Amazon Cognito Amazon Cognito Identity API

The Amazon Cognito Identity API from Amazon Cognito — 23 operation(s) for amazon cognito identity.

Operations 23

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

POST /#X-Amz-Target=AWSCognitoIdentityService.CreateIdentityPool Create an identity pool for federated users · Amazon Cognito Create Identity Pool #
Ask an LLM
“How do I set up a new Cognito identity pool so my app users can get AWS credentials?”
“Can a new identity pool allow guest access for unauthenticated users?”
Tell an agent
Create an identity pool named {name} that does not allow unauthenticated identities.
Create identity pool {name} with guest access set to {allow_guests} and developer provider {developer_provider}.
POST /#X-Amz-Target=AWSCognitoIdentityService.DeleteIdentities Delete identities from an identity pool · Amazon Cognito Delete Identities #
Ask an LLM
“How many identities can I remove from an identity pool in one call?”
“Can I bulk delete a batch of federated identity IDs I no longer need?”
Tell an agent destructive · confirm first
Delete the identities {identity_ids} from their identity pool.
Remove this batch of up to 60 federated identities: {identity_ids}.
POST /#X-Amz-Target=AWSCognitoIdentityService.DeleteIdentityPool Delete an identity pool · Amazon Cognito Delete Identity Pool #
Ask an LLM
“How do I permanently remove a Cognito identity pool I am no longer using?”
“What happens to the identities in an identity pool when the pool itself is deleted?”
Tell an agent destructive · confirm first
Delete identity pool {identity_pool_id}.
Tear down the whole identity pool {identity_pool_id} and everything in it.
POST /#X-Amz-Target=AWSCognitoIdentityService.DescribeIdentity Look up details of a single identity · Amazon Cognito Describe Identity #
Ask an LLM
“How can I see which logins are linked to a specific federated identity ID?”
“When was a given Cognito identity created and last modified?”
Tell an agent
Show me the details and linked logins for identity {identity_id}.
Describe the federated identity {identity_id}.
POST /#X-Amz-Target=AWSCognitoIdentityService.DescribeIdentityPool Get an identity pool's configuration · Amazon Cognito Describe Identity Pool #
Ask an LLM
“How do I check which login providers and guest access settings an identity pool has?”
“Can I see the name and supported providers of an existing identity pool?”
Tell an agent
Describe identity pool {identity_pool_id}.
Show the configured providers and unauthenticated access setting for pool {identity_pool_id}.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetCredentialsForIdentity Get temporary AWS credentials for an identity · Amazon Cognito Get Credentials for Identity #
Ask an LLM
“How does a signed-in app user exchange their Cognito identity for temporary AWS credentials?”
“Can I request credentials for an identity under a specific custom IAM role?”
Tell an agent
Get temporary AWS credentials for identity {identity_id}.
Fetch AWS credentials for identity {identity_id} assuming role {role_arn}.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetId Generate or retrieve a Cognito identity ID · Amazon Cognito Get Id #
Ask an LLM
“How does my app obtain a Cognito identity ID for a user in my identity pool?”
“What happens if I pass several logins when requesting an identity ID?”
Tell an agent
Get or create a Cognito identity ID in pool {identity_pool_id}.
Generate an identity ID in pool {identity_pool_id} for logins {logins}.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetIdentityPoolRoles Get the IAM roles assigned to an identity pool · Amazon Cognito Get Identity Pool Roles #
Ask an LLM
“Which IAM roles do authenticated and guest users in my identity pool assume?”
“How can I review the role mapping rules on an identity pool?”
Tell an agent
Show the roles and role mappings for identity pool {identity_pool_id}.
List which IAM roles pool {identity_pool_id} hands out.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetOpenIdToken Get an OpenID token for an identity · Amazon Cognito Get Open Id Token #
Ask an LLM
“How do I get an OpenID Connect token for an existing Cognito identity?”
“Can I fetch an OIDC token for an identity using its linked login tokens?”
