Amazon Cognito
Amazon Cognito is an AWS service that provides authentication, authorization, and user management for web and mobile applications. It supports OAuth2, OIDC, SAML federation, and social identity providers. Cognito has two main components: User Pools for user authentication and app integration, and Federated Identities for granting temporary AWS credentials to authenticated users. It includes multi-factor authentication, advanced security features, and customizable authentication flows.
Amazon Cognito publishes 2 APIs on the APIs.io network: Identity Provider and Identity (Federated Identities). Tagged areas include Authentication, Authorization, Identity, Identity Provider, and OAuth2.
The Amazon Cognito catalog on APIs.io includes 2 JSON-LD contexts and 2 Spectral governance rulesets.
Amazon Cognito’s developer surface includes authentication, documentation, getting-started guide, pricing, FAQ, developer console, support, and 12 more developer resources.
API Rating
APIs
Amazon Cognito Identity Provider
Control plane API for managing Cognito user pools, app clients, users, groups, identity providers, and resource servers. Supports user authentication flows including SRP, custom...
Amazon Cognito Identity (Federated Identities)
Federated identity service that issues temporary AWS credentials to authenticated and unauthenticated users from Cognito user pools, social identity providers (Facebook, Google,...
Scroll for all 575
GraphQL
Amazon Cognito GraphQL API
GRAPHQLPricing Plans
Rate Limits
FinOps
Aws Cognito Finops
FINOPSFeatures
Fully managed user directories with sign-up, sign-in, and user profile management.
Standards-based OAuth2 authorization server and OpenID Connect identity provider for apps.
Integrate enterprise identity providers via SAML 2.0 for single sign-on.
Sign in with Google, Facebook, Apple, and Amazon without custom backend code.
Built-in MFA with SMS, TOTP, and email verification options.
Lambda triggers for custom authentication challenges, pre-signup validation, and post-confirmation.
Risk-based adaptive authentication with compromised credential detection and device tracking.
Grant temporary AWS credentials to users authenticated via user pools or social providers.
Pre-built customizable sign-in/sign-up pages with OAuth2 endpoint support.
Attribute-based access control with group-based IAM role assignment.
Use Cases
Add user registration, login, and session management to web and mobile applications.
Connect enterprise SAML identity providers for single sign-on to AWS-hosted applications.
Use Cognito JWT tokens to authorize access to API Gateway, AppSync, and custom APIs.
Manage consumer user accounts with self-service registration and profile management.
Issue scoped AWS credentials to authenticated users for direct service access.
Semantic Vocabularies
API Governance Rules
JSON Structure
Cognito Identity Get Open Id Token For Developer Identity Input Structure
5 properties
JSON STRUCTURECognito Identity Get Open Id Token For Developer Identity Response Structure
2 properties
JSON STRUCTURECognito Identity Invalid Identity Pool Configuration Exception Structure
0 properties
JSON STRUCTURECognito Idp Admin Create User Unused Account Validity Days Type Structure
0 properties
JSON STRUCTURECognito Idp Attributes Require Verification Before Update Type Structure
0 properties
JSON STRUCTUREExample Payloads
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API