Amazon Cognito #X Amz Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken API

The #X Amz Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken API from Amazon Cognito — 1 operation(s) for #x amz target=awscognitoidentityproviderservice.associatesoftwaretoken.

OpenAPI Specification

aws-cognito-x-amz-target-awscognitoidentityproviderservice-associatesoftwaretoken-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  version: 2014-06-30
  x-release: v4
  title: 'Amazon Cognito Identity #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AddCustomAttributes #X Amz Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken API'
  description: <fullname>Amazon Cognito Federated Identities</fullname> <p>Amazon Cognito Federated Identities is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. It uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.</p> <p>Using Amazon Cognito Federated Identities, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon) or an Amazon Cognito user pool, and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.</p> <p>For a description of the authentication flow from the Amazon Cognito Developer Guide see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/authentication-flow.html">Authentication Flow</a>.</p> <p>For more information see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-identity.html">Amazon Cognito Federated Identities</a>.</p>
  x-logo:
    url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: cognito-identity
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/cognito-identity-2014-06-30.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
      version: 1.0.0
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://cognito-identity.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity multi-region endpoint
- url: https://cognito-identity.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon Cognito Identity multi-region endpoint
- url: http://cognito-identity.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia)
- url: https://cognito-identity.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon Cognito Identity endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken'
paths:
  /#X-Amz-Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken:
    parameters:
    - $ref: '#/components/parameters/X-Amz-Content-Sha256'
    - $ref: '#/components/parameters/X-Amz-Date'
    - $ref: '#/components/parameters/X-Amz-Algorithm'
    - $ref: '#/components/parameters/X-Amz-Credential'
    - $ref: '#/components/parameters/X-Amz-Security-Token'
    - $ref: '#/components/parameters/X-Amz-Signature'
    - $ref: '#/components/parameters/X-Amz-SignedHeaders'
    post:
      operationId: AssociateSoftwareToken
      description: <p>Begins setup of time-based one-time password (TOTP) multi-factor authentication (MFA) for a user, with a unique private key that Amazon Cognito generates and returns in the API response. You can authorize an <code>AssociateSoftwareToken</code> request with either the user's access token, or a session string from a challenge response that you received from Amazon Cognito.</p> <note> <p>Amazon Cognito disassociates an existing software token when you verify the new token in a <a href="https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API_VerifySoftwareToken.html"> VerifySoftwareToken</a> API request. If you don't verify the software token and your user pool doesn't require MFA, the user can then authenticate with user name and password credentials alone. If your user pool requires TOTP MFA, Amazon Cognito generates an <code>MFA_SETUP</code> or <code>SOFTWARE_TOKEN_SETUP</code> challenge each time your user signs. Complete setup with <code>AssociateSoftwareToken</code> and <code>VerifySoftwareToken</code>.</p> <p>After you set up software token MFA for your user, Amazon Cognito generates a <code>SOFTWARE_TOKEN_MFA</code> challenge when they authenticate. Respond to this challenge with your user's TOTP.</p> </note>
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssociateSoftwareTokenResponse'
              examples:
                AssociateSoftwareToken200Example:
                  summary: Default AssociateSoftwareToken 200 response
                  x-microcks-default: true
                  value:
                    SecretCode: example-value
                    Session: example-value
        '480':
          description: ConcurrentModificationException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConcurrentModificationException'
              examples:
                AssociateSoftwareToken480Example:
                  summary: Default AssociateSoftwareToken 480 response
                  x-microcks-default: true
                  value: example
        '481':
          description: InvalidParameterException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidParameterException'
              examples:
                AssociateSoftwareToken481Example:
                  summary: Default AssociateSoftwareToken 481 response
                  x-microcks-default: true
                  value: example
        '482':
          description: NotAuthorizedException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotAuthorizedException'
              examples:
                AssociateSoftwareToken482Example:
