Amazon Cognito #X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration API

The #X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration API from Amazon Cognito — 1 operation(s) for #x amz target=awscognitoidentityproviderservice.setriskconfiguration.

Business capability
Identity & Access Management BC-620.20

Operations 1

POST /#X-Amz-Target=AWSCognitoIdentityProviderService.SetRiskConfiguration Amazon Cognito Set Risk Configuration #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/amazon-cognito-x-amz-target-awscognitoidentityproviderservice-setriskconfiguration-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

amazon-cognito-x-amz-target-awscognitoidentityproviderservice-setriskconfiguration-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: '2016-04-18'
  x-release: v4
  title: 'Amazon Cognito Identity Provider #X Amz…'
  description: With the Amazon Cognito user pools API, you can set up user pools and app clients, and authenticate users.
  x-logo:
    url: https://twitter.com/awscloud/profile_image?size=original
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: cognito-idp
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-idp-2016-04-18.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
      version: 1.0.0
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://cognito-idp.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity Provider multi-region endpoint
- url: https://cognito-idp.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity Provider multi-region endpoint
- url: http://cognito-idp.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity Provider endpoint for China (Beijing) and China (Ningxia)
- url: https://cognito-idp.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity Provider endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration'
paths:
  /#X-Amz-Target=AWSCognitoIdentityProviderService.SetRiskConfiguration:
    parameters:
    - $ref: '#/components/parameters/X-Amz-Content-Sha256'
    - $ref: '#/components/parameters/X-Amz-Date'
    - $ref: '#/components/parameters/X-Amz-Algorithm'
    - $ref: '#/components/parameters/X-Amz-Credential'
    - $ref: '#/components/parameters/X-Amz-Security-Token'
    - $ref: '#/components/parameters/X-Amz-Signature'
    - $ref: '#/components/parameters/X-Amz-SignedHeaders'
    post:
      operationId: SetRiskConfiguration
      description: 'Configures actions on detected risks. To delete the risk configuration for UserPoolId or ClientId, pass null values for all four configuration types.


        To activate Amazon Cognito advanced security features, update the user pool to include the UserPoolAddOns keyAdvancedSecurityMode.'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SetRiskConfigurationResponse'
              examples:
                SetRiskConfiguration200Example:
                  summary: Default SetRiskConfiguration 200 response
                  x-microcks-default: true
                  value:
                    RiskConfiguration: example
        '480':
          description: ResourceNotFoundException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceNotFoundException'
              examples:
                SetRiskConfiguration480Example:
                  summary: Default SetRiskConfiguration 480 response
                  x-microcks-default: true
                  value: example
        '481':
          description: InvalidParameterException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidParameterException'
              examples:
                SetRiskConfiguration481Example:
                  summary: Default SetRiskConfiguration 481 response
                  x-microcks-default: true
                  value: example
        '482':
          description: TooManyRequestsException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TooManyRequestsException'
              examples:
                SetRiskConfiguration482Example:
                  summary: Default SetRiskConfiguration 482 response
                  x-microcks-default: true
                  value: example
        '483':
          description: NotAuthorizedException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotAuthorizedException'
              examples:
                SetRiskConfiguration483Example:
                  summary: Default SetRiskConfiguration 483 response
                  x-microcks-default: true
                  value: example
        '484':
          description: UserPoolAddOnNotEnabledException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserPoolAddOnNotEnabledException'
              examples:
                SetRiskConfiguration484Example:
                  summary: Default SetRiskConfiguration 484 response
                  x-microcks-default: true
                  value: example
        '485':
          description: CodeDeliveryFailureException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CodeDeliveryFailureException'
              examples:
                SetRiskConfiguration485Example:
                  summary: Default SetRiskConfiguration 485 response
