All skills
aws avatar

/aws-auth

@21be518

Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries. Covers sign-up/sign-in flows and the login page (Cognito-hosted UI / managed login), MFA, password policies, OAuth 2.0 / OIDC flows (auth-code + PKCE, client credentials), social/SAML federation, tokens (ID/access/refresh, rotation, revocation, storage), Cognito Lambda triggers, identity pools (temp AWS creds), and gating API Gateway (or ALB) routes to signed-in users via Cognito/JWT authorizers. Applies when adding a login or sign-up page, configuring a user pool or app client, choosing user pool vs identity pool, wiring social/SAML, refreshing tokens, requiring sign-in on an API Gateway or ALB, or debugging redirect_uri/token/MFA/CORS/federation errors. Does NOT cover Amplify Gen2 backend definitions (defineAuth, npx ampx → aws-amplify), IAM/STS/Identity Center (→ aws-iam), or API Gateway/Lambda resource config beyond the authorizer (→ aws-serverless).

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-auth

This session only. Nothing lands on disk.

referencesidentity-pools.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Identity Pools (Federated Identities)

Overview

An identity pool exchanges a proof of authentication (a user pool token, a third-party OIDC/SAML token, or a social access token) for temporary AWS credentials from AWS STS. Use it only when the client must call AWS services (S3, DynamoDB, etc.) directly. If the client only calls your own backend/API, you do not need an identity pool — send the user pool token to your API instead.

User pool vs identity pool (the core distinction)

  • User pool = authentication. "Who are you?" Issues JWTs.
  • Identity pool = authorization to AWS. "What AWS resources can this identity touch?" Vends temporary AWS credentials via STS.

They compose: the user signs in to the user pool, then the app passes the ID token to the identity pool, which returns temporary AWS credentials.

What each provider passes to an identity pool

The token type is provider-specific — get it wrong and identity resolution fails at configuration time.

Provider Authentication artifact
Cognito user pool ID token
Generic OIDC IdP ID token
Google, Apple (OIDC providers) ID token (id_token)
Facebook, Login with Amazon Access token
SAML 2.0 IdP SAML assertion

Google and Apple are OIDC providers: pass their id_token (Cognito reads it from the accounts.google.com / appleid.apple.com logins key). Only Facebook and Login with Amazon hand the identity pool an access token. Wiring Google (or Apple) with an access token fails identity resolution at config time.

Create and wire an identity pool

aws cognito-identity create-identity-pool \
  --identity-pool-name my_app_identities \
  --no-allow-unauthenticated-identities \
  --cognito-identity-providers ProviderName=cognito-idp.<region>.amazonaws.com/<pool-id>,ClientId=<app-client-id>

aws cognito-identity set-identity-pool-roles \
  --identity-pool-id <identity-pool-id> \
  --roles authenticated=<auth-role-arn>

set-identity-pool-roles replaces the entire roles + RoleMappings structure — it is a full replace, not a merge. To add or change one role mapping on a pool that already has roles or mappings, first read the current state with aws cognito-identity get-identity-pool-roles --identity-pool-id <id>, then re-send all existing roles and RoleMappings plus your addition in a single set-identity-pool-roles call. Sending only the new mapping silently drops the existing default role and every other mapping.

The authenticated role's trust policy MUST scope to this identity pool to prevent confused-deputy attacks where another Cognito identity pool assumes the role. IAM role authoring itself belongs to the aws-iam skill, but this identity-pool-specific condition is not covered there:

"Condition": {
  "StringEquals":         { "cognito-identity.amazonaws.com:aud": "<identity-pool-id>" },
  "ForAnyValue:StringLike": { "cognito-identity.amazonaws.com:amr": "authenticated" }
}

The :aud condition binds the trust to your pool id; :amr = authenticated ensures the guest (unauthenticated) role can never assume the authenticated role. Mirror the pattern with :amr = unauthenticated on the guest role.

Default to --no-allow-unauthenticated-identities. Only enable guest access (--allow-unauthenticated-identities plus an unauthenticated=<guest-role-arn> role) when guest access is genuinely required.

Two credential flows

  • Enhanced (simplified) flow — the recommended default. GetCredentialsForIdentity returns credentials in one step; the pool decides the role.
  • Basic (classic) flow — the app calls GetOpenIdToken then sts:AssumeRoleWithWebIdentity itself, for full control over the assumed role.

Role selection

  • Default role for all authenticated users.
  • Rules-based — choose a role from claims (e.g. a group claim).
  • Role from token (cognito:preferred_role) — the user pool group's associated role. When a user is in multiple groups, the group with the lowest Precedence value wins; see the "User pool groups" section in user-pools.md for create-group / admin-add-user-to-group and the --precedence field.
  • Attributes for access control — map user claims to STS principal tags, then gate access in resource policies with aws:PrincipalTag/.... This is app-level ABAC via Cognito.

Scope the authenticated role tightly (least privilege). The IAM policy language and role authoring itself belong to the aws-iam skill.

Common Errors

Error Cause Fix
NotAuthorizedException / Token is not from a supported provider Provider not registered on the pool, or wrong ClientId Match ProviderName = cognito-idp.<region>.amazonaws.com/<pool-id> and the correct app client id
Access denied after getting credentials Authenticated role policy too narrow, or trust policy wrong Fix the role's permissions (see aws-iam); ensure the role trusts cognito-identity.amazonaws.com with the pool id condition
Guests unexpectedly allowed Unauthenticated identities enabled Disable guest access; remove the unauthenticated role

Related

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides comprehensive guidance for configuring Amazon Cognito and includes security considerations for handling user authentication. While it describes workflows that involve processing external user data, it emphasizes security best practices such as token validation and secure secret handling.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-auth