Invoke Private Api Gateway, Use a single policy and avoid session-based or role-based policies to control traffic to your API.