to set up a simple contact form that triggers a workflow. The form submits to a public API Gateway endpoint, which should trigger a Lambda via a State Machine (Step Functions). The form submission seems to go through (200 OK), but the workflow never starts. CloudWatch logs for the API Gateway and the Lambda show nothing.
My API Gateway integration is set to directly start the Step Function execution. Here's the integration part of my Terraform:
```hcl
resource "aws_api_gateway_integration" "form_submit" {
rest_api_id = aws_api_gateway_rest_api.main.id
resource_id = aws_api_gateway_resource.form.id
http_method = aws_api_gateway_method.form_post.http_method
integration_http_method = "POST"
type = "AWS"
uri = "arn:aws:apigateway:${var.region}:states:action/StartExecution"
credentials = aws_iam_role.api_gateway.arn
request_templates = {
"application/json" = jsonencode({
input = "$util.escapeJavaScript($input.json('$'))",
stateMachineArn = aws_sfn_state_machine.workflow.arn
})
}
}
```
The API method has a `POST` on a `/submit` resource. I'm not seeing any errors in the browser console either. Is there a way to see if the request even reached the Step Functions service? Or maybe my IAM role for API Gateway is missing a permission? I'm kinda stuck because there are no logs to follow.
The 200 OK is the biggest red flag, because it means API Gateway is successfully hitting *something*, just not your State Machine. That 'AWS' integration type with the direct states:action URI is notoriously finicky. You're likely getting a successful response from the API Gateway service itself acknowledging the integration request, while the actual StartExecution call is failing silently due to permissions or a malformed request template.
Your request template is probably the culprit. You're trying to force a JSON structure onto an integration that expects a very specific parameter format. The `input` needs to be a *stringified* JSON, and the `stateMachineArn` parameter is case-sensitive. More often than not, people construct this wrong and the Step Functions API rejects it, but because it's a service integration and not a Lambda, that failure doesn't bubble back to the method response properly. Check the IAM role on the integration as well; it needs `states:StartExecution` permission on that specific resource, obviously, but also check the trust policy allows `apigateway.amazonaws.com` to assume it.
Frankly, this is why everyone eventually gives up and slaps a Lambda proxy in front of Step Functions, despite the extra cost and complexity. AWS sells this as a "direct" integration but the debugging experience is a black box. You might want to enable execution logging on the State Machine itself, it sometimes catches the attempt even if the logs show nothing from API Gateway.