Tell an agent
Get an OpenID token for identity {identity_id}.
Issue an OpenID Connect token for identity {identity_id} using logins {logins}.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetOpenIdTokenForDeveloperIdentity Get an OpenID token for a developer-authenticated user · Amazon Cognito Get Open Id Token for Developer Identity #
Ask an LLM
“How does my own backend auth system register a user and get them a Cognito OpenID token?”
“Can I set how long the token lasts when issuing it for a developer-authenticated identity?”
Tell an agent
Get an OpenID token in pool {identity_pool_id} for my backend user with logins {logins}.
Register developer user logins {logins} in pool {identity_pool_id} and issue a token valid for {duration} seconds.
POST /#X-Amz-Target=AWSCognitoIdentityService.GetPrincipalTagAttributeMap View principal tag mappings for a provider · Amazon Cognito Get Principal Tag Attribute Map #
Ask an LLM
“Which user attributes are mapped to principal tags for an identity provider in my pool?”
“How can I check the attribute-to-session-tag mapping used for access control in an identity pool?”
Tell an agent
Show the principal tag mappings for provider {provider} in identity pool {identity_pool_id}.
Get the attribute-to-tag map that pool {identity_pool_id} uses for {provider}.
POST /#X-Amz-Target=AWSCognitoIdentityService.ListIdentities List the identities in an identity pool · Amazon Cognito List Identities #
Ask an LLM
“How do I see all the identities that exist in one identity pool?”
“Can I hide disabled identities when listing a pool's identities?”
Tell an agent
List up to {max} identities in identity pool {identity_pool_id}.
List the enabled identities in pool {identity_pool_id}, {max} per page, hiding disabled ones: {hide_disabled}.
POST /#X-Amz-Target=AWSCognitoIdentityService.ListIdentityPools List identity pools in the account · Amazon Cognito List Identity Pools #
Ask an LLM
“What identity pools exist in my AWS account?”
“Can I page through all my Cognito identity pools a few at a time?”
Tell an agent
List my identity pools, {max} at a time.
Show the next page of identity pools after token {next_token}.
POST /#X-Amz-Target=AWSCognitoIdentityService.ListTagsForResource List tags on an identity pool · Amazon Cognito List Tags for Resource #
Ask an LLM
“How do I see the cost allocation tags assigned to an identity pool?”
“What tags are currently on my federated identity pool?”
Tell an agent
List the tags on identity pool {resource_arn}.
Show me every tag key and value attached to pool ARN {resource_arn}.
POST /#X-Amz-Target=AWSCognitoIdentityService.LookupDeveloperIdentity Find the identity for a developer user identifier · Amazon Cognito Lookup Developer Identity #
Ask an LLM
“How do I find which Cognito identity ID belongs to a user ID from my own backend?”
“Can I look up all developer user identifiers linked to one identity ID?”
Tell an agent
Look up the identity ID for developer user {developer_user} in pool {identity_pool_id}.
Find the developer user identifiers linked to identity {identity_id} in pool {identity_pool_id}.
POST /#X-Amz-Target=AWSCognitoIdentityService.MergeDeveloperIdentities Merge two developer-authenticated users · Amazon Cognito Merge Developer Identities #
Ask an LLM
“How can I combine two developer-authenticated users into a single Cognito identity?”
“Can I merge users from my backend login who ended up with different identity IDs?”
Tell an agent
Merge developer user {source} into {destination} for provider {provider} in pool {identity_pool_id}.
Fold backend user {source} into user {destination}'s identity in pool {identity_pool_id} under provider {provider}.
POST /#X-Amz-Target=AWSCognitoIdentityService.SetIdentityPoolRoles Set the IAM roles for an identity pool · Amazon Cognito Set Identity Pool Roles #
Ask an LLM
“How do I assign authenticated and unauthenticated IAM roles to an identity pool?”
“Can I add rules that map users to different roles based on their token claims?”
Tell an agent
Set the roles for identity pool {identity_pool_id} to {roles}.
Assign roles {roles} and role mappings {mappings} to pool {identity_pool_id}.