                  x-microcks-default: true
                  value: example
        '486':
          description: InvalidEmailRoleAccessPolicyException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidEmailRoleAccessPolicyException'
              examples:
                SetRiskConfiguration486Example:
                  summary: Default SetRiskConfiguration 486 response
                  x-microcks-default: true
                  value: example
        '487':
          description: InternalErrorException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalErrorException'
              examples:
                SetRiskConfiguration487Example:
                  summary: Default SetRiskConfiguration 487 response
                  x-microcks-default: true
                  value: example
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetRiskConfigurationRequest'
      parameters:
      - name: X-Amz-Target
        in: header
        required: true
        schema:
          type: string
          enum:
          - AWSCognitoIdentityProviderService.SetRiskConfiguration
      summary: Amazon Cognito Set Risk Configuration
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
      tags:
      - '#X Amz Target=AWSCognitoIdentityProviderService.SetRiskConfiguration'
components:
  parameters:
    X-Amz-Signature:
      name: X-Amz-Signature
      in: header
      schema:
        type: string
      required: false
    X-Amz-Security-Token:
      name: X-Amz-Security-Token
      in: header
      schema:
        type: string
      required: false
    X-Amz-Algorithm:
      name: X-Amz-Algorithm
      in: header
      schema:
        type: string
      required: false
    X-Amz-SignedHeaders:
      name: X-Amz-SignedHeaders
      in: header
      schema:
        type: string
      required: false
    X-Amz-Content-Sha256:
      name: X-Amz-Content-Sha256
      in: header
      schema:
        type: string
      required: false
    X-Amz-Date:
      name: X-Amz-Date
      in: header
      schema:
        type: string
      required: false
    X-Amz-Credential:
      name: X-Amz-Credential
      in: header
      schema:
        type: string
      required: false
  schemas:
    AccountTakeoverActionsType:
      type: object
      properties:
        LowAction:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverActionType'
          - description: Action to take for a low risk.
        MediumAction:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverActionType'
          - description: Action to take for a medium risk.
        HighAction:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverActionType'
          - description: Action to take for a high risk.
      description: Account takeover actions type.
    UserPoolAddOnNotEnabledException: {}
    RiskExceptionConfigurationType:
      type: object
      properties:
        BlockedIPRangeList:
          allOf:
          - $ref: '#/components/schemas/BlockedIPRangeListType'
          - description: Overrides the risk decision to always block the pre-authentication requests. The IP range is in CIDR notation, a compact representation of an IP address and its routing prefix.
        SkippedIPRangeList:
          allOf:
          - $ref: '#/components/schemas/SkippedIPRangeListType'
          - description: Risk detection isn't performed on the IP addresses in this range list. The IP range is in CIDR notation.
      description: The type of the configuration to override the risk decision.
    NotifyEmailType:
      type: object
      required:
      - Subject
      properties:
        Subject:
          allOf:
          - $ref: '#/components/schemas/EmailNotificationSubjectType'
          - description: The email subject.
        HtmlBody:
          allOf:
          - $ref: '#/components/schemas/EmailNotificationBodyType'
          - description: The email HTML body.
        TextBody:
          allOf:
          - $ref: '#/components/schemas/EmailNotificationBodyType'
          - description: The email text body.
      description: The notify email type.
    EventFiltersType:
      type: array
      items:
        $ref: '#/components/schemas/EventFilterType'
    ClientIdType:
      type: string
      pattern: '[\w+]+'
      minLength: 1
      maxLength: 128
      format: password
    DateType:
      type: string
      format: date-time
    BlockedIPRangeListType:
      type: array
      items:
        $ref: '#/components/schemas/StringType'
      maxItems: 200
    AccountTakeoverRiskConfigurationType:
      type: object
      required:
      - Actions
      properties:
        NotifyConfiguration:
          allOf:
          - $ref: '#/components/schemas/NotifyConfigurationType'
          - description: The notify configuration used to construct email notifications.
        Actions:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverActionsType'
          - description: Account takeover risk configuration actions.
      description: Configuration for mitigation actions and notification for different levels of risk detected for a potential account takeover.
