Asterrr's Handbook

Customer authentication

Adding sign-in, federation and API authorization to an existing customer-facing app with Cognito user pools, identity pools, ALB and API Gateway authorizers.

Exam tasks: 3.2 (determine a strategy to improve security: authentication and authorization for applications)

The decision: does the app need to know who the user is (a user pool issuing tokens), or does the user's device need AWS credentials to call AWS services directly (an identity pool)? Then: where do you check the token (ALB, API Gateway or the app)?

This page is about customers and app users. For employees signing in to AWS, see federation.

User pool or identity pool?

User poolIdentity pool
What it isA user directory and OIDC identity providerA broker that swaps an identity token for temporary AWS credentials
OutputID, access and refresh tokens (JWTs)STS credentials for an IAM role
Sign-in sourcesIts own users, plus social (Google, Apple, Facebook, Amazon), SAML and OIDC providersUser pools, social providers, SAML, OIDC, your own auth (developer authenticated), or none (guest)
Used to callYour APIs, through ALB or API GatewayAWS services directly: S3, DynamoDB, IoT, Kinesis
AuthorizationGroups and custom claims in tokensIAM roles, rule-based role mapping, principal tags for ABAC

Credentials in a mobile app

"A mobile app uploads photos straight to S3 without embedding keys" points to an identity pool that hands out a role scoped to the user's own prefix, for example with the cognito-identity.amazonaws.com:sub policy variable.

User pools

  • Sign-up and sign-in, email and phone verification, password policies, MFA (SMS, TOTP), and passwordless options (passkeys, one-time codes) on the Essentials and Plus feature plans.
  • Managed login is the ready-made sign-in UI on a Cognito or custom domain. It handles OAuth 2.0 flows and the redirects to social, SAML and OIDC providers, so you don't build those screens.
  • Federation for business customers: add each customer's SAML or OIDC IdP to the user pool. Users are matched to the right IdP by email domain, and the app still receives one kind of token.
  • Lambda triggers customize flows: pre sign-up checks, custom claims (pre token generation), and user migration, which moves users from an old user store the first time they sign in.
  • Threat protection (Plus plan) detects compromised credentials and risky sign-ins and can require MFA or block.

Legacy: use Managed login instead

The older hosted UI is still available as the "classic" hosted UI. New user pools use managed login, which supports branding without custom CSS.

Migrating an existing user base

"Move users from the legacy database without forcing a password reset" points to the user migration Lambda trigger. A bulk CSV import can't bring passwords, so imported users must reset them.

Checking tokens at the front door

Front doorOptionsWhat to know
ALBauthenticate-cognito or authenticate-oidc listener rule actionHTTPS listeners only. ALB runs the login redirect and passes user claims to targets in headers. Good for adding login to an existing web app with no code change
API Gateway REST APICognito user pool authorizer, Lambda authorizer (token or request), IAM (SigV4)Cognito authorizer validates the JWT with no code. Lambda authorizer handles custom tokens or third-party IdPs, with caching
API Gateway HTTP APIJWT authorizer, Lambda authorizer, IAMJWT authorizer works with any OIDC issuer, including Cognito
App codeVerify JWT signature against the user pool's JWKSMost flexible, most work

API keys are not authentication

API Gateway API keys identify a client for usage plans and throttling. They aren't a secure way to authorize users. Use Cognito, Lambda or IAM authorizers for that.

IAM auth for public users

IAM (SigV4) authorization means the caller signs with AWS credentials. For end users that only works if an identity pool gives them credentials first. For a plain web or mobile app talking to your API, a Cognito authorizer is simpler.

Fine-grained authorization

Tokens say who the user is. Deciding "can this user edit booking 4471?" is a separate step.

  • Amazon Verified Permissions stores policies written in Cedar and evaluates them per request. It can use a Cognito user pool as its identity source and can protect API Gateway APIs through a generated Lambda authorizer.
  • Pick it when authorization logic is scattered across services and the team wants one place to change and audit rules.

Scenarios

Scenario
A hotel chain has an internal web app on EC2 behind an Application Load Balancer. It now wants partner travel agents to sign in with their own companies' SAML identity providers before reaching the app, without changing the application code. What should the architect do?
Scenario · choose 2
A fitness app lets users record workout videos on their phones and upload them to S3. Users sign in with Apple or Google. Each user must only be able to write to their own folder, and no long-lived credentials may be on the device. Which TWO components should the architect use?
Scenario
An e-commerce company is moving 2 million customers from a self-managed user database to Cognito. The business doesn't want customers to reset passwords, and the old database will stay online during a 6-month transition. What should the architect use?

Further reading

On this page