A

AWS CLI cognito-idp

CLI discovered

Details
Command
aws cognito-idp
Docs
https://docs.aws.amazon.com/cli/latest/reference/cognito-idp/
Authentication
AWS IAM credentials for Signature Version 4 signing aws_sigv4 discovered Get keys ↗
$ aws configure

Create or use an AWS IAM principal in the AWS IAM console and obtain access key credentials, or use temporary credentials from STS. Grant the principal Cognito user-pool permissions as needed. Requests are signed with AWS Signature Version 4 as described in Signing AWS API requests. For CLI use, configure them with aws configure or another supported AWS credential source.

Cognito user access token bearer discovered Get token ↗
$ aws cognito-idp get-user --access-token <token>

Create a user pool app client in the Amazon Cognito console, then authenticate a user through Cognito sign-in flows such as InitiateAuth or the user-pool domain OAuth 2.0 endpoints. Use the resulting access token for token-authorized self-service API operations; it must include any required scopes such as aws.cognito.signin.user.admin for GetUser.

Cognito user pool app client credentials compound discovered Get key ↗
$ aws cognito-idp initiate-auth --client-id <client_id> ...

In the Amazon Cognito console, open a user pool and create or select an app client under application settings. This yields a client_id; confidential clients can also have a client_secret. Use the app client in public API flows like InitiateAuth, and on the user-pool domain /oauth2/token endpoint with client_secret_basic or client_secret_post when a secret exists.