                  summary: Default AssociateSoftwareToken 482 response
                  x-microcks-default: true
                  value: example
        '483':
          description: ResourceNotFoundException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceNotFoundException'
              examples:
                AssociateSoftwareToken483Example:
                  summary: Default AssociateSoftwareToken 483 response
                  x-microcks-default: true
                  value: example
        '484':
          description: InternalErrorException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalErrorException'
              examples:
                AssociateSoftwareToken484Example:
                  summary: Default AssociateSoftwareToken 484 response
                  x-microcks-default: true
                  value: example
        '485':
          description: SoftwareTokenMFANotFoundException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SoftwareTokenMFANotFoundException'
              examples:
                AssociateSoftwareToken485Example:
                  summary: Default AssociateSoftwareToken 485 response
                  x-microcks-default: true
                  value: example
        '486':
          description: ForbiddenException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenException'
              examples:
                AssociateSoftwareToken486Example:
                  summary: Default AssociateSoftwareToken 486 response
                  x-microcks-default: true
                  value: example
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AssociateSoftwareTokenRequest'
            examples:
              AssociateSoftwareTokenRequestExample:
                summary: Default AssociateSoftwareToken request
                x-microcks-default: true
                value:
                  AccessToken: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
                  Session: example-value
      parameters:
      - name: X-Amz-Target
        in: header
        required: true
        schema:
          type: string
          enum:
          - AWSCognitoIdentityProviderService.AssociateSoftwareToken
      summary: Amazon Cognito Associate Software Token
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
      tags:
      - '#X Amz Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken'
components:
  schemas:
    ResourceNotFoundException: {}
    SessionType:
      type: string
      minLength: 20
      maxLength: 2048
    AssociateSoftwareTokenRequest:
      type: object
      title: AssociateSoftwareTokenRequest
      properties:
        AccessToken:
          allOf:
          - $ref: '#/components/schemas/TokenModelType'
          - description: A valid access token that Amazon Cognito issued to the user whose software token you want to generate.
        Session:
          allOf:
          - $ref: '#/components/schemas/SessionType'
          - description: The session that should be passed both ways in challenge-response calls to the service. This allows authentication of the user as part of the MFA setup process.
    InvalidParameterException: {}
    InternalErrorException: {}
    SoftwareTokenMFANotFoundException: {}
    NotAuthorizedException: {}
    AssociateSoftwareTokenResponse:
      type: object
      properties:
        SecretCode:
          allOf:
          - $ref: '#/components/schemas/SecretCodeType'
          - description: A unique generated shared secret code that is used in the TOTP algorithm to generate a one-time code.
        Session:
          allOf:
          - $ref: '#/components/schemas/SessionType'
          - description: The session that should be passed both ways in challenge-response calls to the service. This allows authentication of the user as part of the MFA setup process.
    TokenModelType:
      type: string
      pattern: '[A-Za-z0-9-_=.]+'
      format: password
    ConcurrentModificationException: {}
    ForbiddenException: {}
    SecretCodeType:
      type: string
      pattern: '[A-Za-z0-9]+'
      minLength: 16
      format: password
  parameters:
    X-Amz-Credential:
      name: X-Amz-Credential
      in: header
      schema:
        type: string
      required: false
    X-Amz-Date:
      name: X-Amz-Date
      in: header
      schema:
        type: string
      required: false
    X-Amz-Signature:
      name: X-Amz-Signature
      in: header
      schema:
        type: string
      required: false
    X-Amz-Algorithm:
      name: X-Amz-Algorithm
      in: header
      schema:
        type: string
      required: false
    X-Amz-Security-Token:
      name: X-Amz-Security-Token
      in: header
      schema:
        type: string
      required: false
    X-Amz-SignedHeaders:
      name: X-Amz-SignedHeaders
      in: header
      schema:
        type: string
      required: false
    X-Amz-Content-Sha256:
      name: X-Amz-Content-Sha256
      in: header
      schema:
        type: string
      required: false
  securitySchemes:
    hmac:
      type: apiKey
      name: Authorization
      in: header
      description: Amazon Signature authorization v4
      x-amazon-apigateway-authtype: awsSigv4
externalDocs:
  description: Amazon Web Services documentation
  url: https://docs.aws.amazon.com/cognito-identity/
x-hasEquivalentPaths: true