I've experienced the same frustrations with the API Gateway. Lack of knowing the IAM principal that authenticated, and no clear way to differentiate if a call came from the API gateway or not makes me feel that this needs some work. SNS, for example, will sign it's HTTP requests and that would be a good start IMHO. Ability to use security groups in proxy mode would make this even better.