If lambda-framework is used, the jwt-authorizer should be used along with AWS API Gateway to authorize the JWT token and enrich the scopes so that the lambda function can verify the scope against the specification. We can deploy the jwt-authorizer to most regions and let the users use the shared lambda function or allow users to deploy on their own.