    UserPoolIdType:
      type: string
      pattern: '[\w-]+_[0-9a-zA-Z]+'
      minLength: 1
      maxLength: 55
    AccountTakeoverEventActionType:
      type: string
      enum:
      - BLOCK
      - MFA_IF_CONFIGURED
      - MFA_REQUIRED
      - NO_ACTION
    SkippedIPRangeListType:
      type: array
      items:
        $ref: '#/components/schemas/StringType'
      maxItems: 200
    RiskConfigurationType:
      type: object
      properties:
        UserPoolId:
          allOf:
          - $ref: '#/components/schemas/UserPoolIdType'
          - description: The user pool ID.
        ClientId:
          allOf:
          - $ref: '#/components/schemas/ClientIdType'
          - description: The app client ID.
        CompromisedCredentialsRiskConfiguration:
          allOf:
          - $ref: '#/components/schemas/CompromisedCredentialsRiskConfigurationType'
          - description: The compromised credentials risk configuration object, including the <code>EventFilter</code> and the <code>EventAction</code>.
        AccountTakeoverRiskConfiguration:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverRiskConfigurationType'
          - description: The account takeover risk configuration object, including the <code>NotifyConfiguration</code> object and <code>Actions</code> to take if there is an account takeover.
        RiskExceptionConfiguration:
          allOf:
          - $ref: '#/components/schemas/RiskExceptionConfigurationType'
          - description: The configuration to override the risk decision.
        LastModifiedDate:
          allOf:
          - $ref: '#/components/schemas/DateType'
          - description: The date and time, in <a href="https://www.iso.org/iso-8601-date-and-time-format.html">ISO 8601</a> format, when the item was modified.
      description: The risk configuration type.
    EmailNotificationBodyType:
      type: string
      pattern: '[\p{L}\p{M}\p{S}\p{N}\p{P}\s*]+'
      minLength: 6
      maxLength: 20000
    CodeDeliveryFailureException: {}
    SetRiskConfigurationRequest:
      type: object
      required:
      - UserPoolId
      title: SetRiskConfigurationRequest
      properties:
        UserPoolId:
          allOf:
          - $ref: '#/components/schemas/UserPoolIdType'
          - description: 'The user pool ID. '
        ClientId:
          allOf:
          - $ref: '#/components/schemas/ClientIdType'
          - description: <p>The app client ID. If <code>ClientId</code> is null, then the risk configuration is mapped to <code>userPoolId</code>. When the client ID is null, the same risk configuration is applied to all the clients in the userPool.</p> <p>Otherwise, <code>ClientId</code> is mapped to the client. When the client ID isn't null, the user pool configuration is overridden and the risk configuration for the client is used instead.</p>
        CompromisedCredentialsRiskConfiguration:
          allOf:
          - $ref: '#/components/schemas/CompromisedCredentialsRiskConfigurationType'
          - description: The compromised credentials risk configuration.
        AccountTakeoverRiskConfiguration:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverRiskConfigurationType'
          - description: The account takeover risk configuration.
        RiskExceptionConfiguration:
          allOf:
          - $ref: '#/components/schemas/RiskExceptionConfigurationType'
          - description: The configuration to override the risk decision.
    EventFilterType:
      type: string
      enum:
      - SIGN_IN
      - PASSWORD_CHANGE
      - SIGN_UP
    AccountTakeoverActionType:
      type: object
      required:
      - Notify
      - EventAction
      properties:
        Notify:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverActionNotifyType'
          - description: Flag specifying whether to send a notification.
        EventAction:
          allOf:
          - $ref: '#/components/schemas/AccountTakeoverEventActionType'
          - description: <p>The action to take in response to the account takeover action. Valid values are as follows:</p> <ul> <li> <p> <code>BLOCK</code> Choosing this action will block the request.</p> </li> <li> <p> <code>MFA_IF_CONFIGURED</code> Present an MFA challenge if user has configured it, else allow the request.</p> </li> <li> <p> <code>MFA_REQUIRED</code> Present an MFA challenge if user has configured it, else block the request.</p> </li> <li> <p> <code>NO_ACTION</code> Allow the user to sign in.</p> </li> </ul>
      description: Account takeover action type.
