C

cognito-idp.us-east-1.amazonaws.com

Amazon Cognito is AWS’s managed identity service for web and mobile applications. The `cognito-idp.us-east-1.amazonaws.com` host is the US East (N. Virginia) regional endpoint for Cognito User Pools, which store users and handle sign-in, authentication challenges, and token issuance.

2 integrations · REST · CLI

Amazon Cognito User Pools exposes a regional HTTPS API at `https://cognito-idp.us-east-1.amazonaws.com` plus the `aws cognito-idp` CLI; the API supports IAM SigV4-signed admin operations, app-client-based public auth flows, and access-token-authorized user self-service operations.

discovered 2mo ago
REST · OpenAPI1
CLI1
Credentials
AWS IAM credentials for Signature Version 4 signingaws_sigv4Get keys ↗

Create or use an AWS IAM principal in the AWS IAM console and obtain access key credentials, or use temporary credentials from STS. Grant the principal Cognito user-pool permissions as needed. Requests are signed with AWS Signature Version 4 as described in Signing AWS API requests. For CLI use, configure them with aws configure or another supported AWS credential source.

Cognito user pool app client credentialscompoundGet key ↗

In the Amazon Cognito console, open a user pool and create or select an app client under application settings. This yields a client_id; confidential clients can also have a client_secret. Use the app client in public API flows like InitiateAuth, and on the user-pool domain /oauth2/token endpoint with client_secret_basic or client_secret_post when a secret exists.

Cognito user access tokenbearerGet token ↗

Create a user pool app client in the Amazon Cognito console, then authenticate a user through Cognito sign-in flows such as InitiateAuth or the user-pool domain OAuth 2.0 endpoints. Use the resulting access token for token-authorized self-service API operations; it must include any required scopes such as aws.cognito.signin.user.admin for GetUser.

conventions · 0/8 published

Publish these signals → /publishing