AWS - Cognito Federated identities

Viewed 718

I have created a federated identities which contains:

  1. Identity pool ID us-west-2:XXXX-XXXXXXX-XXXX-XXXX-XXXX
  2. User Pool ID us-west-2_XXXXXXXXX
  3. App client ID XXXXXX

When I try with Identity pool ID to connect to: https://cognito-idp.us-west-2.amazonaws.com/us-west-2:XXXX-XXXXXXX-XXXX-XXXX-XXXX/.well-known/jwks.json

I get:

{"message":"1 validation error detected: Value 'us-west-2:XXXX-XXXXXXX-XXXX-XXXX-XXXX' at 'userPoolId' failed to satisfy constraint: Member must satisfy regular expression pattern: [\\w-]+_[0-9a-zA-Z]+"}

If I try with User Pool ID us-west-2_XXXXXXXXX https://cognito-idp.us-west-2.amazonaws.com/us-west-2_xxxxxxxxxxxxxxx/.well-known/jwks.json

{"message":"User pool us-west-2_ does not exist."}

How can I fix this?

2 Answers

If you are trying to know the JWKs of the identity pool then you need to invoke this path /.well-known/jwks_uri. the path /.well-known/jwks.json is only for the user pool.

Please note that this consumes time (my experience 0.9~1.0 sec). So I recommend saving these downloaded keys in the server/lambda in an object (kid: jwk) and verify if the key (corresponds to the token to be validated) exists before calling this URL (by checking the kid of the key for example).

Related