I am trying to find the most secure way to use my API gateway without the user in question existing in IAM console.