POST /#X-Amz-Target=AWSCognitoIdentityService.SetPrincipalTagAttributeMap Map user attributes to principal tags · Amazon Cognito Set Principal Tag Attribute Map #
Ask an LLM
“How do I map user attributes from a provider into session tags for attribute-based access control?”
“Can I go back to the default principal tag mappings for a provider in my identity pool?”
Tell an agent
Set principal tag mappings {tags} for provider {provider} in identity pool {identity_pool_id}.
Switch provider {provider} in pool {identity_pool_id} to default tag mappings: {use_defaults}.
POST /#X-Amz-Target=AWSCognitoIdentityService.TagResource Tag an identity pool · Amazon Cognito Tag Resource #
Ask an LLM
“How do I add cost allocation tags to an identity pool?”
“Can I label a federated identity pool with key-value tags for billing?”
Tell an agent
Add tags {tags} to identity pool {resource_arn}.
Tag pool ARN {resource_arn} with {tags}.
POST /#X-Amz-Target=AWSCognitoIdentityService.UnlinkDeveloperIdentity Unlink a developer user from an identity · Amazon Cognito Unlink Developer Identity #
Ask an LLM
“How do I detach a user ID from my own backend from an existing Cognito identity?”
“What happens to a developer-authenticated user after it is unlinked from its identity?”
Tell an agent destructive · confirm first
Unlink developer user {developer_user} of provider {provider} from identity {identity_id} in pool {identity_pool_id}.
Detach backend user {developer_user} from identity {identity_id} (pool {identity_pool_id}, provider {provider}).
POST /#X-Amz-Target=AWSCognitoIdentityService.UnlinkIdentity Unlink a federated login from an identity · Amazon Cognito Unlink Identity #
Ask an LLM
“How do I remove a social or federated login from a user's Cognito identity?”
“What happens if I unlink the last login on an identity?”
Tell an agent destructive · confirm first
Unlink logins {logins_to_remove} from identity {identity_id} using current logins {logins}.
Remove provider {logins_to_remove} from identity {identity_id}, authenticating with {logins}.
POST /#X-Amz-Target=AWSCognitoIdentityService.UntagResource Remove tags from an identity pool · Amazon Cognito Untag Resource #
Ask an LLM
“How do I delete tags I no longer want on an identity pool?”
“Can I strip specific tag keys off a federated identity pool?”
Tell an agent destructive · confirm first
Remove tag keys {tag_keys} from identity pool {resource_arn}.
Untag pool ARN {resource_arn}, dropping keys {tag_keys}.
POST /#X-Amz-Target=AWSCognitoIdentityService.UpdateIdentityPool Update an identity pool's settings · Amazon Cognito Update Identity Pool #
Ask an LLM
“How do I change the login providers or guest access on an existing identity pool?”
“Can I rename an identity pool after it has been created?”
Tell an agent
Update identity pool {identity_pool_id}: rename it to {name} and set guest access to {allow_guests}.
Change the supported login providers on existing pool {identity_pool_id} ({name}, guest access {allow_guests}) to {providers}.

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/amazon-cognito-amazon-cognito-identity-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

amazon-cognito-amazon-cognito-identity-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: '2014-06-30'
  x-release: v4
  title: Amazon Cognito Identity API
  description: 'Amazon Cognito Federated Identities

    Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments.'
  x-logo:
    url: https://twitter.com/awscloud/profile_image?size=original
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: cognito-identity
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
      version: 1.0.0
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://cognito-identity.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity multi-region endpoint
- url: https://cognito-identity.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity multi-region endpoint
- url: http://cognito-identity.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia)
- url: https://cognito-identity.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:


# --- truncated at 32 KB (144 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/amazon-cognito/refs/heads/main/openapi/amazon-cognito-amazon-cognito-identity-api-openapi.yml