    CompromisedCredentialsActionsType:
      type: object
      required:
      - EventAction
      properties:
        EventAction:
          allOf:
          - $ref: '#/components/schemas/CompromisedCredentialsEventActionType'
          - description: The event action.
      description: The compromised credentials actions type.
    ResourceNotFoundException: {}
    EmailNotificationSubjectType:
      type: string
      pattern: '[\p{L}\p{M}\p{S}\p{N}\p{P}\s]+'
      minLength: 1
      maxLength: 140
    CompromisedCredentialsEventActionType:
      type: string
      enum:
      - BLOCK
      - NO_ACTION
    NotAuthorizedException: {}
    CompromisedCredentialsRiskConfigurationType:
      type: object
      required:
      - Actions
      properties:
        EventFilter:
          allOf:
          - $ref: '#/components/schemas/EventFiltersType'
          - description: Perform the action for these events. The default is to perform all events if no event filter is specified.
        Actions:
          allOf:
          - $ref: '#/components/schemas/CompromisedCredentialsActionsType'
          - description: The compromised credentials risk configuration actions.
      description: The compromised credentials risk configuration type.
    ArnType:
      type: string
      pattern: arn:[\w+=/,.@-]+:[\w+=/,.@-]+:([\w+=/,.@-]*)?:[0-9]+:[\w+=/,.@-]+(:[\w+=/,.@-]+)?(:[\w+=/,.@-]+)?
      minLength: 20
      maxLength: 2048
    AccountTakeoverActionNotifyType:
      type: boolean
    SetRiskConfigurationResponse:
      type: object
      required:
      - RiskConfiguration
      properties:
        RiskConfiguration:
          allOf:
          - $ref: '#/components/schemas/RiskConfigurationType'
          - description: The risk configuration.
    NotifyConfigurationType:
      type: object
      required:
      - SourceArn
      properties:
        From:
          allOf:
          - $ref: '#/components/schemas/StringType'
          - description: The email address that is sending the email. The address must be either individually verified with Amazon Simple Email Service, or from a domain that has been verified with Amazon SES.
        ReplyTo:
          allOf:
          - $ref: '#/components/schemas/StringType'
          - description: The destination to which the receiver of an email should reply to.
        SourceArn:
          allOf:
          - $ref: '#/components/schemas/ArnType'
          - description: The Amazon Resource Name (ARN) of the identity that is associated with the sending authorization policy. This identity permits Amazon Cognito to send for the email address specified in the <code>From</code> parameter.
        BlockEmail:
          allOf:
          - $ref: '#/components/schemas/NotifyEmailType'
          - description: Email template used when a detected risk event is blocked.
        NoActionEmail:
          allOf:
          - $ref: '#/components/schemas/NotifyEmailType'
          - description: The email template used when a detected risk event is allowed.
        MfaEmail:
          allOf:
          - $ref: '#/components/schemas/NotifyEmailType'
          - description: The multi-factor authentication (MFA) email template used when MFA is challenged as part of a detected risk.
      description: The notify configuration type.
    InvalidEmailRoleAccessPolicyException: {}
    TooManyRequestsException: {}
    InternalErrorException: {}
    InvalidParameterException: {}
    StringType:
      type: string
      minLength: 0
      maxLength: 131072
  securitySchemes:
    hmac:
      type: apiKey
      name: Authorization
      in: header
      description: Amazon Signature authorization v4
      x-amazon-apigateway-authtype: awsSigv4
externalDocs:
  description: Amazon Web Services documentation
  url: https://docs.aws.amazon.com/cognito-idp/
x-hasEquivalentPaths: true